Cookies
Last updated
On this page7 sections
In short
This site sets four kinds of cookie, and every one of them does a job you asked for: keeping you signed in, showing the right thing in the header, letting a conversation with the assistant continue, and proving to our forms that you are a person.
There are no advertising cookies and no analytics cookies on this site. Nothing here follows you to another site, builds a profile of you, or is shared with an ad network. That is also why you are not being made to dismiss a consent banner before you can read anything: there is nothing to consent to beyond what makes the site work.
What a cookie is
A cookie is a small piece of text a site asks your browser to keep and send back on your next request. It is how a website can tell that two requests came from the same browser — which is what makes it possible to stay signed in rather than typing a password on every page. A cookie cannot read your files, run a program or see anything else you do.
The cookies this site sets
better-auth.session_token- Keeps you signed in. Set when you sign in, deleted when you sign out, and expires after thirty days. It cannot be read by JavaScript, and in production it carries the
__Secure-prefix, so it is only ever sent over an encrypted connection. Set only for people who hold an account. vo_account- A marker that says "someone is signed in on this browser", so the header can show Your account instead of Sign in without the page having to know who you are. It holds no identity and grants no access — on its own it will only ever send you to a sign-in screen. Thirty days.
vo_ask- A random identifier so a conversation with the assistant can continue across messages, and so a browser that abuses it can be blocked. It is sent only to the assistant's own address and never on an ordinary page request, cannot be read by JavaScript, and lasts a year. It carries no name, no account and no address.
- Cloudflare's cookies (
__cf_bm,cf_clearanceand similar) - Set by Cloudflare, which sits in front of this site and runs the Turnstile check on our forms and on the first question you put to the assistant. They tell automated traffic from people. We do not control their names or lifetimes; Cloudflare's own documentation does.
That is the complete list for viaottawa.ca. If you find a cookie on this site that is not described here, please tell us at info@viaottawa.ca — we would want to know.
Cookies set somewhere else
Two things take you off this site, and what happens there is governed by their own notices:
- Stripe, when you pay for a plan or open the billing portal. The payment pages are Stripe's, on Stripe's own address, and the cookies there are theirs.
- A business's own website, when you follow a link from a listing. That site sets whatever it sets.
A map on a listing page loads its tiles from OpenFreeMap. It does not set a cookie, but your browser does contact them directly when a map comes into view — the privacy policy covers what that means.
Turning them off
Every browser lets you see the cookies a site has set, delete them, and block new ones — usually under Settings, then Privacy. You are welcome to do that here.
Blocking or clearing them does not stop you reading the site: the directory, the guides and search all work with no cookies at all. What stops working is anything that needs to know this is still you — you will be signed out, a conversation with the assistant will start fresh, and the bot check on our forms may refuse to complete, which will stop you submitting one.
Changes to this page
The date at the top is the date this list last changed. If we ever add a cookie, this page is updated in the same change that adds it — and if we ever add one that is not needed to make the site work, we will ask you first.
Questions about this page?
Write to us and a person answers by email. If you are asking about a listing, send us its address on the site and we can act on it faster.