Cookies
Last updated 30 September 2026
Draft
This is a starting template, not legal advice. The operator should fill in their details and have a lawyer review it before relying on it.
ChimeBee only uses cookies that are strictly necessary for it to work: to keep you signed in, to keep a guest connected to their stay, to protect forms, and to remember a language choice. There are no advertising, analytics or tracking cookies, and none from other companies, so there is nothing to accept or reject.
| Cookie | What it's for | How long |
|---|---|---|
| authjs.session-token (or __Secure-authjs.session-token) | Keeps a team member signed in. | Up to 30 days |
| authjs.csrf-token, authjs.callback-url | Protect the sign-in form against forged requests. | The browser session |
| ow_login_challenge | Remembers, for a few minutes, that the password was right while you enter your two-step code. | 5 minutes |
| oneweb_guest_session | Keeps a guest connected to their stay, so they can send requests. | Until checkout |
| oneweb_lang | Remembers the language a guest chose. | 1 year |
If you block these cookies in your browser, signing in and guest services won't work.
the company that operates this ChimeBee service