BB Tracker Cookie Policy
Table of Contents
- Introduction
- Our Privacy-First Approach
- What Are Cookies?
- Cookies We Use
- β Cookies We Do NOT Use
- Local Storage & Session Storage
- Third-Party Services
- How to Manage Your Cookie Preferences
- Impact of Disabling Cookies
- Cookie Lifespan Summary
- Data Collected Via Cookies
- Security Measures
- Legal Compliance
- Updates to This Policy
- Contact Information
- Additional Resources
Introduction
Welcome to BB Tracker's Cookie Policy. This policy explains how we use cookies and similar technologies on our bodybuilding and fitness management web application.
Our Core Commitment: We use the absolute minimum number of cookies necessary to provide you with a secure, functional service. We do not track you, sell your data, or use advertising cookies.
Service Information:
- Service Name: BB Tracker
- Website: [TO BE SPECIFIED]
- Contact Email: [TO BE SPECIFIED]
- Jurisdiction: South Africa (POPIA-compliant)
This policy applies to all users of BB Tracker and complies with:
- Protection of Personal Information Act (POPIA) - South Africa
- General Data Protection Regulation (GDPR) - European Union
- California Consumer Privacy Act (CCPA) - United States
Our Privacy-First Approach
β
What We Believe In
- Minimal Data Collection: We only use cookies that are absolutely necessary for service functionality or that you explicitly choose to enable
- No Tracking: We do not track your behavior across websites or build advertising profiles
- User Control: You have full control over non-essential cookies
- Transparency: Every cookie is documented and explained in plain language
- Security First: All cookies use industry-standard security measures
β What We Never Do
- NO advertising or marketing cookies
- NO third-party tracking cookies
- NO cross-site tracking or user profiling
- NO social media pixels or widgets
- NO device fingerprinting
- NO selling or sharing your data with advertisers
- NO persistent tracking beyond what you authorize
What Are Cookies?
Cookies are small text files stored on your device (computer, smartphone, tablet) when you visit a website. They help websites remember information about your visit, such as your login status or preferences.
Types of Cookies
By Duration:
- Session Cookies: Temporary cookies deleted when you close your browser
- Persistent Cookies: Remain on your device for a set period (we use maximum 1 year for preferences)
By Purpose:
- Essential Cookies: Required for the website to function (cannot be disabled)
- Functional Cookies: Enhance your experience but are not strictly necessary (optional)
- Analytics Cookies: Help us understand how the service is used (optional, privacy-respecting)
By Origin:
- First-Party Cookies: Set by BB Tracker directly (all our cookies are first-party)
- Third-Party Cookies: Set by external services (we minimize these and only use privacy-respecting ones)
Cookies We Use
π Essential Cookies
These cookies are strictly necessary for the service to function. They cannot be disabled without making the service unusable. We use the absolute minimum required.
1. Authentication Token
| Property |
Details |
| Cookie Name |
auth_token |
| Purpose |
Maintains your secure login session so you don't have to re-enter credentials on every page |
| Duration |
15 minutes (short-lived for security) |
| Type |
First-party, HTTP-only, Secure, SameSite=Strict |
| Data Stored |
Encrypted JWT token (no personal data in plaintext) |
| Can Be Disabled? |
β No - Required for login functionality |
| Privacy Impact |
Does not track across sites; session-specific only |
Why It's Essential: Without this cookie, you would be logged out after every action, making the service unusable.
2. Refresh Token
| Property |
Details |
| Cookie Name |
refresh_token |
| Purpose |
Allows you to stay logged in without re-entering your password (only if you select "Remember Me") |
| Duration |
7 days maximum |
| Type |
First-party, HTTP-only, Secure, SameSite=Strict |
| Data Stored |
Encrypted refresh token (no personal data) |
| Can Be Disabled? |
β οΈ Only set if you check "Remember Me" at login |
| Privacy Impact |
Does not track across sites; user-controlled |
Why It's Essential: This cookie is only created if you explicitly choose "Remember Me" at login. It prevents you from being logged out after 15 minutes.
