Cookie List and Tracking Technologies
Version 1.0 | Last updated: 12 March 2026
1. Cookies Used on the Platform
The table below lists the cookies used on the BetterCX Platform, broken down by category. Users can manage their cookie preferences via the consent banner displayed on the first visit and in the Platform settings.
| Name | Provider | Purpose / Description | Retention | Type |
|---|---|---|---|---|
| NECESSARY – required for the Platform to function correctly (no consent required) | ||||
| CookieConsent | Cookiebot / BetterCX | Stores the user’s cookie consent status for the current domain. | 1 year | HTTP |
| JSESSIONID | BetterCX | Session cookie that maintains an anonymous user session on the server. | Session | HTTP |
| rc::a / rc::b / rc::c / rc::f | Google (reCAPTCHA) | Distinguishes humans from bots – protection against automated spam and abuse. | Session – Persistent | HTML Local Storage |
| AEC | Prevents malicious sites from acting on behalf of the user (CSRF protection). | 6 months | HTTP | |
| __stripe_mid / __stripe_sid / __stripe_orig_props | Stripe | Payment session identifiers; fraud prevention. | Session – 1 year | HTTP |
| access | BetterCX | Authorisation token | 1 hour | HTTP |
| refresh | BetterCX | Used to refresh the authorisation token | 7 days / 30 days | HTTP |
| csrftoken | BetterCX | Used to protect the application against CSRF attacks | 1 year | HTTP |
| cf_clearance | Cloudflare Inc. | Allows the user to access the site after verification by the Cloudflare protection system (e.g. after passing a CAPTCHA). Prevents blocking of legitimate traffic after detection of suspicious behaviour or DDoS attacks. | 1 year | HTTP |
| FUNCTIONAL – personalisation and remembering preferences (consent required) | ||||
| cmapi_cookie_privacy | Displaying content in the consent manager. | Session | HTTP | |
| notice_gdpr_prefs | Remembering the user’s cookie preferences. | Session | HTTP | |
| NEXT_LOCALE / bettercx-locale | BetterCX | Language preferences | Session duration / 1 year | Session / Persistent |
| ANALYTICAL – Platform usage statistics (consent required) | ||||
| _ga | Google Analytics | Unique user identifier for statistical purposes (Google Analytics 4). Calculates visitor, session and campaign data. | 13 months | HTTP |
| _ga_* | Google Analytics | Identifier linked to Google Analytics 4 – maintains session state. | 13 months | HTTP |
| _gid | Google Analytics | User session identifier (expires after 24h). | 1 day | HTTP |
| _gat / _gat_* | Google Analytics | Request rate throttling on high-traffic sites. | 1 min | HTTP |
| _gcl_au | Google Analytics | Analysing user interactions with the site (conversion attribution). | 3 months | HTTP |
| ph_phc_*_posthog | PostHog | Analysing user interactions with the Platform | 1 year | HTTP |
| MARKETING – advertising and retargeting (consent required) | ||||
| _fbp | Meta (Facebook) | Facebook Pixel identifier – tracking visits for ad delivery and retargeting. | 3 months | HTTP |
| datr | Meta (Facebook) | Browser identifier used by Facebook to assess security and prevent DDoS attacks. | 9 months | HTTP |
| NID | Ad delivery and retargeting in Google services (non-logged-in users). | 6 months | HTTP | |
| _Secure-ENID | Securing and encrypting the Google identifier; may be used for ad personalisation. | 13 months | HTTP | |
2. Analytics, Advertising Tools and Third-Party Technologies
The table below describes third-party tools and services used on the BetterCX Platform that may process user data. Detailed information about each provider’s data processing practices can be found in their respective privacy policies.
