Cookie Policy
Legal
Last updated: 1 October 2026
How we use cookies
In this policy, cookies also includes similar browser technologies such as local storage and session storage. Essential technologies provide requested features, secure sign-in and remember your cookie choice. Optional analytics remembers the source of a visit for 30 days only after consent. We do not use advertising, cross-site tracking or third-party analytics.
Essential technologies are required for the requested service and cannot be disabled through Sportelier. You can remove them using your browser controls, but parts of the service may stop working as expected.
Categories and browser storage
| Name | Purpose | Storage | Duration |
|---|---|---|---|
| sb_session | Keeps an authenticated account signed in securely. | First-party HTTP-only cookie | Up to 180 days from sign-in; the sign-in it holds ends after 30 days unused, at logout or on revocation |
| csrftoken | Protects changes to a signed-in account from requests sent by other sites (CSRF protection). | First-party cookie | Up to 1 year |
| registration_device | Remembers which registration this browser started, so the password you typed on the form is kept when you confirm your address in this browser. | First-party HTTP-only cookie | Up to 7 days, or until the registration is confirmed |
| sportelier_cookie_preferences | Remembers your versioned choice for essential technologies and optional analytics. | First-party local storage | Until cleared or this policy version changes |
| pendingJoin | Continues an event-join flow requested before sign-in. | First-party local storage | Up to 24 hours, or until the join flow completes |
| sb_locale | Remembers your language preference for the interface and transactional text. | First-party cookie | Up to 1 year, or until changed or cleared |
| sourceTagReported | Deduplicates source-tag reports and supplies the link source when you register in the same browser session; no visitor identifier. | First-party session storage | Current browser session only |
| sb_attr | Analytics, only with consent: remembers the link source for attribution at registration. | First-party cookie, HttpOnly | 30 days |
Authentication cookie security
The sb_session cookie is restricted to Sportelier’s API. It is HTTP-only, so browser JavaScript cannot read it, and uses SameSite=Lax. In production it is transmitted only over secure HTTPS connections. Every change to a signed-in account also needs the token from the csrftoken cookie, which only Sportelier’s own pages can read, so another site cannot send one on your behalf.
Third-party sign-in scripts
The "Sign in with Google" button loads Google Identity Services, a script served from Google's own domain. It is loaded only on sign-in and registration pages, and only to offer Google sign-in as an option. If you interact with the button, Google may set its own cookies on its domain according to Google's privacy and cookie practices, which are outside Sportelier's control.
The "Log in with Facebook" button loads Meta's JavaScript SDK from connect.facebook.net. It is loaded only where that button is shown (the sign-in and registration pages and your profile's security settings), and only to offer Facebook sign-in as an option. Sportelier stores no Facebook cookie on its own domain for it. If you interact with the button, Meta may set its own cookies on its domains according to Meta's privacy and cookie practices, which are outside Sportelier's control.
The "Sign in with Apple" button loads Apple's Sign in with Apple JS script from appleid.cdn-apple.com. It is loaded only where that button is shown (the sign-in and registration pages and your profile's security settings), and only to offer Apple sign-in as an option. Sportelier stores no Apple cookie on its own domain for it. If you use the button, Apple opens its own sign-in window on appleid.apple.com and may set its own cookies on its domains according to Apple's privacy practices, which are outside Sportelier's control.
Analytics (optional)
Analytics is off by default. If you agree, Sportelier stores the sanitized source/medium/campaign from UTM parameters or the src alias in sb_attr, a first-party HttpOnly cookie. It links a tagged visit to a later registration for up to 30 days. The cookie contains no visitor identifier, uses SameSite=Lax and is Secure on HTTPS. Without consent, attribution stays in sourceTagReported in session storage for the current browser session. Anonymous source reports do not identify a visitor. No third-party analytics tool is enabled.
Your controls
Use Change cookie settings in the footer to accept analytics, choose only essential technologies, or save your selection. Withdrawing analytics consent removes sb_attr; same-session attribution remains in session storage. Your access to Sportelier stays the same. You can also clear cookies and site data in your browser. Removing the authentication cookie signs you out.
Changes to this policy
We may update this policy when our technology or legal obligations change. The date at the top identifies the current version. If an update introduces a new optional purpose, Sportelier will request your choice before activating it.
Questions
If you have a question about cookies or browser storage used by Sportelier, please visit our Support Center.