Cookie policy
Last updated: 27 July 2026
BookOS uses a small number of cookies and similar technologies (including HTML5 local storage and session storage) to operate bookos.io and the BookOS application. Strictly necessary cookies are set without consent because the Service cannot work without them, as permitted by Article 5(3) of the ePrivacy Directive (2002/58/EC) and the Danish Cookie Order (Bekendtgørelse nr. 1148 af 9. december 2011). Any optional cookies (analytics, product telemetry) are only set after you grant consent in the cookie banner.
Categories we use
We follow the IAB Europe TCF categorisation, simplified for clarity:
- Strictly necessary — required for the Service to function (login, CSRF, load-balancing, consent storage). Set without consent.
- Functional — remember preferences such as language or theme. Set only when you use the relevant feature.
- Analytics — help us understand product usage in aggregate. Off by default; loaded only after opt-in consent. None active at this time.
- Marketing — track ad performance and personalise content. We do not use marketing cookies and do not load third-party advertising tags.
Cookies and storage we set
| Name | Purpose | Party | Category | Retention |
|---|---|---|---|---|
| __Secure-authjs.session-token | Authentication session | First-party | Strictly necessary | 8 hours |
| __Host-authjs.csrf-token | CSRF protection on auth endpoints | First-party | Strictly necessary | Session |
| g_oauth_state | Google OAuth CSRF (calendar sync) | First-party | Strictly necessary | 10 minutes |
| cookie-consent (local storage) | Remembers your cookie choices | First-party | Strictly necessary | 12 months (until cleared) |
| __stripe_mid, __stripe_sid | Fraud-prevention cookies set by Stripe Checkout / Elements when you reach a payment page | Third-party (Stripe) | Strictly necessary | __stripe_mid: 1 year; __stripe_sid: 30 minutes |
| m (Stripe) | Fraud-prevention signals on payment pages, set by Stripe | Third-party (Stripe) | Strictly necessary | 2 years |
Local and session storage
In addition to cookies, we use the browser’s HTML5 localStorage and sessionStorage for small, non-tracking purposes (e.g. remembering your cookie choice, draft form state). These entries stay on your device and are never sent to BookOS unless required to complete a request you initiated.
Third-party services
We do not use third-party analytics, advertising, retargeting, or social-media tags by default. Stripe sets the cookies listed above only on pages that load Stripe Checkout / Elements, and only when you initiate a payment action. When enabled, Cloudflare Turnstile processes limited browser and network signals on the signup form to prevent automated abuse. This is treated as strictly necessary security for that form. A configured Trustpilot TrustBox is functional content: its third-party script loads only after you accept optional cookies and may provide Trustpilot with your IP address and associated request metadata. Instagram feeds are fetched server-side and do not load an Instagram script in your browser. We do not currently use a consent-management platform (CMP) certified under the IAB TCF; if we adopt one, we will update this page first.
Managing consent
Strictly necessary cookies are required and cannot be switched off. You can withdraw or change any optional consent at any time using the control below, by reopening the cookie banner, or by clearing cookies and site data in your browser. Clearing the consent entry will re-show the banner on your next visit.
Contact
Questions: privacy@bookos.io.
