Version 1.1 · Published 2 October 2026

Cookies and device storage

Your choice

Necessary storage operates to deliver requested services. Optional Google Analytics runs only on organiser pages that use it, after you choose Accept analytics. Reject non-essential cookies is equally available. Close without changing leaves optional Analytics off for a new visitor. You can revisit your choice using Cookie settings in the legal footer on every BMSAQ surface. Withdrawal disables further Analytics, deletes the known Analytics cookies and reloads a page that has loaded Analytics so its listeners stop. Other open BMSAQ tabs check for a changed preference once a second and on focus. A request already sent cannot be recalled.

The consent choice lasts 180 days and is shared across bmsaq.com subdomains. No advertising category is enabled by this choice. We do not infer consent from browsing or from signing in. Declining Analytics does not prevent requested sign-in, registration, basket, payment or Challenge functions.

Cookies and storage

Name or keyProvider / sitePurpose and categoryDuration / party
bmsaq_consent_v1 cookieBMSAQ, all current sitesNecessary: remembers the versioned analytics choice180 days; first party, shared across subdomains
_ga, _ga_57SZDRNC6K cookiesGoogle Analytics on organiser pagesOptional analytics: visitor/session measurement, only after analytics consentConfigured one-year maximum, refreshed by use; first-party cookies with processing by Google
firebaseLocalStorageDb, firebaseLocalStorageFirebase Authentication, organiser and ChallengeAuthentication: stores the requested signed-in account/sessionDepends on session choice and sign-out; no fixed cookie expiry; first-party IndexedDB
firebase-app-check-database, firebase-app-check-store; _grecaptchaFirebase / Google reCAPTCHA, protected servicesSecurity: app verification and anti-abuse for requested sign-in, registration, account/Challenge and checkout servicesToken expiry is provider-issued; no fixed browser-key expiry established; first-party IndexedDB/localStorage, Google security requests
firebase-heartbeat-database, firebase-heartbeat-storeFirebase SDK, service pagesSDK client/version heartbeat for requested backend servicesSDK-managed; exact removal interval not verified; first-party IndexedDB
firebase:host:bmsaq-ee763-default-rtdb.europe-west1.firebasedatabase.appFirebase, organiserRemembers the database connection hostPersistent localStorage; no explicit expiry established; first party
bmsaq:last-activity:<uid>BMSAQ, authenticated organiser/ChallengeAuthentication/security: last activity for session handlingPersistent localStorage; no fixed browser-key expiry; first party
bmsaqSessionVerificationReasonBMSAQ organiserSession verification status, read and removed at sign-inSessionStorage; first party
bmsaq:registration-operation:<uid>BMSAQ organiserRegistration operation/idempotency stateSessionStorage, removed on completed operation; first party
bmsaq-region, bmsaq-region-suggestion-dismissed; existing bmsaq-language readBMSAQ public siteFunctional: remembers an explicitly chosen region or dismissed suggestion; reads an existing language preferenceLocalStorage; no automatic expiry in the current script; first party
bmsaq-store-basket-v1BMSAQ organiser legacy storeRequested basket contents, where this older basket is presentPersistent localStorage; current public basket uses page memory; first party
bmsaq_feedback_v2, older bmsaq_feedbackBMSAQ, all current sitesFunctional: remembers an explicit feedback dismissal/submission so the invitation is not repeatedCurrent dismissal one day, submission 180 days; older cookie lifetime depends on when set; first party
bmsaq-feedback-participantBMSAQ, requested feedbackFunctional/anti-abuse: identifier created when you submit optional feedbackLocalStorage with no fixed expiry; first party

This inventory distinguishes measured runtime storage from route-specific source-confirmed keys. Some keys appear only after a requested sign-in, registration or feedback action. A current SDK can create internal stores without an active signed-in account. Storage left by an older release is not evidence that optional collection still runs. Older @firebase/performance/config and @firebase/performance/configexpire keys were present in an existing browser profile; current sampled production routes did not load Firebase Performance or Analytics SDKs.

Payment and external services

Stripe payment pages are opened only when you request secure checkout. Stripe controls its own payment, fraud-prevention and device technologies on those pages; its notice is available there. No purchase is required to reject BMSAQ Analytics. Choosing Google’s external translation sends the requested public page to Google; the translation confirmation explains this before navigation. Those external services have their own storage and privacy information.

Security and control

Google reCAPTCHA Enterprise / Firebase App Check remains active for protection of requested services independently of optional Analytics. It processes device/interaction information for app verification and anti-abuse and can use provider security storage. This is not included in Accept analytics and does not enable advertising tracking. Read the Google privacy and terms links shown by the security widget. The necessity of particular provider operations remains under review; we do not claim that everything a provider calls security is automatically exempt.

Clearing necessary browser storage may sign you out or remove your saved preferences. Ask info@bmsaq.com about a key or provider operation. Our Privacy Notice explains suppliers, international processing, retention policy and your rights.

Full Privacy Notice · Pupil notice · Schools and families · Purchase terms · Organiser terms · Cookies and storage