Cookie Policy
Last updated: July 30, 2026
- BEETTER S.R.L.
- Trade Registry no.: J2026010326006
- CUI: 53947502
- Registered office: Intr. Gheorghe Simionescu 19, Ap. B26, Sector 1, București, 014155
- Share capital: 500 RON
- Email: [email protected]
- Phone: +40 779 300 558
1. About this policy
This policy explains which cookies and similar technologies BEETTER S.R.L. (full identification details are shown in the "Identification" section above) uses on the beetter.ro website and on the app.beetter.ro client platform, why we use them, on what legal basis, and how you control your choices.
How we process your personal data in general is described in the Privacy Policy. The terms governing use of the website are set out in the Terms and Conditions.
2. What cookies and similar technologies are
A cookie is a small text file that a website saves in your browser. On subsequent visits, your browser sends it back to the website, which thereby "remembers" you — for example, that you are logged in or which language you have chosen.
- Session cookies — deleted automatically when you close your browser.
- Persistent cookies — remain in your browser for a defined period or until you delete them.
- First-party cookies — placed by beetter.ro. Third-party cookies — placed by other companies whose services we use (see Section 5).
localStorage is a storage area in your browser, similar to cookies, but not sent automatically to the server. Technically, it is not a cookie — however, the rules on storing and accessing information on your device (Romanian Law no. 506/2004) apply in the same way, so we treat it identically in this policy.
3. What we actually use today
The table below is the complete list of cookies and technologies that we ourselves place (first-party). In addition to these, Cloudflare may set technical security cookies — we describe them in Section 5. We do not use any other cookies or tracking technologies.
| Name | Purpose | Type | Duration | Category |
|---|---|---|---|---|
| Session cookie (Laravel) | Maintains your session from one page to the next and your authentication on app.beetter.ro. | First-party, session cookie | Deleted when the session ends | Necessary |
| XSRF-TOKEN | Security: protects forms against CSRF attacks (forged submissions made in your name). | First-party, session cookie | Deleted when the session ends | Necessary |
| beetter_lang | Remembers the language you have chosen (Romanian / English). | First-party, persistent cookie | Approximately 1 year | Preferences |
| Consent choices | Remembers the choices you made in the consent manager, so that we do not ask you on every visit. | localStorage (not a cookie) | Until you delete them from your browser or reset your choices | Necessary |
We do not currently run any analytics or marketing cookies or scripts. Details in the next section.
4. The categories in the consent manager
On your first visit we show you a consent manager with four categories:
- Necessary — always active; without them the website does not work (session, security, remembering your choices). They cannot be disabled.
- Preferences — remember options that make your visit more convenient, such as your chosen language (beetter_lang).
- Statistics — would serve to measure traffic in anonymised/aggregated form. Today there is no active script in this category.
- Marketing — would serve advertising and remarketing purposes. Today there is no active script in this category either.
In short, the Statistics and Marketing categories exist in the manager for future activations (for example Google Analytics 4). Regardless of what you tick today in these two categories, no script of this kind is loaded, because we do not yet use any. If we ever activate such a tool: (1) we will first update this policy and the table in Section 3, and (2) we will ask for your consent before any script in that category runs. Nothing is activated retroactively on the basis of a box ticked today.
5. Third-party cookies: Cloudflare
Traffic to the website passes through Cloudflare, Inc. (USA), which provides us with proxy, CDN and attack-protection services. In this role, Cloudflare may set technical security cookies, used exclusively to distinguish legitimate traffic from attacks and bots. We consider them strictly necessary: they do not depend on consent and do not serve to track you for commercial purposes.
The transfer of data to Cloudflare in the USA is covered by standard contractual clauses (SCCs) and by the EU–US Data Privacy Framework. Details on recipients and transfers can be found in the Privacy Policy.
6. Legal basis
Under Romanian Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector and Regulation (EU) 2016/679 (GDPR):
- Strictly necessary cookies (session, XSRF-TOKEN, storage of your consent choices, Cloudflare security cookies) do not require consent — they are indispensable for providing the service you request. The legal basis is our legitimate interest in operating a functional and secure website (Art. 6(1)(f) GDPR).
- All other categories (Preferences, Statistics, Marketing) operate exclusively on the basis of consent (Art. 6(1)(a) GDPR), given granularly, per category, through the consent manager. Refusing does not limit your access to the website.
7. How long your consent remains valid
Your choices are saved locally, in your browser (localStorage), and remain valid until you change or delete them. We will ask for your consent again if:
- we activate a new category or a new tool (for example GA4);
- we make significant changes to this policy;
- you delete your browsing data (your choices disappear along with it).
You can withdraw or change your consent at any time, just as easily as you gave it — see the next section. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
8. How to change your choices
8.1. From the consent manager
Open the Cookie settings at any time — the button is also available in the footer of every page. From there you can enable or disable each category, with immediate effect.
8.2. From your browser
Any modern browser (Chrome, Firefox, Safari, Edge) allows you, from its privacy settings, to view, block or delete cookies — for all websites or only for beetter.ro. Deleting "site data" also removes the information in localStorage, including your consent choices.
Please note: blocking necessary cookies may render the website unusable — for example, you will not be able to log in to app.beetter.ro or submit forms securely.
9. Your data and your rights
The data processed through the cookies above is minimal (session identifiers, chosen language) and we do not use it for profiling or for automated decisions with legal effect. Your rights — access, rectification, erasure, restriction, objection, portability, withdrawal of consent — and how to exercise them are described in the Privacy Policy.
If you consider that the processing infringes your rights, you may lodge a complaint with the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP, the Romanian National Supervisory Authority for Personal Data Processing): B-dul G-ral Gheorghe Magheru nr. 28-30, Bucharest, dataprotection.ro. We would, however, be glad if you wrote to us first, at [email protected] — as a rule, we resolve matters directly.
10. Changes to this policy
We update this page whenever the cookies or technologies we use change; the date of the last update is shown at the top. For significant changes — in particular the activation of the Statistics or Marketing categories — we will ask for your consent again before the change takes effect.
11. Contact and governing law
Questions about cookies or about this policy: [email protected] or +40 779 300 558. The controller's full details are in the "Identification" section above.
This policy is governed by Romanian law. The document is available in Romanian and English; in the event of any discrepancy, the Romanian-language version prevails.