Cookie Policy
Shot Flow · Cookie Policy · v1.0 · Effective 21 July 2026
| Field | Value |
| Operator | CHALET AQUARIUS LTD |
| Company number | 15587263 |
| Registered office | 20 Wenlock Road, London, England, N1 7GU |
| Trading name / brand | Shot Flow |
| Website | https://shot-flow.com |
| Contact email | info@shot-flow.com |
| Support / complaints | info@shot-flow.com (Monday–Friday, 09:00–17:00 UK time, excluding public holidays) |
| Governing law | Laws of England and Wales |
| Document version | v1.0 |
| Effective date | 21 July 2026 |
| Cookie choice: Essential cookies and comparable technologies operate without optional consent where they are strictly necessary for security, checkout, account access or digital delivery. Analytics, advertising and other non-essential technologies are used only where the required consent has been obtained. |
1. Introduction and scope
1.1 Introduction and scope standard. This policy explains cookies and comparable browser or device technologies used on Shot Flow. For introduction and scope, the provision is confined to cookies, local storage, tags, pixels, secure checkout technologies and consent choices and does not enlarge the user’s rights beyond the product description, Order confirmation or applicable law.
1.2 Requests about introduction and scope. For cookies, local storage, tags, pixels, secure checkout technologies and consent choices, safeguards used for introduction and scope protect purchasers, rights holders, payment participants and the service. They may be tightened where a credible security or rights risk exists and relaxed after that risk is resolved.
1.3 Information relevant to introduction and scope. The normal treatment of introduction and scope may be adjusted for technologies strictly necessary for a requested service or secure communications. Any adjustment must remain proportionate and must not remove a right that cannot lawfully be excluded.
1.4 Decision criteria for introduction and scope. Within cookies, local storage, tags, pixels, secure checkout technologies and consent choices, a notice dealing with introduction and scope should identify what happened, the relevant effective time and the practical next step, unless disclosure would compromise security, another person’s rights or a lawful investigation.
2. What cookies and similar technologies are
2.1 What cookies and similar technologies are standard. Cookies, local storage, pixels and server-side identifiers can recognise a session, preserve a choice or measure an interaction. For what cookies and similar technologies are, the provision is confined to cookies, local storage, tags, pixels, secure checkout technologies and consent choices and does not enlarge the user’s rights beyond the product description, Order confirmation or applicable law.
2.2 Decision criteria for what cookies and similar technologies are. Within cookies, local storage, tags, pixels, secure checkout technologies and consent choices, a notice dealing with what cookies and similar technologies are should identify what happened, the relevant effective time and the practical next step, unless disclosure would compromise security, another person’s rights or a lawful investigation.
2.3 Related provisions for what cookies and similar technologies are. Within cookies, local storage, tags, pixels, secure checkout technologies and consent choices, a question or correction about what cookies and similar technologies are may be sent to info@shot-flow.com with enough detail to identify the relevant Order, account or interaction. Full payment credentials and unrelated personal information must not be sent by email.
2.4 Controls for what cookies and similar technologies are. A decision concerning what cookies and similar technologies are may take account of consent records, tag configuration, browser tests, provider documentation and deployment records. The weight assigned to a record depends on reliability, context and any credible contrary material supplied by the user.
2.5 Correction of what cookies and similar technologies are. For cookies, local storage, tags, pixels, secure checkout technologies and consent choices, operational delivery of what cookies and similar technologies are may depend on provider systems and the user’s device or network. A temporary technical limitation does not alter the underlying contractual or statutory position.
3. Why we use these technologies
3.1 Why we use these technologies standard. Technologies support security, account functions, checkout, delivery, preferences, measurement and permitted marketing. For why we use these technologies, the provision is confined to cookies, local storage, tags, pixels, secure checkout technologies and consent choices and does not enlarge the user’s rights beyond the product description, Order confirmation or applicable law.
3.2 How why we use these technologies operates. To administer why we use these technologies, Shot Flow uses a consent interface, script controls, browser storage, provider configuration and periodic inventory checks. Each control is selected for the stated purpose and must not be repurposed for an unrelated objective.
3.3 Outcome for why we use these technologies. The rules on why we use these technologies should be read with the Privacy Policy and applicable electronic-communications rules. Where two provisions address the same event, the more specific operational rule governs that event while mandatory law prevails over both.
