Cookie policy
Last updated: 5 October 2026
1. Scope and controller
This policy covers cookies and storage on the Bookelya website, in customer and professional areas, and third-party services loaded by your browser. A cookie may contain an identifier that recognises a device. These identifiers and IP addresses are not necessarily anonymous.
Bookelya is operated by KURT Brûsk, an individual trading as NOWAVE, enterprise number 0803.438.231, VAT BE 0803.438.231, Rue T. Marcotty 5A, 4101 Seraing, Belgium. Contact: contact@bookelya.com; telephone: +1 646 208 2714.
2. Choices and actual loading of services
The panel offers “Accept all”, “Reject all” and “Customise”. The categories are necessary, analytics, advertising and personalisation. Services required for the requested service and functional preferences are used independently of optional categories. The panel does not disable every external resource.
Google Tag Manager, Google Analytics and Google Ads are not loaded before your choice or after “Reject all”. On Bookelya, the tag manager combines analytics and advertising, so it loads only if you accept both categories. If you accept just one of these categories, Google tags remain blocked. Once both categories are accepted, Google may receive your IP address, the pages you visit, browser identifiers and navigation events.
The bookelya_attribution cookie and its session copy are created only after advertising consent. A preference cookie without an identifier, bookelya_consent, communicates this choice to the server. Analytics events and the local professional registration completion marker require analytics consent. Server-side Google Analytics conversions are blocked until explicit consent can be passed to that service.
Crisp chat loads automatically in the professional area after personalisation is enabled. Requesting chat may enable that category while preserving your other choices. If the panel is unavailable, an explicit chat request may load Crisp directly. When consent management is disabled, chat may load automatically in the professional area.
3. Cookie inventory
The table distinguishes cookies created by Bookelya and possible third-party trackers or those listed in the panel. They are not all present on every visit. The website domain means Bookelya or the salon domain depending on the page. Lifetimes come from the code or, where specified, from the panel or provider.
| Name | Provider | Purpose | Duration | Category | Domain |
|---|---|---|---|---|---|
| bookelya-session (configurable name) | Bookelya | Maintains the session and sign-in. | 2 hours by default, renewed on each request | Necessary | Domain of the website visited |
| XSRF-TOKEN | Bookelya | Protects actions against forged requests (CSRF). | Same lifetime as the session: 2 hours by default | Necessary | Domain of the website visited |
| remember_web_* | Bookelya | Keeps you signed in persistently, including during professional registration. | 365 days by default (configurable); deleted on sign-out | Necessary | Domain of the website visited |
| bookelya_locale | Bookelya | Remembers the selected language. | 1 year | Functional | Domain of the website visited |
| appearance | Bookelya | Remembers the light, dark or system theme. | 1 year | Functional | Domain of the website visited |
| sidebar_state | Bookelya | Remembers whether the sidebar is open. | 7 days | Functional | Domain of the website visited |
| bookelya_skip_pro_space_prompt | Bookelya | Remembers your choice to hide the professional access prompt. | 180 days | Functional | Domain of the website visited |
| social_redirect / social_context / social_nonce | Bookelya | Supports the return flow and security when signing in through an external account. | 10 minutes | Necessary | Domain of the website visited |
| verify_return_url | Bookelya | Returns you to the booking after email verification. | 1 hour | Necessary | Domain of the website visited |
| pro_register_mobile / pro_register_ref | Bookelya | Preserves the context and a temporary reference for professional registration. | 1 hour | Necessary | Domain of the website visited |
| bky_embed | Bookelya | Enables booking embedded in a salon website. | 1 year | Necessary | Domain of the website visited |
| bookelya_consent | Bookelya | Communicates the advertising choice to the server without a personal identifier. Deleted on withdrawal. | 182 days | Necessary | Domain of the website visited |
| bookelya_attribution | Bookelya | Links a visit to a campaign (UTM parameters and click identifiers) only after advertising consent. Deleted when that category is withdrawn. | 90 days | Advertisement | Domain of the website visited |
| _ga / _ga_* | Google Analytics | Measures visits and sessions when the corresponding tags are enabled. | 2 years by default according to Google; the browser may shorten this period | Audience measurement | Domain of the website visited |
| _gid / _gat | Google Analytics | Legacy trackers listed in the panel; activation unconfirmed. | 24 hours / 1 minute listed in the panel for these legacy trackers | Audience measurement | Domain of the website visited |
| _clck / _clsk / CLID / MUID | Microsoft Clarity | Clarity trackers listed in the panel that may be used by a configured tag. They are not present on every visit. | _clck, CLID and MUID: 1 year; _clsk: 1 day, as listed in the panel | Audience measurement | Website domain and Microsoft domains associated with Clarity |
| _gcl_au / _gcl_aw | Google Ads | Attributes advertising conversions when these tags are enabled. | 90 days listed in the panel | Advertisement | Domain of the website visited |
| IDE / test_cookie | Google DoubleClick | Advertising trackers listed in the panel; not observed during the check without consent. | IDE: according to Google settings; test_cookie: 15 minutes listed in the panel | Advertisement | doubleclick.net |
| _fbp | Meta Pixel | Identifies the browser for advertising measurement when the salon enables Meta Pixel and advertising is accepted. | 3 months according to Meta; the browser may shorten this period | Advertisement | Domain of the website visited |
| crisp-client/* | Crisp | Keeps the conversation when the chat loads. | 6 months, renewed when the chat loads | Personalisation / requested chat | Domain of the website visited |
| __stripe_mid / __stripe_sid | Stripe | Secures the requested payment and prevents fraud; possible trackers when Stripe.js loads. | 1 year / 30 minutes according to Stripe | Necessary | Website domain or checkout.stripe.com depending on the flow |
4. Local storage and session storage
localStorage keeps information between visits. sessionStorage keeps it in the tab until it closes. These mechanisms differ from cookies but can also remember identifiers and preferences. The following functional storage is not controlled by the buttons that reject optional categories.
