Cookie List and Tracking Technologies

Version 1.0 | Last updated: 12 March 2026

1. Cookies Used on the Platform

The table below lists the cookies used on the BetterCX Platform, broken down by category. Users can manage their cookie preferences via the consent banner displayed on the first visit and in the Platform settings.

NameProviderPurpose / DescriptionRetentionType
NECESSARY – required for the Platform to function correctly (no consent required)
CookieConsentCookiebot / BetterCXStores the user’s cookie consent status for the current domain.1 yearHTTP
JSESSIONIDBetterCXSession cookie that maintains an anonymous user session on the server.SessionHTTP
rc::a / rc::b / rc::c / rc::fGoogle (reCAPTCHA)Distinguishes humans from bots – protection against automated spam and abuse.Session – PersistentHTML Local Storage
AECGooglePrevents malicious sites from acting on behalf of the user (CSRF protection).6 monthsHTTP
__stripe_mid / __stripe_sid / __stripe_orig_propsStripePayment session identifiers; fraud prevention.Session – 1 yearHTTP
accessBetterCXAuthorisation token1 hourHTTP
refreshBetterCXUsed to refresh the authorisation token7 days / 30 daysHTTP
csrftokenBetterCXUsed to protect the application against CSRF attacks1 yearHTTP
cf_clearanceCloudflare Inc.Allows the user to access the site after verification by the Cloudflare protection system (e.g. after passing a CAPTCHA). Prevents blocking of legitimate traffic after detection of suspicious behaviour or DDoS attacks.1 yearHTTP
FUNCTIONAL – personalisation and remembering preferences (consent required)
cmapi_cookie_privacyGoogleDisplaying content in the consent manager.SessionHTTP
notice_gdpr_prefsGoogleRemembering the user’s cookie preferences.SessionHTTP
NEXT_LOCALE / bettercx-localeBetterCXLanguage preferencesSession duration / 1 yearSession / Persistent
ANALYTICAL – Platform usage statistics (consent required)
_gaGoogle AnalyticsUnique user identifier for statistical purposes (Google Analytics 4). Calculates visitor, session and campaign data.13 monthsHTTP
_ga_*Google AnalyticsIdentifier linked to Google Analytics 4 – maintains session state.13 monthsHTTP
_gidGoogle AnalyticsUser session identifier (expires after 24h).1 dayHTTP
_gat / _gat_*Google AnalyticsRequest rate throttling on high-traffic sites.1 minHTTP
_gcl_auGoogle AnalyticsAnalysing user interactions with the site (conversion attribution).3 monthsHTTP
ph_phc_*_posthogPostHogAnalysing user interactions with the Platform1 yearHTTP
MARKETING – advertising and retargeting (consent required)
_fbpMeta (Facebook)Facebook Pixel identifier – tracking visits for ad delivery and retargeting.3 monthsHTTP
datrMeta (Facebook)Browser identifier used by Facebook to assess security and prevent DDoS attacks.9 monthsHTTP
NIDGoogleAd delivery and retargeting in Google services (non-logged-in users).6 monthsHTTP
_Secure-ENIDGoogleSecuring and encrypting the Google identifier; may be used for ad personalisation.13 monthsHTTP

2. Analytics, Advertising Tools and Third-Party Technologies

The table below describes third-party tools and services used on the BetterCX Platform that may process user data. Detailed information about each provider’s data processing practices can be found in their respective privacy policies.

