BIMENT Cookie and Local Storage Notice
This notice forms part of the BIMENT Privacy Policy. It explains how Anhui Baimeng Technology Co., Ltd. uses browser local storage, session storage, and similar technologies on the BIMENT website.
1. Current Use
The website does not currently use cross-site advertising cookies, marketing-profiling cookies, or social-media tracking pixels. After a customer signs in, the website uses one strictly necessary session cookie to authenticate the customer.
| Name or category | Technology | Purpose | Retention | | --- | --- | --- | --- | | `biment_customer_session` | HttpOnly cookie on the API host | Authenticates the customer after sign-in; webpage scripts cannot read the session token | Up to 30 days; deleted on sign-out, token expiry, or when site data is cleared | | `biment:customer:session` | Browser local storage | Stores public account profile information and a sign-in status marker; it does not store a session token that can call the API | Up to 30 days; deleted on sign-out, token expiry, or when site data is cleared | | `biment:home-content:*` | Browser local storage | Caches published homepage content so the most recently loaded content can be shown during a network failure | Deleted when the page version changes or the user clears site data | | Administrator session | Administration-system session storage | Maintains administrator sign-in in the current browser session on an authorized management device | Up to 8 hours; deleted when the session closes, the administrator signs out, or the token expires | | Administration-interface preferences | Administration-system local or session storage | Stores table widths, pagination, open tabs, and unsubmitted editing drafts | Deleted when an administrator clears or overwrites the data, or when the browser clears it |
2. Sign-In Token Security
- Customer session tokens, passwords, SMS or email verification codes, Alibaba Cloud keys, and database passwords are not stored in browser local storage.
- The customer session cookie uses `HttpOnly`, `Secure`, and `SameSite=Lax`. By default, it is sent only to the `/api/v1` path on the API host. Cookie-authenticated requests that change data also verify the website origin.
- Customer and administrator tokens use different signing keys, different domains, and different storage areas. They cannot be substituted for one another.
- The website uses a Content Security Policy (CSP) to restrict script sources. The administration system additionally requires an authorized-device client certificate and account password.
- Do not remain signed in on a public device. Sign out after use and install browser security updates promptly.
3. How to Manage These Technologies
You can view or delete the data described above through your browser's site-data settings. Deleting sign-in data signs you out. Deleting cached public content or interface preferences does not delete your account or business records stored on BIMENT servers.
If we introduce non-essential analytics or marketing cookies, or new third-party tracking technologies in the future, we will first update this notice and provide a choice or obtain consent where required by law.
For more information about how BIMENT processes personal information, see the BIMENT Privacy Policy at https://www.biment.cn/en/legal/privacy-policy.
4. Contact Us
- Controller: Anhui Baimeng Technology Co., Ltd. (安徽百梦特科技有限公司)
- Privacy contact: service@biment.cn
- Telephone: Not currently available; please contact us by email
This English translation is provided so international users can understand the notice. If there is an inconsistency, the Chinese notice governs to the extent permitted by applicable law.
