COOKIES

Cookie policy

What this site puts in your browser. It is a short list, and analytics stay off until you say yes.

Last updated

The short version

You can read every page on this site without a single cookie. The handful we do set exist to make a form submission safe, to keep you signed in, and — only if you accept — to count visits. There is no advertising, no retargeting, no pixel, no fingerprinting and no session recording anywhere on this site.

Your choice is not a cookie

When you accept or reject in the banner, we save one value in your browser's local storage under the key bmx-cookie-consent. Local storage is not attached to requests, so that value never reaches our server — we do not know what you chose. It is simply why the banner does not come back on your next visit.

Clearing site data for this domain resets it, and so does the control further down this page.

Always set

These two are strictly necessary: without them a form cannot be submitted safely and you cannot stay signed in. They carry a random value and nothing about you, and they are first-party — no other site can read them.

  • csrftoken — set by Django when a page containing a form is delivered. It proves the form you submit came from this site and not from someone else's page in another tab. Expires after one year.
  • sessionid — created when you sign in, and when the site has to remember something across one visit: a confirmation message after a form, or what you had typed into a form that came back with an error. It holds a random identifier only; everything attached to it lives on our server. Expires after two weeks, or when you sign out.

Only after you accept

Accepting loads Google Analytics 4, through Google Tag Manager if we have a container configured. Google then sets, on our behalf:

  • _ga — tells a returning visit from a new one. two years.
  • _ga_<measurement id> — keeps the state of the current session. two years.

IP addresses are truncated before Google stores them. If we ever add a tag that sets something else, it will be listed here before it goes live.

Reject, or leave the banner alone, and none of this is fetched. There is nothing to opt out of afterwards, because nothing was started.

What we do not use

  • No advertising or retargeting cookies, from anyone.
  • No social network pixels, no "like" or "share" widgets. LinkedIn and YouTube appear here as ordinary links: nothing loads until you click, and then you are on their site, under their rules.
  • No third-party fonts, stylesheets or scripts. Everything a page needs is served from this domain — which means no other company sees your IP address just because a page rendered.
  • No cross-site tracking, no device fingerprinting, no session recording or heatmaps.

Embedded content

The only embed on the site is the map on the contact page, and it does not load on its own: you see a schematic, and the interactive map is fetched only when you press the button. Once you do, the map provider can set its own cookies and will see your IP address — at that point their policy applies alongside ours. Press nothing and nothing is fetched.

Managing it in your browser

Every browser lets you see, block and delete cookies and site data, usually under Privacy or Site settings, and every browser has a mode that discards them when you close the window. Blocking the two strictly necessary cookies above will stop forms and sign-in from working — not because we made it so, but because there is then no way to tell a genuine submission from a forged one.

Changes

If the list above changes, this page changes with it, and the date at the top moves. A new cookie that is not strictly necessary will not be set before you have had the chance to accept it.

Questions: privacy@badgermecx.com. What we do with the data behind all this is in the privacy notice.