Legal

Cookies

There is no consent banner on this site, and that is not an oversight.

Last updated 25 August 2026

B2Pair sets no advertising cookies, no analytics cookies, and no third-party tags of any kind.

There is no tracking pixel on this page. Nothing here reports your visit to an advertising network, a social platform or an analytics company, because none of them are loaded.

What is actually set

Named, so you can check this against your own browser.

  • better-auth.session_token — set once you sign in, so the product knows it is you on the next page. Thirty days, renewed as you use it, and gone when you sign out. Over HTTPS it carries a __Secure- prefix.
  • b2pair_gate — set only while the site is closed behind a shared password, so everybody working on it does not have to retype it. Thirty days. It holds a hash rather than the password, and it will disappear from this list on the day the site opens.
  • b2pair_impersonating — set only while an administrator is signed in as somebody with permission, which that person is told about and can end themselves. One hour at the outside. It names the session rather than the person, so it cannot be edited into being somebody else.

That is the complete list of cookies. All of it is strictly necessary to provide a service you asked for, which is why no consent banner appears: under the ePrivacy rules consent is required for the cookies that are not necessary, and there are none.

One thing that is not a cookie

Your light or dark preference is kept in your browser’s own storage under b2pair-theme, which means it never travels to us on a request. It is here for completeness rather than because it has to be: nothing about it reaches our server, and clearing your browser data removes it.

If that ever changes

The day anything non-essential is added — analytics, a marketing tag, anything that reports what you did to somebody else — a consent banner appears with it and this page changes on the same day. It will not be added quietly.

Related

What we collect and who can see it is set out in the privacy policy, and everybody who touches it is named on the sub-processor page.

An organiser’s own public event page, hosted here, follows the same rule: no trackers are injected into it by us.