LEGAL
Cookies and storage
Every cookie and every piece of browser storage this product sets, what it is for, and why none of them needs a consent banner.

Why there is no cookie banner
Because there is nothing to consent to. UK law requires consent for cookies that are not strictly necessary — advertising, analytics, profiling — and this product sets none of them.
There is no Google Analytics, no advertising pixel, no session recording, no A/B testing tool and no third-party script of any kind on these pages. Every item below exists because something you asked for would not work without it.
The complete list
- better-auth.session_token (Cookie)
- Keeps you signed in, whether as a business or as a customer. Without it every page would ask for your password again.
Kept for: Until it expires or you sign out - bexus_shop (Cookie)
- Remembers which of your businesses you are working in, if you run more than one. It grants nothing on its own: it is a key looked up against the permissions your session already proves, so a value naming a business you cannot administer selects nothing.
Kept for: Until you choose a different business or sign out - bexus_booking_access (Cookie)
- Lets you manage an appointment you booked without an account. It holds the personal link from your confirmation email, so that the link itself does not have to stay in the address bar where it would end up in browser history and in screenshots.
Kept for: 30 minutes - bexus.demo.v1 (Browser storage (sessionStorage))
- Remembers what you changed in the barbering demonstration, so a refresh does not throw your work away. It never leaves your tab and is never sent to us.
Kept for: Until you close the tab or press Reset - bexus.wcdemo.v1 (Browser storage (sessionStorage))
- The same thing for the window-cleaning demonstration, which keeps its own separate state. It never leaves your tab and is never sent to us.
Kept for: Until you close the tab or press Reset
How the cookies are set
All three cookies — and there are only three — are HttpOnly, so no script on the page can read them, and SameSite=Lax, so they are not sent from another site’s request. On any deployment served over HTTPS they also carry Secure, so a browser will not send them over a plain connection. The booking-management cookie is additionally scoped by path, so it is not attached to a single request outside the page it is for.
Turning them off
Your browser can block or delete any of them. Blocking the session cookie means you cannot stay signed in; blocking the booking-management cookie means you will need your confirmation email each time you want to change an appointment. Nothing else is affected, because there is nothing else.
What we do with the data behind all of this is in the privacy notice.
Who we are
- Trading name
- Bexus Systems, a UK sole trader established in England and Wales.
- Trader
- Carl Guinney
- Contact
- hello@bexusbooking.com
- Trading address
- 30 The Perrings, Bristol, BS48 4YL