Cookie and Similar Technologies Policy
Last updated: July 19, 2026
This Policy explains how la2base.com (the “Website”, “we”, “us” or “our”) uses cookies, browser local storage (localStorage) and similar technologies. This Policy supplements the Website’s Privacy Policy.
1. Cookies and Similar Technologies
Cookies are small text files stored in a user’s browser by a website or a third-party service. Cookies can be used to maintain an authenticated session, provide security, remember preferences and, with the user’s consent, collect statistics about use of the Website.
The Website also uses localStorage, which is browser-based local storage. localStorage data are not cookies and are not automatically transmitted to the server with each request. However, consent requirements may also apply to these technologies.
Cookies may be:
session cookies, which are deleted when the browser session ends;
persistent cookies, which remain until their expiry date or until the user deletes them;
first-party cookies, which are set by la2base.com;
third-party cookies, which are set or accessed by external service providers.
2. Strictly Necessary Cookies
These cookies are required to provide functions requested by the user, maintain authentication and security, and remember the user’s cookie choices. They are used without separate consent only to the extent necessary for the relevant function.
Blocking them in the browser may prevent certain Website functions, including account sign-in, from working correctly.
Name | Type and attributes | Retention | Purpose |
|---|---|---|---|
| First-party; HttpOnly; Secure; SameSite=Strict | 15 minutes | Authentication token used to verify the user’s session. It is unavailable to client-side JavaScript because of the HttpOnly attribute. |
| First-party; HttpOnly; Secure; SameSite=Strict | Up to 30 days; the period may be renewed when the session is refreshed | Used to securely refresh an authenticated session after the |
| First-party; HttpOnly; Secure; SameSite=Strict | 5 minutes or until the two-factor authentication check is completed | Temporary token required to complete two-factor authentication. |
| First-party; SameSite=Lax | 400 days | Stores whether the user permits analytics technologies or chooses strictly necessary technologies only. |
| First-party | 1 year | Stores the selected interface language: Russian ( |
3. Browser Local Storage
Key | Retention | Purpose |
|---|---|---|
| Until the preference is changed or browser data are deleted | Stores the selected appearance setting: |
| 400 days or until the choice is changed or browser data are deleted | Duplicates the user’s analytics choice so that the consent-management interface can operate. |
| Until the draft is saved or explicitly cleared, or browser data are deleted | Stores drafts created in the editor. The |
4. Analytics Technologies
Analytics technologies are not strictly necessary. They are used only after the user chooses “Accept all”. Refusing analytics does not restrict the core functions of the Website.
4.1. Google Analytics 4
The Website uses Google Analytics 4, measurement ID G-ZKD9TD53T2, to obtain statistics about visits to and use of the Website.
Google may process information about the device and browser, approximate location, referral source, pages visited and actions performed on the Website.
Name | Default retention | Purpose |
|---|---|---|
| Up to 2 years | Used to distinguish users. |
| Up to 2 years | Persists session state for the Google Analytics 4 property used by the Website. |
The actual retention period may be shorter because of browser settings, device restrictions or changes to the provider’s configuration.
For more information, see Google Analytics cookie usage and the Google Privacy Policy.
4.2. Yandex Metrica
The Website uses Yandex Metrica, tag number 10081075. Session Replay, click maps, link tracking and accurate bounce-rate measurement are enabled.
The service may process technical information about the browser and device, approximate location, referral source, pages visited and interactions with the Website.
Name or pattern | Typical retention | Purpose |
|---|---|---|
| 1 year | Used to distinguish visitors. |
| 1 year | Stores the date of the visitor’s first visit. |
| 20 hours | Determines whether the visitor uses an ad blocker. |
| 60 minutes | Checks whether Yandex Metrica cookies can be set correctly. |
| 30 minutes | Supports Session Replay. The |
| 1 day | Limits the number of requests sent by Yandex Metrica. |
Depending on the browser, region, session state and service features, Yandex may also create or use other cookies and localStorage or sessionStorage entries, including: _ym_fa, _ym_ucs, gdpr, is_gdpr, is_gdpr_b, yandexuid, yuidss, ymex, usst, i, yabs-sid, _ym10081075_lastHit, _ym10081075_lsid, _ym10081075_reqNum and _ym_retryReqs.
The current set and retention periods are determined by the service provider.
