Legal
Cookie Policy
How essential browser storage and optional measurement choices are handled.
Effective 15 July 2026
This Cookie Policy explains how the European Airsoft Federation (EAF) uses cookies, browser storage and similar technologies on its public website, administrator dashboard and User Portal. It should be read with the Privacy Policy. The English website is the principal version; translations are provided for convenience.
1. Who is responsible
The EAF is responsible for its use of storage and first-party analytics. Questions or requests can be sent to office@airsofteurope.com or through the contact page.
2. What cookies and similar technologies are
A cookie is a small text value stored by a browser. Local storage keeps a preference on the device without automatically sending it with every request. Session storage normally lasts until the browser tab or session is closed. Similar technologies may read or write identifiers or settings on a device. Dutch cookie rules can apply to all of these technologies, not only files named “cookies”.
3. Our categories
Strictly necessary and requested-function storage
This storage supports security, sign-in, language and theme preferences, remembering a cookie choice, and services specifically requested by the user. The website cannot provide some protected or preference-based functions without it. It is not used for advertising.
Optional first-party audience measurement
If audience measurement is enabled by an authorised EAF administrator, it remains off for a visitor until that visitor affirmatively allows analytics in Cookie settings. Refusing analytics does not limit access to the public website. The EAF does not use advertising cookies, cross-site tracking or commercial profiling.
External media
Gallery videos and other external media are not connected automatically. A placeholder is shown first. Only after you choose to load or play external content may the provider receive technical information and use its own cookies or similar technologies under its policies.
4. Storage used by the EAF website
| Name or type | Purpose | Typical lifetime | Category |
|---|---|---|---|
eaf-cookie-preferences-v1 (local storage) | Records whether essential storage and optional analytics were selected, the time of the choice and the applicable analytics-notice version. A material change invalidates the old choice and asks again. | Until removed in Cookie settings, replaced after a material notice change or cleared from the browser. | Necessary preference |
eaf.language (local storage) | Remembers the language chosen on that device. | Until changed or cleared. | Requested preference |
EAF_THEME_DEFAULT and EAF_THEME_MEMBER | Remember the public theme or authenticated member’s theme choice. | Up to 30 days; the member value is limited to the User Portal path. | Requested preference |
EAF_ADMIN and EAF_MEMBER | Maintain a secure authenticated session and help prevent session misuse. | Session cookie; server sessions also expire after configured inactivity and absolute limits. | Strictly necessary |
| First-party visitor and session identifiers | When analytics is enabled and consented to, distinguish visits without storing a name, email address or raw IP address as the identifier. | Visitor identifier no longer than 12 months; session identifier for the current session or limited inactivity window. | Optional analytics |
Exact names may change for security or technical maintenance. A replacement will keep the same limited purpose unless this policy and, where required, the consent request are updated first.
5. Information measured when analytics is allowed
The first-party system may record the date and time, pseudonymous visitor and session identifiers, page URL and title, page or article type, selected website language, referring site and broad traffic source, coarse country, device category, browser family, operating-system family, estimated session start/end and duration, page views, document downloads, clicks to external federation websites and contact-form submission counts.
“Anonymous visitor identifier” in dashboard wording means a randomly generated pseudonymous value, not proof of irreversible anonymity. It is not intended to reveal a person’s name. The EAF does not store raw IP addresses in the analytics record and does not send an IP address to a third-party geolocation service. Country is derived only from a trusted hosting or reverse-proxy country indication or a local privacy-preserving lookup when configured; otherwise it is recorded as unknown. Browser and operating-system values are reduced to broad families rather than retaining a complete user-agent string.
6. Exclusions and safeguards
Known bots and search-engine crawlers, authenticated administrator activity, and visits to localhost, development or staging hosts are excluded. Events are allowlisted, rate-limited and accepted only from the same website. Analytics records are kept in protected same-origin storage and are not exposed through the public content API. Statistics are aggregated for the dashboard and CSV export available to authorised administrators.
These controls reduce privacy risk but cannot guarantee that every automated visitor is detected or that a pseudonymous record could never relate to a person when combined with other information. The EAF therefore treats detailed analytics with appropriate data-protection safeguards.
7. Retention
Detailed analytics records are automatically removed no later than 12 months after collection. Anonymous monthly totals may be retained after the underlying detailed records are deleted so long-term website development can be assessed without retaining visitor- or session-level identifiers. Security and backup copies are overwritten under the periods stated in the Privacy Policy.
8. Legal basis and your choice
Strictly necessary storage is used to deliver a service you request, secure protected accounts and operate the site. Optional audience measurement is based on your consent where consent is required by Dutch telecommunications and data-protection law. No optional analytics identifier or event is created before an affirmative choice. The analytics option is not preselected, refusing is as easy as accepting, and public content remains available after refusal.
You can change or withdraw your choice at any time by selecting Cookie settings in the footer. Withdrawal stops new optional collection on that device; it does not make earlier lawful processing unlawful. Clearing browser storage may remove the saved choice, in which case the website will ask again. You can also clear or block storage in browser settings, although doing so can affect sign-in and preferences.
9. External video and third-party services
The EAF may offer embedded media from YouTube, Vimeo, Dailymotion or another identified provider. The external player is blocked until you actively load it. YouTube links use its privacy-enhanced youtube-nocookie.com domain where supported, but this does not make playback anonymous or place the provider under EAF control. Once loaded, the provider may receive the IP address, browser data, page referrer and playback interaction, and may set or read its own storage. Logged-in provider accounts may also associate playback with that account.
Review the provider’s privacy and cookie information before loading the media. The EAF cannot change or delete third-party storage; use the provider’s and browser’s controls.
10. Contact forms, downloads and external clicks
A contact-form submission, document download or external federation link may increase an aggregate counter when optional analytics is allowed. The content of a message and uploaded attachment is not placed in the analytics record. Contact-form content is processed separately as described in the Privacy Policy and contact-form notice.
11. Changes to this policy
We may update this policy when storage, analytics, external services or legal requirements change. The effective date will be changed and material changes will be communicated through the website or a renewed consent request where necessary.
12. Contact and complaints
For questions or to exercise data-protection rights, contact office@airsofteurope.com. You may also complain to the Autoriteit Persoonsgegevens or another competent supervisory authority. This policy is designed to describe the actual V11 controls and should be reviewed periodically by qualified Dutch privacy counsel or the EAF’s data-protection adviser.