| Tool / Service | Description and purpose |
|---|---|
| Google Analytics 4 (with Google Signals) | Analysis of Platform traffic and user behaviour. IP anonymisation enabled by default in GA4. Google Signals allows visits to be linked to logged-in Google user accounts (with their consent). Statistical data deleted after 14 months. Legal basis: consent (Art. 6(1)(a) GDPR). Provider: Google Ireland Ltd, Dublin. Transfer to USA: EU-US DPF + SCC. |
| Google Tag Manager | Managing analytics and marketing tags on the Platform. GTM itself does not collect personal data – it manages the triggering of external scripts. Provider: Google Ireland Ltd. |
| Google reCAPTCHA | Protecting Platform forms from bots and automated spam. Distinguishes humans from bots based on behavioural analysis. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). Provider: Google Ireland Ltd. |
| Meta Pixel (Facebook) | Measuring the effectiveness of advertising campaigns on Facebook and Instagram, retargeting, and creating Custom Audiences. The Pixel transmits data about Platform visits to Meta’s servers. Joint controllers: AppWave + Meta Platforms Ireland Ltd. Legal basis: consent (Art. 6(1)(a) GDPR). Transfer to USA: EU-US DPF + SCC. |
| Stripe / Stripe Connect | Processing payments and prepayments for bookings. Stripe is an independent controller of payment data – AppWave does not have access to full card data. Provider: Stripe Inc. (USA/Ireland). Transfer to USA: EU-US DPF + SCC. |
| Amazon Web Services (AWS) | Hosting the Platform infrastructure. Servers in the EU region (EEA). Certifications: ISO 27001, SOC 2 Type II, CSA STAR. Provider: Amazon Web Services EMEA SARL. |
| OpenAI API | Language processing (message analysis, response generation). API data is not used to train models (by default). Log retention: up to 30 days. Encryption: AES-256 + TLS 1.2+. Provider: OpenAI, L.L.C. (San Francisco). Transfer to USA: EU-US DPF + SCC. |
| Cloudflare | DDoS protection, load speed optimisation, CDN proxy. As an intermediary, Cloudflare has access to some transmitted data. Servers primarily in the EEA; some data may be transferred to the USA. Provider: Cloudflare Inc. (EU-US DPF). |
| PostHog | Analysis of user behaviour and Platform usage statistics. Data collected for analytics and service optimisation purposes. Data retention: up to 12 months by default. Encryption: TLS 1.2+. Servers primarily in the EEA. Provider: PostHog Ltd. (UK). |
| Shopify | E-commerce integration enabling browsing of products and checking order statuses by order number. Servers primarily in the EEA and USA. Provider: Shopify Inc. |
| WooCommerce | E-commerce integration for WordPress enabling browsing of products and checking order statuses. Servers primarily in the EEA. Provider: Automattic Inc. |
| PrestaShop | E-commerce integration enabling browsing of products and checking order statuses. Servers primarily in the EEA. Provider: PrestaShop S.A. |
| Connection to the user’s account for receiving messages and notifications via webhook. Data includes message content and conversation metadata. Servers primarily in the USA and EEA. Provider: Meta Platforms, Inc. | |
| Connection to the user’s account for receiving and sending messages via webhook. Data includes phone number, message content and metadata. End-to-end encryption. Servers in the EEA and USA. Provider: Meta Platforms, Inc. | |
| Messenger | Connection to the user’s account for receiving messages and notifications via webhook. Data includes message content and conversation metadata. TLS 1.2+ encryption. Servers primarily in the USA and EEA. Provider: Meta Platforms, Inc. |
| Outlook | Email integration for sending, receiving and managing messages. Data includes message content, attachments and metadata. Servers in the EEA and USA. Provider: Microsoft Corporation. |
| Outlook Calendar | Calendar integration for planning events and managing schedules. Data includes event titles, attendees and dates. Servers in the EEA and USA. Provider: Microsoft Corporation. |
| Gmail | Google email integration for sending and receiving messages. Data includes message content, metadata and attachments. Servers primarily in the EEA and USA. Provider: Google LLC. |
| Google Calendar | Calendar integration for managing events, meetings and reminders. Data includes event titles, attendees and dates. Servers primarily in the EEA and USA. Provider: Google LLC. |
| HubSpot | CRM and marketing tool for managing customer relationships, leads and campaigns. Data includes contact information, interaction history and marketing statistics. Servers primarily in the EEA and USA. Provider: HubSpot, Inc. |
| Pipedrive | CRM for managing sales, contacts and pipelines. Data includes contact information, deal statuses and sales notes. Servers in the EEA and USA. Provider: Pipedrive OÜ. |
| Google Drive | Cloud file storage and sharing. Data includes documents, spreadsheets, presentations and file metadata. Encryption: TLS 1.2+ and AES-256. Servers primarily in the EEA and USA. Provider: Google LLC. |
| SendGrid | Bulk and transactional email delivery service. Data includes message content, email metadata and delivery reports. Servers primarily in the EEA and USA. Provider: Twilio Inc. |
3. Local Storage and Session Storage
The Platform also uses Local Storage and Session Storage technologies provided by the user’s browser. Unlike cookies, this data is not sent to the server with every HTTP request.
| Technology | Description | Retention |
|---|---|---|
| Local Storage | Storage of configuration data, UI preferences and cached data in the browser memory. Data is not sent to the server. Available after reopening the browser. | Until manually deleted by the user (Browser settings → Clear data). |
| Session Storage | Works analogously to Local Storage, but data is automatically deleted when the browser tab is closed. | Duration of the session (until the tab is closed). |
4. Server Logs
Use of the Platform involves the automatic recording of HTTP requests in server logs. Logs contain: IP address, request and response time, URL of the visited page, browser information (user-agent), operating system information, referring URL (referer) and error information.
Log data is not associated with specific users and is used exclusively for server administration, security and abuse prevention. Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR). Retention period: up to 12 months.
5. Third-Party Links and Embedded Content
The Platform may contain links to third-party websites and embedded content (e.g. video materials, social media widgets). Using such content involves the transmission of data (IP address, browser data) to the providers of those materials, in accordance with their privacy policies. The Service Provider does not control the processing of data by third parties.