Cookie Policy
Effective 22 August 2026 · Last updated: 22 August 2026
1. What cookies are, in plain words
A cookie is a small note a website asks your browser to keep and hand back on your next visit. Notes written by the site you are on are first party; notes written by another company whose code the site uses are third party. A cookie holds only what was put into it — ours hold a country code, a timezone, or a record of the link you arrived by — and none can read anything else on your computer.
2. The cookies moveu.in uses
This is the whole list, checked against the code that sets it on 22 August 2026. If a cookie is not in this table, this site does not set it — there are no advertising or social-media pixels on moveu.in today.
| Name | Set by | What it does | How long it lasts | Party |
|---|---|---|---|---|
_ga | Google Analytics 4 (gtag.js, property G-4WJS7N4N8D) | Tells one browser apart from another so visits can be counted. It does not identify you by name. | 2 years (Google’s default, refreshed on each visit) | First party |
_ga_4WJS7N4N8D | Google Analytics 4 | Keeps the analytics session state for the MoveU property. | 2 years (Google’s default) | First party |
mu_ft | MoveU — our own server, at the edge | First touch. Records how you first reached the site: campaign parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term, utm_id), advertising click identifiers (gclid, wbraid, gbraid, fbclid, ttclid, msclkid, ScCid), the referring website, the page you landed on, and the date. Written once and never overwritten, and only if you arrive with campaign parameters or from another website. | 90 days | First party |
mu_lt | MoveU — our own server, at the edge | Last touch. The same fields, refreshed each time you arrive with new campaign parameters — so we can tell which advert or link led to an enquiry. | 90 days | First party |
mu_geo | MoveU — our own server, at the edge | Coarse location — country code, timezone and city — read from our host’s IP-geolocation headers and stored as COUNTRY|TIMEZONE|CITY. It defaults the phone country code on the booking form and helps us call you at a sensible local hour. The IP address itself is not stored in the cookie. | 24 hours | First party |
cf_… | Cloudflare Turnstile, on challenges.cloudflare.com | The bot check on our booking form may keep a note on Cloudflare’s own domain so that a browser which has already passed a check is not asked again. We have not observed any Cloudflare cookie on the moveu.in domain — this site is not served through Cloudflare’s proxy, so there is no clearance cookie here. | Set and expired by Cloudflare, on Cloudflare’s domain | Third party |
All three MoveU cookies are set with Path=/; SameSite=Lax; Secure. Our server writes them in the HTTP response rather than in JavaScript, which is why they last as long as the table says instead of expiring after a week in Safari. Our own scripts can read them — the booking form does, so an enquiry carries the link it came from — and they are never sent to anyone else. They are not set on our programming interfaces, on static files, or on the site’s internal routes.
2.1 Analytics — Google Analytics 4
We use Google Analytics 4 to understand how the site is used: which pages people read, which programs they look at, roughly where in the world they are, which device they used. We do not use it to identify individuals, and no health-related information from the booking form is ever sent to it. Because we use Google Analytics, Google asks us to point you to its own notice: How Google uses information from sites that use its services.
2.2 Tag delivery — Google Tag Manager
Google Tag Manager (container GTM-5JN46NJ9) runs on every page of this site. It is the delivery mechanism for the tags listed here. The container itself sets no cookies, and today it delivers nothing beyond what the table above shows.
2.3 Where you came from — mu_ft and mu_lt
These two answer one question: did that advert, article or referral actually bring anyone? They are set only if you arrive with campaign parameters in the address, or from another website — a plain, direct visit to moveu.in sets neither, and writes only mu_geo. Clearing them costs you nothing: the booking form works exactly as before, we simply lose the record of how you found us.
2.4 Coarse location — mu_geo
Our host tells our server, from your IP address, roughly which country and timezone you are in. mu_geo keeps that summary for a day so the booking form can preselect your phone country code and so we know not to ring you at three in the morning. Your IP address is not kept in it.
2.5 Bot protection on the booking form — Cloudflare Turnstile
The booking form uses Cloudflare Turnstile to check that a submission comes from a person and not a bot. Turnstile loads from challenges.cloudflare.com and may set a short-lived cookie of its own on that Cloudflare domain, so a browser that has already passed a check is not asked again — Cloudflare’s cookies on Cloudflare’s domain, which we cannot read. Cloudflare is named in our Privacy Policy as the service that handles the anti-bot token and, in the moment, your IP address.
