Cookie Policy
Effective 18 September 2026 · Version 2026-09-18
Draft pending legal review. This document describes how the platform actually works today, but it has not yet been reviewed by counsel. It is published so that nothing in the product refers to a document that does not exist; the wording may change.
There are six things that can store something in your browser when you use this site, and none of them is advertising or analytics. This page lists all of them.
It accompanies our Privacy Policy, which covers everything else we collect.
What we do not do
We run no analytics, no advertising, no tag manager, no session replay and no tracking pixels. Nothing on this site profiles you, follows you to other sites, or builds an audience segment out of you. There is no advertising technology in the product at all.
That is why the notice at the bottom of the page tells you what is set rather than asking you to accept it: everything on the list below is needed for something you asked the site to do, so there is nothing to opt out of that would still leave the site working. There are no categories to toggle and nothing is pre-ticked. If we ever add something non-essential, we will ask first, and this page will change before it does.
Everything that stores something
| Name | Set by | Purpose | Category | Lasts |
|---|---|---|---|---|
| sb-…-auth-token | Us, via Supabase | Keeps you signed in. Only set once you sign in | Strictly necessary | Your session, refreshed as you browse |
| admin-theme | Us | Remembers a staff member's light or dark preference. Set by an explicit click in the staff tools, never on a ticket-buying page | Functional | 1 year |
| __stripe_mid, __stripe_sid | Stripe | Detects payment fraud. Stripe's script loads as soon as you open an event page, so these are set while you are browsing, before you enter any card details and whether or not you buy | Strictly necessary | 1 year and 30 minutes respectively |
| Stripe Link | Stripe | Only if you pay with Link, Stripe's wallet. Link remembers you so that next time — here or at any other business that offers it — you can confirm with a code sent to you instead of typing a card again. Signing up to Link signs you up with Stripe, not with us, and we cannot see what is saved in it. Paying by card instead uses none of this | Third party | Set by Stripe |
| Google's own cookies | Google Maps | Only if you press “Show map” on an event whose organizer picked a venue from Google Maps. Your browser then loads the map from Google directly, so Google receives your IP address and can set its own cookies. Nothing is sent to Google until you press it | Third party | Set by Google |
| bd-cookie-notice | Us | Remembers that you dismissed the notice at the bottom of the page, so you are not shown it again. Browser storage, not a cookie — it is never sent to our servers | Strictly necessary | Until you clear your browser storage |
What the categories mean
- Strictly necessary — the site cannot do what you asked without it. Staying signed in, and Stripe’s fraud checks on a payment.
- Functional — remembers a preference you set. Only one, and only in the staff tools.
- Third party — set by another company for its own purposes, not only ours. Google’s map, and Stripe’s Link wallet if you choose to use it. Both are optional and the site works without either.
There is no “advertising” or “analytics” category on this list because there is nothing to put in it.
Stripe, Link and Google Maps
Stripe.Our payment provider’s script loads on event pages, not only at the payment step, so its cookies are set while you browse even if you never buy anything. Stripe uses them to tell real buyers from fraudulent ones. We do not use them for anything, and we cannot read them.
Stripe Link, if you use it. Link is Stripe’s wallet. Pay with it and Stripe remembers you, so next time you confirm with a code it sends you instead of typing a card again — and that works at every other business that offers Link, not only here. Two things about it are worth being direct about. First, a Link account is an account with Stripe, not with us: we cannot see what is saved in it, and closing it is something you do with Stripe. Second, when you reach the payment step, Stripe’s script reads the email address and phone number you typed into our checkout and uses them to start that sign-up, and paying can enrol you as part of paying rather than as a separate step. If you would rather none of that happened, pay by card: Link is one option in the payment box, never the only one.
Google Maps. If the organizer picked their venue from Google Maps, the event page can embed a Google map — but it does not load until you press Show map. Until then nothing about you reaches Google. Press it and your browser fetches the map from Google directly, so Google receives your IP address and browser details and may set its own cookies under its own policy, not ours. The venue address and the directions link work without ever loading it.
Controlling cookies
Your browser can block or delete cookies, and there are instructions for doing so in its own help. Blocking our own first-party entries will sign you out, lose a theme preference and bring the notice at the foot of the page back; blocking Stripe’s may prevent a payment from completing, because Stripe’s fraud checks depend on them.
The two pieces of third-party content on the site both have their control on the page itself: Google’s map loads when you press Show mapand not before, and Stripe’s Link wallet is used only if you pick it at the payment step instead of entering a card.
Because we run no advertising or analytics, there is no opt-out to offer you here beyond your browser’s own controls.
How this list was built
We walked the site in a real browser on 16 September 2026and recorded what actually loaded, rather than copying a vendor’s documentation. Doing that corrected one entry: Stripe’s script turned out to load on event pages, not at checkout as we had assumed.
We also confirmed at that point that the site stored nothing else in your browser — no local storage, no session storage, no device database — and that the only outside address any page contacted was Stripe’s. Since then we have added two things to that list, and both are on it: the flag remembering that you dismissed the notice at the foot of the page, and Stripe’s Link wallet at the payment step.
These entries could not be seen during that walk and are described from our own code and the vendor’s terms instead:
- sb-…-auth-token — Set only for signed-in users, so it did not appear during the anonymous walk.
- admin-theme — Staff-only, and set by an explicit toggle rather than on page load.
- Stripe Link — Link is not switched on in production yet, so no browser walk has seen it. Described from Stripe's documentation and from the payment origins our own security policy allows.
- Google's own cookies — No event with a Google-resolved venue was published on the day of the inventory, so this row comes from the code path and Google's terms rather than from observation. Since #418 the embed is click-to-load, so it cannot be set without a deliberate press.
- bd-cookie-notice — Set by `CookieNotice` when you press “Got it”, and by nothing else. Added after the browser walk; declared from the component that writes it, and pinned by a test.
Contact
Backdoor Tickets — support@backdoor.tools. Questions about anything on this page are welcome.