Skip to main content Skip to content
Bookbag

Legal

Cookie policy

Last updated: 17 July 2026

This page describes every cookie and every browser-storage entry Bookbag sets, why we set it, and how you can change your consent. We follow the Privacy and Electronic Communications Regulations 2003 (PECR): strictly-necessary items are always on, everything else is off unless you opt in.

1. Change your cookie preferences

Update your consent at any time. Your choice takes effect immediately and stays in force until you clear your browser cookies. We re-prompt if we materially change what a category covers.

Cookie preferences

Turn analytics and marketing cookies on or off.

Manage preferences

2. Strictly necessary

These items are set without asking because the site or the signed-in service cannot function without them.

Name Purpose Lifetime Type
bookbag-consent Records your cookie consent decision so we know what to load. 6 months First-party cookie
bookbag-auth Signed session cookie for the closed-trials password gate. Session First-party cookie (HttpOnly)
sb-*-auth-token Supabase authentication session for signed-in Bookbag platform users. Session First-party localStorage (SPA only)
bookbag-current-brand-v1 Remembers which brand you are acting as, for operators managing multiple brands. Until removed First-party localStorage (SPA only)
bookbag-draft-* In-progress campaign the wizard is saving so you don't lose work on refresh. Until the draft is submitted or discarded First-party localStorage (SPA only)

Two other services run on every marketing page but set no cookies or persistent storage:

3. Analytics (opt-in)

Only set if you tick the analytics category on the cookie banner.

Name Purpose Lifetime Type
_gcl_au Google Tag Manager bootstrap identifier. Set by the GTM script itself. 3 months First-party cookie (via GTM)
Any tag loaded via GTM Currently the GTM container has no cookie-setting tags active. This row exists so we can add a specific tag (e.g. GA4 or a conversion pixel) here when we do. Third-party

4. Marketing (opt-in)

Nothing is set in this category today. It exists so that if we add advertising or conversion pixels in future (for example Meta, LinkedIn or Google Ads) they only run for people who have pre-consented. When we add a tag we will bump the consent version so the banner re-asks and this table will list the specific cookies.

5. Third-party services

Full list of processors that receive data from Bookbag is on the Privacy Notice. This page covers only what those services set in your browser.

← Back to home