Cookies are small files a site stores in your browser. 100mL uses them only where the marketplace cannot work without them. We run no advertising cookies, no cross-site trackers, and no third-party marketing pixels on our own pages.
Because every cookie we set is strictly necessary, we do not show a consent banner. There is nothing optional to consent to.
Cookies we set
- Session cookie (better-auth.session_token, prefixed __Secure- over HTTPS) — keeps you signed in after password, Google, SSO, or one-time-code authentication, and identifies your organization and role on every request. It lasts 30 days from your last use and is deleted when you sign out. If you sign in with a password and leave “Remember me” unticked, it lasts only until you close your browser instead.
- Remember-me preference (better-auth.dont_remember) — records that choice for the current sign-in, so the session cookie knows not to outlive your browser. Set only when you leave the box unticked, and cleared when you sign out.
- Authentication state cookies — short-lived, first-party values used to protect Google and enterprise SSO redirects against request forgery and callback mix-ups; deleted or expired after the sign-in attempt.
- Sign-in continuity cookies (ml_login_email, and ml_admin_login_email on the administrator sign-in screen) — used only by the retained one-time-code fallback to carry the email address from request to verification, so it never has to travel in a web address. They last ten minutes and are deleted once the code is verified. The two are kept separate so opening one sign-in screen cannot change the address awaiting verification on the other.
All of these are first-party, HTTP-only where the browser supports it, set with a same-site restriction, and tied to this site alone rather than shared with any other address. None is used for analytics or advertising.
Third-party cookies
Our public application and contact forms are protected by Cloudflare Turnstile, which filters automated submissions. Turnstile may set its own cookies or local storage on the Cloudflare challenge domain to remember that a browser has already passed a challenge. It is a privacy-preserving alternative to a CAPTCHA and is not used for advertising or cross-site profiling.
If you are signed in as a buyer and start setting up bank payment on your billing page, we load Stripe.js so your bank details reach Stripe directly and never pass through our servers. Stripe then sets its own cookies (__stripe_mid and __stripe_sid) to detect fraud on that payment setup. This happens only at that point, only for signed-in buyers, and never on our public pages — so no visitor to this site encounters them by browsing. Stripe is our payment processor and is listed as such in the privacy policy.
Analytics
We measure page traffic with Vercel Web Analytics, which is cookieless: it records aggregate page views and performance without storing an identifier in your browser or tracking you between sites.
What we deliberately do not do
- No advertising or retargeting cookies, and no ad-network pixels.
- No cross-site behavioral profiles, and no sale or sharing of personal information for advertising.
- No client-side marketing scripts — our email platform is called only from our servers, never from your browser.
- No session recording or heatmap tools.
Managing cookies
Every major browser lets you view, block, and delete cookies in its settings. Blocking our session cookie will stop you signing in — the marketplace cannot keep you authenticated without it. Public pages such as this one work fine with cookies blocked.
Changes and contact
If we introduce a cookie that is not strictly necessary, we will update this page and ask for your consent before setting it. Questions: privacy@100mlhospitality.com.
100mL Trade Inc. · 139 Budlong Street, Hillsdale, MI 49242 · Incorporated in Delaware, United States.