idbuddy
For companies
For associations
For members
Log in
Membership TermsTerms and ConditionsPrivacy PolicyData Processing Agreement

Cookie Policy

Last updated: 19 September 2026 · Version 1.0

This page lists everything idbuddy stores on your device or reads back from it, what each thing is for, and how long it stays. It covers idbuddy.io and the app, administrator and operations sites at app.idbuddy.io, admin.idbuddy.io and ops.idbuddy.io.

Swedish law covers more than cookies here. Chapter 9, Section 28 of the Electronic Communications Act (2022:482) applies to anything stored in or read from your equipment, so the entries below include browser local storage as well.

Section 17 of our Privacy Policy at idbuddy.io/privacy says the same things in the context of everything else we do. Where the two disagree, this page is the more detailed one and we will correct the other.

In a nutshell

Organisations and members. In short: the six things worth knowing before the rest.
  • One thing on this page is optional, and you are asked about it. Everything else is needed to sign you in and keep the service running.
  • Nothing here is used for advertising, and nothing is shared with an ad network or a data broker.
  • Usage measurement is off until you say yes, and the page addresses it reports are stripped of anything identifying.
  • The sign-in pages run a bot check, which sets its own entries while it works.
  • Every entry is listed by name, with what it is for and how long it lasts. There are no third-party entries.
  • You can reopen the panel and change your answer whenever you want, and a browser that refuses on your behalf is taken at its word.

1. What you are asked, and what you are not

Organisations and members. In short: One thing is optional and you are asked about it. Everything else is needed to run the service and is not.

We ask about one thing: measuring how the site is used. Nothing is switched on before you answer, and answering nothing leaves it switched off.

Everything else in section 2 is there because the service cannot work without it. We do not ask permission for those, because consent is not the legal basis for them: signing you in, remembering which language you chose and carrying you through an invitation link are things you asked for by using the service.

We use nothing for advertising, and nothing that follows you to other websites.

2. Strictly necessary

Organisations and members. In short: Six entries, all first party, none of them optional.
  • idbuddy.locale. A cookie and a matching local storage entry holding the language you picked. It lasts 365 days and is scoped to the registrable domain, so one choice carries across every site above.
  • The sign-in session. A cookie named after our database project, sometimes split across two entries, set when you sign in and removed when you sign out. It can last up to 400 days.
  • idbuddy_terms_ok. A cookie holding the identity of a signed-in person who has already accepted the current terms and privacy policy, so the check does not run on every request. It lasts one hour, is not readable by scripts, and is only a short cache: publishing a new version reaches you within the hour.
  • pending_invite_id and pending_invite_link_id. Cookies holding the invitation you clicked, so that after signing in you land in the organisation that invited you. They last between five and ten minutes.
  • idbuddy_admin_selected_company. A local storage entry in the administrator tool remembering which organisation you last had open. It is written when you first open the tool and stays until you clear your browser storage.
  • Cookies beginning KP_. Set by the bot protection on the sign-in pages, described in section 4.

3. Usage measurement

Organisations and members. In short: Off unless you say yes. Vercel Web Analytics, with page addresses stripped of anything identifying.

If you accept, we load Vercel Web Analytics, which counts page views so we can see which parts of the service get used. It does not use cookies to identify you and does not build a profile.

Before any event is sent, the page address is stripped: every identifier, every token and the whole query string are replaced. What is sent is the shape of the path, so a page about one organisation is indistinguishable from a page about another.

Your answer is kept in a first-party cookie named idbuddy_consent for 180 days. Declining stores the refusal, so you are not asked again until it expires.

4. Bot protection

Organisations and members. In short: Runs on the sign-in pages only, to stop automated attacks on accounts.

The sign-in pages are protected by Vercel BotID, which uses Kasada. It examines characteristics of the browser to tell a person from a script, and sets cookies beginning KP_ while doing so.

It runs when a sign-in is attempted and nowhere else. We treat it as strictly necessary, because an unprotected sign-in page is an open invitation to credential stuffing, and protecting accounts is part of the service rather than an extra.

5. Changing your mind

Organisations and members. In short: The same panel, whenever you want it.

Accepting or declining is not final. The consent panel is reachable from the notice, and reopening it lets you change the answer at any time. The change takes effect immediately.

Clearing your browser's cookies for our sites also clears the answer, and you will be asked again on your next visit.

Withdrawing consent is as easy as giving it, which is what Article 7(3) GDPR requires.

6. Automated signals

Organisations and members. In short: A browser that says no on your behalf is taken at its word.

If your browser sends a Global Privacy Control signal, we treat that as a refusal. You are not shown the notice, and the measurement never loads.

Global Privacy Control is a setting in some browsers and privacy extensions that tells every site at once that you do not want to be tracked. Honouring it is required by several United States state laws and is not in conflict with anything in the EU.

7. Changes to this page

Organisations and members. In short: The version and date at the top say which one you are reading.

We update this page when something we store changes. A change that makes something optional, or adds a new purpose, means asking you again rather than assuming the old answer still applies.

For questions about anything on this page, write to info (at) idbuddy.io.

idbuddy

Membership made simple - no app required.

Support
FAQHelp us improve
Contact us
info (at) idbuddy.ioLinkedIn
Privacy PolicyOur HistoryTerms and ConditionsData Processing AgreementCookie Policy
© 2026 idbuddy · Byte Buddies AB, Malmö. All rights reserved.