| Name | Provider | Purpose | Duration | Category | Domain |
|---|---|---|---|---|---|
| cc_cookie (localStorage) | Bookelya | Keeps your choice for 182 days. The former cookie with the same name is migrated to this storage and deleted. | 182 days | Necessary | Domain of the website visited |
| appearance (localStorage) | Bookelya | Keeps the display theme. | No automatic expiry; until deletion | Functional | Domain of the website visited |
| salon-cart-* / salon-pcart-* (localStorage) | Bookelya | Remembers the salon service and product cart; removed when the cart is emptied. | No automatic expiry; until deletion | Functional | Domain of the website visited |
| booking-resume-* (localStorage) | Bookelya | Resumes a booking after sign-in; expires when read after 30 minutes or is deleted on resumption. | 30 minutes; checked on read | Necessary | Domain of the website visited |
| bookelya_onboarding_snoozed_until / bookelya_onboarding_collapsed / seen-feature:* / changelog-builder:panes (localStorage) | Bookelya | Keeps professional guide preferences, previously viewed features and the administrative editor layout. | No automatic expiry; until deletion | Functional | Domain of the website visited |
| bookelya_pro_onboarding_complete_v1 (localStorage) | Bookelya | Prevents duplicate professional registration completion events, only after analytics consent. Erased when consent is withdrawn. | Until consent is withdrawn or expires (182 days), checked when the page loads | Audience measurement | Domain of the website visited |
| bookelya:lastHeroBg / phone_country_by_ip (sessionStorage) | Bookelya | Avoids repeating the home image and remembers the suggested phone country. | Until the tab is closed | Functional | Domain of the website visited |
| bookelya.embed.auth_token / bookelya.checkout.* / purchase-command:* (sessionStorage) | Bookelya | Supports sign-in within an embedded booking and prevents duplicate orders or payments; some entries are deleted at the end of the flow. | Until the tab is closed | Necessary | Domain of the website visited |
5. Fonts, CDNs, payments and notifications
Adobe Fonts continue to load from use.typekit.net and p.typekit.net before your choice and after refusal. These connections send your IP address and technical information to Adobe in the United States, even without setting a cookie. The panel does not block them. Bookelya hosts the consent panel files locally; displaying it requires no connection to jsDelivr.
The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914).
For Crisp, established in France, the main service is provided within the EEA, without transfers outside the EEA for that service. The supplier’s data processing agreement applies.
Stripe.js is used in the payment process you request. It may communicate with js.stripe.com and Stripe payment and fraud prevention domains. The __stripe_mid and __stripe_sid cookies may be used to assess transaction risk. Their presence depends on the payment process. The table gives the lifetimes published by Stripe and does not imply that all its cookies are set for every payment.
Some screens suggest a phone country from your IP address using ipapi.co without checking cookie preferences. Maps may load Apple MapKit from cdn.apple-mapkit.com. These external services receive the information needed for the network connection.
OneSignal is used server-side for mobile application notifications. No OneSignal web SDK was identified on the website. App notification permissions are managed in the app and your device settings, separately from the website cookie panel.
6. Salon websites and embedded booking
A salon may configure Google Analytics, Plausible and Meta Pixel on its own website. Outside preview mode, Google Analytics and Plausible load only after analytics consent; Meta Pixel loads only after advertising consent. The Bookelya tag manager is not loaded on these websites. Google Fonts may continue to load from fonts.googleapis.com and fonts.gstatic.com independently of these choices. The salon must inform visitors about the services it has configured and their purposes.
Salon analytics connections may involve googletagmanager.com, google-analytics.com and plausible.io; Meta Pixel connections include connect.facebook.net and facebook.com. The integrated Plausible script does not use cookies. The absence of cookies does not mean there is no network transmission. The table lists the main possible trackers; their presence depends on the services enabled by the salon and the visitor’s choices.
For embedded bookings using embed=1, the Bookelya panel is hidden and Bookelya Google scripts are blocked. Consent on the salon’s domain is not presumed to apply on the Bookelya domain. Advertising attribution is also disabled in this context. Embedded session cookies and payment services may still be necessary for the requested process.
7. Change or withdraw your choice
You can reopen the panel using the button below or the cookie settings button where available. Accepting, rejecting or changing optional categories preserves access to the main website functions. Withdrawal concerns future processing and does not erase data already sent to providers.
When you withdraw a category, the corresponding events stop being emitted. The local analytics marker is erased when analytics are refused. The attribution cookie and its server session copy are deleted when advertising is refused. The page reloads to stop scripts that have already run. The panel also deletes accessible cookies belonging to withdrawn categories. Bookelya cannot directly erase cookies on suppliers’ domains or recall data already transmitted.
You can also delete website cookies and storage, or block domains, in your browser settings. This may sign you out, empty carts and erase preferences. If you delete cc_cookie, the panel will ask for your choice again. A choice applies to the browser and domain where it is saved for 182 days; another device may require a new choice.
8. Further information
For personal data processing, recipients, possible transfers outside the European Economic Area and exercising your rights, see our privacy policy. Cookie choices do not replace mobile app permissions or any consent required for health information collected by a salon.