Privacy controls

Cookies & Storage Technologies

BADWEB separates storage needed to provide a requested service from optional analytics storage. The main BADWEB marketing site does not require an advertising tracker to present its public content.

Last updated 2026-09-06

Main BADWEB site

The public marketing pages are designed to work without an advertising or cross-site marketing cookie. The product-creation form submits the details you enter directly to BADWEB. The former public language-preference storage is not used; the public BADWEB site is English.

Authentication cookies

When you sign in, BADWEB uses first-party session cookies needed to authenticate the requested account service. Customer sessions use the cookie name __Host-machine_session with Secure, HttpOnly and SameSite=Lax attributes. Platform-owner sessions use a separate __Host-machine_owner_session cookie with Secure, HttpOnly and SameSite=Strict.

These cookies are security and authentication mechanisms, not advertising cookies. Blocking them can prevent authenticated account or administration functions from working.

Other browser storage

The authenticated web application uses browser session storage for anti-CSRF state that supports secure requests. Generated Business Websites can also store a visitor’s explicit cookie/analytics choice in first-party browser storage so the site can remember whether optional analytics were accepted or rejected.

Optional analytics on generated Business Websites

A generated Business Website can be configured to require visitor consent before optional analytics storage. In that mode, BADWEB does not create the analytics visitor identifier or send optional page/form analytics until the visitor accepts. Rejecting optional analytics leaves the public content and contact form available.

Billing provider

If you choose a paid plan, checkout is handled through Paddle. Paddle may use its own cookies or similar technologies for checkout, fraud prevention, payment processing and legal compliance under Paddle’s own notices and configuration.

Managing choices

Where a generated site displays a privacy-choices banner, use the Accept or Reject controls. You can also clear first-party storage in your browser. Clearing authentication storage signs you out. If consent-based analytics are introduced or materially changed, the consent experience should be updated before optional storage is used.

Need to act now?

Account holders can use the account area for billing, security, support, export and controlled data requests.

Open account