Legal
Legal · Cookies

Cookie & Local Storage Notice

Last updated: Effective: Status: Draft

Draft: pending legal review. This is a working draft. It is not legal advice and is not yet in force. Highlighted text in brackets is a placeholder to fill in ([like this]) or an open business decision ([Decision: like this]). Purple "Drafting note" boxes are for reviewers and must be removed before publishing.

This notice lists every cookie and browser-storage item Bonus Round uses, on our own website and inside games that run our SDK. The list is short on purpose.

The short version

  • On bonusround.io we set one cookie to keep you signed in, and one more, br_ref, only if you open someone's referral link.
  • In games, our SDK sets no cookies. It keeps a random anonymous ID and a list of recent round times in the game site's local storage, to cap and count ads.
  • No analytics, no advertising pixels, no third-party ad trackers, no fingerprinting.

Cookies and local storage, briefly

A cookie is a small file a website asks your browser to keep and send back on later visits. Local storage is a similar feature that lets a page's scripts keep data in your browser. Neither leaves the site it belongs to: data saved by one website can't be read by another.

On bonusround.io

NameTypePurposeLastsCategory
br_sessionFirst-party cookie. HttpOnly (scripts can't read it), SameSite=Lax, and Secure on HTTPS.Keeps you signed in to the dashboard. It holds a random token; we store only a hash of it.30 days, or until you log outStrictly necessary
br_refFirst-party cookie. HttpOnly, SameSite=Lax, and Secure on HTTPS.Set only when you open someone’s referral link (/r/…). Remembers the referral code and when you arrived, so the person who invited you gets credit if you sign up. The first link you open wins. Deleted when you create an account. Not used for advertising or tracking across sites. See the Referral Programme Terms.30 days, or until you sign upFunctional
br.billing.accountLocal storageRemembers which ad account you last chose on the billing page.Until you clear site dataFunctional (preference)

For visitors who aren't signed in, the only cookie we set is br_ref, and only when they open a referral link. The public preview on our home page limits free use with a salted hash of your IP address, stored on our server, not with a cookie.

Inside games that use our SDK

Our SDK runs inside the game's own web page, so these items are stored under the game's website, not under bonusround.io. A game on one site can't read the values saved by a game on another site.

NameTypePurposeLasts
br_pidLocal storage on the game's siteA random anonymous player ID (for example p_k3x9…). Used only to apply frequency caps, count and de-duplicate ad events, and detect invalid traffic. Not linked to a name, email, account or device fingerprint, and never used for targeting.Until the player clears the site's data
br_roundsLocal storage on the game's siteTimes of the sponsored rounds shown in the last hour, so the SDK can apply the game's hourly cap.Rolling: entries older than one hour are dropped

The SDK sets no cookies and doesn't read the game's cookies. If the browser blocks local storage, the SDK still works; frequency caps are then less precise.

No-storage mode and Global Privacy Control. A game can load the SDK in no-storage mode, for example until the player consents. The SDK also honours the browser's Global Privacy Control signal. In both cases neither item above is written, and each ad request uses a fresh random ID.

Consent in the EU, EEA and UK. Rules such as the ePrivacy Directive and the UK PECR require consent for storing information in a browser unless it is strictly necessary for a service the user asked for. Publishers are responsible for getting any consent their players need, using the SDK's no-storage mode until then. See the Publisher Terms. [Decision: Legal view on whether frequency-capping storage needs consent]

Drafting note (remove before publishing)

Verify each of these against the shipped code before publishing; they were in progress when this draft was written: the SDK's no-storage mode and its Global Privacy Control handling.

Third parties

WhoWhereWhat happens
StripeStripe's own pages (Checkout, the billing portal and Connect onboarding), when you pay or set up payoutsStripe sets its own cookies on its own domains, for example for fraud prevention and to remember your session. Our pages don't load Stripe's scripts. See Stripe's cookie policy.
Google FontsEvery page on bonusround.ioYour browser downloads our fonts from Google's servers, which receive your IP address and user agent. Google Fonts doesn't set cookies. [Decision: Whether to self-host fonts so no visitor data goes to Google]

The SDK doesn't load Google Fonts or any other third-party resources in games.

What we don't use

If we ever add any of these, we will update this notice first and ask for consent where the law requires.

Your choices

Contact

Questions: aidan@dreampark.app. For more about how we use personal data, read our Privacy Policy.