Cookie Policy
Effective from: 1 July 2026
This Cookie Policy explains the cookies and similar technologies Bitte uses on https://bitte.uk, the Bitte apps, the merchant dashboard, and restaurant white-label storefronts. It sits alongside our Privacy Policy, which explains everything else we do with your personal data.
1. Who we are
This Cookie Policy is published by Bitte Limited ("Bitte", "we", "us", "our").
| Item | Detail |
|---|---|
| Legal name | Bitte Limited |
| Companies House number | 17140318 |
| Registered office | 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ |
| ICO registration number | ZC193676 |
| Data protection contact | privacy@bitte.uk |
2. What cookies and similar technologies are
A cookie is a small text file a website asks your browser to store. On a later visit the browser sends it back, so the site can recognise your session, remember a preference, or measure how the site is used.
"Similar technologies" covers anything that stores or reads information on your device for the same purposes — including browser local storage, pixels / tracking beacons, and SDKs inside our mobile apps. UK law treats all of these the same way. Where this policy says "cookies" it means all of these unless we say otherwise. We tell you specifically where we use local storage rather than a cookie — for example, your cookie-consent choice itself is stored in local storage, not in a cookie.
3. The law, in plain terms
Two regimes apply together:
- PECR (as amended by the Data (Use and Access) Act 2025) governs storing or reading information on your device. The default rule is that we must tell you clearly what each non-exempt cookie does and get your consent before we set it. A small set of cookies is exempt (see Section 4).
- UK GDPR governs what we then do with any personal data a cookie collects — detailed in our Privacy Policy.
4. Which cookies need your consent — and which don't
4.1 Strictly necessary cookies — no consent needed, always on
Some cookies are strictly necessary for a service you have asked for: keeping you signed in, protecting a form against cross-site request forgery, remembering your basket, and basic security. PECR exempts these from consent. You cannot switch these off through our banner, but you can block all cookies in your browser settings (Section 8) — parts of the site may then stop working.
4.2 The new 2025 exemptions — and why we still ask anyway
From 5 February 2026 a new exemption allows cookies used solely for first-party analytics without consent, if we give clear information and a free opt-out. We have decided not to rely on it. Instead we ask for your opt-in consent before setting any analytics cookie, because we also run Meta Pixel for advertising measurement — and the analytics exemption does not apply where data can feed advertising. This makes Bitte stricter than the law requires, by design.
4.3 Analytics and marketing cookies — consent required, off by default
Everything that is not strictly necessary — analytics and marketing/advertising cookies — is off until you opt in through the cookie banner. Nothing in those categories loads on your first visit, and nothing loads at all if you choose "Reject all".
5. How we ask, and how you change your mind
On your first visit you see a banner offering "Accept all", "Reject all" and "Customise" — with the reject option presented as easily as accept, no pre-ticked boxes, and no analytics or marketing cookie set until you choose. Closing the banner counts as reject.
You can change your mind at any time using Cookie settings in the footer (or Privacy settings in the app) to re-open the banner. When you turn a category off, we stop setting those cookies and do not load the associated scripts on later page views; on bitte.uk, withdrawing analytics consent also clears the Google Analytics identifiers (_ga*). We treat a stored choice as valid for 12 months, then re-prompt.
6. The cookies we use
"First-party" means set on a Bitte domain; "third-party" means set by the named provider on their own domain.
6A. bitte.uk, the Bitte apps, and the merchant dashboard
Strictly necessary — always on
| Name | Provider | Purpose | Type / lifetime |
|---|---|---|---|
XSRF-TOKEN | Bitte | Cross-site request forgery protection | Cookie · session |
bitte_access_token | Bitte | Keeps you signed in (short-lived) | Cookie · 15 minutes · HttpOnly + Secure |
bitte_refresh_token | Bitte | Re-authenticates when the access token expires | Cookie · 30 days · HttpOnly + Secure |
bitte_session | Bitte | Non-sensitive "you have a session" marker | Cookie · 7 days |
i18nextLng | Bitte | Remembers your language | Local storage |
__cf_bm | Cloudflare | Bot-management / abuse protection | Cookie · ~30 minutes |
| Cart, theme preference | Bitte | Remembers your basket and display preference | Local storage |
bitte-gdpr-consent | Bitte | Stores your cookie choices + timestamp | Local storage · 12 months |
Analytics — only if you accept "Analytics"
| Name | Provider | Purpose | Type / lifetime |
|---|---|---|---|
_ga, _ga_<id> | Google Analytics 4 | Measures how the site is used so we can improve it | Cookie · up to 2 years |
_gid (if set) | Google Analytics 4 | Distinguishes visitors over a short window | Cookie · 24 hours |
bitte_booking_source | Bitte | Records which channel led you to a page, for attribution | Cookie · 60 minutes |
bitte_anon_id | Bitte (first-party) | Pseudonymous device identifier that groups your first-party behavioural events (page/menu/item views, funnel and search signals — see Privacy Policy §4A) so we can measure and improve the diner journey | Local storage, not a cookie · up to ~13 months |
bitte_anon_session_id | Bitte (first-party) | Pseudonymous session identifier tying the events within a single visit together for the same analytics purpose | Local storage, not a cookie · per browsing session |
On-device storage note (PECR).
