Cookie & Local Storage Notice
Draft: pending legal review. This is a working draft. It is not legal advice and is not yet in force. Highlighted text in brackets is a placeholder to fill in ([like this]) or an open business decision ([Decision: like this]). Purple "Drafting note" boxes are for reviewers and must be removed before publishing.
This notice lists every cookie and browser-storage item Bonus Round uses, on our own website and inside games that run our SDK. The list is short on purpose.
The short version
- On bonusround.io we set one cookie to keep you signed in, and one more,
br_ref, only if you open someone's referral link. - In games, our SDK sets no cookies. It keeps a random anonymous ID and a list of recent round times in the game site's local storage, to cap and count ads.
- No analytics, no advertising pixels, no third-party ad trackers, no fingerprinting.
Cookies and local storage, briefly
A cookie is a small file a website asks your browser to keep and send back on later visits. Local storage is a similar feature that lets a page's scripts keep data in your browser. Neither leaves the site it belongs to: data saved by one website can't be read by another.
On bonusround.io
| Name | Type | Purpose | Lasts | Category |
|---|---|---|---|---|
br_session | First-party cookie. HttpOnly (scripts can't read it), SameSite=Lax, and Secure on HTTPS. | Keeps you signed in to the dashboard. It holds a random token; we store only a hash of it. | 30 days, or until you log out | Strictly necessary |
br_ref | First-party cookie. HttpOnly, SameSite=Lax, and Secure on HTTPS. | Set only when you open someone’s referral link (/r/…). Remembers the referral code and when you arrived, so the person who invited you gets credit if you sign up. The first link you open wins. Deleted when you create an account. Not used for advertising or tracking across sites. See the Referral Programme Terms. | 30 days, or until you sign up | Functional |
br.billing.account | Local storage | Remembers which ad account you last chose on the billing page. | Until you clear site data | Functional (preference) |
For visitors who aren't signed in, the only cookie we set is br_ref, and only when they open a referral link. The public preview on our home page limits free use with a salted hash of your IP address, stored on our server, not with a cookie.
Inside games that use our SDK
Our SDK runs inside the game's own web page, so these items are stored under the game's website, not under bonusround.io. A game on one site can't read the values saved by a game on another site.
| Name | Type | Purpose | Lasts |
|---|---|---|---|
br_pid | Local storage on the game's site | A random anonymous player ID (for example p_k3x9…). Used only to apply frequency caps, count and de-duplicate ad events, and detect invalid traffic. Not linked to a name, email, account or device fingerprint, and never used for targeting. | Until the player clears the site's data |
br_rounds | Local storage on the game's site | Times of the sponsored rounds shown in the last hour, so the SDK can apply the game's hourly cap. | Rolling: entries older than one hour are dropped |
The SDK sets no cookies and doesn't read the game's cookies. If the browser blocks local storage, the SDK still works; frequency caps are then less precise.
No-storage mode and Global Privacy Control. A game can load the SDK in no-storage mode, for example until the player consents. The SDK also honours the browser's Global Privacy Control signal. In both cases neither item above is written, and each ad request uses a fresh random ID.
Consent in the EU, EEA and UK. Rules such as the ePrivacy Directive and the UK PECR require consent for storing information in a browser unless it is strictly necessary for a service the user asked for. Publishers are responsible for getting any consent their players need, using the SDK's no-storage mode until then. See the Publisher Terms. [Decision: Legal view on whether frequency-capping storage needs consent]
Verify each of these against the shipped code before publishing; they were in progress when this draft was written: the SDK's no-storage mode and its Global Privacy Control handling.
Third parties
| Who | Where | What happens |
|---|---|---|
| Stripe | Stripe's own pages (Checkout, the billing portal and Connect onboarding), when you pay or set up payouts | Stripe sets its own cookies on its own domains, for example for fraud prevention and to remember your session. Our pages don't load Stripe's scripts. See Stripe's cookie policy. |
| Google Fonts | Every page on bonusround.io | Your browser downloads our fonts from Google's servers, which receive your IP address and user agent. Google Fonts doesn't set cookies. [Decision: Whether to self-host fonts so no visitor data goes to Google] |
The SDK doesn't load Google Fonts or any other third-party resources in games.
What we don't use
- No analytics tools (such as Google Analytics) on our website or in the SDK.
- No advertising pixels, tags or third-party ad trackers, including in sponsored rounds.
- No cross-site cookies and no device fingerprinting.
If we ever add any of these, we will update this notice first and ask for consent where the law requires.
Your choices
- Signing out deletes your session cookie and ends the session on our server.
- Clearing site data in your browser's settings removes the cookie and local storage for that site. Clearing a game site's data resets its
br_pid, and the SDK will create a new, unrelated ID. - Blocking cookies for bonusround.io will stop you signing in to the dashboard. Blocking local storage for a game site won't stop the game or its ads from working.
Contact
Questions: aidan@dreampark.app. For more about how we use personal data, read our Privacy Policy.