Skip to content
Bitte
Version v1.1

Cookie Policy

Effective from: 1 July 2026

This Cookie Policy explains the cookies and similar technologies Bitte uses on https://bitte.uk, the Bitte apps, the merchant dashboard, and restaurant white-label storefronts. It sits alongside our Privacy Policy, which explains everything else we do with your personal data.

1. Who we are

This Cookie Policy is published by Bitte Limited ("Bitte", "we", "us", "our").

ItemDetail
Legal nameBitte Limited
Companies House number17140318
Registered office71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
ICO registration numberZC193676
Data protection contactprivacy@bitte.uk

2. What cookies and similar technologies are

A cookie is a small text file a website asks your browser to store. On a later visit the browser sends it back, so the site can recognise your session, remember a preference, or measure how the site is used.

"Similar technologies" covers anything that stores or reads information on your device for the same purposes — including browser local storage, pixels / tracking beacons, and SDKs inside our mobile apps. UK law treats all of these the same way. Where this policy says "cookies" it means all of these unless we say otherwise. We tell you specifically where we use local storage rather than a cookie — for example, your cookie-consent choice itself is stored in local storage, not in a cookie.

3. The law, in plain terms

Two regimes apply together:

  • PECR (as amended by the Data (Use and Access) Act 2025) governs storing or reading information on your device. The default rule is that we must tell you clearly what each non-exempt cookie does and get your consent before we set it. A small set of cookies is exempt (see Section 4).
  • UK GDPR governs what we then do with any personal data a cookie collects — detailed in our Privacy Policy.

4. Which cookies need your consent — and which don't

4.1 Strictly necessary cookies — no consent needed, always on

Some cookies are strictly necessary for a service you have asked for: keeping you signed in, protecting a form against cross-site request forgery, remembering your basket, and basic security. PECR exempts these from consent. You cannot switch these off through our banner, but you can block all cookies in your browser settings (Section 8) — parts of the site may then stop working.

4.2 The new 2025 exemptions — and why we still ask anyway

From 5 February 2026 a new exemption allows cookies used solely for first-party analytics without consent, if we give clear information and a free opt-out. We have decided not to rely on it. Instead we ask for your opt-in consent before setting any analytics cookie, because we also run Meta Pixel for advertising measurement — and the analytics exemption does not apply where data can feed advertising. This makes Bitte stricter than the law requires, by design.

4.3 Analytics and marketing cookies — consent required, off by default

Everything that is not strictly necessary — analytics and marketing/advertising cookies — is off until you opt in through the cookie banner. Nothing in those categories loads on your first visit, and nothing loads at all if you choose "Reject all".

5. How we ask, and how you change your mind

On your first visit you see a banner offering "Accept all", "Reject all" and "Customise" — with the reject option presented as easily as accept, no pre-ticked boxes, and no analytics or marketing cookie set until you choose. Closing the banner counts as reject.

You can change your mind at any time using Cookie settings in the footer (or Privacy settings in the app) to re-open the banner. When you turn a category off, we stop setting those cookies and do not load the associated scripts on later page views; on bitte.uk, withdrawing analytics consent also clears the Google Analytics identifiers (_ga*). We treat a stored choice as valid for 12 months, then re-prompt.

6. The cookies we use

"First-party" means set on a Bitte domain; "third-party" means set by the named provider on their own domain.

6A. bitte.uk, the Bitte apps, and the merchant dashboard

Strictly necessary — always on

NameProviderPurposeType / lifetime
XSRF-TOKENBitteCross-site request forgery protectionCookie · session
bitte_access_tokenBitteKeeps you signed in (short-lived)Cookie · 15 minutes · HttpOnly + Secure
bitte_refresh_tokenBitteRe-authenticates when the access token expiresCookie · 30 days · HttpOnly + Secure
bitte_sessionBitteNon-sensitive "you have a session" markerCookie · 7 days
i18nextLngBitteRemembers your languageLocal storage
__cf_bmCloudflareBot-management / abuse protectionCookie · ~30 minutes
Cart, theme preferenceBitteRemembers your basket and display preferenceLocal storage
bitte-gdpr-consentBitteStores your cookie choices + timestampLocal storage · 12 months

Analytics — only if you accept "Analytics"

