About this policy
Cookies are small files that a website stores in your browser. Browser local storage works in a similar way. This policy explains what the Ruhunu NextGen Tourism website stores, why, and how you can control it.
We keep this to a minimum. The site itself uses only storage that is strictly necessary for it to work securely, and we do not use analytics or advertising cookies. Some pages show posts from our Facebook page; Meta may set its own cookies when they load, and you can switch this off.
Strictly necessary storage
These items are needed for the site to work and stay secure, so they are always on. They are not used to track you.
- rn_consent remembers your privacy choices, such as whether you switched off Facebook content.
- payload-token keeps authorised staff signed in to the admin area. It is set only when staff sign in. Ordinary visitors never receive it.
- Cloudflare, which protects the site, may set security cookies such as __cf_bm to tell people apart from automated bots.
Optional: Facebook content
Some pages show a feed from our Facebook page, which loads automatically. You can switch it off at any time by choosing "Necessary only" in the privacy banner, or by turning off Facebook content in Privacy settings. Once it is off, your browser does not connect to Facebook from this site.
While the feed is on, Meta Platforms may set its own cookies, for example datr and fr, and collect data such as your IP address. Meta decides how this data is used. See Meta's Cookies Policy at https://www.facebook.com/privacy/policies/cookies/ and its Privacy Policy at https://www.facebook.com/privacy/policy/
A plain link to our Facebook page does not load anything from Facebook until you click it.
Full list of cookies and storage
- rn_consent. Provider: this website. Type: browser local storage. Purpose: remembers your privacy choices. Duration: 12 months. Category: strictly necessary.
- payload-token. Provider: this website. Type: cookie. Purpose: keeps authorised staff signed in to the admin area. Duration: until the staff member signs out or the login session expires. Category: strictly necessary.
- __cf_bm. Provider: Cloudflare. Type: cookie. Purpose: bot protection. Duration: about 30 minutes. Category: strictly necessary.
- Other Cloudflare security cookies. Provider: Cloudflare. Type: cookie. Purpose: may be set during a security check. Duration: short, set by Cloudflare. Category: strictly necessary.
- Facebook content cookies, for example datr and fr. Provider: Meta Platforms. Type: cookie. Purpose: set by Meta when the Facebook feed loads. Duration: set by Meta. Category: optional, can be switched off in Privacy settings.
Changing your choices
You can change your mind at any time. Select "Privacy settings" in the footer of any page to open the privacy banner again.
If you turn off Facebook content, the feed will not load again. Cookies that Meta has already set stay in your browser until they expire or you delete them, as explained below.
Clearing cookies and storage in your browser
Most browsers let you see and delete cookies and site data. Look in the browser's settings under Privacy, Security, or Site settings. You can usually delete data for one site only.
- Clearing data for this site removes rn_consent, so the privacy banner will appear again on your next visit.
- To remove Meta's cookies, delete site data for facebook.com.
- On a phone, open the browser's settings menu and look for site data or browsing data.
If you block all cookies, the public pages will still work. Staff will not be able to sign in to the admin area, and some security checks may not work as expected.
Legal grounds
Strictly necessary storage is used because it is needed to provide the site you asked for and to keep it secure. We show the Facebook feed so that visitors can follow programme news, relying on the programme's legitimate interest in keeping the public informed. You can object at any time by switching it off in Privacy settings, and it then stops loading. Our Privacy Notice explains our legal grounds under Sri Lanka's Personal Data Protection Act in full.
Questions and changes
If you have a question about this policy, contact us at [email protected] or +94 91 222 4072. We will update this policy if the storage the site uses changes.
Last updated: 4 October 2026
