01Introduction
The OFFBET websites (OFFBET.app and my.OFFBET.app) use a short list of cookies to make the site work, to keep you signed in on the authenticated subdomain, and to power our live-chat support. We do not use cookies for advertising, cross-site tracking, or behavioural retargeting — there is no Meta Pixel, no Facebook SDK, and no AdTech vendor anywhere on this site.
Privacy-friendly audience measurement is being added — see section 03 below for the planned scope (Google Analytics 4 with IP truncation, and Microsoft Clarity for UX heatmaps). These analytics cookies are opt-in only and will not fire until you accept them via the upcoming consent banner.
Where consent is legally required for a non-essential cookie, we ask for it. See the table below for what we set and why.
02What Is a Cookie?
A cookie is a small text file a website stores on your browser. The next time you visit, the browser sends the cookie back to the site, which is how the site can “remember” you (your login, your language preference, etc.) without asking again.
Cookies can be set by the site you’re visiting (“first-party”) or by services the site embeds (“third-party” — e.g. a chat widget, a payment processor). We label each cookie below with its provider so you can tell which is which.
03Cookies We Use
The full list of cookies that may be set when you visit OFFBET, what each one is for, and how long it stays.
| Cookie | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
__cf_bm | Cloudflare | CDN bot management at the edge | Strictly necessary | 30 minutes |
cf_clearance | Cloudflare | Anti-bot challenge result | Strictly necessary | Up to 1 year |
NEXT_LOCALE | OFFBET (next-intl) | Remembers your language preference across visits | Functional | 1 year |
offbet_admin | OFFBET | Admin-area gate — present only on staff accounts | Strictly necessary | Session |
Firebase Auth session | Google Firebase | Keeps you signed in on my.OFFBET.app (auth subdomain only) | Strictly necessary | Session |
tidio_state_*, __tidio_chat | Tidio (Poland, EU) | Live chat widget — remembers if you opened or dismissed it | Up to 1 year | |
__stripe_mid | Stripe | Payment-fraud prevention — set only when you initiate a paid checkout (no checkout active during the launch-free phase) | Strictly necessary | 1 year |
_ga, _ga_*Coming soon | Google Analytics 4 (linked to our Firebase project) | Anonymised audience measurement — page views, country, device class. IP truncated, no cross-site profile. Opt-in via consent banner. | Analytics (consent) | Up to 2 years |
_clck, _clsk, MUIDComing soon | Microsoft Clarity | Anonymised UX analytics — aggregated heatmaps and session replays of marketing pages to find UX friction. No PII, no ads. Opt-in via consent banner. | Analytics (consent) | Up to 1 year |
Cookies marked Strictly necessary are set without consent because the site cannot function without them (CDN protection, authentication, fraud prevention on checkout). Cookies marked Functional (consent) are non-essential and you can opt out at any time via the steps in section 04 below.
04Managing Cookies
A granular per-category consent banner is on the roadmap for the OFFBET marketing site. Until it ships, you have three direct ways to manage cookies right now:
- Browser-level controls. Every modern browser lets you block third-party cookies entirely, clear cookies for a specific site, or set a clear-on- exit policy. See your browser’s privacy/security settings.
- Disable the live-chat widget. If you do not want Tidio to set cookies, do not open the chat bubble. The script lazy-loads on page load but the chat session cookies only stick if you interact with the widget. You can also block
code.tidio.coat your browser or DNS level. - Use the OFFBET marketing site without signing in. The marketing pages (OFFBET.app) set no authentication cookies — those are only on my.OFFBET.app once you create an account.
For details on the broader data we collect once you have an account, see our Privacy Policy. To request deletion of all your data, use /delete-your-data/.
05Retention Period
The exact duration of each cookie is shown in the table in section 03. In summary:
- Session cookies expire when you close the browser tab.
- Functional cookies (language preference, chat state) expire after up to 1 year and are refreshed on each visit.
- Strictly-necessary CDN cookies (Cloudflare bot management) expire automatically — typically 30 minutes for
__cf_bmand up to 1 year forcf_clearance.
CNIL recommendation: consent records are kept for 6 months. We will honour that interval once the consent banner is live.
06Your Rights
Under the GDPR, you have the following rights over the personal data we process via cookies and otherwise:
- Access to your data.
- Rectification in case of error.
- Deletion of your data.
- Restriction of processing.
- Objection to non-essential cookies.
- Data portability.
- Withdrawal of any consent previously given.
Full detail on how to exercise each right is in our Privacy Policy. You can also contact us directly at [email protected].
If you believe we’ve mishandled your data, you may file a complaint with the French data-protection authority (CNIL): www.cnil.fr.