Cookie Policy
1. Scope
This Cookie Policy describes cookies and similar browser-storage technologies that TradeBridge currently uses on the Platform (first-party cookies, localStorage, and sessionStorage where applicable).
It does not describe every personal-data processing activity. For broader processing, see the Privacy Policy (/privacy). Contractual rules for subscriptions, Orders, and payments remain in the Terms and Conditions (/terms).
This Policy reflects current implementation. If new non-essential analytics or advertising tools are enabled later, this Policy and consent controls will be updated before those tools are used.
2. Cookies and browser storage
Cookies are small text files a site stores on your device. TradeBridge also uses browser localStorage and, in limited cases, sessionStorage for preferences and short-lived UI helpers.
Server logs (for example IP addresses in application logs) are not cookies; they are covered under the Privacy Policy (/privacy), not this page.
UTM or similar campaign parameters in a URL are request metadata unless persisted by TradeBridge. TradeBridge does not currently treat UTM values as cookies.
3. Essential cookies
Essential (strictly necessary) cookies support authentication continuity, security and abuse resistance, live customer-support sessions when opened, short-lived secure document viewing, and core Platform operation.
Essential cookies may be set when needed to provide those functions. Blocking all cookies in your browser can break sign-in, support chat, secured document access, and related features.
Active first-party essential cookies include: refreshToken (authenticated session refresh); mb_did (device identifier for security and abuse resistance); mb_cs_session (live human-support session when chat is used); and tb_doc_access (short-lived authorized document/PDF access when you open secured documents).
4. Authentication and session continuity
When you sign in, TradeBridge may set an HttpOnly refreshToken cookie so the Platform can renew your authenticated session without exposing the refresh credential to page JavaScript.
In production, that cookie is configured with Secure and SameSite attributes where applicable. Its lifetime follows the Platform refresh-session configuration (longer when “remember me” applies; shorter otherwise).
Access credentials used for API calls are held in the application’s in-memory session state for the browsing session — not as a long-lived access-token cookie listed here. Non-secret localStorage hints (such as session or trader flags) may exist for UX only and do not store payment card numbers or refresh tokens.
Signing out and clearing site cookies ends the cookie-backed refresh session according to Platform logout behavior.
5. Language preferences
mb-locale remembers your selected language (Arabic or English) so the interface can load in that language. It is a preference cookie (also mirrored in localStorage under the same key for the locale store).
Language switching continues to work without any analytics or advertising cookies. Cookie max-age for mb-locale is one year as configured in the product.
6. Customer support sessions
When you use live human support, the Platform may set an HttpOnly mb_cs_session cookie scoped to the support-session API path. It keeps support-session authentication context for the live chat window (about four hours) and is not a permanent public transcript cookie.
Support content and retention of support communications are governed by the Privacy Policy (/privacy). Opening the FAQ/assistant alone does not by itself create a permanent marketing profile cookie.
7. Secure document access
tb_doc_access is a short-lived HttpOnly cookie used so your browser can load authenticated customer documents (for example invoices/PDFs) on same-origin document routes. It expires quickly (about five minutes) and is not a tracking or advertising cookie.
It exists only to authorize document delivery for a signed-in customer session and is cleared or expires after that short window.
8. Consent preferences
After first interaction (or a short idle fallback), TradeBridge may show a cookie notice with an Accept control and links to this Cookie Policy and the Privacy Policy.
Accepting stores a local acknowledgment flag mb_cookie_consent with value “1” in localStorage so the notice is not shown again on every visit. The current UI does not offer a separate “Reject” control or a granular category preference center, because TradeBridge does not currently activate non-essential analytics or advertising cookies.
Essential cookies described above may still be required for the Platform to function even if you never click Accept. Clearing site data removes the acknowledgment and may show the notice again.
9. Local and session storage
localStorage may hold: language preference (mb-locale); cookie-notice acknowledgment (mb_cookie_consent); non-secret auth session/trader hints; and optional remembered-login convenience data if you choose that option. It does not store full card PAN/CVV.
sessionStorage may hold short-lived UI helpers for the tab — for example a cached country code for phone-dial defaults (mb_geo_country) and certain in-app tab/UI continuity keys. These are not advertising identifiers.
Closing the tab clears sessionStorage. Clearing browser site data clears localStorage items for this origin.
10. Third-party service cookies
When you are redirected to or interact with a provider-hosted payment service (for example hosted card Checkout when enabled, such as Stripe Checkout when that path is active), that provider may set its own cookies or similar technologies on its domains under its own privacy and cookie policies.
TradeBridge does not control those third-party cookies and does not treat them as TradeBridge first-party cookies. Simple footer links to external sites (including social profiles) are ordinary navigation links and do not by themselves plant social-media tracking pixels on TradeBridge.
11. Non-essential analytics and advertising
TradeBridge does not currently use non-essential analytics or advertising cookies unless such tools are actually enabled and disclosed through the consent controls and an updated policy.
No Google Analytics, Meta Pixel, TikTok Pixel, Hotjar, Clarity, or similar advertising/analytics pixels are currently active on the Platform. Internal operational dashboards used by operators are not customer-facing marketing cookies.
If non-essential analytics or advertising tools are enabled in the future, this Policy and consent controls will be updated before use as required.
12. Cookie retention
Retention follows configured lifetimes: refreshToken according to refresh-session settings; mb-locale about one year; mb_did about 400 days; mb_cs_session about four hours when live support is used; tb_doc_access about five minutes when secured documents are opened; mb_cookie_consent until you clear site data; sessionStorage for the browser tab only.
Exact durations are implementation-defined and may be adjusted for security; this Policy is updated when material changes occur.
13. Managing cookies
You can control cookies through your browser settings (block, delete, or restrict). You can change language in the product UI. You can clear localStorage/site data to remove the consent acknowledgment and preference stores.
TradeBridge does not currently provide an in-product tool to manage each cookie individually by category, because non-essential analytics/advertising categories are not active.
Some authentication and security cookies are configured with attributes such as HttpOnly, Secure in production, and SameSite where applicable.
14. Effects of disabling cookies
Because current TradeBridge cookies are primarily essential or preference-related, blocking all cookies may interrupt login and session continuity, language persistence, live support sessions, secured document viewing, and related Platform features.
Rejecting or not acknowledging the cookie notice does not itself remove essential cookies required for security and core operation. There is no separate “reject analytics” control while analytics cookies are not active.
15. Relationship with the Privacy Policy
This Cookie Policy focuses on cookies and browser storage. Personal-data categories, purposes, retention, rights, and processors are described in the Privacy Policy (/privacy).
Read this Policy together with the Terms and Conditions (/terms) where relevant to Platform use.
16. Policy updates
We may update this Cookie Policy when cookie or storage behavior changes — including if non-essential analytics or advertising tools are introduced. The version and “last updated” date on this page identify the current text.
Material changes that introduce non-essential cookies will be accompanied by updated disclosure and consent controls before those tools are used.
17. Contact us
For Cookie Policy or privacy questions: support@tradebridge-tb.com, or use Contact Us (/contact).