Cookie policy
Last updated August 12, 2026. This is our own document, written by the operator of BroomDesk. It is not legal advice from a law firm, and it is not a substitute for advice about your own business.
The short version
- Five cookies exist across the website and the product, and every one of them is strictly necessary. They keep you signed in, keep a portal or demo session alive, and run the cookie banner itself. The table below names all five.
- The banner appears if you are in the EEA or the UK, and also when we cannot tell which country you are in. Your answer is kept in one cookie on your device for 12 months.
- We measure page views with Plausible. It sets no cookie, stores nothing on your device, and builds no profile of you across sites, so it runs for every visitor and is not behind the banner.
- No advertising pixel, no session recording, no heatmap, no cross-site tracking. If we ever add one, it loads only after you switch marketing on, and it is listed here before it runs.
The summary is here to be read. The full text below is what applies.
The cookies that exist
This is the complete list, taken from the code rather than from a template. All five are strictly necessary, which means they are needed to deliver something you asked for, or to run the cookie choice itself, and no consent is required for them. None of them is used to track you on any other website.
| Cookie | Set where | What it does | Lifetime |
|---|---|---|---|
| bd_region | Every page of broomdesk.com except the embedded widgets, written by our edge middleware | Holds a single label, one of eea, uk, other or unknown, worked out from the country your request arrives with. The banner reads it to decide whether it has to appear. It carries no country name, no address and nothing that identifies you. | 24 hours, rewritten on the next visit |
| bd_cookie_choice | When you answer the banner, or save on the cookie preferences page | Records the two switches you set, analytics and marketing, plus the date you set them, so you are not asked again on every page. It is readable by the page rather than HTTP-only, because the script gate has to check it in the browser before anything optional could load. We keep no copy of it on our servers. | 12 months from the date you chose, then we ask again |
| sb-<project>-auth-token, sometimes split across .0 and .1 | The app, after you sign in | Holds your Supabase Auth session so you stay signed in between pages. Set by our authentication provider, Supabase. | Refreshed automatically while you are active, cleared when you sign out |
| bd_portal_session | The client portal at /portal, after a magic link is used | Signed session for a client of a cleaning business, scoped to the /portal path, HTTP-only, so the portal knows which customer you are without asking for a password. The business can end the session from their side. | 30 days, or until sign out |
| bd_demo_session | The demo sandbox at /demo, when you open it | Signed token that seats you in the shared demo workspace, scoped to the /demo path, HTTP-only. It carries no name, no email address and no account, because the demo has none to carry. | 1 hour |
Booking and calculator widgets embedded on a cleaning company's website set no cookies. They keep the state of the form in the page while you fill it in, and that is gone when the page closes.
Analytics
We use Plausible on the public pages of broomdesk.com to count page views: how many people read a page, and which site sent them. It runs for every visitor, including you, and it is loaded on the live site only, not in development or on preview deployments.
Plausible sits outside the banner on purpose, and this is the reason: it sets no cookie, it stores nothing on your device, it gives you no cross-site identifier and it builds no profile of you. There is nothing for you to consent to storing, because nothing is stored on your device. It does not run inside the app after you sign in.
If we ever replace it with something that does store data on your device or follow you across sites, that thing goes behind the analytics switch first, and this page says so before it runs. Server logs kept by our hosting provider are separate and are described in the privacy policy.
Advertising and tracking pixels
None. No Meta pixel, no Google Ads tag, no LinkedIn tag, no session recording, no heatmaps. The registry of third-party scripts the site is able to load is empty in the code, and the only function that can inject one asks that registry what your choice permits. If we ever add a pixel, it loads only after you switch marketing on, and it is listed here first.
The banner, and what it does
The banner appears if your visit looks like it comes from the EEA or the UK, and also when we cannot read a country for it at all, because showing a banner to someone who did not need one is a nuisance and skipping one for someone who did is a breach. Outside those places no banner is shown, and an answer you give anyway is still respected.
Accept all, only necessary, or choose what loads: whichever you press, the answer is written to bd_cookie_choice on your device and nowhere else. It is not stored against your account, it is not sent to any other company, and it is not logged. After 12 months it stops counting and you are asked again, so a choice you made once does not follow you forever.
Changing your choice
Open the cookie preferences page. It shows what this browser has chosen, when, and whether it still counts, and it saves a new answer with JavaScript switched off. You can also clear cookies for broomdesk.com in your browser settings, which removes the choice and the region label along with everything else. Blocking cookies entirely means the app cannot keep you signed in, the client portal cannot recognise you, and the banner has nowhere to record your answer, so it asks again on every visit.
Third-party pages we link to, such as Stripe's hosted checkout, run their own cookies under their own policies once you are on them.
Questions
Questions about cookies, or something you saw in your browser that is not listed here. Email support@broomdesk.com, or use the contact form. We reply within one business day.
BroomDesk is operated by Amortoae Petru PFA (CUI 52361814), Romania. Postal address and registration details are on any invoice we issue you through Stripe.