Easebourne Scouts & Guides

Cookies

Last updated: 13 September 2026

Easebourne Scouts & Guides sets only the cookies it needs to operate. It sets no analytics, advertising, or cross-site tracking cookies. If the operator has enabled third-party sign-in (for example, Google) and you use it, that provider may set cookies on its own domain when you sign in there; those are governed by the provider's policies, not ours.

Cookies we set

NamePurposeLifetime
authjs.session-token (or __Secure-authjs.session-token over HTTPS)Keeps organizers signed in after they sign in.Session
authjs.csrf-token (__Host-authjs.csrf-token over HTTPS)Prevents cross-site request forgery on the sign-in form.Short-lived
authjs.callback-url (__Secure-authjs.callback-url over HTTPS)Remembers where to return you after a successful magic-link sign-in.Short-lived
os_commitLets participants who already committed to a slot return and edit or cancel without re-entering their email. httpOnly; not readable from JavaScript.60 days
os_oauth_sessionRecords which organizer is signed in while connecting an app or AI assistant to their account. Sent only to the connection endpoints under /api/oauth.24 hours
os_oauth_interactionTies a pending connection request to the browser that started it, so only that browser can approve it.15 minutes
os_oauth_resumeCarries your allow-or-decline answer back to finish (or cancel) the connection.15 minutes

The three os_oauth_* cookies are set only when an organizer connects an app or AI assistant to their account, and each one is paired with a .sig cookie of the same name and lifetime holding the signature that proves we set it. All of them are httpOnly, limited to the page or endpoint that needs them, and marked Secure over HTTPS. See the privacy policy for what a connected app can reach and how to disconnect it.

Why there is no cookie banner

Every cookie above is strictly necessary to make the service work — for sign-in, to let a participant edit their own commitment, or to complete a connection an organizer asked for. Under GDPR/ePrivacy, strictly-necessary cookies do not require a consent banner. That is why you don't see a popup.

Related

See the privacy policy for what data we store and how to request a copy or deletion.