Last updated 21 September 2026

Cookie policy

Which cookies Bonim sets, and when. The short version is that these public pages set none at all, and signing in sets the few that keep you signed in.

Who we are

This site is operated by 24-7 LOGISTICS AND SERVICES UK LTD, company number 10426878, registered office 1st Floor North Westgate House, Harlow, Essex, CM20 1YS. Questions about this policy go to [TBC: data protection contact name] at [TBC: data protection contact email].

These pages set no cookies

The marketing pages, the sign-in page and an agency’s public careers pages set no cookies whatsoever. Not a preference, not a session identifier, nothing.

That is not a policy we intend to keep to — it is a property of how the site is built. The code that renders a public page has no route to write a cookie at all, so setting one would take a change to the architecture rather than a change of mind.

Signing in sets a few

When you sign in successfully we set cookies that keep you signed in as you move between pages. Their names begin “sb-”, and a long one may be split across several numbered cookies because of browser size limits.

  • What they hold: a token proving you signed in, and a second token used to renew the first one quietly so you are not signed out mid-task.
  • How long they last: the sign-in token is short-lived and renewed as you use the site. The renewal token lasts until you sign out or stop using it.
  • What they are not: they carry no advertising identifier, they are not shared with anybody, and they are not used to work out anything about you beyond whether you are signed in and as whom.

What we do not set

There is no analytics cookie, no advertising or retargeting pixel, and no social media button that phones home. Opening a page here loads nothing from any other company. We also store nothing in your browser’s local storage.

Watch a demo is an ordinary link.

Book a call, and the cookies Cal.com sets

Book a call is the one place another company’s code runs on this site, and it runs only if you click it. Until then nothing is loaded from Cal.com and they are not contacted. That is deliberate: the usual way to add a booking calendar loads it on every page for every visitor, whether or not they ever wanted a call.

When you do click, the calendar opens in a frame that belongs to Cal.com, and Cal.com sets cookies of its own inside it. When we checked on 21 September 2026 there were three: __cf_bm, which Cloudflare uses to tell people from bots, and __Secure-next-auth.csrf-token and __Secure-next-auth.callback-url, which are security cookies belonging to Cal.com’s own sign-in system. They are set on cal.com, not on our domain. We cannot read them and we set none of our own, before or after. Cal.com may change what it sets, and its own privacy policy covers what it does with them.

If you would rather not load it, open the link in a new tab instead of clicking — that takes you to the same calendar on Cal.com’s own site, with nothing of theirs running on ours — or write to us and we will arrange a time by email.

Why there is no cookie banner

Cookies that are strictly necessary to provide a service you have asked for do not require consent under the Privacy and Electronic Communications Regulations. Keeping you signed in after you have chosen to sign in is that case, and it is the only cookie we set.

The booking calendar is the same kind of thing: it loads because you clicked a button asking for it, and the cookies Cal.com sets there are ones it needs to show it to you safely.

If that ever changes — if we add analytics, or anything from another company that loads without you asking for it — you will get a banner asking first, and this page will change with it.

Controlling them

Every browser lets you see the cookies a site has set, delete them, and block them. Doing that here is safe, with one consequence worth knowing: deleting or blocking these cookies signs you out, and blocking them entirely means you cannot sign in at all, because staying signed in is exactly what they do.

If you would rather ask us than change a setting, [TBC: data protection contact email] reaches somebody.