BB Tracker Cookie Policy


Table of Contents

  1. Introduction
  2. Our Privacy-First Approach
  3. What Are Cookies?
  4. Cookies We Use
  5. ❌ Cookies We Do NOT Use
  6. Local Storage & Session Storage
  7. Third-Party Services
  8. How to Manage Your Cookie Preferences
  9. Impact of Disabling Cookies
  10. Cookie Lifespan Summary
  11. Data Collected Via Cookies
  12. Security Measures
  13. Legal Compliance
  14. Updates to This Policy
  15. Contact Information
  16. Additional Resources

Introduction

Welcome to BB Tracker's Cookie Policy. This policy explains how we use cookies and similar technologies on our bodybuilding and fitness management web application.

Our Core Commitment: We use the absolute minimum number of cookies necessary to provide you with a secure, functional service. We do not track you, sell your data, or use advertising cookies.

Service Information:

This policy applies to all users of BB Tracker and complies with:


Our Privacy-First Approach

βœ… What We Believe In

❌ What We Never Do


What Are Cookies?

Cookies are small text files stored on your device (computer, smartphone, tablet) when you visit a website. They help websites remember information about your visit, such as your login status or preferences.

Types of Cookies

By Duration:

By Purpose:

By Origin:


Cookies We Use

πŸ”’ Essential Cookies

These cookies are strictly necessary for the service to function. They cannot be disabled without making the service unusable. We use the absolute minimum required.

1. Authentication Token

Property Details
Cookie Name auth_token
Purpose Maintains your secure login session so you don't have to re-enter credentials on every page
Duration 15 minutes (short-lived for security)
Type First-party, HTTP-only, Secure, SameSite=Strict
Data Stored Encrypted JWT token (no personal data in plaintext)
Can Be Disabled? ❌ No - Required for login functionality
Privacy Impact Does not track across sites; session-specific only

Why It's Essential: Without this cookie, you would be logged out after every action, making the service unusable.


2. Refresh Token

Property Details
Cookie Name refresh_token
Purpose Allows you to stay logged in without re-entering your password (only if you select "Remember Me")
Duration 7 days maximum
Type First-party, HTTP-only, Secure, SameSite=Strict
Data Stored Encrypted refresh token (no personal data)
Can Be Disabled? ⚠️ Only set if you check "Remember Me" at login
Privacy Impact Does not track across sites; user-controlled

Why It's Essential: This cookie is only created if you explicitly choose "Remember Me" at login. It prevents you from being logged out after 15 minutes.


3. CSRF Protection Token

Property Details
Cookie Name csrf_token
Purpose Prevents cross-site request forgery attacks (security protection)
Duration Session (deleted when browser closes)
Type First-party, HTTP-only, Secure, SameSite=Strict
Data Stored Random security token (no personal data)
Can Be Disabled? ❌ No - Required for security
Privacy Impact Does not track; security-only purpose

Why It's Essential: This cookie protects you from malicious websites attempting to perform actions on your behalf without your knowledge.


4. Cookie Consent Preferences

Property Details
Cookie Name cookie_consent
Purpose Remembers your cookie preferences so we don't ask repeatedly
Duration 1 year
Type First-party
Data Stored Your consent choices (e.g., "essential_only" or "all_accepted")
Can Be Disabled? ❌ No - Required by POPIA to remember your preferences
Privacy Impact Does not track; preference storage only

Why It's Essential: POPIA requires us to remember your cookie choices. Without this cookie, we would need to ask for consent on every visit.


βš™οΈ Functional Cookies (Optional)

These cookies enhance your experience but are not strictly necessary. You can disable them, though some convenience features won't work.

1. User Preferences

Property Details
Cookie Name user_prefs
Purpose Remembers your UI settings (dark/light theme, metric/imperial units, language)
Duration 1 year
Type First-party
Data Stored UI preferences only (e.g., "theme=dark, units=metric, language=en")
Can Be Disabled? βœ… Yes - Settings won't persist between sessions
Privacy Impact Does not track; convenience only

If Disabled: You'll need to reconfigure your theme, units, and language preferences each time you visit.


2. Session Preferences

Property Details
Cookie Name session_prefs
Purpose Remembers temporary UI state during your session (e.g., collapsed sidebars, expanded sections)
Duration Session (deleted when browser closes)
Type First-party
Data Stored Temporary UI state (no personal data)
Can Be Disabled? βœ… Yes - Minor inconvenience only
Privacy Impact Does not track; session-specific

If Disabled: UI elements won't remember their expanded/collapsed state during your session.


πŸ“Š Analytics Cookies (Optional, Privacy-Respecting)

We use minimal, privacy-respecting analytics to understand how our service is used and improve it. These cookies are entirely optional.

