Cookie Policy
RustSnowball uses necessary storage for sessions and security, preference storage, pseudonymous first-party traffic analytics, and Cloudflare security/performance services. We do not use third-party advertising cookies or cross-context behavioral tracking. The inventory below explains what is set and why.
Last updated: July 14, 2026
This Cookie Policy explains what cookies and similar storage technologies we use, why we use them, and how you can manage them. It supplements our Privacy Policy and forms part of our Terms of Service.
1. What is a cookie?
A "cookie" is a small text file stored by your browser when you visit a website. "Similar technologies" include localStorage, sessionStorage, IndexedDB, the browser cache, and request signals such as user-agent, locale, and accept-language that we read from the request rather than store on your device. We treat all of the above as cookies for the purpose of this Policy.
2. Categories of cookies we use
Strictly necessary. Cookies and storage items we cannot operate the Platform without: authentication, CSRF protection, rate limiting, anti-abuse, security, basic UI state. No opt-out is possible; disabling these cookies will break the Platform.
Functional / preference. Cookies that remember your settings: language, theme, sound, accepted modals. Optional; disabling them resets the preference but does not break the Platform.
Analytics & performance. Our first-party page-view beacon uses pseudonymous browser and visit identifiers. It does not send your RustSnowball account or Steam ID, but the API derives device, browser, operating system, country, city and coarse coordinates (rounded to approximately 11 km) from the request. Analytics rows are normally retained for 90 days. Cloudflare may also collect security and performance telemetry as our edge provider. We do not use advertising pixels or cross-context tracking. The first-party beacon does not run when your browser sends Global Privacy Control.
3. Cookie inventory
The cookies actively set by the Platform are:
- __Host-rt_session (or
rt_sessionin non-prod). Strictly necessary. Holds your authenticated session JWT. HttpOnly, Secure, SameSite=Lax. Duration: up to 60 days (rotated each visit). - rt_state / rt_state_*. Strictly necessary. Signed CSRF / return-URL state for one or more concurrent Steam OpenID attempts. Production scopes these HttpOnly, Secure, SameSite=Lax cookies to rustsnowball.com so the public-site callback relay and API can complete the same login. Path:
/auth. Duration: 15 minutes. - __Host-rt_staff_session. Strictly necessary. Staff-only admin session cookie (host-only, Path=/). HttpOnly, Secure, SameSite=Strict. Duration: short- lived per staff policy. Not set on player browsers.
- cf_clearance / __cf_bm. Strictly necessary. Set by Cloudflare for bot mitigation, DDoS protection and Turnstile challenges. HttpOnly, Secure, SameSite=None. Duration: per Cloudflare default. See Cloudflare's cookie policy for detail.
- rt_anon_id. Analytics. Random pseudonymous browser identifier in localStorage, used to deduplicate page views. It is not your account or Steam ID and remains until browser/site storage is cleared. The analytics request is sent without cookies or other credentials, and the endpoint also refuses to link the identifier or visit to an account.
- rt_visit_id. Analytics. Random per-tab visit identifier in sessionStorage, removed when that browser tab/session ends.
- rt_geo. Functional. Country code supplied by our trusted edge and used to offer a language suggestion. Secure, SameSite=Lax, JavaScript-readable. Duration: 24 hours.
- rt_prefs / other rt_* keys. Functional. Stores interface preferences and short-lived client state such as muted sounds, accepted modals, locale, tab coordination and recent public chat history. The authenticated profile, balance, wagering, deposit and withdrawal totals are not persisted to Web Storage.
- NEXT_LOCALE. Functional. Persists the chosen interface language. Duration: 1 year.
We may add or remove cookies as the Platform evolves. This inventory is updated at least every six months and on any material change.
4. Browser and device controls
You can refuse, accept, or delete cookies via your browser settings. The exact path varies by browser; the major vendors publish instructions at the following pages:
You can also send a Global Privacy Control (GPC) signal. The page-view beacon is skipped whenever the browser exposes that signal.
5. Do Not Track
We do not currently respond to Do Not Track (DNT), which is not standardized. Our first-party analytics beacon does not run when the browser sends Global Privacy Control (GPC), and we honor GPC for any additional processing where applicable law requires.
6. Consequences of disabling strictly necessary cookies
You cannot log in, place wagers, or initiate deposits or withdrawals without strictly necessary cookies. If you disable them, the Platform will not function and you will not be able to complete the contract you formed under our Terms of Service.
7. Changes to this Policy
We may update this Cookie Policy from time to time. Updates take effect when posted on the Platform.
8. Contact
Questions about cookies: support@rustsnowball.com.
