Summary
TrucklineMP uses a small number of cookies and browser storage items that it needs to work and to stay secure. We only use analytics cookies if you choose "Accept" in the cookie banner. Saying no doesn't limit anything on the site.
We don't use advertising cookies, and we don't track you across other websites.
You can change your choice at any time with the privacy settings link in the footer. If your browser sends a Do Not Track or Global Privacy Control signal, we don't start analytics, whatever you chose in the banner.
1. Cookies we need to run the service
These are needed for sign-in, security, fraud prevention and features you ask for, so we don't ask for your consent to use them.
Sign-in and security
| Cookie | What it does | How long it lasts |
|---|---|---|
__Secure-better-auth.session_token | Keeps you signed in across TrucklineMP sites | 7 days, renewed while you use it |
__Secure-better-auth.better-auth-passkey, tlmp_passkey_proof | Complete a passkey check | 2 to 5 minutes |
tlmp_steam_nonce | Links a Steam sign-in back to your browser | 30 minutes |
__Host-tlmp_qr_* | Links a QR sign-in code to the browser showing it | 3 minutes |
tlmp_mfa_trust | Remembers a trusted device so you can skip 2FA codes | 30 days |
Fraud prevention
| Cookie | What it does | How long it lasts |
|---|---|---|
tlmp_did | A random device ID used only to detect ban evasion and duplicate accounts. We store only a hashed copy with your account. We never use it for advertising or analytics. | 1 year |
Website features
| Cookie | What it does | How long it lasts |
|---|---|---|
queue_id | Holds your place in the queue when the site is busy | 24 hours |
maintenance_bypass | Lets staff use the site during maintenance | 24 hours |
tlmp-locale, tlmp-i18n-preview | Remember your language and translation preview | Up to 1 year |
beta_nda_state, beta_nda_identity | Complete the Discord step when you accept the beta NDA | 10 minutes to 1 hour |
tlmp_analytics_consent | Remembers whether you accepted or rejected analytics | 1 year |
Set by Cloudflare
| Cookie | What it does | How long it lasts |
|---|---|---|
__cf_bm, cf_clearance | Protect the site from bots and attacks | 30 minutes to 1 year, set by Cloudflare |
Beta sites use the same cookies. Some have a beta prefix.
2. Analytics cookies (only if you accept)
| Cookie | What it does | How long it lasts |
|---|---|---|
ph_* | PostHog analytics: tells repeat visits apart and groups page views into sessions | Up to 1 year |
PostHog runs on our own servers. It is not a third-party advertising service. The Privacy Policy (section 3.13) explains what it records.
If you withdraw consent, we stop analytics and delete these cookies. If a ph_ cookie is still there, you can clear it in your browser.
3. Other browser storage
We also save some data in your browser's local and session storage. Most of it is used only for the purpose listed here:
- your theme and language (
tmlp-theme,tlmp-locale); - your last sign-in method (
tl_last_login_method); - drafts of support tickets and applications, so you don't lose your work;
- anonymous poll voting credentials (
polls-v2:capability:*). These let you vote anonymously, so clearing them may stop you voting or changing your vote; - developer console settings and your saved API requests (never your API key);
- navigation data about your own account, such as your permissions and companies (session storage, cleared when you close the tab);
- which banners and pop-ups you have dismissed, and simple settings such as your download platform;
- PostHog session data, only after you accept analytics.
We don't use browser storage for advertising, fingerprinting or cross-site tracking.
4. Third-party content
Some pages load content from other services straight into your browser. When that happens, the service may set its own cookies or receive your IP address and browser details under its own privacy policy:
- Cloudflare Turnstile, the human check on sign-in pages;
- Spotify, Apple Music and Discord widgets in profiles and company pages;
- YouTube, Vimeo and Twitch videos after you click them (YouTube preview images load straight away);
- images hosted elsewhere, including in posts, galleries and event banners;
- map fonts from OpenMapTiles on the live map;
- the DMCA.com badge in our footer.
5. Managing cookies
-
Analytics: use the privacy settings link in the footer.
-
Everything else: you can block or delete cookies in your browser settings.
If you block the cookies in section 1, sign-in and security features won't work. Clearing
tlmp_diddoesn't stop ban-evasion checks: they also use other signals (see the Privacy Policy).
6. Changes and contact
When we change how we use cookies, we update this policy and its version. If you have questions, email [email protected].
What changed in this version
- Complete cookie list. Added the passkey, Steam sign-in, QR sign-in, trusted-device, language and beta NDA cookies, and Cloudflare's
cf_clearance. Addedqueue_iddetails. - Browser storage. Listed the local and session storage we use.
- Third-party content. Listed Turnstile, OpenMapTiles and the DMCA.com badge.
- Session replay. Removed the claim that session replay is always on. Analytics, including any session replay, remains optional.