Bazeta (bazeta.com) — Cookie Policy. Version 1.0.

This policy explains how Bazeta uses cookies and similar technologies (local storage, session storage, service-worker caches, push tokens and advertising identifiers in our apps) and how you can control them. It supplements our Privacy Policy.

1. What cookies are

Cookies are small text files stored by your browser when you visit a website. They let the site remember you between pages and visits. Local storage works similarly but is only readable by the site that set it. Our mobile apps use equivalent device storage.

2. Cookies we set ourselves (first-party)

Name Purpose Type Duration
session Keeps you signed in; identifies your session on the server Strictly necessary 30 days (or until logout)
csrf Protects forms against cross-site request forgery Strictly necessary Session
lang Remembers the interface language you chose Preference 1 year
country, city Remembers the country and city you selected for browsing Preference 1 year
theme Light or dark theme Preference 1 year
consent Stores your cookie choices so we do not ask again Strictly necessary 12 months
pow / Turnstile token Human verification when posting, registering or messaging Strictly necessary Minutes
rid Random request identifier used for rate limiting and abuse prevention Strictly necessary Session

Local storage keys: theme, recent_searches, recently_viewed, draft_listing (your unsaved listing form), dismissed_banners. Service-worker cache: static assets and the offline shell of the app.

Strictly necessary cookies and preferences cannot be switched off in our banner because the Service would not work without them; you can still delete them in your browser.

3. Third-party cookies and identifiers

Provider Purpose Category Control
Cloudflare (__cf_bm, cf_clearance, Turnstile) Bot protection, security, CDN Strictly necessary —
Google AdSense (web, non-subscribers only) Displaying and measuring advertising; Google and its partners may use cookies to serve ads based on your visits to this and other sites Advertising Consent banner / GPC / Pro subscription / Google Ads Settings
Adsterra (web, non-subscribers only) Displaying and measuring advertising; may set cookies and read device information Advertising Consent banner / GPC / Pro subscription
Google AdMob (mobile apps, non-subscribers only) Displaying advertising in apps using the device advertising identifier Advertising App consent dialog / device settings ("Limit ad tracking", "Reset advertising ID")
Travelpayouts Drive (our own public pages only, never on users' listings) Turning links to travel brands into partner links and attributing bookings; may set cookies Advertising Consent banner ("Decline" — the script is not loaded)
Polar (checkout pages) Payment session, fraud prevention Strictly necessary on checkout pages —
YouTube / Vimeo (embedded video on EXPO booths and articles) Video playback; loaded only after you press play (privacy-enhanced embed) Functional Do not press play

We do not use Google Analytics or any cross-site tracking pixel. Traffic statistics are computed from our own server logs in aggregated form.

If you are in California or another US state with a privacy law, the use of advertising cookies may be considered "sharing" of personal information. You can opt out through the banner, by enabling Global Privacy Control (GPC) in your browser — we treat a GPC signal as an opt-out — or by subscribing to Pro, which removes third-party advertising entirely.

Subscribers to Pro or Business plans do not see third-party advertising on the website or in the apps, and no advertising cookies are set for them.

5. How to control cookies

  • Our banner: choose "Accept all", "Only necessary" or customise. Reopen it from the footer link "Cookie settings".
  • Browser settings: every browser lets you block or delete cookies. Blocking strictly necessary cookies will prevent login and posting.
  • Mobile apps: in the app's Settings you can withdraw advertising consent; in iOS/Android system settings you can limit ad tracking or reset the advertising identifier.
  • Do Not Track / GPC: we honour the Global Privacy Control signal as an opt-out of advertising cookies. The older "Do Not Track" header has no agreed meaning and is not honoured separately.

6. Push notifications

Web push notifications require your explicit permission in the browser. The subscription (endpoint and keys) is stored on our servers until you disable notifications in Settings or in your browser. In the apps, a device token is stored while notifications are enabled.

7. Changes

We may update this policy when we add or remove tools. The version at the top indicates the current version.

8. Contact

Questions about cookies: [email protected].