BuildSideways

Cookie policy

There are three, and none of them follow you anywhere.

Last updated 2026-10-07.

We do not have a cookie banner, because we do not set anything that needs consent under the GDPR or the ePrivacy Directive. Here is the complete list.

What we set

CookieWhat it doesWhenHow long
`bs_session`Keeps you signed inOnly after you sign in30 days, or until you sign out
`bs_csrf`Stops other sites submitting forms as youOnly after you sign inSame as the session
`bs_theme`Remembers light or dark if you override your system settingOnly if you change it1 year

`bs_session` and `bs_csrf` are HttpOnly, Secure and SameSite=Lax. They are strictly necessary for a service with accounts, which is why they do not need consent. `bs_theme` stores the word "light" or "dark" and nothing else.

What we do not set

No advertising cookies. No cross-site tracking. No Google Analytics, no Facebook pixel, no session recording, no fingerprinting. Our analytics is Cloudflare Web Analytics, which is privacy-first and does not use client-side state to identify visitors.

Local storage

The planner keeps your in-progress build in your browser's local storage so you do not lose it if you reload before signing up. It never leaves your browser unless you save the build to an account. Clearing site data clears it.

Retailer links

When you click through to a retailer, that retailer will set its own cookies under its own policy, and if we have an affiliate programme with them the link may carry a tracking parameter so the referral is attributed. That is disclosed on the affiliate disclosure page. We have no control over what a retailer does once you are on their site.

Turning them off

Your browser can block or delete all of these. If you block `bs_session` you cannot stay signed in, but everything that does not need an account - including building a full plan - still works.

Why there is no cookie banner

Consent under the GDPR and the ePrivacy Directive is required for cookies that are not strictly necessary for a service the user has asked for. A session cookie and a CSRF token on a site with accounts are strictly necessary, and a theme preference you set yourself is a preference you set yourself. Nothing here profiles you, follows you to another site, or is shared with a third party.

We could show a banner anyway, as many sites do defensively. We would rather not add an interstitial to every first visit for no legal benefit and no user benefit, and instead publish the complete list above - which is short enough to read.

If you are evaluating this for compliance

The practical summary: no third-party cookies, no advertising or analytics cookies, no cross-site identifiers, no fingerprinting, no session recording, and no consent management platform because there is nothing to manage consent for. Analytics is Cloudflare Web Analytics, which is privacy-first and does not use client-side state to identify visitors. Payment pages are hosted by Stripe, which sets its own cookies under its own policy at the point you reach them.

The one place a third party sets cookies as a result of something we did is an outbound retailer link, where the retailer's own cookies apply on their site, and where an affiliate tracking parameter may be present once a programme is approved. That is covered on the affiliate disclosure page, and as of the date above we are not in any affiliate programme, so no tracking parameter is currently being added to anything.

Changes

If we ever add a cookie that is not on the list above, this page gets updated and the date at the top changes. If we ever add one that needs consent, you will be asked - and we will say so here.