Skip to content

Cookie Policy

The few cookies Shipbell uses: strictly necessary cookies that keep you signed in and protect sign-in, and one cookie that remembers the appearance you pick on a board. No analytics, advertising or tracking.

Last updated

In short

  • We use only strictly necessary cookies, and one preference cookie that remembers the appearance you pick on a board.
  • We use no analytics, advertising or tracking cookies. The only cookie from another company is the one Google's sign-in button stores in the admin, described below.
  • Every cookie belongs to one Shipbell site only, and is sent only over HTTPS.

What cookies are

A cookie is a small piece of text that a website stores in your browser and that the browser sends back to that website. Websites can also store data in your browser in other ways, such as local storage. This policy covers both.

In the admin (app.shipbell.app)

__Host-sb_admin keeps you signed in to the admin.

  • Type: strictly necessary.
  • Lifetime: your session ends after 12 hours without use, and at the latest after 7 days.
  • Content: a random session token. We store only a hash of it.
  • Set by our server, only for app.shipbell.app. Scripts on the page cannot read it.

__Host-sb_gis protects your sign-in with Google's button, described below.

  • Type: strictly necessary.
  • When it is set: when a page or dialog with Google's button opens, before you choose a way to sign in.
  • Lifetime: 10 minutes, renewed while that page or dialog stays open and in view.
  • Content: a random value that ties Google's answer to this browser.
  • Set by our server, only for app.shipbell.app. Scripts on the page cannot read it.

__Host-sb_oauth protects your sign-in when you continue with Google from a button that takes you to Google's own page, as on iPhone and iPad or where Google's button cannot load.

  • Type: strictly necessary.
  • When it is set: only when you choose to continue with Google.
  • Lifetime: 10 minutes. It is removed when Google sends you back.
  • Content: random values that prove Google's answer belongs to the sign-in you started, and what you started it for. It is encrypted, so its content cannot be read, and any change to it is detected.
  • Set by our server, only for app.shipbell.app. Scripts on the page cannot read it.

The appearance you choose in the admin (System, Light or Dark) is kept in your browser's local storage, under the name "shipbell:color-mode". It is a preference. It stays until you change it or clear your browser's data for app.shipbell.app, and it is not sent to our servers.

On the sign-in and sign-up pages, in the dialog that asks you to confirm it is you when it offers Google, and in the dialog that connects Google in your security settings, the admin shows Google's own "Sign in with Google" button, which loads from Google when the page or dialog opens, even if you then use another way. Google's script stores a cookie named g_state for app.shipbell.app, which keeps the state of Google's sign-in button and is kept for up to 180 days, and Google receives technical data such as your IP address and browser details when the button loads. Google's privacy policy applies to what Google processes.

On boards

Each board has its own address on shipbell.app, and its own cookies. One board cannot read the cookies of another board.

__Host-sb_session keeps you signed in to a board after you sign in through the app.

  • Type: strictly necessary.
  • Lifetime: the session ends after 14 days without use, and at the latest after 30 days. It can also be ended earlier.
  • Content: a random session token. We store only a hash of it.
  • Set by our server, only for the board where you signed in. Scripts on the page cannot read it.

__Host-sb_sso_state protects your sign-in while you sign in to a board through the app.

  • Type: strictly necessary.
  • Lifetime: 10 minutes.
  • Content: a random value that proves the sign-in response belongs to the sign-in you started, and the board page to return to afterwards. It is signed, so any change to it is detected.
  • Set by our server, only for that board.

__Host-sb_theme remembers the appearance you pick on a board: System, Light or Dark.

  • Type: preference.
  • When it is set: only when you pick an appearance with the switch in the board's header, or when an app opens the board with an appearance already chosen. Our server never sets it.
  • Lifetime: one year when you pick an appearance; the note under the switch tells you so. When the appearance comes from a link from an app, the cookie lasts only until you close your browser.
  • Content: only the word system, light or dark. It does not identify you and is not a session.
  • Set by the board page itself, only for that board.

Our website, the API, the widget and the iOS package

  • shipbell.app, api.shipbell.app and widget.shipbell.app set and read no cookies.
  • The web widget in other websites sets no cookies. It keeps a report that has not been sent yet only in memory, while the page is open. The website that uses the widget may set cookies of its own; its own policy covers them.
  • The iOS package sets no cookies. It keeps reports that could not be sent yet on the device, protected by the device's file protection and left out of device backups, until they are sent. Reports that are still unsent after 30 days are deleted.

How our cookies are protected

  • All our cookies start with "__Host-". Browsers then send them only over HTTPS, and only to the exact site that set them, and no other site on shipbell.app can set or replace them.
  • Browsers do not send our cookies with requests that websites outside shipbell.app start in the background. They send them when you follow a link to a Shipbell page.
  • The session cookies cannot be read by scripts on the page.

Other companies

We set no cookies for other companies. Some forms may use a bot check from our network provider, which runs in your browser on those forms only. Apart from that check and Google's sign-in button in the admin, described above, our pages load no scripts, fonts or trackers from other companies.

Strictly necessary cookies do not need consent, because you cannot sign in, or sign in safely, without them. The appearance cookie is set only when you pick an appearance yourself, and the note next to the switch tells you that your choice is remembered in a cookie for one year. When the appearance comes from an app's link and you have not picked it, the cookie lasts only for your browser session. In the admin, your appearance setting is likewise stored only when you pick one. We set no other cookies, so there is nothing else to ask you about.

How to control cookies

  • You can see and delete cookies and local storage in your browser's settings at any time, and you can block them.
  • If you block the session cookies, you cannot sign in to the admin or to a board.
  • If you block the appearance cookie, your choice applies only to the page you are on, and the board otherwise follows your device's setting.

Changes and contact

We update this policy when our cookies change. The date at the top shows the current version. Questions: info@shipbell.app. Our Privacy Policy explains how we handle personal data.