NameProviderPurposeType / lifetime
_ga, _ga_<id>Google Analytics 4Measures how the site is used so we can improve itCookie · up to 2 years
_gid (if set)Google Analytics 4Distinguishes visitors over a short windowCookie · 24 hours
bitte_booking_sourceBitteRecords which channel led you to a page, for attributionCookie · 60 minutes
bitte_anon_idBitte (first-party)Pseudonymous device identifier that groups your first-party behavioural events (page/menu/item views, funnel and search signals — see Privacy Policy §4A) so we can measure and improve the diner journeyLocal storage, not a cookie · up to ~13 months
bitte_anon_session_idBitte (first-party)Pseudonymous session identifier tying the events within a single visit together for the same analytics purposeLocal storage, not a cookie · per browsing session

On-device storage note (PECR). bitte_anon_id and bitte_anon_session_id are local-storage items, not cookies. Because they store and read information on your device they are still governed by PECR reg. 6, so we set them only after you accept Analytics — never before.

Marketing / advertising — only if you accept "Marketing"

NameProviderPurposeType / lifetime
_fbp, _fbcMeta PixelMeasures advertising effectiveness and builds audiences (bitte.uk web only — not used in the mobile apps)Cookie · 3 months
frMetaDelivery and measurement of Meta advertising (bitte.uk web only)Third-party cookie · 3 months

6B. Restaurant white-label storefronts

Storefronts use a smaller set and no advertising cookies: the same strictly-necessary security/session cookies and __cf_bm; your consent record in local storage (bitte_store_gdpr_consent_v2) plus a legacy companion cookie (bitte_store_gdpr_consent); and, only if you accept analytics, Cloudflare Web Analytics, which is cookieless (it sets no tracking cookie and does not fingerprint you), together with the first-party bitte_anon_id / bitte_anon_session_id local-storage identifiers described above — both set only after you accept Analytics and used only for aggregate, single-storefront diner-journey analytics (see Privacy Policy §4A). Storefronts never set Meta Pixel or any marketing cookie.

7. Third parties, and what leaves the UK

When you accept Analytics or Marketing, some data (such as your cookie ID, IP address and the pages you view) is shared with the provider operating that cookie.

ProviderUsed forCategoryRegion + transfer basis
GoogleGoogle Analytics 4 — first-party site statisticsAnalyticsUK/EEA entity → US under the UK Extension to the EU-US Data Privacy Framework and/or the UK IDTA / SCC Addendum
MetaMeta Pixel — advertising measurement and audiencesMarketingUK/EEA entity → US under the UK Extension to the EU-US DPF and/or the UK IDTA / SCC Addendum
Cloudflare UK LtdEdge security (__cf_bm) and cookieless storefront analyticsStrictly necessary + AnalyticsUK point-of-presence first

We do not sell your data. Full detail of every processor we use (AWS, Stripe, PayPal, Brevo, Firebase) is in our Privacy Policy. You can request a copy of the safeguard for any specific transfer at privacy@bitte.uk.

8. Controlling cookies in your browser

You can manage or delete cookies through your browser settings (Chrome, Safari, Firefox, Edge), or use private / incognito browsing. Blocking all cookies will stop strictly-necessary cookies too, so sign-in and checkout may break. Where your browser sends a recognised Global Privacy Control signal we aim to keep analytics and marketing cookies off; the most reliable control remains the cookie banner.

9. Cookies in the Bitte mobile apps

Our apps don't use browser cookies but use SDKs for similar purposes: Firebase (Google) for authentication, push notifications and chat (strictly necessary), and crash/stability diagnostics with no advertising identifiers. We do not use a mobile advertising SDK or collect your device's advertising ID for marketing. Your operating system also gives you controls (iOS App Tracking Transparency, Android ad-ID settings).

10. Changes to this policy

We update this policy when our cookie use changes or the law does. Material changes are reflected here with a new "Last updated" date, and where a change introduces a new cookie purpose we re-prompt you through the banner.

11. Contact and complaints

Questions about cookies? Email privacy@bitte.uk. If you are unhappy with our response you can complain to the UK Information Commissioner's Office (0303 123 1113, https://ico.org.uk/make-a-complaint/).


Questions? privacy@bitte.uk.