Privacy Policy
Bond numbers and user-selected NS&I ZIP files are processed locally in your browser. This site has no holder’s-number field or account system. Cloudflare may process ordinary request and device data for hosting and security. Optional analytics loads only after you choose Accept.
Information processed only in your browser
- User-selected ZIP files, their names and contents, and the local parsed index are not uploaded.
- Holder’s Numbers are not collected. Bond Numbers are not uploaded.
- Prize and holding amounts, tracker notes and personal names are not sent to business analytics. Return Tracker data stays on this device.
Browser storage
Checker imports remain in memory unless you explicitly choose local persistence. Return Tracker data is saved only after you opt in and can be deleted in the tool. The single cpb-consent local-storage item remembers Accept or Reject. Clear this site’s browser data to reset the choice and remove browser or provider cookies controlled through site-data settings.
Hosting and technical logs
The site runs on Cloudflare Pages and does not build user-level application logs. Cloudflare may process IP address, device and browser metadata, and request data for security, abuse protection and content delivery under its applicable terms. Sensitive tool inputs are not added by this application to URLs, network requests, analytics payloads or logs.
Analytics and cookies
Google Analytics 4 (Google), Microsoft Clarity (Microsoft), Ahrefs Web Analytics (Ahrefs), and Plausible Analytics software served from plausible.shipsolo.io load together only after you choose Accept. If you choose Reject or make no choice, no analytics script or analytics request is made.
Our business analytics records only these event types and sends no custom event properties: home checker click, checker route selected, official NS&I click, local checker start, ZIP import started, ZIP import success, ZIP import failed, bond check started, bond check complete, results view, calculator start, calculator complete, tracker start and tracker prize added.
Provider-native collection after consent is separate from those business events and may include page URL, referrer, interaction, browser and device information, and approximate network location. We do not describe Google Analytics or Clarity data as anonymous.
Business events never include a Holder’s Number, Bond Number, imported ZIP filename or content, prize or holding amount, tracker note, personal name, or an identifier created from those values. Analytics data is not sold. No advertising, affiliate or social-tracking script is included in this build.
| Situation | Next step |
|---|---|
| Google Analytics 4 (Google) | GA4 uses first-party cookies including _ga and _ga_<container-id>, whose Google default expiry is two years unless a verified configuration overrides it. This property’s user-level and event-level retention is 14 months, with reset on new activity on. |
| Microsoft Clarity (Microsoft) | Clarity uses pseudonymous first- and third-party cookies for interaction metrics, heatmaps and session recordings. Webmaster-accessible recording data is retained for up to 30 days, and the site sends the supported positive consent signal only after Accept. |
| Ahrefs Web Analytics (Ahrefs) | Ahrefs is used in its default cookieless mode and says that mode does not collect personal data or store personally identifiable information. Advanced conversion cookies are off. Its dashboard does not expose a fixed site-data retention or deletion period; we have asked Ahrefs Support to confirm it and will update this notice when confirmed. |
| Plausible Analytics software (Shipsolo) | The software is served from plausible.shipsolo.io and operated by Shipsolo in the United States. Analytics retention is 14 months, after which Shipsolo deletes the data. |
Sharing and sale
We do not sell bond numbers, tracker entries or imported files. External links open services governed by their own privacy terms.
Your rights and contact
For UK data-protection purposes, the operator of Check Premium Bonds is the controller. Contact the controller at support@checkpremiumbonds.co.uk for privacy-related requests including access, deletion and complaints. This policy is effective 9 September 2026.
Method and limitations
Method and limitations: This page summarises the official routes and sources listed below. Requirements, rates and timescales can change. It is general information, not financial, legal, tax or probate advice.