3. CSRF Protection Token
| Property |
Details |
| Cookie Name |
csrf_token |
| Purpose |
Prevents cross-site request forgery attacks (security protection) |
| Duration |
Session (deleted when browser closes) |
| Type |
First-party, HTTP-only, Secure, SameSite=Strict |
| Data Stored |
Random security token (no personal data) |
| Can Be Disabled? |
β No - Required for security |
| Privacy Impact |
Does not track; security-only purpose |
Why It's Essential: This cookie protects you from malicious websites attempting to perform actions on your behalf without your knowledge.
4. Cookie Consent Preferences
| Property |
Details |
| Cookie Name |
cookie_consent |
| Purpose |
Remembers your cookie preferences so we don't ask repeatedly |
| Duration |
1 year |
| Type |
First-party |
| Data Stored |
Your consent choices (e.g., "essential_only" or "all_accepted") |
| Can Be Disabled? |
β No - Required by POPIA to remember your preferences |
| Privacy Impact |
Does not track; preference storage only |
Why It's Essential: POPIA requires us to remember your cookie choices. Without this cookie, we would need to ask for consent on every visit.
βοΈ Functional Cookies (Optional)
These cookies enhance your experience but are not strictly necessary. You can disable them, though some convenience features won't work.
1. User Preferences
| Property |
Details |
| Cookie Name |
user_prefs |
| Purpose |
Remembers your UI settings (dark/light theme, metric/imperial units, language) |
| Duration |
1 year |
| Type |
First-party |
| Data Stored |
UI preferences only (e.g., "theme=dark, units=metric, language=en") |
| Can Be Disabled? |
β
Yes - Settings won't persist between sessions |
| Privacy Impact |
Does not track; convenience only |
If Disabled: You'll need to reconfigure your theme, units, and language preferences each time you visit.
2. Session Preferences
| Property |
Details |
| Cookie Name |
session_prefs |
| Purpose |
Remembers temporary UI state during your session (e.g., collapsed sidebars, expanded sections) |
| Duration |
Session (deleted when browser closes) |
| Type |
First-party |
| Data Stored |
Temporary UI state (no personal data) |
| Can Be Disabled? |
β
Yes - Minor inconvenience only |
| Privacy Impact |
Does not track; session-specific |
If Disabled: UI elements won't remember their expanded/collapsed state during your session.
π Analytics Cookies (Optional, Privacy-Respecting)
We use minimal, privacy-respecting analytics to understand how our service is used and improve it. These cookies are entirely optional.
1. Cloudflare Bot Management
| Property |
Details |
| Cookie Name |
__cf_bm |
| Purpose |
Distinguishes between humans and bots for security (not tracking) |
| Duration |
30 minutes |
| Type |
First-party (set by Cloudflare on our behalf) |
| Data Stored |
Bot management token (no personal data) |
| Can Be Disabled? |
β
Yes - Via cookie settings or Do Not Track (DNT) signal |
| Privacy Impact |
Cloudflare does NOT track users across sites; aggregated data only |
Privacy Guarantee: Cloudflare Analytics is privacy-respecting and does not identify individual users. Data is aggregated and anonymized. Learn more
If Disabled: No impact on functionality. Slightly reduces our ability to detect and prevent bot attacks.
