- Welcome
-
- Innovation Consulting Decades of leadership steering complex government, enterprise, and startup programs
- AI Enterprise Adoption Sovereign AI adoption and Forward-Deployed Engineering via Legion
- Executive Engagements In-the-trenches CxO development, from startups to the Fortune 500
- Skunkworks Outpost Outsourced innovation discovery from a first-principles perspective
- About
- Contact
Legal
Cookie Policy
This policy explains the cookies and similar technologies used on spearstone.partners, operated by Spearstone, Inc.
The short version
This site sets strictly necessary cookies only. It sets no analytics cookie, no advertising cookie, and no cross-site tracking cookie. That is why you are not asked to accept a cookie banner: there is nothing optional to consent to. Under the EU ePrivacy rules, Canadian privacy law, and equivalent regimes, consent is required for non-essential cookies — and we do not set any.
1. What cookies are
A cookie is a small text file a website asks your browser to store. It can be read back on a later request, which is what lets a site recognise a returning browser. Related technologies — local storage, session storage, pixels, and device fingerprinting — can be used the same way. Where this policy says “cookies”, it covers all of them.
2. Cookies this site uses
The cookies below are the only ones this site may set. All are strictly necessary — required to deliver the site securely and protect it from automated abuse — and all are set by Cloudflare, our infrastructure and security provider, not by us. Strictly necessary cookies are exempt from consent requirements.
In practice most visits set no cookie at all: these are issued only when Cloudflare's security layer determines one is needed, for example when a request is challenged. On a routine visit to this site, our own testing records zero cookies stored.
| Name | Set by | Purpose | Duration |
|---|---|---|---|
__cf_bm |
Cloudflare | Bot management. Distinguishes automated traffic from human visitors so we can block attacks and abuse. | Up to 30 minutes |
cf_clearance |
Cloudflare | Records that a browser has passed a security challenge, so it is not challenged repeatedly. Set only if a challenge is issued. | Up to 1 year |
__cflb |
Cloudflare | Load balancing. Keeps a session on a consistent server. Set only where load balancing applies. | Session |
| Turnstile tokens | Cloudflare | Our contact form uses Cloudflare Turnstile to verify you are not a bot. It may store a short-lived token in your browser while the check completes. Present on the contact page only. | Session |
Cookie names and durations are set by Cloudflare and may change. See Cloudflare’s cookie reference for their current definitions.
3. Analytics, without cookies
We do measure aggregate traffic, because we need to know whether the site works. We do it without cookies.
Our analytics provider (PostHog) is configured so that:
- Nothing is written to your device. It runs in a memory-only mode, so no cookie and no local storage entry is created. Data is discarded when you close the tab.
- No visitor profile is created. We never call any identification function, so events are not attached to a person record.
- Visits are not linked together. We cannot tell that two page views came from the same person.
- Session recording is disabled. We do not capture replays of your screen, clicks, or keystrokes.
- Query strings are removed from recorded page addresses before they leave your browser.
- Autocapture is off. Only a plain page view is recorded.
The result is a count of page views, referrers, and approximate country — and nothing that identifies you.
4. Do Not Track and Global Privacy Control
Many sites ignore these signals. We honour them. If your browser sends a Do Not Track header or a Global Privacy Control signal, our analytics does not load at all. Strictly necessary security cookies still apply, because the site cannot be served safely without them.
5. What we do not do
- We do not use advertising or retargeting cookies.
- We do not embed social media tracking pixels or share buttons that track you.
- We do not participate in cross-context behavioural advertising.
- We do not sell or share personal information. See our Privacy Policy.
- We do not fingerprint your device.
6. Managing cookies
You can view, block, and delete cookies through your browser settings. Because this site only uses strictly necessary cookies, blocking them may cause security challenges to reappear or prevent the contact form from submitting, but it will not otherwise affect your ability to read the site.
Instructions: Chrome, Firefox, Safari, Edge.
7. If you leave this site
When you follow a link to a third-party service — for example our scheduling provider, or a technology partner’s website — that service sets its own cookies under its own policy. This policy covers only spearstone.partners.
8. Changes
If we ever introduce a non-essential cookie, we will update this policy and implement a consent mechanism before that cookie is set. The “last updated” date above will change.
9. Contact
Questions about this policy:
privacy@spearstone.partners
Spearstone, Inc., 330 – 5th Ave SW, Suite 1800, Calgary, Alberta, Canada T2P 0L4