Privacy & Cookies
Last updated: 5 August 2026
cmgraph is a directory of UK manufacturing businesses. There are no accounts, no adverts, and no tracking of you as an individual — traffic is counted only in cookieless aggregate — so there is very little to say here, which is why you are not seeing a cookie banner.
Cloudflare sits in front of this site
Since 5 August 2026, every request to cmgraph.com passes through Cloudflare before it reaches us. Cloudflare is a content-delivery and security network: your browser connects to whichever Cloudflare data centre is nearest you — London, for most UK visitors — and Cloudflare forwards the request on to the single machine that runs this site.
Cloudflare handles your traffic in the clear. The connection is encrypted from your browser to Cloudflare, and encrypted again from Cloudflare to our server, but Cloudflare decrypts it in between in order to route and filter it. In practice that means Cloudflare sees everything you send us: your IP address, the page you asked for, your browser string, and anything you type into the site, including the search box and the dispute form. We spell this out because it is a wider disclosure than the cookieless analytics described above, and because it was not true before 5 August 2026 — until then, traffic went straight to our own server.
Why we did it. We turned proxying on during an incident: a distributed scrape, routed through ordinary home internet connections in eight countries, had slowed pages to several seconds for real visitors and was pushing the server towards falling over. That kind of traffic cannot be recognised one address at a time, and a single machine cannot absorb it. Cloudflare can. As with server logs, our basis for this is a legitimate interest in keeping the service available and secure.
Cloudflare’s role. Cloudflare processes this traffic on our behalf as our service provider, under its own terms and privacy policy; it is not free to use it to profile or advertise to you. Cloudflare, Inc. is a US company operating a worldwide network, so a request may be handled at a data centre outside the UK. You can read Cloudflare’s privacy policy for what it does with data it handles for sites like ours.
What we have deliberately left switched off. Cloudflare’s bot-fighting and CAPTCHA-style challenge features are off, as a matter of policy: cmgraph is meant to be readable by search engines, AI assistants and automated agents, and we do not block them. There is a side effect that matters to you — challenges are the thing that would put a Cloudflare cookie in your browser, so with them off, the “no cookies” statement above still holds. We confirmed that against the live site’s responses rather than assuming it. If we ever have to switch a challenge on for the filtered listing pages, it would set a short-lived security cookie, and this page will be updated to say so.
Two smaller consequences. Static files such as images, fonts and scripts may be served to you from a Cloudflare cache instead of from our server; the pages themselves are still generated by our server on each request. And Cloudflare asks browsers to report failed connections back to it — a standard network-error report naming the address you tried to reach and why it failed — which is used to diagnose outages.
What we collect when you visit
Almost nothing, and none of it identifies you to us:
- Server logs. Our web server records each request it serves: your IP address, the page you asked for, your browser string, the page you came from, the response status, how long it took, and basic connection details such as the encryption version your browser negotiated. These are kept for 14 days and then deleted automatically — the deletion is enforced by the web server itself, not by someone remembering to run a cleanup. They stay on that machine; we do not ship them to any third-party logging service.
- Cloudflare’s own records. Because requests now reach us through Cloudflare, Cloudflare also keeps its own short-term record of the traffic it handles for us, under its retention periods rather than ours. On our plan we do not receive those request-by-request records — what comes back to us is aggregate traffic and security statistics. See “Cloudflare sits in front of this site” above.
- Why we keep them. Only to keep the site up and to recognise automated abuse. Distributed scrapers have taken cmgraph offline before, and they arrive spread across thousands of ordinary home internet addresses — without request logs there is no way to tell that traffic apart from real visitors. This is a legitimate interest in the security and availability of the service. We do not build visitor profiles from these logs, we do not combine them with anything else to identify you, and we do not sell or share them.
- Rate limiting. Requests to our API are counted per-IP in a short rolling window to stop abuse. The counters expire within minutes.
- Disputes. If you file a dispute against a claim, we store what you wrote plus a one-way hash of your IP and browser string, used only to rate-limit the anonymous channel. The raw IP and browser string are never stored or logged. That is deliberate and enforced in two places: the dispute form only ever computes the hash, and the dispute address is explicitly excluded from the server logs described above, so filing a dispute leaves no request line carrying your IP. One caveat we would rather state than leave implied: since 5 August 2026 a dispute travels through Cloudflare like every other request, so Cloudflare’s network handles it as it handles the rest of our traffic. Nothing on our side writes your raw IP down, and we do not receive a per-request record of it from Cloudflare either.
- Search. What you type into the search box is used to answer that request. It is not kept as a per-user history.
- Analytics. Cloudflare Web Analytics records the page viewed, the referrer, coarse location (country), and timing metrics — in aggregate, without cookies or per-visitor identifiers (see “Cookies and analytics” above).
Business listings and personal data
Listings describe companies, not people. Facts come from public sources — the Companies House register, certification and trade bodies, and businesses’ own websites — and every claim on the site links back to the source it came from. We deliberately do not ingest Companies House officer or persons-with-significant-control records, and we do not publish home addresses or personal contact details.
Some information can still be personal data in practice — a sole trader trading under their own name, for example, or a business address that is someone’s home. We publish it on the basis of legitimate interests (UK GDPR Art. 6(1)(f)): the value of a complete, evidence-linked directory of UK manufacturers, weighed against the low privacy impact of republishing information already made public in a business capacity.
If a listing concerns you, you can ask to see what we hold and where it came from, have it corrected, or object to it being published. Email hello@cmgraph.com and we will respond within one month. If you are not satisfied, you can complain to the Information Commissioner’s Office.
Changes to this notice
If we start collecting more than the above, this page will be updated and the “last updated” date will change.