Privacy

Last verified

There’s no account to create on this site, no form to fill in, no comments section, no newsletter, no advertising and no social media embeds. It sets no cookies of its own. We don’t know who you are, and we have no way of finding out.

Three things still involve data, and this page is about those three: the company that delivers the page to your browser, the analytics we use to see whether anyone’s reading, and email, if you choose to send us one.

Who runs this site

lithium.com.au is run by Lithium Systems, a registered business name of a sole trader in New South Wales, Australia, ABN 78 235 743 812. Anything on this page can be taken up by email at [email protected].

What we collect from you directly

Nothing. There’s nowhere on this site to type anything, and no part of it changes depending on who’s visiting. Every page is a static file, built ahead of time and identical for everybody.

Cookies

This site sets none. We checked the live response headers on 31 August 2026: no Set-Cookie header is sent for any page.

Cloudflare, which serves the site, can set its own short-lived security cookies: __cf_bm for bot detection and cf_clearance when a visitor is challenged. Cloudflare’s documentation describes __cf_bm as being “placed on end-user devices that access customer sites protected by Bot Management or Bot Fight Mode”. We don’t run those products on this site and haven’t seen either cookie set, but Cloudflare controls that layer, not us, and we’d rather tell you it’s possible than promise something we don’t control.

What Cloudflare sees

The site is a folder of static files hosted on Cloudflare Pages. Delivering a page means Cloudflare necessarily receives the request: your IP address, the address of the page you asked for, your browser’s user-agent string, and the time. Cloudflare’s privacy policy describes the information it processes for customers like us as including “IP addresses, traffic routing data, system configuration information”.

We have no access to per-visitor logs and can’t look up an individual request. Cloudflare also adds Network Error Logging headers to responses, which ask your browser to report failed connections back to Cloudflare rather than to us.

The analytics beacon

One third-party script runs on every page: beacon.min.js, loaded from static.cloudflareinsights.com. It’s Cloudflare Web Analytics, and it’s the only script of any kind on this site.

Cloudflare states that it:

does not use any client-side state, such as cookies or localStorage, to collect usage metrics. We also don’t “fingerprint” individuals via their IP address, User Agent string, or any other data for the purpose of displaying analytics.

What we see as a result are counts, not people: how many times each page was loaded, roughly where in the world from, which browser, how fast the page rendered, and which site a visitor came from. Cloudflare counts “a visit” as “a successful page view that has an HTTP referer that doesn’t match the hostname of the request”. There’s no profile, no visitor history and nothing that follows you to another site. Cloudflare’s analytics also don’t log query strings, which is where sensitive data usually leaks into analytics.

To be straight about it: this is still a third-party script running in your browser on every page, and that’s worth saying even though it’s cookieless. We use it because a site nobody reads should be improved or stopped, and we can’t tell which without measuring something. We’re not willing to install anything that follows you elsewhere to find out.

If you’d rather not run it, block it. Most content blockers already do. Nothing on this site depends on JavaScript. The pages are plain HTML, and every one of them works exactly the same with the beacon blocked.

Email

The site’s contact address is [email protected]. Mail sent there lands in a mailbox hosted by Google, and stays there while the correspondence is useful.

We read it, we reply, and that’s the end of it. There’s no mailing list to be added to. We don’t pass your address to anyone, and we won’t publish your name or your email address without asking you first. That includes when you’ve sent us a correction to a page, which we actively want you to do.

Where Australian privacy law sits on this

The Privacy Act 1988 doesn’t cover most small businesses. The Office of the Australian Information Commissioner defines a small business operator as one with “an annual turnover of $3 million or less”. Lithium Systems is far below that line and falls into none of the categories that are covered regardless of size: it isn’t a health service provider, doesn’t trade in personal information, and isn’t a credit reporting body or a Commonwealth contractor.

Small businesses can formally opt in to the Act under section 6EA. We haven’t. We’d rather say so than let a privacy policy imply obligations that don’t apply.

What we do instead is simpler than a promise about legislation: we collect nothing, so there’s nothing to mishandle. The little that does exist, an email you chose to send, is treated the way the Australian Privacy Principles would require. If that ever stops being true, because the site grows a form or a login or an account, this page changes first and the feature ships second.

Asking us what we hold

Email us. In practice the answer will be “an email you sent us, and nothing else”. If you want that deleted, say so and it will be.

Changes to this page

The Last verified date at the top is the date this page was last checked against what the site actually does. It’s the same field every page on this site carries, and the same re-checking cycle covers it. A privacy policy that’s drifted from the site it describes is worse than none, so it gets re-read whenever the site changes, and on the ordinary cycle regardless.

Sources