What cookies are, and why be1crypto.com uses them
A cookie is a small text file your browser stores and hands back on the next request. That handoff is the only reason be1crypto.com can keep you signed in between the markets page and the order ticket. This policy also covers technologies doing the same job by other means: local storage, session storage, IndexedDB, pixels and mobile app identifiers.
A cookie cannot read files on your computer, see your other tabs, or run code. It can carry a session identifier, which is why ours is set HttpOnly, Secure and SameSite: page scripts cannot read it, it never travels over plain HTTP, and it is not sent from other sites. What we collect and why sits in our privacy policy, and your account contract is in the terms and conditions.
The four categories, and what each one costs you
Every cookie we set belongs to exactly one of four categories. Three of them are off when you arrive and stay off unless you turn them on.
Strictly necessary
Sign-in, session integrity, fraud checks and load balancing. They run without consent because no logged-in session exists without them, and they carry no advertising payload.
Functional
Remembers your language, chart theme, default market pair and support-chat thread. Declining costs you convenience, not access.
Analytics
Aggregate measurement: which screens people abandon, how long an order ticket takes to load, whether a fix worked. Identifiers are pseudonymous, never joined to your verification record.
Marketing
Campaign attribution and ad measurement. The only category where a third party could see activity across sites, which is why it is opt-in.
Full cookie inventory
This is the complete list, not a sample. Names beginning b1c_ are ours; the rest belong to a named third party. Where a lifetime says Session, the cookie dies when you close the browser. We audit the table quarterly and on any release that adds a vendor.
| Category | Cookie | Purpose | Duration | Party |
|---|---|---|---|---|
| Strictly necessary | b1c_session | Holds your authenticated session so you stay signed in between the markets page and the order ticket | Session | First-party |
| Strictly necessary | b1c_csrf | Signs every form and order request so another site cannot submit one on your behalf | Session | First-party |
| Strictly necessary | b1c_consent | Stores which categories you accepted, plus the timestamp and policy version | 12 months | First-party |
| Strictly necessary | b1c_rgn | Records the regulatory region serving you, so the correct disclosures and asset list load | 30 days | First-party |
| Strictly necessary | __cf_bm | Bot-management check at the CDN edge that separates human traffic from scripted abuse | 30 minutes | Third-party (Cloudflare) |
| Functional | b1c_locale | Remembers your language, number format and time zone | 12 months | First-party |
| Functional | b1c_theme | Remembers chart theme, candle interval and density preference | 12 months | First-party |
| Functional | b1c_pairs | Remembers your last-viewed market pair and watchlist column layout | 6 months | First-party |
| Functional | ss_ticket | Links the support chat widget to your open ticket so you are not asked to repeat yourself | 30 days | Third-party (support desk) |
| Analytics | b1c_aid | Rotating pseudonymous analytics ID that counts unique sessions without naming you | 13 months | First-party |
| Analytics | b1c_perf | Samples page-load and order-submit latency so we can see slow paths in the terminal | 7 days | First-party |
| Analytics | _ga | Aggregate page and funnel measurement with IP truncation enabled and ad signals disabled | 13 months | Third-party (Google Analytics 4) |
| Marketing | b1c_ref | Records which campaign or partner link brought you here, so attribution is credited once | 30 days | First-party |
| Marketing | _fbp | Measures whether a social ad led to a registration; set only after you accept marketing | 90 days | Third-party (Meta) |
| Marketing | li_fat_id | Conversion measurement for professional-network campaigns; set only after you accept marketing | 30 days | Third-party (LinkedIn) |
Third-party cookies and who sets them
A third-party cookie is set by a domain other than be1crypto.com while you are on our pages. We keep the list short, because each entry is another company with its own retention practice. Every vendor below is under a written data processing agreement, and none receives your verification documents or balances.
- Cloudflare
- Our CDN and bot filter. One 30-minute cookie tells a human apart from a scripted login attempt. It carries no profile and is never used for advertising.
- Google Analytics 4
- Loads only after you accept analytics, with IP truncation on and Google Signals disabled, so the data cannot be pushed into ad audiences.
- Support desk provider
- Powers the chat widget. Its cookie keeps one conversation attached to one ticket, and loads only when you open the widget.
- Meta and LinkedIn
- Loaded only with marketing consent, and only to measure whether an ad produced a registration. Until you accept, the scripts are not fetched at all.
Local storage, session storage and pixels
Browser storage is not a cookie and does not expire on its own. It stays on your device until you or the site clears it, and it is never sent automatically with requests.
| Key | What it holds | Lifetime |
|---|---|---|
| b1c.draft-order | An unsent order ticket, so a refresh does not wipe what you typed | Until submitted or cleared |
| b1c.chart-drawings | Trend lines and levels you drew on a chart, stored on your device only | Until you clear site data |
| b1c.instruments | Cached market metadata such as tick size and minimum order size, so the terminal opens fast | 24 hours, then refetched |
| b1c.watchlists (IndexedDB) | Your saved watchlists when you use the platform signed out | Until you clear site data |
We never place private keys, seed phrases, passwords or authentication tokens in local storage. Anything there is readable by page scripts, so it holds only data harmless in the wrong hands. Tracking pixels fire only with marketing consent, and our mobile apps use OS-level identifiers under the same four categories. The wider security model is on the security page.