π Our Analytics Approach
What We Use:
- β
Cloudflare Analytics (privacy-respecting, aggregated, no personal data)
What We Do NOT Use:
- β Google Analytics
- β Facebook Pixel
- β Twitter Analytics
- β Any third-party tracking or advertising analytics
Data We Collect (Aggregated Only):
- Page views (which pages are most visited)
- Session duration (how long users spend on the service)
- Browser/device type (for compatibility testing)
- Geographic region (country-level only, for performance optimization)
Data We Do NOT Collect:
- β Individual user identification
- β Precise geolocation
- β Browsing history on other sites
- β Personal health or fitness data (stored server-side, encrypted, never in cookies)
Respecting Your Choices:
- We honor Do Not Track (DNT) browser signals
- Analytics cookies are disabled by default if DNT is enabled
- You can disable analytics cookies at any time via Cookie Settings
β Cookies We Do NOT Use
We are committed to minimal tracking. Here's what we explicitly DO NOT use:
Advertising & Marketing
- β Advertising Cookies: We do not display ads or use advertising cookies
- β Marketing Cookies: We do not track you for marketing purposes
- β Retargeting Cookies: We do not follow you around the web with ads
- β Conversion Tracking: We do not track conversions for advertising
Third-Party Tracking
- β Third-Party Tracking Cookies: We do not share data with advertisers or data brokers
- β Cross-Site Tracking: We do not track your behavior across other websites
- β Social Media Pixels: No Facebook, Twitter, Instagram, LinkedIn, or TikTok pixels
- β Social Media Widgets: No embedded social sharing buttons that track you
Invasive Technologies
- β Device Fingerprinting: We do not create unique device fingerprints
- β Canvas Fingerprinting: We do not use canvas or WebGL fingerprinting
- β Zombie Cookies: We do not use cookies that respawn after deletion
- β Supercookies: We do not use persistent identifiers beyond standard cookies
Long-Term Tracking
- β Persistent Tracking: No tracking cookies beyond 1 year (and only for preferences)
- β Forever Cookies: No cookies without expiration dates
- β Cross-Device Tracking: We do not link your activity across devices
Local Storage & Session Storage
In addition to cookies, modern browsers support Local Storage and Session Storage. These are similar to cookies but are not sent to the server with every request.
Local Storage (Persists After Browser Close)
| Storage Key |
Purpose |
Duration |
Can Be Cleared? |
user_data_cache |
Encrypted cache of your profile data for faster loading |
Until logout or manual clear |
β
Yes |
workout_draft |
Auto-saves workout data to prevent loss if browser crashes |
Until workout is saved or discarded |
β
Yes |
calculator_history |
Recent calculator inputs for convenience |
Until manual clear |
β
Yes |
encryption_key_cache |
Temporary cache of decryption key (encrypted) |
Until logout |
β
Yes |
Privacy Notes:
- Local storage is client-side only (never sent to our servers)
- Contains no personal data in plaintext (encrypted if sensitive)
- You can clear via browser settings or our "Clear Cache" button in Account Settings
Session Storage (Deleted When Browser Closes)
| Storage Key |
Purpose |
Duration |
Can Be Cleared? |
temp_upload |
Temporary file data during upload process |
Until upload completes |
β
Yes |
form_state |
Preserves form data during navigation |
Until form is submitted |
β
Yes |
session_cache |
Temporary session data for performance |
Until browser closes or logout |
β
Yes |
Privacy Notes:
- Session storage is automatically deleted when you close your browser
- Contains no sensitive data (temporary UI state only)
- Never sent to our servers
Third-Party Services
We minimize third-party services to protect your privacy. Here are the only external services that may set cookies or process data:
1. Cloudflare (Infrastructure & Security)
Purpose: Hosting, content delivery network (CDN), DDoS protection, bot management
Cookies Set:
__cf_bm (bot management, 30 minutes)
Privacy Commitment:
- Privacy-respecting analytics (aggregated, anonymized)
- No cross-site tracking
- No personal data collection
- GDPR-compliant with Standard Contractual Clauses
Privacy Policy: https://www.cloudflare.com/privacypolicy/
2. Payment Processor (e.g., Stripe)
Purpose: Securely process subscription payments
Cookies Set:
- Stripe sets cookies on their domain only during checkout (not on BB Tracker's domain)
- We do not receive or control Stripe's cookies
Privacy Commitment:
- Payment data is processed by Stripe, not stored on our servers
- PCI DSS Level 1 certified (highest security standard)
- We never see or store your full credit card number
Privacy Policy: https://stripe.com/privacy
Note: When you click "Pay," you are redirected to Stripe's secure checkout page. Cookies set during this process are governed by Stripe's privacy policy.
