BADB trust centre
Cookies and browser storage
The cookies and local browser storage BADB currently uses, why they exist, and how to control BADB-owned optional attribution. Last updated: 14 August 2026Your BADB cookie choice
On a first visit, BADB asks whether its own social attribution may run. Allow and Reject are equally available, Manage choices explains the setting, and the permanent Cookie settings control lets you change it later.
This first-party choice controls only BADB-owned attribution. It is not a Google Analytics or advertising consent control. Google advertising consent, before ad serving in applicable regions, will be handled by a separate Google-certified consent management platform.
Current browser storage
| Name | Type | Purpose | Duration |
|---|---|---|---|
BADB_PRIVACY_CHOICES | Necessary preference | Remembers whether BADB-owned social attribution is allowed or rejected. | 180 days |
badb_refresh | Necessary authentication | Secure HttpOnly refresh credential after sign-in. | 30 days |
BADB_COUNTRY | Necessary preference | Remembers a country you explicitly select for Home. | 180 days |
badb.public_theme.v1 | Necessary local storage | Remembers dark or light theme. | Until changed or cleared |
badb.access_token | Necessary authenticated local storage | Keeps the signed-in browser session; removed on logout or failed refresh. | Access token: 15 minutes |
badb.favorite_shortlist.v1 | Necessary local storage | Keeps a guest shortlist until imported or cleared. | Until imported or cleared |
BADB_X_ATTRIBUTION | Optional BADB attribution | Measures visits from owned BADB social posts when allowed. | 42 days |
_ga and related GA4 identifiers | External analytics | Measures public site usage independently of the BADB-owned cookie choice. | Controlled by Google Analytics settings |
Google AdSense site-verification and advertising identifiers | External site verification / advertising | The AdSense publisher loader verifies the site and can contact Google. No BADB ad units or Auto Ads are enabled in this release. | Controlled by Google and, when advertising is enabled, the applicable certified consent platform |
PHPSESSID (runtime-configurable) | Necessary runtime | Created lazily only when a feature needs server session state. | Browser session unless runtime configuration changes it |
Withdrawal and browser controls
Rejecting BADB measurement deletes the matching BADB attribution session, expires `BADB_X_ATTRIBUTION` and stops future BADB-owned attribution. It does not configure or clear Google Analytics or AdSense. Advertising choices, when ads are enabled, will be managed through the separate certified consent platform. Browser controls can clear all site data, which may sign you out and reset theme, country or shortlist preferences.