1. Cloudflare Bot Management

Property Details
Cookie Name __cf_bm
Purpose Distinguishes between humans and bots for security (not tracking)
Duration 30 minutes
Type First-party (set by Cloudflare on our behalf)
Data Stored Bot management token (no personal data)
Can Be Disabled? βœ… Yes - Via cookie settings or Do Not Track (DNT) signal
Privacy Impact Cloudflare does NOT track users across sites; aggregated data only

Privacy Guarantee: Cloudflare Analytics is privacy-respecting and does not identify individual users. Data is aggregated and anonymized. Learn more

If Disabled: No impact on functionality. Slightly reduces our ability to detect and prevent bot attacks.


πŸ“Š Our Analytics Approach

What We Use:

What We Do NOT Use:

Data We Collect (Aggregated Only):

Data We Do NOT Collect:

Respecting Your Choices:


❌ Cookies We Do NOT Use

We are committed to minimal tracking. Here's what we explicitly DO NOT use:

Advertising & Marketing

Third-Party Tracking

Invasive Technologies

Long-Term Tracking


Local Storage & Session Storage

In addition to cookies, modern browsers support Local Storage and Session Storage. These are similar to cookies but are not sent to the server with every request.

Local Storage (Persists After Browser Close)

Storage Key Purpose Duration Can Be Cleared?
user_data_cache Encrypted cache of your profile data for faster loading Until logout or manual clear βœ… Yes
workout_draft Auto-saves workout data to prevent loss if browser crashes Until workout is saved or discarded βœ… Yes
calculator_history Recent calculator inputs for convenience Until manual clear βœ… Yes
encryption_key_cache Temporary cache of decryption key (encrypted) Until logout βœ… Yes

Privacy Notes:


Session Storage (Deleted When Browser Closes)

Storage Key Purpose Duration Can Be Cleared?
temp_upload Temporary file data during upload process Until upload completes βœ… Yes
form_state Preserves form data during navigation Until form is submitted βœ… Yes
session_cache Temporary session data for performance Until browser closes or logout βœ… Yes

Privacy Notes:


Third-Party Services

We minimize third-party services to protect your privacy. Here are the only external services that may set cookies or process data:

1. Cloudflare (Infrastructure & Security)

Purpose: Hosting, content delivery network (CDN), DDoS protection, bot management

Cookies Set:

Privacy Commitment:

Privacy Policy: https://www.cloudflare.com/privacypolicy/


2. Payment Processor (e.g., Stripe)

Purpose: Securely process subscription payments

Cookies Set:

Privacy Commitment:

Privacy Policy: https://stripe.com/privacy

Note: When you click "Pay," you are redirected to Stripe's secure checkout page. Cookies set during this process are governed by Stripe's privacy policy.


3. Email Service Provider (e.g., SendGrid)

Purpose: Send transactional emails (account verification, password reset, workout reminders)

Cookies Set:

Privacy Commitment:

Privacy Policy: [TO BE SPECIFIED based on email provider]


βœ… What We Do NOT Use


You have full control over non-essential cookies. Here are multiple ways to manage your preferences:

1. Cookie Consent Banner (First Visit)

When you first visit BB Tracker, you'll see a cookie consent banner with these options:

Your choice is remembered for 1 year via the cookie_consent cookie.


2. Cookie Settings Page

Access via:

Granular Controls:

Category Description Can Disable?
πŸ”’ Essential Login, security, consent preferences ❌ Always On
βš™οΈ Functional UI preferences (theme, units, language) βœ… Optional
πŸ“Š Analytics Privacy-respecting usage analytics βœ… Optional

Changes take effect immediately - no page reload required.


3. Browser Settings

You can also manage cookies directly in your browser:

Google Chrome:

  1. Settings > Privacy and security > Cookies and other site data
  2. Choose "Block third-party cookies" or "Block all cookies"
  3. Manage exceptions for BB Tracker

Mozilla Firefox:

  1. Settings > Privacy & Security > Cookies and Site Data
  2. Choose "Delete cookies and site data when Firefox is closed"
  3. Manage exceptions for BB Tracker

Apple Safari:

  1. Preferences > Privacy > Manage Website Data
  2. Search for BB Tracker and remove cookies
  3. Enable "Prevent cross-site tracking"

Microsoft Edge:

  1. Settings > Cookies and site permissions > Manage and delete cookies
  2. Choose "Block third-party cookies"
  3. Manage exceptions for BB Tracker

⚠️ Warning: Blocking essential cookies will prevent you from logging in and using BB Tracker.


4. Do Not Track (DNT) Signal

We respect Do Not Track (DNT) browser signals.

How to Enable DNT:

What Happens When DNT is Enabled:


5. Clear Cookies & Cache

Via BB Tracker:

Via Browser:


Impact of Disabling Cookies

πŸ”’ Essential Cookies Disabled

Impact:

Recommendation: Do not disable essential cookies if you want to use the service.


βš™οΈ Functional Cookies Disabled

Impact:

Recommendation: Keep functional cookies enabled for convenience, but disabling them won't break the service.


πŸ“Š Analytics Cookies Disabled

Impact:

Recommendation: Entirely your choice. Analytics cookies are privacy-respecting and optional.