3. Email Service Provider (e.g., SendGrid)
Purpose: Send transactional emails (account verification, password reset, workout reminders)
Cookies Set:
- None - Email service is server-side only; no cookies set in your browser
Privacy Commitment:
- Email addresses used only for transactional emails (no marketing)
- No tracking pixels in emails
- You can opt out of non-essential emails in Account Settings
Privacy Policy: [TO BE SPECIFIED based on email provider]
β
What We Do NOT Use
- β Google Analytics, Google Tag Manager, Google Ads
- β Facebook Pixel, Facebook Login, Facebook Comments
- β Twitter Analytics, Twitter Widgets
- β LinkedIn Insights, LinkedIn Widgets
- β TikTok Pixel
- β Hotjar, Crazy Egg, or other session recording tools
- β Intercom, Drift, or other third-party chat widgets
- β YouTube embeds (if we add videos, they will be self-hosted or privacy-respecting)
- β Third-party fonts (Google Fonts, Adobe Fonts) - all fonts self-hosted
- β Third-party CDNs for JavaScript libraries (self-hosted when possible)
How to Manage Your Cookie Preferences
You have full control over non-essential cookies. Here are multiple ways to manage your preferences:
1. Cookie Consent Banner (First Visit)
When you first visit BB Tracker, you'll see a cookie consent banner with these options:
- "Accept Essential Only" - Only essential cookies (login, security) will be set
- "Accept All" - Essential + functional + analytics cookies will be set
- "Cookie Settings" - Customize which categories you want to enable
Your choice is remembered for 1 year via the cookie_consent cookie.
2. Cookie Settings Page
Access via:
- Footer link: "Cookie Settings"
- Account Settings > Privacy > Cookie Preferences
Granular Controls:
| Category |
Description |
Can Disable? |
| π Essential |
Login, security, consent preferences |
β Always On |
| βοΈ Functional |
UI preferences (theme, units, language) |
β
Optional |
| π Analytics |
Privacy-respecting usage analytics |
β
Optional |
Changes take effect immediately - no page reload required.
3. Browser Settings
You can also manage cookies directly in your browser:
Google Chrome:
- Settings > Privacy and security > Cookies and other site data
- Choose "Block third-party cookies" or "Block all cookies"
- Manage exceptions for BB Tracker
Mozilla Firefox:
- Settings > Privacy & Security > Cookies and Site Data
- Choose "Delete cookies and site data when Firefox is closed"
- Manage exceptions for BB Tracker
Apple Safari:
- Preferences > Privacy > Manage Website Data
- Search for BB Tracker and remove cookies
- Enable "Prevent cross-site tracking"
Microsoft Edge:
- Settings > Cookies and site permissions > Manage and delete cookies
- Choose "Block third-party cookies"
- Manage exceptions for BB Tracker
β οΈ Warning: Blocking essential cookies will prevent you from logging in and using BB Tracker.
4. Do Not Track (DNT) Signal
We respect Do Not Track (DNT) browser signals.
How to Enable DNT:
- Chrome: Settings > Privacy and security > Send a "Do Not Track" request
- Firefox: Settings > Privacy & Security > Send websites a "Do Not Track" signal
- Safari: Preferences > Privacy > Website tracking: "Prevent cross-site tracking"
- Edge: Settings > Privacy, search, and services > Send "Do Not Track" requests
What Happens When DNT is Enabled:
- β
Essential cookies remain active (required for service)
- β Optional analytics cookies are automatically disabled
- β
Your preference is honored without needing to configure Cookie Settings
5. Clear Cookies & Cache
Via BB Tracker:
- Account Settings > Privacy > "Clear Cache & Cookies"
- This clears all BB Tracker cookies and local storage
- Note: You will be logged out
Via Browser:
- Use your browser's "Clear browsing data" feature
- Select "Cookies and other site data"
- Choose time range (e.g., "Last hour" or "All time")
Impact of Disabling Cookies
π Essential Cookies Disabled
Impact:
- β Cannot log in - Authentication will not work
- β Security features disabled - CSRF protection will fail
- β Service completely non-functional - You cannot use BB Tracker
Recommendation: Do not disable essential cookies if you want to use the service.
βοΈ Functional Cookies Disabled
Impact:
- β οΈ UI preferences won't persist - Theme, units, language reset each visit
- β οΈ Must reconfigure settings - You'll need to set preferences every session
- β
Core functionality works - Login, workout tracking, data entry still functional
Recommendation: Keep functional cookies enabled for convenience, but disabling them won't break the service.
