Cookies
Cookies and browser storage.
The application uses server-managed cookies for account access and a browser-tab preference for the illustrative finance example. The live host and provider inventory remain deployment checks.
Account storage
Account cookies support server-side sign-in. The application requests HttpOnly, SameSite=Lax cookies and Secure cookies on HTTPS. The installed SDK uses project-specific names; final live names, attributes and provider session settings still need verification.
Optional tools need a real choice
Any optional analytics or marketing tools must have the appropriate choice mechanism. A decorative consent banner is not a working preference control.
Current application source
The example-market preference uses sessionStorage key biocng.marketing-market for this tab. Account access uses server-managed Supabase session cookies. Enquiry forms do not require sign-in and save privately for review without sending an automatic email. No analytics or advertising scripts are included in the reviewed application source; the deployed host, Cloudflare and providers need their own actual inventory.
Changing the example
Use the Example market selector in the finance preview to change the choice or return to Choose a market. A blocked storage setting does not prevent the example from working during the current visit.
Current application preference
The example market.
- Name
biocng.marketing-market- Storage
- Browser session storage
- Value
- IN, GB, US, DE or an empty selection
- Purpose
- Choose the fictional market and currency shown in the finance example. It does not set a real project’s currency.
- Duration
- The tab’s session, managed by your browser
Account sessions
Staying signed in.
- Name
sb-…-auth-tokenis the installed SDK’s project-specific naming pattern; longer values can use numbered chunks. Actual deployed names still need verification.- Purpose
- Keep account access and refresh tokens for server-side sign-in. The application requests HttpOnly, SameSite=Lax cookies and Secure cookies on HTTPS; page scripts cannot read the HttpOnly cookies.
- Duration
- The current SDK requests a 400-day maximum cookie age. Cookie storage and provider session validity are separate; actual live token and session settings still need verification.
- Sign out
- Sign-out clears this browser’s session cookie and ends its provider session. Other devices have separate sessions.
- Live service
- Confirmed-account access, email delivery, HTTPS and the final cookie inventory remain deployment checks.
Operator and contact
BIO CNG operates the BioCNG.ai pilot. For enquiries or data requests, email [email protected]. Keep bank details, identification numbers and confidential documents out of enquiries.
Pilot preparation
Checks still open.
Live customer collection requires the remaining policy and deployment checks below.
- The deployed host, providers and any additional cookies or scripts need an actual inventory.
- Final account cookie names, attributes and provider session settings await live verification.
- Any future measurement or optional tools require their own purpose, provider, duration and choice review.
- Notice requirements must be reviewed for the agreed pilot scope; no compliance certification is claimed.