Tool / ServiceDescription and purpose
Google Analytics 4 (with Google Signals)Analysis of Platform traffic and user behaviour. IP anonymisation enabled by default in GA4. Google Signals allows visits to be linked to logged-in Google user accounts (with their consent). Statistical data deleted after 14 months. Legal basis: consent (Art. 6(1)(a) GDPR). Provider: Google Ireland Ltd, Dublin. Transfer to USA: EU-US DPF + SCC.
Google Tag ManagerManaging analytics and marketing tags on the Platform. GTM itself does not collect personal data – it manages the triggering of external scripts. Provider: Google Ireland Ltd.
Google reCAPTCHAProtecting Platform forms from bots and automated spam. Distinguishes humans from bots based on behavioural analysis. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). Provider: Google Ireland Ltd.
Meta Pixel (Facebook)Measuring the effectiveness of advertising campaigns on Facebook and Instagram, retargeting, and creating Custom Audiences. The Pixel transmits data about Platform visits to Meta’s servers. Joint controllers: AppWave + Meta Platforms Ireland Ltd. Legal basis: consent (Art. 6(1)(a) GDPR). Transfer to USA: EU-US DPF + SCC.
Stripe / Stripe ConnectProcessing payments and prepayments for bookings. Stripe is an independent controller of payment data – AppWave does not have access to full card data. Provider: Stripe Inc. (USA/Ireland). Transfer to USA: EU-US DPF + SCC.
Amazon Web Services (AWS)Hosting the Platform infrastructure. Servers in the EU region (EEA). Certifications: ISO 27001, SOC 2 Type II, CSA STAR. Provider: Amazon Web Services EMEA SARL.
OpenAI APILanguage processing (message analysis, response generation). API data is not used to train models (by default). Log retention: up to 30 days. Encryption: AES-256 + TLS 1.2+. Provider: OpenAI, L.L.C. (San Francisco). Transfer to USA: EU-US DPF + SCC.
CloudflareDDoS protection, load speed optimisation, CDN proxy. As an intermediary, Cloudflare has access to some transmitted data. Servers primarily in the EEA; some data may be transferred to the USA. Provider: Cloudflare Inc. (EU-US DPF).
PostHogAnalysis of user behaviour and Platform usage statistics. Data collected for analytics and service optimisation purposes. Data retention: up to 12 months by default. Encryption: TLS 1.2+. Servers primarily in the EEA. Provider: PostHog Ltd. (UK).
ShopifyE-commerce integration enabling browsing of products and checking order statuses by order number. Servers primarily in the EEA and USA. Provider: Shopify Inc.
WooCommerceE-commerce integration for WordPress enabling browsing of products and checking order statuses. Servers primarily in the EEA. Provider: Automattic Inc.
PrestaShopE-commerce integration enabling browsing of products and checking order statuses. Servers primarily in the EEA. Provider: PrestaShop S.A.
InstagramConnection to the user’s account for receiving messages and notifications via webhook. Data includes message content and conversation metadata. Servers primarily in the USA and EEA. Provider: Meta Platforms, Inc.
WhatsAppConnection to the user’s account for receiving and sending messages via webhook. Data includes phone number, message content and metadata. End-to-end encryption. Servers in the EEA and USA. Provider: Meta Platforms, Inc.
MessengerConnection to the user’s account for receiving messages and notifications via webhook. Data includes message content and conversation metadata. TLS 1.2+ encryption. Servers primarily in the USA and EEA. Provider: Meta Platforms, Inc.
OutlookEmail integration for sending, receiving and managing messages. Data includes message content, attachments and metadata. Servers in the EEA and USA. Provider: Microsoft Corporation.
Outlook CalendarCalendar integration for planning events and managing schedules. Data includes event titles, attendees and dates. Servers in the EEA and USA. Provider: Microsoft Corporation.
GmailGoogle email integration for sending and receiving messages. Data includes message content, metadata and attachments. Servers primarily in the EEA and USA. Provider: Google LLC.
Google CalendarCalendar integration for managing events, meetings and reminders. Data includes event titles, attendees and dates. Servers primarily in the EEA and USA. Provider: Google LLC.
HubSpotCRM and marketing tool for managing customer relationships, leads and campaigns. Data includes contact information, interaction history and marketing statistics. Servers primarily in the EEA and USA. Provider: HubSpot, Inc.
PipedriveCRM for managing sales, contacts and pipelines. Data includes contact information, deal statuses and sales notes. Servers in the EEA and USA. Provider: Pipedrive OÜ.
Google DriveCloud file storage and sharing. Data includes documents, spreadsheets, presentations and file metadata. Encryption: TLS 1.2+ and AES-256. Servers primarily in the EEA and USA. Provider: Google LLC.
SendGridBulk and transactional email delivery service. Data includes message content, email metadata and delivery reports. Servers primarily in the EEA and USA. Provider: Twilio Inc.

3. Local Storage and Session Storage

The Platform also uses Local Storage and Session Storage technologies provided by the user’s browser. Unlike cookies, this data is not sent to the server with every HTTP request.

TechnologyDescriptionRetention
Local StorageStorage of configuration data, UI preferences and cached data in the browser memory. Data is not sent to the server. Available after reopening the browser.Until manually deleted by the user (Browser settings → Clear data).
Session StorageWorks analogously to Local Storage, but data is automatically deleted when the browser tab is closed.Duration of the session (until the tab is closed).

4. Server Logs

Use of the Platform involves the automatic recording of HTTP requests in server logs. Logs contain: IP address, request and response time, URL of the visited page, browser information (user-agent), operating system information, referring URL (referer) and error information.

Log data is not associated with specific users and is used exclusively for server administration, security and abuse prevention. Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR). Retention period: up to 12 months.

5. Third-Party Links and Embedded Content

The Platform may contain links to third-party websites and embedded content (e.g. video materials, social media widgets). Using such content involves the transmission of data (IP address, browser data) to the providers of those materials, in accordance with their privacy policies. The Service Provider does not control the processing of data by third parties.

AppWave Sp. z o.o. | KRS 0001193213 | NIP 9820394623