π Analytics Cookies Disabled
Impact:
- β
No impact on functionality - Service works exactly the same
- β οΈ Slightly reduces our ability to improve - We won't know which features are most used
- β
Your privacy choice is respected - No analytics data collected
Recommendation: Entirely your choice. Analytics cookies are privacy-respecting and optional.
Cookie Lifespan Summary
| Cookie Type |
Lifespan |
Purpose |
Can Disable? |
| Session Cookies |
Deleted when browser closes |
Temporary session data, CSRF protection |
β Essential |
| Short-Term (Auth) |
15 minutes |
Authentication token |
β Essential |
| Medium-Term (Refresh) |
7 days |
"Remember Me" functionality |
β οΈ Only if you choose |
| Long-Term (Preferences) |
1 year |
UI settings, cookie consent |
βοΈ Functional (optional) |
| Analytics |
30 minutes |
Bot detection (Cloudflare) |
β
Optional |
What We Do NOT Use
- β Persistent tracking cookies beyond 1 year
- β "Forever" cookies with no expiration
- β Zombie cookies that respawn after deletion
- β Cross-site tracking cookies that follow you across the web
Data Collected Via Cookies
β
What We Collect
Via Essential Cookies:
- Authentication status (logged in/out)
- Session security tokens (CSRF protection)
- Cookie consent choices
Via Functional Cookies (If Enabled):
- UI preferences (theme, units, language)
- Temporary UI state (collapsed sidebars, expanded sections)
Via Analytics Cookies (If Enabled):
- Aggregated, anonymized usage data:
- Page views (which pages are visited)
- Session duration (how long users spend on the service)
- Browser/device type (for compatibility)
- Geographic region (country-level only)
β What We Do NOT Collect
- β Personal identity (name, email) via cookies - stored server-side, encrypted
- β Precise geolocation (GPS coordinates, street address)
- β Browsing history on other websites
- β Sensitive health data - stored server-side, encrypted, never in cookies
- β Device fingerprints (beyond basic browser/OS for compatibility)
- β Cross-site tracking data (we don't track you across the web)
- β Social media activity (no social media pixels)
- β Search queries on other sites
- β Purchase history on other sites
Data Retention
| Data Type |
Retention Period |
Deletion Method |
| Session cookies |
Until browser closes |
Automatic |
| Authentication tokens |
15 minutes |
Automatic expiration |
| Refresh tokens |
7 days (if "Remember Me") |
Automatic expiration or logout |
| Functional preferences |
1 year |
Automatic expiration or manual clear |
| Analytics data |
30 minutes (cookie); aggregated data retained 90 days |
Automatic |
Your Right to Deletion:
- You can delete cookies at any time via browser settings or our "Clear Cache & Cookies" button
- You can request deletion of all your data via Account Settings > Delete Account
- We comply with POPIA, GDPR, and CCPA data deletion rights
Security Measures
We take cookie security seriously. Here are the measures we implement:
π Cookie Security Flags
HTTP-Only Flag:
- β
Applied to authentication and security cookies
- Prevents JavaScript from accessing cookies (XSS attack protection)
- Cookies can only be read by the server
Secure Flag:
- β
Applied to all cookies
- Cookies only sent over HTTPS (encrypted in transit)
- Prevents interception over unsecured connections
SameSite=Strict:
- β
Applied to authentication and security cookies
- Prevents CSRF attacks (cookies not sent with cross-site requests)
- Cookies only sent when you're directly on BB Tracker
π Encryption & Tokenization
Encrypted Content:
- Authentication tokens are encrypted JWT (JSON Web Tokens)
- Refresh tokens are encrypted and hashed
- No personal data stored in plaintext in cookies
Short Expiration:
- Authentication tokens expire after 15 minutes (reduces risk window)
- Refresh tokens expire after 7 days maximum
- Session cookies deleted when browser closes
π‘οΈ Regular Security Audits
What We Do:
- β
Regular security audits of cookie usage and implementation
- β
Penetration testing includes cookie security testing
- β
Vulnerability disclosure program (report security issues to [TO BE SPECIFIED])
- β
Compliance audits for POPIA, GDPR, CCPA
Third-Party Security:
- Cloudflare: SOC 2 Type II certified, ISO 27001 certified
- Stripe: PCI DSS Level 1 certified (highest payment security standard)