4. Cookie categories
4.1 Strictly necessary. These technologies support authentication, security, checkout, fraud prevention, consent storage and delivery of purchased files. Blocking them may prevent the website or Order process from working.
4.2 Functional. These remember optional interface choices such as language, display or saved preferences. They are enabled according to the consent rule that applies in the user’s location.
4.3 Analytics. These help measure aggregate visits, navigation and technical performance. They are not activated before consent where United Kingdom rules require consent.
4.4 Advertising. If introduced, these technologies would measure campaigns or support interest-based advertising and would be disabled until valid consent is recorded.
5. Lawful basis and consent
5.1 Essential operation. A technology may operate without consent only where its sole or principal purpose is strictly necessary to transmit a communication or provide a service expressly requested by the user.
5.2 Optional choice. Non-essential analytics, advertising and comparable tracking remain off until the user makes an affirmative choice where consent is required.
5.3 Withdrawal. Withdrawing consent is as easy as granting it. Withdrawal does not invalidate earlier lawful processing but stops future optional placement or reading.
5.4 Proof of choice. A limited consent record may store the version, categories, time and regional setting necessary to demonstrate and honour the user’s choice.
6. Cookie inventory and example technology
6.1 Cookie inventory and example technology standard. The inventory below identifies the operational classes expected for the current service. For cookie inventory and example technology, the provision is confined to cookies, local storage, tags, pixels, secure checkout technologies and consent choices and does not enlarge the user’s rights beyond the product description, Order confirmation or applicable law.
6.2 Outcome for cookie inventory and example technology. The rules on cookie inventory and example technology should be read with the Privacy Policy and applicable electronic-communications rules. Where two provisions address the same event, the more specific operational rule governs that event while mandatory law prevails over both.
6.3 User duties for cookie inventory and example technology. Within cookies, local storage, tags, pixels, secure checkout technologies and consent choices, when cookie inventory and example technology requires user input, the user must give accurate and current information, use the available account or support route and take reasonable steps within the user’s control. Deliberate circumvention or materially misleading information may change the available outcome.
6.4 Misuse safeguards for cookie inventory and example technology. In applying cookie inventory and example technology to cookies, local storage, tags, pixels, secure checkout technologies and consent choices, if an initial decision relied on incomplete information, the user may submit material new evidence. Shot Flow will reconsider the affected point without requiring repetition of information already held.
6.5 Limits on cookie inventory and example technology. If cookie inventory and example technology cannot be completed as expected, the response may include blocking, deletion, consent refresh, provider reconfiguration or temporary disablement. The response should address the affected Order, account, record or use rather than impose a broader restriction without reason.
7. Third-party cookies and embedded services
7.1 Third-party cookies and embedded services standard. Payment, hosting, content delivery, support or analytics providers may set technologies under their own controls. For third-party cookies and embedded services, the provision is confined to cookies, local storage, tags, pixels, secure checkout technologies and consent choices and does not enlarge the user’s rights beyond the product description, Order confirmation or applicable law.
7.2 Limits on third-party cookies and embedded services. If third-party cookies and embedded services cannot be completed as expected, the response may include blocking, deletion, consent refresh, provider reconfiguration or temporary disablement. The response should address the affected Order, account, record or use rather than impose a broader restriction without reason.
7.3 Correction of third-party cookies and embedded services. For cookies, local storage, tags, pixels, secure checkout technologies and consent choices, operational delivery of third-party cookies and embedded services may depend on provider systems and the user’s device or network. A temporary technical limitation does not alter the underlying contractual or statutory position.
7.4 Information relevant to third-party cookies and embedded services. The normal treatment of third-party cookies and embedded services may be adjusted for technologies strictly necessary for a requested service or secure communications. Any adjustment must remain proportionate and must not remove a right that cannot lawfully be excluded.
8. Managing preferences
8.1 Consent tool. Use the cookie-settings link or banner control to review categories and change an optional choice.
8.2 Browser controls. Browsers can delete or block cookies and site storage. Blocking essential technologies may interrupt account access, checkout, payment authentication or secure downloads.
8.3 Multiple devices. Choices are normally device and browser specific. Repeat the choice on each browser or after clearing storage.
