Skip to content

    Cookie Policy

    Top Floor Security, LLC

    Effective Date: March 26, 2026 · Last Updated: August 14, 2026

    1. What Are Cookies

    Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites function properly, improve performance, and provide information to the site owner. Cookies may be set by the website you are visiting ("first-party cookies") or by third-party services that the website uses ("third-party cookies").

    This Cookie Policy explains which cookies and similar technologies are used on topfloorsecurity.com (the "Site"), operated by Top Floor Security, LLC ("TFS," "we," "us," or "our"), why we use them, and how you can manage your preferences.

    2. Cookies We Use

    2.1 First-Party Cookies: None

    Top Floor's own code sets no cookies. It is a static site with no user accounts and no sign-in, so there is no session to maintain and no authentication or identity cookie to store. Contact and emergency forms post directly to our backend over HTTPS, carrying a public application key in the request itself rather than a cookie. There is therefore no "strictly necessary" cookie category on this Site, nothing in that category to consent to, and nothing to disable.

    The only cookies that can ever appear are the ones described in Sections 2.2 and 2.3, and none is set until you accept non-essential cookies. They are placed by third-party services, but that does not make all of them third-party cookies: Google Analytics writes its cookies on this Site's own domain, so your browser treats them as first-party. Section 3.2 explains what that means for the browser settings you might reach for. Separately from cookies, the Site keeps a short list of preference values in your browser's own storage; those are listed in full in Section 2.5.

    2.2 Analytics Cookies (Google Analytics)

    When configured, we use Google Analytics to understand how visitors interact with the Site. Google Analytics sets cookies that collect information in an aggregated form, including the number of visitors, the pages they visit, and the sources that referred them. This data helps us improve the Site's content and user experience. Google Analytics is only active when the NEXT_PUBLIC_GA_MEASUREMENT_ID environment variable is configured.

    CookiePurposeDuration
    _gaDistinguishes unique users by assigning a randomly generated identifier2 years
    _ga_<container id>Maintains session state for the specific Google Analytics 4 property2 years

    Google Analytics cookies are only set if you accept non-essential cookies via our cookie consent banner. Until you accept, Google Consent Mode is set to deny analytics storage, so no analytics cookie is placed. If you reject, we signal the denial to Google and delete any Google Analytics cookie already on your device, including the older _gid and _gat cookies from earlier versions of Google Analytics if your browser still holds them.

    For more information about how Google processes your data, visit Google's Privacy Policy and Google Analytics Opt-Out Browser Add-On.

    2.3 Advertising Cookies (LinkedIn Insight Tag)

    With your consent, we use the LinkedIn Insight Tag, an advertising technology provided by LinkedIn Corporation. It allows us to measure the effectiveness of our LinkedIn campaigns (conversion tracking) and to reach website visitors with relevant professional content on LinkedIn (retargeting). The Insight Tag is loaded only after you accept non-essential cookies via our consent banner, and never when your browser sends a Global Privacy Control (GPC) signal, which we honor as an opt-out of advertising trackers.

    CookiePurposeDuration
    li_fat_idFirst-party member indirect identifier for conversion tracking, retargeting, and analytics30 days
    ln_orDetermines whether LinkedIn campaign measurement can be carried out on this site1 day
    bcookie, li_sugr, and similarThird-party cookies set by LinkedIn on the linkedin.com domain (browser identification, probabilistic matching)Set by LinkedIn; see LinkedIn's cookie policy

    If you reject non-essential cookies, the Insight Tag is not loaded. If you withdraw consent after previously accepting, we remove the first-party LinkedIn cookies and stop the tag; however, cookies LinkedIn set on its own linkedin.com domain cannot be removed by us. You can opt out of LinkedIn's cookie use directly via LinkedIn's opt-out controls and learn more in LinkedIn's Cookie Policy.

    2.4 Privacy-Friendly Analytics

    The Site can also run Plausible, a cookieless analytics service, and does so whenever the NEXT_PUBLIC_PLAUSIBLE_DOMAIN environment variable is configured. Plausible sets no cookies and stores nothing on your device, which is why it is not placed behind the consent banner. Google Analytics remains our primary analytics tool and is loaded only after you consent.