bitte_anon_idandbitte_anon_session_idare local-storage items, not cookies. Because they store and read information on your device they are still governed by PECR reg. 6, so we set them only after you accept Analytics — never before.
Marketing / advertising — only if you accept "Marketing"
| Name | Provider | Purpose | Type / lifetime |
|---|---|---|---|
_fbp, _fbc | Meta Pixel | Measures advertising effectiveness and builds audiences (bitte.uk web only — not used in the mobile apps) | Cookie · 3 months |
fr | Meta | Delivery and measurement of Meta advertising (bitte.uk web only) | Third-party cookie · 3 months |
6B. Restaurant white-label storefronts
Storefronts use a smaller set and no advertising cookies: the same strictly-necessary security/session cookies and __cf_bm; your consent record in local storage (bitte_store_gdpr_consent_v2) plus a legacy companion cookie (bitte_store_gdpr_consent); and, only if you accept analytics, Cloudflare Web Analytics, which is cookieless (it sets no tracking cookie and does not fingerprint you), together with the first-party bitte_anon_id / bitte_anon_session_id local-storage identifiers described above — both set only after you accept Analytics and used only for aggregate, single-storefront diner-journey analytics (see Privacy Policy §4A). Storefronts never set Meta Pixel or any marketing cookie.
7. Third parties, and what leaves the UK
When you accept Analytics or Marketing, some data (such as your cookie ID, IP address and the pages you view) is shared with the provider operating that cookie.
| Provider | Used for | Category | Region + transfer basis |
|---|---|---|---|
| Google Analytics 4 — first-party site statistics | Analytics | UK/EEA entity → US under the UK Extension to the EU-US Data Privacy Framework and/or the UK IDTA / SCC Addendum | |
| Meta | Meta Pixel — advertising measurement and audiences | Marketing | UK/EEA entity → US under the UK Extension to the EU-US DPF and/or the UK IDTA / SCC Addendum |
| Cloudflare UK Ltd | Edge security (__cf_bm) and cookieless storefront analytics | Strictly necessary + Analytics | UK point-of-presence first |
We do not sell your data. Full detail of every processor we use (AWS, Stripe, PayPal, Brevo, Firebase) is in our Privacy Policy. You can request a copy of the safeguard for any specific transfer at privacy@bitte.uk.
8. Controlling cookies in your browser
You can manage or delete cookies through your browser settings (Chrome, Safari, Firefox, Edge), or use private / incognito browsing. Blocking all cookies will stop strictly-necessary cookies too, so sign-in and checkout may break. Where your browser sends a recognised Global Privacy Control signal we aim to keep analytics and marketing cookies off; the most reliable control remains the cookie banner.
9. Cookies in the Bitte mobile apps
Our apps don't use browser cookies but use SDKs for similar purposes: Firebase (Google) for authentication, push notifications and chat (strictly necessary), and crash/stability diagnostics with no advertising identifiers. We do not use a mobile advertising SDK or collect your device's advertising ID for marketing. Your operating system also gives you controls (iOS App Tracking Transparency, Android ad-ID settings).
10. Changes to this policy
We update this policy when our cookie use changes or the law does. Material changes are reflected here with a new "Last updated" date, and where a change introduces a new cookie purpose we re-prompt you through the banner.
11. Contact and complaints
Questions about cookies? Email privacy@bitte.uk. If you are unhappy with our response you can complain to the UK Information Commissioner's Office (0303 123 1113, https://ico.org.uk/make-a-complaint/).
Questions? privacy@bitte.uk.