π¨ Incident Response
If a cookie-related security incident occurs:
- We will investigate immediately
- Affected users will be notified within 72 hours (GDPR/POPIA requirement)
- We will revoke compromised tokens and force re-authentication
- We will publish a transparent incident report
Report Security Issues:
- Email: [TO BE SPECIFIED]
- We offer a vulnerability disclosure program (responsible disclosure)
Legal Compliance
πΏπ¦ POPIA Compliance (South Africa)
Protection of Personal Information Act (POPIA) requires:
β
Consent:
- We obtain explicit consent before setting non-essential cookies
- Consent is freely given, specific, informed, and unambiguous
- Granular consent options (not just "accept all or nothing")
- Easy to withdraw consent at any time via Cookie Settings
β
User Rights:
- Right to know what cookies are used (this policy)
- Right to control non-essential cookies (cookie settings)
- Right to withdraw consent (delete cookies or change settings)
- Right to complain to the Information Protection Regulator South Africa
β
Data Minimization:
- We use the shortest lifespan necessary for each cookie
- No persistent tracking cookies beyond 1 year (functional preferences only)
- Session cookies deleted when browser closes
β
Transparency:
- Clear, plain-language explanations of every cookie
- Purpose, duration, and data collected disclosed
- Regular updates to this policy
Regulator Contact:
πͺπΊ GDPR Compliance (European Union)
Even though BB Tracker is based in South Africa, we comply with GDPR for EU users:
β
Lawful Basis:
- Essential cookies: Legitimate interest (necessary for service)
- Functional cookies: Consent (freely given, specific, informed)
- Analytics cookies: Consent (freely given, specific, informed)
β
Consent Requirements:
- Obtained before setting non-essential cookies
- Granular consent options (not bundled)
- Easy to withdraw consent at any time
- Clear information about each cookie
β
User Rights (GDPR Articles 15-22):
- Right to access (see what cookies are set)
- Right to rectification (update preferences)
- Right to erasure ("right to be forgotten" - delete cookies)
- Right to restrict processing (disable non-essential cookies)
- Right to data portability (export your data)
- Right to object (opt out of analytics)
β
Data Protection Officer:
- Contact: [TO BE SPECIFIED]
πΊπΈ CCPA Compliance (California, USA)
For California residents, we comply with the California Consumer Privacy Act (CCPA):
β
Disclosure:
- All cookies disclosed in this policy and our Privacy Policy
- Categories of personal information collected via cookies disclosed
β
No Sale of Personal Information:
- We do NOT sell personal information collected via cookies
- We do NOT share data with third-party advertisers
- No "Do Not Sell My Personal Information" link required (we don't sell data)
β
Opt-Out Rights:
- You can opt out of non-essential cookies via Cookie Settings
- You can delete cookies at any time
- You can request deletion of all your data
β
Non-Discrimination:
- We do NOT discriminate against users who opt out of non-essential cookies
- Service functionality remains the same (except for convenience features)
π Other Jurisdictions
We strive to comply with cookie laws worldwide, including:
- ePrivacy Directive (EU)
- PIPEDA (Canada)
- Privacy Act (Australia)
- LGPD (Brazil)
If you have questions about compliance in your jurisdiction, contact us at [TO BE SPECIFIED].
Updates to This Policy
How We Update This Policy
When We May Update:
- Adding or removing cookies
- Changing cookie purposes or durations
- Improving privacy protections
- Complying with new legal requirements
- Clarifying language based on user feedback
Notification of Changes:
- Material changes: Users notified via email and prominent banner on the website
- Minor changes: Effective date updated; no notification required
- Effective date shown at the top of this policy
Re-Consent:
- If changes materially affect your privacy, we will ask for renewed consent
- Previous consent remains valid for unchanged cookies
Version History
| Version |
Date |
Changes |
| 1.0 |
[TO BE SPECIFIED] |
Initial Cookie Policy |
Access Previous Versions:
- All previous versions available at [TO BE SPECIFIED]
- Changelog maintained for transparency
Questions or Concerns?
