This notice explains how the joinb28.app marketing site uses cookies and similar local storage, what they are for, and how you can control them. It is short on purpose, because the site does very little: its main job is to let you submit an email for early access. As things stand today, the site sets only the strictly necessary cookies needed to work and to remember your choice, and no analytics or other optional cookies at all. The B28 wallet app is separate and local-first, so most of what follows is about the website, not the app.
This Cookie Notice is published by B28 OÜ, a private limited company registered in Tallinn, Estonia (EU), registered seat at [registered street address to be confirmed before publication], Estonian Commercial Register code [registry code to be confirmed before publication]. It should be read together with our Privacy Policy, which describes the wider context of how we handle personal data. We provide this information as required by the Estonian Information Society Services Act and Article 13 of the GDPR.
The current state, in one line
Right now, the only cookies and similar local storage the site uses are strictly necessary ones. We are not currently running any analytics, measurement, advertising, or other non-essential cookies, and none are set without your consent. If that ever changes, we will only set non-essential cookies after you have given consent through the cookie banner, and we will update this notice first. This matches what our Privacy Policy says.
What cookies and local storage are
A cookie is a small text file that a website asks your browser to store on your device. When you return, the browser can send that file back, so the site can remember something between page views or visits. Similar technologies, such as local storage and session storage, also keep small amounts of information in your browser without using a traditional cookie file. We refer to all of these together as "cookies" in this notice.
Cookies can be set by the site you are visiting (first-party) or, in some cases, by a different provider whose code runs on the page (third-party). They can last only for the current visit (session cookies) or stay for a set period (persistent cookies). We tell you below which kind we use and for how long.
The legal rule we follow
Under Article 5(3) of the EU ePrivacy Directive (2002/58/EC), as implemented in Estonia, we may store or read information on your device without your consent only where it is strictly necessary to provide a service you have asked for, such as serving the page you requested securely. For anything that is not strictly necessary, including analytics and measurement, we must obtain your prior consent before the cookie is set.
Where consent is needed, it must meet the standard set by the GDPR and the European Data Protection Board: it must be freely given, specific, informed, and unambiguous, given by a clear affirmative action. That means, in practice, that:
- We do not set non-essential cookies until you have actively accepted them. Nothing optional runs in the background while you decide.
- There are no pre-ticked boxes and no "consent by continuing to browse". Silence or simply scrolling is not consent.
- Rejecting is as easy as accepting. The banner gives a reject option with the same prominence as accept, so you can decline in one click.
- Consent is granular: you can accept or refuse the optional category without being forced to accept everything to use the site.
- You can withdraw or change your choice at any time, as easily as you gave it (see "How to control or withdraw your choice" below), and withdrawing does not affect anything that was lawfully done before.
- Declining optional cookies does not block access to the site or the early-access form.
If you only ever see the strictly necessary cookies, that is because, as noted above, those are the only ones we currently use. The consent banner exists so that the moment we introduce anything optional, your choice is asked for first and honoured.
The categories we use
We keep the site lean. We do not use cross-site advertising or tracking cookies, do not build advertising profiles of you, and do not sell your data.
Strictly necessary (always on, no consent required)
These are needed for the site to work and to keep it secure. They handle things like remembering your cookie choice, basic security and abuse prevention, and load balancing so pages serve reliably. The site cannot function properly without them, so under Article 5(3) of the ePrivacy Directive they do not require consent. They do not track you across other websites.
Analytics and other optional cookies (not currently used; consent-gated if introduced)
We do not currently run analytics, measurement, advertising, or any other optional cookies. None are set today. If, in future, we decide to measure, in aggregate, how the site is used (for example, which pages are visited and whether the early-access form works), we would use a privacy-respecting tool configured to avoid cross-site tracking and to minimise or de-identify the data. In that case we would set those cookies only after you accept them through the banner, you could decline without losing access to the site, and we would update the table below and this notice before any such cookie went live.
The cookies we set, their purpose, and duration
The table below lists the cookies and similar storage the site sets today. All of them are strictly necessary. We do not list any analytics or advertising cookies because we do not set any. If we add an optional cookie in future, we will add it here, with its purpose and duration, before it runs.
- Cookie consent choice (strictly necessary): remembers your cookie preference so we do not ask again on every page, and so we can honour a rejection. Stored for up to 12 months.
- Security and abuse prevention (strictly necessary): helps protect the site and the early-access form against abuse and automated attacks. Session, or up to 24 hours.
- Session and load balancing (strictly necessary): keeps your connection routed to a working server during your visit. Session only, cleared when you close the browser.
Exact technical names and durations can shift slightly as we update the site or our hosting provider, but the categories and the consent rules above do not change. We will keep this list current.
How to control or withdraw your choice
You can reopen the cookie banner or preference control at any time to change your choice, including withdrawing consent to any optional category if one is ever active. Because we currently set only strictly necessary cookies, there is nothing optional to switch off today, but the control remains available so your choice always rules.
You can also control cookies through your browser. Most browsers let you see what is stored, delete cookies, and block new ones. Look in your browser's settings under privacy or cookies. The help pages for Chrome, Safari, Firefox, and Edge are useful starting points. Note that blocking strictly necessary cookies may stop parts of the site from working, and clearing cookies will also clear your saved cookie preference, so you may be asked again.
The wallet app is local-first
This notice covers the website. The B28 wallet app is a separate, non-custodial app that runs on your own device. Your keys and recovery phrase are generated and stored on your device, behind your device's biometrics, and never leave it. The app does not rely on website cookies, and we never receive your keys or recovery phrase. For how the app and the website handle personal data more generally, see our Privacy Policy.
Changes to this notice
We may update this Cookie Notice as the site or our providers change, and in particular before we ever introduce an optional cookie. When we do, we will revise the content here. If a change is significant, we will make that clear on the site.
Contact
If you have questions about cookies or this notice, contact us at hello@joinb28.app. You can also reach us at B28 OÜ, Tallinn, Estonia. For security matters, write to security@joinb28.app.