8.4 Provider opt-outs. Where a third-party provider offers a recognised opt-out, it may be used in addition to the Shot Flow consent tool.
9. Retention and review
9.1 Retention and review standard. Cookie duration is limited by purpose, security and configured provider settings. For retention and review, the provision is confined to cookies, local storage, tags, pixels, secure checkout technologies and consent choices and does not enlarge the user’s rights beyond the product description, Order confirmation or applicable law.
9.2 Information relevant to retention and review. The normal treatment of retention and review may be adjusted for technologies strictly necessary for a requested service or secure communications. Any adjustment must remain proportionate and must not remove a right that cannot lawfully be excluded.
9.3 Decision criteria for retention and review. Within cookies, local storage, tags, pixels, secure checkout technologies and consent choices, a notice dealing with retention and review should identify what happened, the relevant effective time and the practical next step, unless disclosure would compromise security, another person’s rights or a lawful investigation.
10. Do-Not-Track and browser signals
10.1 Do-Not-Track and browser signals standard. Where no binding standard applies, the consent interface and recognised legal preference signals govern. For do-not-track and browser signals, the provision is confined to cookies, local storage, tags, pixels, secure checkout technologies and consent choices and does not enlarge the user’s rights beyond the product description, Order confirmation or applicable law.
10.2 User duties for do-not-track and browser signals. Within cookies, local storage, tags, pixels, secure checkout technologies and consent choices, when do-not-track and browser signals requires user input, the user must give accurate and current information, use the available account or support route and take reasonable steps within the user’s control. Deliberate circumvention or materially misleading information may change the available outcome.
10.3 Misuse safeguards for do-not-track and browser signals. In applying do-not-track and browser signals to cookies, local storage, tags, pixels, secure checkout technologies and consent choices, if an initial decision relied on incomplete information, the user may submit material new evidence. Shot Flow will reconsider the affected point without requiring repetition of information already held.
10.4 Limits on do-not-track and browser signals. If do-not-track and browser signals cannot be completed as expected, the response may include blocking, deletion, consent refresh, provider reconfiguration or temporary disablement. The response should address the affected Order, account, record or use rather than impose a broader restriction without reason.
10.5 How do-not-track and browser signals operates. To administer do-not-track and browser signals, Shot Flow uses a consent interface, script controls, browser storage, provider configuration and periodic inventory checks. Each control is selected for the stated purpose and must not be repurposed for an unrelated objective.
11. Children and age
11.1 Children and age standard. The website is intended for adults aged 18 or over and is not designed to profile children. For children and age, the provision is confined to cookies, local storage, tags, pixels, secure checkout technologies and consent choices and does not enlarge the user’s rights beyond the product description, Order confirmation or applicable law.
11.2 Limits on children and age. If children and age cannot be completed as expected, the response may include blocking, deletion, consent refresh, provider reconfiguration or temporary disablement. The response should address the affected Order, account, record or use rather than impose a broader restriction without reason.
11.3 How children and age operates. To administer children and age, Shot Flow uses a consent interface, script controls, browser storage, provider configuration and periodic inventory checks. Each control is selected for the stated purpose and must not be repurposed for an unrelated objective.
12. International data flows
12.1 International data flows standard. A provider may process identifiers outside the United Kingdom under an appropriate transfer mechanism. For international data flows, the provision is confined to cookies, local storage, tags, pixels, secure checkout technologies and consent choices and does not enlarge the user’s rights beyond the product description, Order confirmation or applicable law.
12.2 Related provisions for international data flows. Within cookies, local storage, tags, pixels, secure checkout technologies and consent choices, a question or correction about international data flows may be sent to info@shot-flow.com with enough detail to identify the relevant Order, account or interaction. Full payment credentials and unrelated personal information must not be sent by email.
12.3 Controls for international data flows. A decision concerning international data flows may take account of consent records, tag configuration, browser tests, provider documentation and deployment records. The weight assigned to a record depends on reliability, context and any credible contrary material supplied by the user.
12.4 Correction of international data flows. For cookies, local storage, tags, pixels, secure checkout technologies and consent choices, operational delivery of international data flows may depend on provider systems and the user’s device or network. A temporary technical limitation does not alter the underlying contractual or statutory position.