3. Other browser storage we use (not cookies)
Two things live in your browser’s own storage rather than in cookies:
- A draft of the booking form (
moveu:lead:v3, in session storage, kept for 24 hours) so a half-finished enquiry is not lost if you navigate away. It holds only the non-identifying answers — service, who it is for, age band, contact preference, preferred time, phone country, a random enquiry reference and a timestamp. It does not store your name, phone number, email address or your message. It is cleared when you submit, and disappears when you close the tab. - Copies of the two attribution cookies (
mu_ftandmu_lt, in local storage), a fallback for when the cookies themselves cannot be read. Same contents, same purpose; they have no expiry of their own, so clear them with your browser’s “site data” control — see section 5.
4. Consent — and how it works where you are
There is no cookie banner on moveu.in today, and we would rather say so than imply otherwise. On a normal visit the cookies in the table above are set; nothing asks you to agree to them first, and no part of this page should be read as a record that you consented.
Region-scoped consent defaults — Google Consent Mode v2 — are being put in place for this site. When they are live, visitors in the European Economic Area, Iceland, Liechtenstein, Norway, the United Kingdom and Switzerland will have analytics and advertising storage default to denied: Google’s tags will still send cookieless signals, but no _ga cookie will be written unless consent is given. Everywhere else, including India, the Gulf and the United States, they will default to granted. Until that is live and verified, treat the table above as describing every visit, wherever you are.
One part already works this way: when someone enquires from the EEA, the UK or Switzerland, our server withholds advertising click identifiers from the conversion signal it sends to Google and marks that signal as not consented. That is in the code today, not a plan.
Why no banner yet: MoveU markets in India and to English-speaking clients around the world. India’s Digital Personal Data Protection consent obligations phase in by 2027, and a consent-management tool will be adopted before then — or before any marketing begins in the EU or the Gulf, whichever comes first. When it ships, this page gains a control for managing your preferences and this section is rewritten. We have no preference centre today, and we will not pretend to.
5. How to refuse, withdraw or delete cookies
- Delete everything for this site. Every major browser can clear cookies and site data for a single site: Chrome, Safari, Firefox and Edge each document how. This also clears the browser storage in section 3.
- Block them before they are set, in your browser’s settings — third-party cookies or all of them. A private or incognito window discards everything when you close it.
- Opt out of Google Analytics specifically, on every site you visit, with the Google Analytics opt-out browser add-on.
- In the EEA, the UK or Switzerland: once the consent defaults in section 4 are live, nothing will be stored for analytics or advertising unless you allow it.
- Ask us. Email info@moveu.in or message us on WhatsApp at +91 96251 08363. Your rights of access, correction, deletion and withdrawal of consent are set out in our Privacy Policy.
- One honest caveat. Blocking the bot-protection check may stop the booking form from being submitted at all — a security measure rather than tracking. If it happens, call or message us and we will take your enquiry that way.
6. Cookies set by other companies
Two companies are involved today and no others: Google, for Analytics and Tag Manager, and Cloudflare, for the bot check on the booking form. Both are named in our Privacy Policy with what they do for us. If you contact us on WhatsApp, that conversation happens under Meta’s terms, outside this site.
No advertising or social-media pixels are live on moveu.in. If that changes, this page and its table are updated in the same release that adds the tag — a cookie policy is only true on the day it was last checked.
7. How this connects to our Privacy Policy
This page covers the storage mechanism: what is kept in your browser, by whom, for how long. Our Privacy Policy covers everything else — what the booking form collects, how the optional health notes are handled, who processes an enquiry, and how to have it corrected or deleted. Our Terms of Service govern the services themselves.
8. Changes to this policy
When a cookie is added, removed, or changes what it does, we update the table above and give this page a new “last updated” date. That date is the honest answer to “when was this last true?”.
9. Questions
Ask us anything about this page — including “what exactly do you have on me?”. Email info@moveu.in, call or message +91 96251 08363, or contact us.
This policy is provided in English; contact us if you need help understanding it.