Version 1.1 · Published 2 October 2026
Cookies and device storage
Your choice
Necessary storage operates to deliver requested services. Optional Google Analytics runs only on organiser pages that use it, after you choose Accept analytics. Reject non-essential cookies is equally available. Close without changing leaves optional Analytics off for a new visitor. You can revisit your choice using Cookie settings in the legal footer on every BMSAQ surface. Withdrawal disables further Analytics, deletes the known Analytics cookies and reloads a page that has loaded Analytics so its listeners stop. Other open BMSAQ tabs check for a changed preference once a second and on focus. A request already sent cannot be recalled.
The consent choice lasts 180 days and is shared across bmsaq.com subdomains. No advertising category is enabled by this choice. We do not infer consent from browsing or from signing in. Declining Analytics does not prevent requested sign-in, registration, basket, payment or Challenge functions.
Cookies and storage
| Name or key | Provider / site | Purpose and category | Duration / party |
|---|---|---|---|
bmsaq_consent_v1 cookie | BMSAQ, all current sites | Necessary: remembers the versioned analytics choice | 180 days; first party, shared across subdomains |
_ga, _ga_57SZDRNC6K cookies | Google Analytics on organiser pages | Optional analytics: visitor/session measurement, only after analytics consent | Configured one-year maximum, refreshed by use; first-party cookies with processing by Google |
firebaseLocalStorageDb, firebaseLocalStorage | Firebase Authentication, organiser and Challenge | Authentication: stores the requested signed-in account/session | Depends on session choice and sign-out; no fixed cookie expiry; first-party IndexedDB |
firebase-app-check-database, firebase-app-check-store; _grecaptcha | Firebase / Google reCAPTCHA, protected services | Security: app verification and anti-abuse for requested sign-in, registration, account/Challenge and checkout services | Token expiry is provider-issued; no fixed browser-key expiry established; first-party IndexedDB/localStorage, Google security requests |
firebase-heartbeat-database, firebase-heartbeat-store | Firebase SDK, service pages | SDK client/version heartbeat for requested backend services | SDK-managed; exact removal interval not verified; first-party IndexedDB |
firebase:host:bmsaq-ee763-default-rtdb.europe-west1.firebasedatabase.app | Firebase, organiser | Remembers the database connection host | Persistent localStorage; no explicit expiry established; first party |
bmsaq:last-activity:<uid> | BMSAQ, authenticated organiser/Challenge | Authentication/security: last activity for session handling | Persistent localStorage; no fixed browser-key expiry; first party |
bmsaqSessionVerificationReason | BMSAQ organiser | Session verification status, read and removed at sign-in | SessionStorage; first party |
bmsaq:registration-operation:<uid> | BMSAQ organiser | Registration operation/idempotency state | SessionStorage, removed on completed operation; first party |
bmsaq-region, bmsaq-region-suggestion-dismissed; existing bmsaq-language read | BMSAQ public site | Functional: remembers an explicitly chosen region or dismissed suggestion; reads an existing language preference | LocalStorage; no automatic expiry in the current script; first party |
bmsaq-store-basket-v1 | BMSAQ organiser legacy store | Requested basket contents, where this older basket is present | Persistent localStorage; current public basket uses page memory; first party |
bmsaq_feedback_v2, older bmsaq_feedback | BMSAQ, all current sites | Functional: remembers an explicit feedback dismissal/submission so the invitation is not repeated | Current dismissal one day, submission 180 days; older cookie lifetime depends on when set; first party |
bmsaq-feedback-participant | BMSAQ, requested feedback | Functional/anti-abuse: identifier created when you submit optional feedback | LocalStorage with no fixed expiry; first party |
This inventory distinguishes measured runtime storage from route-specific source-confirmed keys. Some keys appear only after a requested sign-in, registration or feedback action. A current SDK can create internal stores without an active signed-in account. Storage left by an older release is not evidence that optional collection still runs. Older @firebase/performance/config and @firebase/performance/configexpire keys were present in an existing browser profile; current sampled production routes did not load Firebase Performance or Analytics SDKs.
Payment and external services
Stripe payment pages are opened only when you request secure checkout. Stripe controls its own payment, fraud-prevention and device technologies on those pages; its notice is available there. No purchase is required to reject BMSAQ Analytics. Choosing Google’s external translation sends the requested public page to Google; the translation confirmation explains this before navigation. Those external services have their own storage and privacy information.
Security and control
Google reCAPTCHA Enterprise / Firebase App Check remains active for protection of requested services independently of optional Analytics. It processes device/interaction information for app verification and anti-abuse and can use provider security storage. This is not included in Accept analytics and does not enable advertising tracking. Read the Google privacy and terms links shown by the security widget. The necessity of particular provider operations remains under review; we do not claim that everything a provider calls security is automatically exempt.
Clearing necessary browser storage may sign you out or remove your saved preferences. Ask info@bmsaq.com about a key or provider operation. Our Privacy Notice explains suppliers, international processing, retention policy and your rights.
Full Privacy Notice · Pupil notice · Schools and families · Purchase terms · Organiser terms · Cookies and storage