Cookie Type Lifespan Purpose Can Disable?
Session Cookies Deleted when browser closes Temporary session data, CSRF protection ❌ Essential
Short-Term (Auth) 15 minutes Authentication token ❌ Essential
Medium-Term (Refresh) 7 days "Remember Me" functionality ⚠️ Only if you choose
Long-Term (Preferences) 1 year UI settings, cookie consent βš™οΈ Functional (optional)
Analytics 30 minutes Bot detection (Cloudflare) βœ… Optional

What We Do NOT Use


Data Collected Via Cookies

βœ… What We Collect

Via Essential Cookies:

Via Functional Cookies (If Enabled):

Via Analytics Cookies (If Enabled):


❌ What We Do NOT Collect


Data Retention

Data Type Retention Period Deletion Method
Session cookies Until browser closes Automatic
Authentication tokens 15 minutes Automatic expiration
Refresh tokens 7 days (if "Remember Me") Automatic expiration or logout
Functional preferences 1 year Automatic expiration or manual clear
Analytics data 30 minutes (cookie); aggregated data retained 90 days Automatic

Your Right to Deletion:


Security Measures

We take cookie security seriously. Here are the measures we implement:

πŸ”’ Cookie Security Flags

HTTP-Only Flag:

Secure Flag:

SameSite=Strict:


πŸ” Encryption & Tokenization

Encrypted Content:

Short Expiration:


πŸ›‘οΈ Regular Security Audits

What We Do:

Third-Party Security:


🚨 Incident Response

If a cookie-related security incident occurs:

  1. We will investigate immediately
  2. Affected users will be notified within 72 hours (GDPR/POPIA requirement)
  3. We will revoke compromised tokens and force re-authentication
  4. We will publish a transparent incident report

Report Security Issues:


πŸ‡ΏπŸ‡¦ POPIA Compliance (South Africa)

Protection of Personal Information Act (POPIA) requires:

βœ… Consent:

βœ… User Rights:

βœ… Data Minimization:

βœ… Transparency:

Regulator Contact:


πŸ‡ͺπŸ‡Ί GDPR Compliance (European Union)

Even though BB Tracker is based in South Africa, we comply with GDPR for EU users:

βœ… Lawful Basis:

βœ… Consent Requirements:

βœ… User Rights (GDPR Articles 15-22):

βœ… Data Protection Officer:


πŸ‡ΊπŸ‡Έ CCPA Compliance (California, USA)

For California residents, we comply with the California Consumer Privacy Act (CCPA):

βœ… Disclosure:

βœ… No Sale of Personal Information:

βœ… Opt-Out Rights:

βœ… Non-Discrimination:


🌍 Other Jurisdictions

We strive to comply with cookie laws worldwide, including:

If you have questions about compliance in your jurisdiction, contact us at [TO BE SPECIFIED].


Updates to This Policy

How We Update This Policy

When We May Update:

Notification of Changes:

Re-Consent:


Version History

Version Date Changes
1.0 [TO BE SPECIFIED] Initial Cookie Policy

Access Previous Versions:


Contact Information

Questions or Concerns?

General Inquiries:

Privacy & Data Protection:

Cookie-Specific Questions:

Security Issues:


Regulatory Complaints

If you believe we are not complying with cookie laws, you can contact:

South Africa (POPIA):

European Union (GDPR):

California (CCPA):


Additional Resources

Learn More About Cookies

General Information:

Browser Cookie Settings:


Related BB Tracker Policies


Legal & Regulatory Information

POPIA (South Africa):

GDPR (European Union):

CCPA (California):


Our Transparency Commitment

What We Promise

We are committed to:


How We're Different

Most fitness apps:

BB Tracker:


Your Privacy Matters

We built BB Tracker with privacy as a core principle, not an afterthought. Your fitness data is personal and sensitive, and we treat it with the respect it deserves.

Thank you for trusting BB Tracker with your fitness journey.



Quick Reference: Cookie Summary Table

Cookie Name Type Duration Purpose Can Disable?
auth_token πŸ”’ Essential 15 minutes Secure login session ❌ No
refresh_token πŸ”’ Essential 7 days "Remember Me" functionality ⚠️ Only if you choose
csrf_token πŸ”’ Essential Session CSRF attack protection ❌ No
cookie_consent πŸ”’ Essential 1 year Remember your cookie preferences ❌ No
user_prefs βš™οΈ Functional 1 year UI settings (theme, units, language) βœ… Yes
session_prefs βš™οΈ Functional Session Temporary UI state βœ… Yes
__cf_bm πŸ“Š Analytics 30 minutes Bot detection (Cloudflare) βœ… Yes

Total Cookies: 7 (4 essential, 2 functional, 1 analytics)

Compare to Industry Average: Most fitness apps use 20-50+ cookies, including advertising and third-party tracking cookies.


This Cookie Policy is designed to be transparent, user-friendly, and compliant with POPIA, GDPR, and CCPA. If you have any questions or suggestions for improvement, please contact us at [TO BE SPECIFIED].