Short answer
Think of visiting a website like visiting a restaurant.
You sit down, choose something from the menu and place your order. The waiter takes the useful parts of that order to the kitchen: what you ordered, how you would like it prepared and the number of your table.
A website cookie performs a similar job. It is a small piece of information that a website gives to your browser. Your browser keeps it and presents it again when communicating with that website.
That is how the website can remember that you have already made a choice.
The cookie might identify your table, remember something you placed in a shopping basket or record a setting you selected. Without it, each new request could look as though it came from a completely new customer.
The restaurant, the browser and the cookie
To keep our restaurant comparison straight:
- You are the person visiting the website.
- Your browser is sitting at the table on your behalf.
- The website is the restaurant.
- The website’s server is the kitchen doing the work behind the scenes.
- The cookie is the useful information kept with your order.
- The waiter carries information between your table and the kitchen.
The cookie is not a little person watching what you do. It is not a program, and it cannot wander around your computer reading your files.
It is simply stored information.
However, what that information represents—and who receives it—can still matter.
Session cookies and returning customers
Some cookies only last for your current visit. These are called session cookies.
Imagine leaving the restaurant briefly to take a telephone call. When you return, you would not expect the kitchen to throw away your order and make you order again. A session cookie helps the website recognise that you are still the same visitor during that browsing session.
Other cookies remain for longer. These are sometimes called persistent cookies.
They are more like a restaurant remembering something for your next visit: perhaps your preferred table, your usual choice or the fact that you have already answered a question.
Persistent does not mean permanent. These cookies normally have an expiry date, and you can remove them yourself.
Look at Tech & Talk’s biscuits
The internet calls them cookies. At Tech & Talk, we call them biscuits. Same thing—better with tea.
When you make choices using our biscuit tin, your browser remembers those choices. This means we do not need to present the tin as though you were a completely new visitor every time you move between pages or return to the website.
Strictly speaking, websites can use several kinds of browser storage to perform this job. Not everything commonly discussed as a “cookie” is technically a cookie. Our biscuit tin uses browser storage, but the restaurant analogy remains the same: your browser keeps a small record of the choices you made.
Our essential Tech & Talk Biscuit remembers which other biscuits you have chosen.
Optional biscuits allow additional services to be used, such as:
- live chat;
- maps;
- videos;
- online meetings;
- payments;
- the website pet.
Those services are kept outside until you choose to let them in. If you do not take a particular biscuit, the corresponding service should not load.
You can reopen the tin and change your mind at any time.
Why do other services need their own cookies?
Suppose the restaurant invites another business inside to provide something it does not offer itself.
Perhaps somebody else runs the entertainment, handles payments or manages parking. That business may need information to deliver its part of the service. It may also operate under its own rules.
Websites work in a similar way. A site may include services supplied by other companies, such as a map, video player, live-chat system or payment provider.
When one of those services loads, information about your visit may be sent to that provider. It may also store its own cookies or use similar browser storage.
This does not automatically mean that anything improper is happening. It does mean that more than one organisation may now be involved—which is why optional services should be explained clearly.
Can a cookie be dangerous?
A normal cookie cannot install a virus, damage your computer or read all your personal files.
The concern is usually not the existence of the cookie itself. The important questions are:
- What information does it represent?
- Why is it being stored?
- How long will it remain?
- Who can receive it?
- Is it being used to follow your activity between different websites?
An order ticket is not inherently dangerous. Nevertheless, you might reasonably want to know what has been written on it and whether it is being passed around.
Some cookies are useful and fairly ordinary. Others may be used for advertising, profiling or tracking visitors across multiple websites.
The word cookie covers many different purposes, so accepting one cookie does not mean that every cookie deserves the same level of trust.
What can the waiter overhear?
The waiter has a separate role in our analogy.
The kitchen only needs the information required to prepare your order. The waiter, however, is present at your table and may be able to hear or observe more than the kitchen needs to know.
In the same way, information can be encountered at different points while you use an online service. The website may receive information needed to respond to you, while embedded services may receive additional information when they are allowed to load.
That is why it is worth knowing who operates a service—not merely whether a cookie exists.
It is also sensible not to enter sensitive information into a website unless you trust the website and understand why it is asking for that information.
What do HTTP and HTTPS change?
Information must travel between your browser and the website.
On an old, unsecured HTTP connection, that journey is more like discussing your order loudly enough for somebody nearby to overhear it.
An HTTPS connection protects the information while it travels between your browser and the website. You will normally see https:// at the beginning of the web address, although modern browsers may hide that part until you click the address bar.
HTTPS is important, but it does not prove that the website itself is honest.
It protects the journey to the restaurant. It does not guarantee that you chose a trustworthy restaurant.
Should I accept or reject cookies?
You do not need to accept every cookie simply because a website asks.
A useful beginner’s rule is:
- Accept an optional cookie when you understand what it enables and want to use that feature.
- Refuse it when the explanation is unclear or the feature is of no use to you.
- Be particularly cautious about advertising and cross-site tracking.
- Remember that refusing optional cookies should not prevent the basic website from working.
- If you are not sure, refuse it. You can usually change your mind later.
Some essential storage may be required for a service you have specifically requested—for example, remembering the contents of a shopping basket or keeping you signed in securely.
The website should distinguish that necessary storage from optional uses such as advertising or analytics.
How do I remove cookies?
Your browser lets you remove stored information for one website or clear it more widely.
The exact controls differ between browsers, but you can often begin by selecting the icon beside the website address or by opening the browser’s privacy settings.
Be aware that removing a website’s cookies may:
- sign you out;
- empty a shopping basket;
- remove saved preferences;
- make a consent question appear again.
You are not damaging the website. You are simply asking your browser to forget the information it was keeping for that particular restaurant.
Things to remember
- Cookies are stored information, not miniature programs.
- Your browser stores them and presents them to the relevant website.
- Some last for one browsing session; others remain for future visits.
- Cookies can provide useful memory, but they can also support tracking.
- Third-party maps, videos and chat systems may use their own storage.
- HTTPS protects information while it travels, but it does not guarantee that a website is trustworthy.
- You can refuse optional cookies and change your choice later.
- When you are not sure, refusing is a perfectly sensible choice.
Still not sure?
Bring your browser—or the device that is bothering you—to a Tech & Talk workshop, and we will work through it together. Tea and biscuits are considerably easier to understand when both are available.
💡 Workshop Tip
Workshop Tip placeholder.