Skip to main content
360 Degrees Interactive

Website appendix

Cookie notice

Twelve short rules for the website rather than the games. Everything claimed on this page can be checked from your own browser in about a minute, and Rule 8 explains how.

Effective 14 August 2026Second editionPrivacy Act 1988 (Cth)

Rule 1The one-line answer

We write nothing to your device from these pages. No counter, no advertising, no pixel, no recorded session, no picture of who you are.

Two things nonetheless reach past the page you are reading: a security token that the company serving this site may place, and a request for the typefaces the page is set in. Rules 4 and 6 take each of those apart.

Rule 2Which law is doing the work

Browser storage has no consent regime of its own in this country. Nothing here corresponds to the ePrivacy rules written for Europe, and no Australian statute demands a banner before a cookie may be written.

What governs the question is the Privacy Act 1988 (Cth). A cookie gathering material about somebody reasonably identifiable is gathering personal information, and once that is true the Australian Privacy Principles attach to it — APP 3 to the taking, APP 5 to the telling, APP 6 to whatever is done with it afterwards.

Which makes "was a box ticked" the wrong question. The three that count are whether you were told, whether the thing was needed at all, and whether it is being put to any use beyond the one declared. Rules 4 to 7 take them in that order.

Rule 3Why nobody is asking you to agree

Consent is a mechanism for permission, and permission is only meaningful where refusing it would change something. Nothing on this site depends on your agreement, so a dialogue asking for it would be theatre with a dismiss button.

Worse than useless, in fact. A banner that appears where the answer cannot matter teaches the habit of clicking past banners on sites where the answer matters a great deal. We would rather not add to that.

Should this site ever carry something that genuinely needs your agreement, you will be asked before it loads, refusing will take exactly as many taps as accepting, and this page will be rewritten with a new effective date before any of it goes live.

Rule 4The whole inventory

Everything this website can place on your device
TokenPlaced byDoing whatLastingNeeds consent
__cf_bmCloudflare, the company serving this siteTelling scripted traffic apart from people, so abusive requests can be turned away. Necessary to keep the site standing30 minutes, refreshed while you browseNo, strictly necessary
cf_clearanceCloudflarePlaced only where you were shown a challenge and cleared it, so the same challenge is not put in front of you againUp to 30 daysNo, strictly necessary

Those two rows are the complete list. Neither carries anything we could read as a name, an account or a history, and nothing is added to them from our end.

Rule 5What is not running here

  • No visitor counting of any brand, hosted or self-hosted, first party or third.
  • No advertising, and nothing an advertiser could place.
  • No conversion pixel from any social or advertising platform.
  • No session replay, no heatmap, no scroll or rage-click capture.
  • No embedded player, map, comment widget or social button.
  • Nothing written by our code into local storage, session storage or a database in the browser.
  • No fingerprinting, and no attempt to work out whether you have been here before.

Rule 8 is how you confirm every line of that rather than taking it on trust.

Rule 6The request that leaves our server

The page is set in Young Serif and Onest, and both are fetched from Google's font service as the page loads. That means two hosts are contacted: fonts.googleapis.com for the stylesheet describing the faces, then fonts.gstatic.com for the font files themselves.

Making those requests hands Google the address you connected from, the browser string your device sends, and the page that asked for them. Google states that its font service places no cookie and does not feed the requests into advertising or profiling.

Serving the files from our own server would remove the requests entirely, and that job is on the list. Until it is done, this rule is the honest description of what happens rather than an omission you would have to catch. Block both hosts and the pages still lay out correctly in whatever face your system falls back to.

Rule 7What the access log holds

Every server on the internet records what it was asked for, and this one is no exception. Each request leaves behind the address it came from, the time, the path, the browser string and the response code.

None of that is a cookie and none of it is written to your device, but an address you connected from is personal information under the Privacy Act, so it belongs in an honest inventory rather than in a footnote about cookies specifically.

The log belongs to the company serving the pages and expires on that company's own cycle, presently under 30 days. It is read for delivering pages and for pushing back abuse. Nothing is joined to it, and no picture of a returning visitor is built from it.

Rule 8Checking all of this yourself

Take none of the above on trust. Every claim on this page is externally observable from the machine you are using right now.

  1. Open the developer tools your browser already ships with, on any page of this site.
  2. Look at the storage panel. The only entries will be the two rows at Rule 4, and only where Cloudflare has placed them.
  3. Look at the network panel and reload. Everything requested comes from this domain, apart from the two font hosts named at Rule 6.

A page you can audit in a minute is worth more than a paragraph of assurances, which is why this rule exists and why the inventory above is short enough to check against.

Rule 9Clearing it and blocking it

Any browser worth running lets you inspect what a site has stored, throw it away, and refuse to accept more. Refuse the two tokens at Rule 4 and Cloudflare may put a challenge in front of you rather more often than it would otherwise; the pages carry on working exactly as before.

The control is buried under a slightly different name in each one:

  • Chrome files it beneath Privacy and security, labelled Third-party cookies.
  • Safari hides it beneath Privacy, behind a Manage Website Data button.
  • Firefox names the whole panel Cookies and Site Data.
  • Edge sweeps it into Cookies and site permissions.

Clearing site data for this domain removes both rows in a single action. Nothing on our side replaces them, and Cloudflare only writes a fresh one when it has a reason to.

Rule 10Signals your browser can send

Some browsers attach a header announcing that you would rather not be tracked, whether that is the older Do Not Track header or a Global Privacy Control signal. Both are respected here.

Respecting them is admittedly easy, since the answer does not change what happens: no extra storage and no extra processing occurs whether the header arrives or not. We say so anyway, because a site that quietly discards those headers has made a decision it is hoping nobody checks.

Rule 11A game is not a browser

Cookies belong to browsers. Our titles have no use for them and do not carry any. What a title works with instead is a set of handset identifiers, each with its own reset switch, described at Rule 4 of the privacy policy.

Arrived here hoping to stop a game following you around? Rule 10 of that same document is the one you want. The short version is that personalised advertising sits switched off until you switch it on, and switching it back costs you nothing in the game.

Rule 12If any of this changes

Add anything to this site that stores more than the two rows at Rule 4 and this page gets rewritten, with a fresh effective date, before the change reaches you. Where the law that applies to you calls for your agreement first, you will be asked for it first.

A question about this page reaches a person at [email protected], and an answer comes back within 5 working days. Requests made under the Privacy Act run to 30 days instead, and Rule 22 of the privacy policy lists what to put in one.

Dissatisfied with the answer, escalate it to the Australian Information Commissioner's office: GPO Box 5218, Sydney NSW 2001, phone 1300 363 992, or oaic.gov.au.

360 DEGREES INTERACTIVE PTY LTD, ACN 697 527 834, ABN 27 697 527 834.