Where we stand on device fingerprinting
Fingerprinting means identifying a browser from its own characteristics, such as fonts, canvas rendering, screen size and installed plugins, without storing anything on the device. It is used across the industry to rebuild advertising profiles after someone clears cookies. We do not do that, and we do not permit a vendor to do it through our pages.
We do compute a coarse device signal for security: browser family, operating system, screen class, language and time zone, hashed into a risk score at login and before a withdrawal. It flags a password arriving from an unfamiliar machine in an unfamiliar country. That runs on legitimate interests, not consent; the signal is kept 18 months and is never sold, shared with an ad network, or used to re-identify you. Our control set maps to the NIST Cybersecurity Framework, so the distinction is auditable rather than a matter of our word.
Managing your choices on be1crypto.com
Three routes change a decision made here, all reaching the same preference record:
- The banner. Accept all, Reject all and Manage preferences sit on the first layer with equal visual weight. Reject all is one click, not three.
- Cookie settings in the footer. On every page, including this one, with your current choices preselected.
- Inside your account. Settings, then Privacy, then Cookies and tracking. Choices saved while signed in follow you to other devices.
Turning a category off stops that collection immediately: the matching cookies expire on the next page load, and any analytics identifier tied to your sessions is deleted within 30 days. Strictly necessary cookies cannot be switched off, because without them the site cannot authenticate you. With no cookies you can still read live markets and how it works, but not hold a signed-in session.
Browser-level controls
Browser settings override anything we do, and they apply to every site you visit. Menu wording shifts between versions, so treat these as current paths, not permanent ones.
Google Chrome
- Settings, Privacy and security, Third-party cookies
- To clear: Delete browsing data, Cookies and other site data
Safari
- macOS: Safari, Settings, Privacy, Manage Website Data
- iOS: Settings, Safari, Block All Cookies
Mozilla Firefox
- Settings, Privacy and Security, Enhanced Tracking Protection
- Custom blocks cross-site cookies only
Microsoft Edge
- Settings, Cookies and site permissions, Manage and delete cookies
- Tracking prevention: Basic, Balanced or Strict
One warning worth stating plainly: blocking all cookies blocks the strictly necessary ones too. Sign-in then fails, or you are logged out on every navigation and two-factor prompts repeat. Blocking only third-party cookies costs you nothing here, because every cookie your session needs is first-party.
Do Not Track and Global Privacy Control
Do Not Track
The DNT header was never standardized: its working group closed without agreeing what a site must do on receiving one, so two sites honoring DNT can behave in opposite ways. We do not treat DNT alone as a withdrawal of consent. If your browser sends DNT, use cookie settings or GPC instead.
Global Privacy Control
GPC is different: it has a defined meaning and legal recognition. We treat it as an opt-out of sale and of sharing for cross-context behavioral advertising under California law, and as a withdrawal of consent for analytics and marketing under the EU regime. It applies on the first request, before any non-essential script loads. The signal travels with the browser, so it works per device; if you are signed in, we write the opt-out to your account too. The California Attorney General explains the right in the CCPA guidance, and the consent standard we apply for EU and UK visitors is set out at gdpr.eu.
How consent is recorded, renewed and withdrawn
A choice writes one consent record: the categories you accepted, the UTC timestamp, the policy version shown to you, the consent string, and a truncated IP address showing the region it came from. It is kept three years as evidence that we asked properly, then deleted, and it is the only thing the banner writes before you decide.
Some things deliberately do not count as consent. Scrolling is not consent. Continuing to browse is not consent. Closing the banner with the X is not consent, and leaves every optional category off. Pre-ticked boxes are not used anywhere in the flow.
How long a choice lasts
- 12 months, then we ask again. Acceptances and rejections both last the full year, so declining does not mean being asked again on your next visit.
- Sooner, if something material changes. Adding a vendor or a category, or using existing data for a new purpose, resets consent for the affected categories rather than inheriting the old answer.
- Immediately, if you clear cookies. The record lives in b1c_consent, so clearing site data deletes it and the banner returns as if you were new.
Withdrawing is as easy as granting, which is the legal test and also the fair one. Reopen cookie settings, switch a category off, save. Withdrawal is not retroactive: it cannot un-send data collected while consent was valid, but it stops future collection and deletes or aggregates the associated analytics records within 30 days. For data already gathered, use the rights process in the privacy policy.
Changes to this cookie policy
Each revision carries a version number and effective date, shown at the top of this page. A minor correction updates the page and the date. A change affecting what is collected, or who receives it, resets the relevant consents and re-prompts, so an old answer is never stretched to cover a question you were not asked. Nothing here alters our risk disclaimer, which you should read before trading.
Questions about cookies
Write to privacy@be1cryptos.com or support@be1cryptos.com, call +1 (888) 555-0142, or open a ticket through the contact page. Postal mail reaches our privacy team at 24 Exchange Plaza, Suite 1900, New York, NY 10005, United States. For a question about a specific cookie, tell us your browser and version: that is usually the difference between a setting and a bug.