13. Changes to this policy
13.1 Changes to this policy standard. Material inventory or purpose changes will be reflected in the published version and consent interface. For changes to this policy, the provision is confined to cookies, local storage, tags, pixels, secure checkout technologies and consent choices and does not enlarge the user’s rights beyond the product description, Order confirmation or applicable law.
13.2 How changes to this policy operates. To administer changes to this policy, Shot Flow uses a consent interface, script controls, browser storage, provider configuration and periodic inventory checks. Each control is selected for the stated purpose and must not be repurposed for an unrelated objective.
13.3 Requests about changes to this policy. For cookies, local storage, tags, pixels, secure checkout technologies and consent choices, safeguards used for changes to this policy protect purchasers, rights holders, payment participants and the service. They may be tightened where a credible security or rights risk exists and relaxed after that risk is resolved.
13.4 Information relevant to changes to this policy. The normal treatment of changes to this policy may be adjusted for technologies strictly necessary for a requested service or secure communications. Any adjustment must remain proportionate and must not remove a right that cannot lawfully be excluded.
14. Contact
14.1 Contact standard. Cookie questions may be sent to info@shot-flow.com. For contact, the provision is confined to cookies, local storage, tags, pixels, secure checkout technologies and consent choices and does not enlarge the user’s rights beyond the product description, Order confirmation or applicable law.
14.2 How contact operates. To administer contact, Shot Flow uses a consent interface, script controls, browser storage, provider configuration and periodic inventory checks. Each control is selected for the stated purpose and must not be repurposed for an unrelated objective.
14.3 Requests about contact. For cookies, local storage, tags, pixels, secure checkout technologies and consent choices, safeguards used for contact protect purchasers, rights holders, payment participants and the service. They may be tightened where a credible security or rights risk exists and relaxed after that risk is resolved.
14.4 Information relevant to contact. The normal treatment of contact may be adjusted for technologies strictly necessary for a requested service or secure communications. Any adjustment must remain proportionate and must not remove a right that cannot lawfully be excluded.
Cookie category decision table
| Category | Purpose | Consent required | Effect if disabled |
| Strictly necessary | Security, authentication, checkout, consent storage and digital fulfilment | No, where strictly necessary | Login, payment or download functions may fail |
| Functional | Remember optional interface and service preferences | Usually yes, subject to applicable rules | Preferences may reset between visits |
| Analytics | Measure aggregate traffic, navigation and technical performance | Yes where required | Core purchase and delivery functions remain available |
| Advertising / attribution | Measure campaigns or tailor advertising if introduced | Yes | Advertising may be less relevant; core service remains available |
Current technology inventory
| Cookie / technology | Type | Purpose | Typical duration | Provider |
| Essential session identifier | Strictly necessary | Maintain a secure session and prevent request forgery | Session | Shot Flow / hosting provider |
| Consent preference record | Strictly necessary | Store categories accepted or rejected and policy version | Up to 24 months | Shot Flow / consent tool |
| Checkout security token | Strictly necessary | Protect cart and checkout integrity | Session to 24 hours | Shot Flow / commerce provider |
| Payment authentication identifier | Strictly necessary | Support payment authorisation, fraud checks and strong customer authentication | Session to provider-defined security period | Payment service provider |
| Download access token | Strictly necessary | Authorise and evidence access to a purchased Asset or Bundle | Order window or account life | Shot Flow / content-delivery provider |
| Preference storage | Functional | Remember optional display or language settings | Up to 12 months | Shot Flow |
| Analytics identifier | Analytics | Measure aggregate usage and diagnose performance | Up to 14 months | Analytics provider, only after consent |
| Campaign attribution identifier | Advertising / attribution | Associate a permitted campaign with a purchase | Up to 90 days | Marketing provider, only after consent |
Practical cookie-control checklist
1. Use the consent interface before continuing if you wish to reject optional categories while retaining essential checkout and delivery functions.
2. After changing a choice, refresh the page if an optional script was already loaded during the same session.
3. Clear both cookies and local storage when troubleshooting a stale consent or account-session issue.
4. Avoid blocking payment-provider domains during checkout because authentication may fail and the Order may remain pending.
5. Contact support with the browser, device, approximate time and screenshot of the consent panel if a saved choice is not respected.
Shot Flow · Cookie Policy · v1.0 · Effective 21 July 2026 · Published on the website; subject to update; the current published version governs.