General Inquiries:
- Email: [TO BE SPECIFIED]
- Website: [TO BE SPECIFIED]
Privacy & Data Protection:
- Data Protection Officer: [TO BE SPECIFIED]
- Email: [TO BE SPECIFIED]
Cookie-Specific Questions:
- Email: [TO BE SPECIFIED]
- Subject line: "Cookie Policy Inquiry"
Security Issues:
- Email: [TO BE SPECIFIED]
- Subject line: "Security Vulnerability Report"
- We offer a responsible disclosure program
Regulatory Complaints
If you believe we are not complying with cookie laws, you can contact:
South Africa (POPIA):
European Union (GDPR):
California (CCPA):
Additional Resources
Learn More About Cookies
General Information:
Browser Cookie Settings:
Related BB Tracker Policies
- Privacy Policy: [TO BE SPECIFIED]
- Terms of Service: [TO BE SPECIFIED]
- Data Processing Agreement: [TO BE SPECIFIED]
- Security Policy: [TO BE SPECIFIED]
Legal & Regulatory Information
POPIA (South Africa):
GDPR (European Union):
CCPA (California):
Our Transparency Commitment
What We Promise
We are committed to:
- β
Minimal Cookies: Using the absolute minimum cookies necessary for service functionality
- β
Transparency: Being clear and honest about every cookie we use
- β
User Control: Giving you full control over non-essential cookies
- β
Privacy Respect: Honoring your privacy choices, including Do Not Track (DNT) signals
- β
No Tracking: Never tracking you across websites or building advertising profiles
- β
No Data Selling: Never selling or sharing your data with advertisers or data brokers
- β
Regular Audits: Continuously reviewing and minimizing cookie usage
- β
Security First: Implementing industry-leading security measures for all cookies
- β
Legal Compliance: Complying with POPIA, GDPR, CCPA, and other privacy laws
- β
Responsive Support: Answering your questions and addressing concerns promptly
How We're Different
Most fitness apps:
- β Use dozens of tracking cookies
- β Share data with advertisers
- β Track you across websites
- β Use invasive analytics
- β Bury cookie information in legal jargon
BB Tracker:
- β
Uses only 4 essential + 2 optional functional + 1 optional analytics cookie
- β
Never shares data with advertisers
- β
Never tracks you across websites
- β
Uses privacy-respecting analytics only (optional)
- β
Explains every cookie in plain language
Your Privacy Matters
We built BB Tracker with privacy as a core principle, not an afterthought. Your fitness data is personal and sensitive, and we treat it with the respect it deserves.
Thank you for trusting BB Tracker with your fitness journey.
Quick Reference: Cookie Summary Table
| Cookie Name |
Type |
Duration |
Purpose |
Can Disable? |
auth_token |
π Essential |
15 minutes |
Secure login session |
β No |
refresh_token |
π Essential |
7 days |
"Remember Me" functionality |
β οΈ Only if you choose |
csrf_token |
π Essential |
Session |
CSRF attack protection |
β No |
cookie_consent |
π Essential |
1 year |
Remember your cookie preferences |
β No |
user_prefs |
βοΈ Functional |
1 year |
UI settings (theme, units, language) |
β
Yes |
session_prefs |
βοΈ Functional |
Session |
Temporary UI state |
β
Yes |
__cf_bm |
π Analytics |
30 minutes |
Bot detection (Cloudflare) |
β
Yes |
Total Cookies: 7 (4 essential, 2 functional, 1 analytics)
Compare to Industry Average: Most fitness apps use 20-50+ cookies, including advertising and third-party tracking cookies.
This Cookie Policy is designed to be transparent, user-friendly, and compliant with POPIA, GDPR, and CCPA. If you have any questions or suggestions for improvement, please contact us at [TO BE SPECIFIED].