    2.5 Local and Session Storage

    Instead of cookies, the Site remembers your preferences in your browser's own storage. Local storage persists until you clear it; session storage is discarded when you close the tab. This is the complete list of what the Site writes:

    KeyPurposeWhere and how long
    tfs-cookie-consent-v2Your current cookie consent choice (accepted or rejected). Version 2 was introduced when advertising cookies were added, so a choice made before that change is not carried overLocal storage, until you clear it
    tfs-cookie-consentThe earlier consent key, kept in step with the current choice so a rejection is honored either wayLocal storage, until you clear it
    tfs-themeYour display theme preference (dark or light)Local storage, until you clear it
    tfs-exit-dismissedTimestamp of when you closed the offer that appears as you leave, so it is not shown again for seven daysLocal storage, until you clear it
    tfs-exit-shownRecords that the leaving offer has already appeared once in this browsing sessionSession storage, until you close the tab
    tfs-sticky-cta-dismissedRecords that you dismissed the offer bar at the bottom of the pageSession storage, until you close the tab

    These values stay in your browser and are never transmitted to our servers. None of them identifies you: each is a preference, a timestamp, or a yes or no flag. Because the Site has no accounts and no sign-in, no authentication or session token is stored either. You can remove all of them by clearing site data for this domain in your browser, which also resets the consent banner.

    3. How to Manage Cookies

    3.1 Cookie Consent Banner

    When you first visit the Site, a cookie consent banner appears at the bottom of the page. You can choose to Accept All cookies or Reject Non-Essential cookies. Your preference is stored in your browser's local storage (key: tfs-cookie-consent-v2) and is respected on all subsequent visits. You can change or withdraw your preference at any time via the "Cookie settings" link in the page footer, which reopens the banner. We also honor the Global Privacy Control (GPC) browser signal as an opt-out of advertising trackers, regardless of your stored banner preference.

    3.2 Browser Controls

    Most web browsers allow you to control cookies through their settings. You can typically find these controls in the "Settings," "Preferences," or "Privacy" section of your browser. Common options include:

    • Block all cookies: You can configure your browser to block all cookies. The Site itself sets none, so blocking them does not stop it working. Blocking browser storage as well means your consent choice and other preferences cannot be remembered, so the consent banner will reappear on every visit.
    • Block third-party cookies: This setting is less effective here than it sounds. Google Analytics is a third-party service, but the cookies it sets are written on this Site's own domain, which makes them first-party cookies as far as your browser is concerned; blocking third-party cookies does not remove them. It does restrict the cookies set on LinkedIn's own domain. To stop the analytics cookies reliably, withdraw consent using the Cookie settings link in the footer, or block all cookies.
    • Delete cookies: You can delete cookies already stored on your device. Note that this will not prevent new cookies from being set on future visits unless you also withdraw consent or adjust your browser settings.
    • Private/incognito browsing: Most browsers offer a private or incognito mode that automatically deletes cookies and browser storage when the session ends.

    For specific instructions on managing cookies in your browser, please consult your browser's help documentation or visit allaboutcookies.org.

    Rejecting cookies does not restrict any part of the Site. Every page, the contact form, and the emergency intake form work exactly the same way whether you accept or reject.

    4. Changes to This Policy

    We may update this Cookie Policy from time to time to reflect changes in the cookies we use or for other operational, legal, or regulatory reasons. Material changes will be indicated by updating the "Last Updated" date at the top of this page. We encourage you to review this policy periodically to stay informed about how we use cookies.

    5. Contact

    If you have questions about this Cookie Policy or our use of cookies and similar technologies, please contact us at:

    Top Floor Security, LLC

    30 N Gould St, Ste N, Sheridan, WY 82801, USA

    Email: info@topfloorsecurity.com

    Website: topfloorsecurity.com

    Revision History

    VersionDateSummary of Changes
    1.4August 15, 2026Removed the tfs-language and tfs-language-banner-dismissed rows. The Site is now published in English only, so it no longer offers a language switch and no longer stores a language preference or a record that you dismissed that offer. If your browser still holds either value from an earlier visit, nothing on the Site reads it; you can clear it with the browser controls described above.
    1.3August 14, 2026Corrected the policy to describe the cookies and storage the Site actually uses. Removed the strictly necessary table, which listed session cookies, CSRF tokens and 7 day authentication tokens that are never set: the Site has no accounts and no sign-in. Replaced the Google Analytics rows with the two cookies Google Analytics 4 sets. Listed every local and session storage key by name, added the language, exit offer and offer bar keys that were missing, and removed the Supabase authentication token row. Corrected the browser-controls guidance, which claimed that blocking cookies would break the Site. Described Plausible as configuration-dependent rather than planned.
    1.2July 17, 2026Added Advertising Cookies section (LinkedIn Insight Tag), versioned consent key with re-prompt for pre-advertising consents, Global Privacy Control support; corrected the analytics configuration variable name
    1.1March 26, 2026Added cookie consent banner documentation, local storage items, consent-gated analytics
    1.0March 26, 2026Initial publication