For more information, see Yandex Metrica cookie usage and the Yandex Privacy Policy.
5. Registration and Sign-In Through Telegram
The Telegram Login Widget, provided by Telegram, is available on the registration and sign-in pages and uses the @La2base_bot bot.
To display the widget, the browser loads a resource from telegram.org. As a result, Telegram may receive technical information normally transmitted with a network request, including the IP address, browser and device information, and the date and time of access.
Telegram may also use cookies or similar technologies on its own domains.
If the user voluntarily chooses registration or sign-in through Telegram and approves authentication, Telegram may provide the Website with:
the Telegram account ID;
first name and last name;
Telegram username, where available;
profile photo URL, where available;
authentication date;
a cryptographic signature (
hash) used to verify the authenticity of the response.
The Website does not receive the user’s Telegram password, private messages, contact list or telephone number through the Telegram Login Widget.
After successful authentication, the Website uses the standard access_token and refresh_token cookies. No separate first-party cookie specifically for Telegram is created.
Telegram determines the types and retention periods of technologies used on its own domains. For more information, see the Telegram Login Widget documentation and the Telegram Privacy Policy.
6. Registration and Sign-In Through Discord
The Website may offer registration and sign-in through Discord using OAuth 2.0.
When this method is selected, the user is redirected to Discord, where Discord displays the requested permissions and allows the user to approve or reject the authorisation request.
Discord may receive technical information about the request and may use cookies or similar technologies on its own domains.
When the minimum identify permission is used, Discord may provide the Website with:
the Discord account ID;
username and display name;
Discord tag or discriminator, where applicable;
avatar and other basic public profile information available under the
identifypermission;interface language and certain technical account attributes where returned by the Discord API.
If the Website also requests the email permission and the user grants it, Discord may provide the email address associated with the account and its verification status.
The Website does not receive the user’s Discord password, private messages, server list, contacts or other information unless separate permission for that information has been requested and granted.
The short-lived authorisation code and Discord OAuth token are used by the server to complete sign-in and obtain the information authorised by the user.
They should not be stored in storage accessible to client-side JavaScript and are not used as the primary la2base.com session.
After successful authentication, the Website creates the standard access_token and refresh_token cookies. No separate first-party cookie specifically for Discord is created.
The user may reject authentication on the Discord page. Previously granted access may be revoked through Discord’s authorised-app settings.
For more information, see the Discord OAuth2 documentation and the Discord Privacy Policy.
7. Legal Bases
Strictly necessary technologies are used to provide functions requested by the user, maintain an authenticated session, secure the Website and remember the user’s cookie choices.
Google Analytics and Yandex Metrica are used on the basis of the user’s prior consent. Users may refuse analytics without losing access to the core functions of the Website and may withdraw previously given consent at any time.
Processing associated with registration or sign-in through Telegram or Discord is initiated when the user selects the relevant authentication method.
Further information about the purposes and legal bases of processing, recipients, international transfers, personal-data retention and user rights is provided in the Website’s Privacy Policy.
8. Managing Consent and Deleting Data
On the first visit, users may allow analytics technologies or choose strictly necessary technologies only.
The choice may be changed at any time using the “Cookie Settings” button in the Website footer. Withdrawing consent must be as easy as giving it.
Withdrawal does not affect the lawfulness of processing performed before consent was withdrawn. After the choice is changed, the Website stops initiating new analytics loads on subsequent page loads.
Third-party cookies already stored in the browser may remain until they expire. To remove them immediately, the user must delete the relevant website data through the browser settings.
Cookies and localStorage data can also be deleted or blocked through browser settings. Menu names may vary depending on the browser version:
Chrome: Settings → Privacy and security → Third-party cookies / Site data;
Firefox: Settings → Privacy & Security → Cookies and Site Data;
Safari: Settings → Privacy → Manage Website Data;
Edge: Settings → Cookies and site permissions.
Blocking access_token and refresh_token prevents use of an authenticated account.
Blocking analytics technologies does not prevent use of the core functions of the Website.
9. Changes to This Policy
We may update this Policy when the technologies, service providers or legal requirements change. The current version will be published on this page together with its effective date.
If a change requires new consent, consent will be requested before the relevant processing begins.
10. Contact
The controller responsible for the processing of personal data is: Alexander Ott.
Address: comming...
Privacy contact email: [email protected].
You may also contact us using the contact form.
