Cookie Policy
Everything booking.norba.io stores in your browser, what it is for, and the one part you can switch off.
Effective date: 31 August 2026
This page lists cookies, local storage and session storage alike, because the law is about storage and not about the word “cookie”.
Only one group is optional, and it is off until you switch it on. Nothing here is used for advertising, we run no ad networks or social pixels, and we do not sell or share your data with data brokers.
Strictly necessary
These make the site work: they keep you signed in, let a confirmation link open your own booking, hold the flight you are part-way through choosing, and remember the language, currency and theme you picked. They are exempt from consent under Article 5(3) of the ePrivacy Directive because the service you asked for cannot be delivered without them — so there is no switch for them.
| Name | Type | Set by | What it is for | How long |
|---|---|---|---|---|
| __Host-norba_session | Cookie (httpOnly, Secure, SameSite=Lax) | Norba (first party) | The signed-in session. httpOnly means no script on the page can read it — deliberate, because the same session opens your saved passport details. It is only ever read on the server. | Up to 7 days, or until you sign out |
| __Host-norba_og_<order id> | Cookie (httpOnly) | Norba (first party) | A signed grant that lets you open one specific booking from a confirmation link without signing in, and — for a shorter window — change it. Scoped to that one order and to nothing else. | 24 hours to view, 2 hours to manage |
| norba_consent | Cookie + local storage | Norba (first party) | Your answer on this very subject, with the date you gave it. Without it we could not honour a refusal, and we would have to ask on every page. | 6 months, then we ask again |
| locale | Cookie | Norba (first party) | The language you picked, so the server renders the first page in it. | 1 year |
| norba_currency | Local storage | Norba (first party) | The currency you asked prices in. | Until you clear it |
| theme | Local storage | Norba (first party) | Light or dark, read before the first paint so the page does not flash the wrong one. | Until you clear it |
| norba:offer:*, norba:last-search | Session storage | Norba (first party) | The flight you are in the middle of booking and the search you found it in, so moving between the steps does not lose them. Session storage on purpose: a fare goes stale in minutes, and a stale one must not survive into tomorrow. | Until you close the tab |
| norba_oauth_state | Session storage | Norba (first party) | A one-time random value that ties a “Continue with Google” round trip to the tab that started it, so somebody else's sign-in cannot be planted in your browser. | Deleted the moment the sign-in completes; gone when the tab closes |
- __Host-norba_session
- The signed-in session. httpOnly means no script on the page can read it — deliberate, because the same session opens your saved passport details. It is only ever read on the server.
- Cookie (httpOnly, Secure, SameSite=Lax) · Norba (first party) · Up to 7 days, or until you sign out
- __Host-norba_og_<order id>
- A signed grant that lets you open one specific booking from a confirmation link without signing in, and — for a shorter window — change it. Scoped to that one order and to nothing else.
- Cookie (httpOnly) · Norba (first party) · 24 hours to view, 2 hours to manage
- norba_consent
- Your answer on this very subject, with the date you gave it. Without it we could not honour a refusal, and we would have to ask on every page.
- Cookie + local storage · Norba (first party) · 6 months, then we ask again
- locale
- The language you picked, so the server renders the first page in it.
- Cookie · Norba (first party) · 1 year
- norba_currency
- The currency you asked prices in.
- Local storage · Norba (first party) · Until you clear it
- theme
- Light or dark, read before the first paint so the page does not flash the wrong one.
- Local storage · Norba (first party) · Until you clear it
- norba:offer:*, norba:last-search
- The flight you are in the middle of booking and the search you found it in, so moving between the steps does not lose them. Session storage on purpose: a fare goes stale in minutes, and a stale one must not survive into tomorrow.
- Session storage · Norba (first party) · Until you close the tab
- norba_oauth_state
- A one-time random value that ties a “Continue with Google” round trip to the tab that started it, so somebody else's sign-in cannot be planted in your browser.
- Session storage · Norba (first party) · Deleted the moment the sign-in completes; gone when the tab closes
Analytics and session replay — your choice
Off by default. Nothing in this group loads, and no request to the provider is made, until you enable it. You can turn it back off at any time; doing so deletes what the provider stored and reloads the page so the recorder stops within the same visit rather than at the next one.
| Name | Type | Set by | What it is for | How long |
|---|---|---|---|---|
| Better Stack browser tag (b.js) and the storage it creates | Script, cookies and local storage | Better Stack (BetterStack s.r.o., Czech Republic) | Which pages are used and how fast they are, JavaScript errors, and a replay of the interaction with every text node and every input masked before capture. Never loaded on /book, /account, /trips or /confirmation — the pages where a passport or a card is on screen — with or without consent. Once you sign in, the session is tagged with your account id and nothing else: no name, no email address. | Set by Better Stack; the tag is never loaded before you consent |
- Better Stack browser tag (b.js) and the storage it creates
- Which pages are used and how fast they are, JavaScript errors, and a replay of the interaction with every text node and every input masked before capture. Never loaded on /book, /account, /trips or /confirmation — the pages where a passport or a card is on screen — with or without consent. Once you sign in, the session is tagged with your account id and nothing else: no name, no email address.
- Script, cookies and local storage · Better Stack (BetterStack s.r.o., Czech Republic) · Set by Better Stack; the tag is never loaded before you consent
What we do not do
- No advertising or retargeting cookies, and no ad network of any kind.
- No social-media pixels — no Meta, no LinkedIn, no TikTok, no X.
- No Google Analytics, and no Google Tag Manager.
- No fingerprinting, no cross-site tracking and no data sold or licensed to brokers.
- No cookie walls: you can search, book and manage a trip with the optional group refused.
- No card data in your browser's storage. This site does not take payment at all — see the booking terms.
- Fonts are served from our own domain, not fetched from Google Fonts at page load, so reading a page does not tell Google you did.
Changing your mind
Withdrawing is as easy as consenting, which is the point of the button below and of the “Cookie preferences” link at the bottom of every page. Because a stored answer stops being a current one, we ask again after six months.
You can also clear or block storage in your browser's settings. Blocking the strictly necessary group will sign you out and stop a booking from completing; blocking the optional group is exactly equivalent to refusing it here.
The rest of the picture
What personal data we collect, why, who else sees it and how long we keep it is in the privacy policy for both Norba sites: Privacy Policy.