Cookie policy
What we store on your device — cookies, localStorage and sessionStorage — for what purpose, and how to change your decision.
Version 0.1-draft · Last updated September 3, 2026
Summary
| Item | Details |
|---|---|
| What this policy covers | Cookies and any other device for storing and retrieving data on your terminal equipment: HTTP cookies, localStorage and sessionStorage. |
| Controller | [PENDING: legal name], Tax ID [PENDING: NIF/CIF], with registered address at [PENDING: full postal address]. Contact: [PENDING: privacy contact email]. |
| What we use | Technical and functional storage that is strictly necessary to provide the service (session, payments, language, theme, form drafts), preference storage, cookieless performance measurement and, only if you accept it, product analytics (PostHog). |
| Legal basis | Technical and functional storage is exempt from the consent requirement (Art. 22.2 LSSI-CE). Product analytics is enabled only with your consent, given in the cookie banner. |
| How to withdraw it | From “Cookie preferences” in the app, or by clearing the site’s storage in your browser. Details in section 5. |
| Third parties | Stripe (payments), Cloudflare (performance and cookieless measurement) and PostHog (analytics, only with your consent), all acting as processors. Details in sections 4 and 6. |
1. What a cookie is and what other storage we use
A cookie is a small text file that a website stores in your browser when you visit it. It makes it possible to remember information across pages and across visits: for example, that you are signed in or the language you prefer.
Article 22.2 of the LSSI-CE is not limited to cookies: it covers any form of storing information and retrieving information already stored on the user’s terminal equipment. This policy therefore also informs you about the use of:
localStorage: persistent storage in the browser, with no automatic expiry date. It stays until it is explicitly cleared.sessionStorage: storage that is cleared when the tab or browser is closed.
In this policy, unless stated otherwise, “cookies” refers to all of these techniques.
2. Applicable law
- Article 22.2 of Law 34/2002 (LSSI-CE), on Information Society Services and Electronic Commerce.
- Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD), where the use of cookies involves the processing of personal data.
- The Spanish Data Protection Agency (AEPD) Guidance on the use of cookies.
3. Types of cookies by purpose
- Technical or necessary: essential for the page to work and to provide the service you request (keeping the session, security, remembering your cookie choice). No consent is required.
- Preference or personalisation: they remember options you have chosen (language, light/dark theme, notices you have dismissed) so you are not asked again. They are considered exempt where the service has been expressly requested by you.
- Analytics or measurement: they make it possible to understand, in aggregate, how the application is used in order to improve it. They require your consent and are only enabled if you accept them in the banner.
- Cookieless measurement: tools that measure site performance without storing or reading anything on your device. They fall outside Article 22.2 and therefore require no consent, but we disclose them anyway. Details in section 4.4.
Reservo does not use behavioural advertising cookies and does not share data with third parties for advertising purposes.
4. Details of the storage used
4.1 HTTP cookies
| Name | Ownership | Purpose | Duration | Category |
|---|---|---|---|---|
better-auth.session_token (or __Secure-better-auth.session_token over HTTPS) | First party | Securely keep you signed in after you log in. | 30 days | Technical (necessary) |
better-auth.session_data | First party | Temporary cache of session data to reduce server lookups on each request. | 5 minutes | Technical (necessary) |
better-auth.account_data | First party | Temporary cache of account data, for the same purpose as the previous one. [PENDING: confirm it is issued in the current flow.] | 5 minutes | Technical (necessary) |
__stripe_mid | First party — written by Stripe.js on our domain | Identify the device to prevent payment fraud. Only created when you open a payment form. | 1 year | Technical (necessary) |
__stripe_sid | First party — written by Stripe.js on our domain | Identify the payment session to prevent fraud. Only created when you open a payment form. | 30 minutes | Technical (necessary) |
m | Third party — Stripe (m.stripe.com) | Fraud prevention within the embedded payment frame. | [PENDING: confirm duration] | Technical (necessary) |
ph_[project-id]_posthog | Third party — PostHog ([PENDING: confirm entity and country; processing in the EU]) | Identify the device across visits for product analytics. Only created if you accept analytics. | 12 months (PostHog default; [PENDING: confirm]) | Analytics (consent) |
4.2 localStorage (persistent browser storage)
| Key | Ownership | Purpose | Duration | Category |
|---|---|---|---|---|
reservo-consent | First party | Remember your decision about product analytics so the banner is not shown again. | Persistent until you clear the site data | Technical (necessary) |
reservo-theme | First party | Remember whether you chose the light or dark theme. | Persistent | Preferences |
reservo-lang | First party | Remember the selected language (Spanish or English). | Persistent | Preferences |
reservo:register-form-draft | First party | Keep what you have typed in the sign-up form if you leave without finishing, so you can resume it. | Until sign-up is completed or discarded | Technical (functional) |
reservo:login-form-draft | First party | Same as above, for the login form. | Until you sign in | Technical (functional) |
reservo-push-prompt-shown | First party | Remember that you have already been offered push notifications so the prompt is not repeated. | Persistent | Preferences |
reservo-pwa-install-dismissed | First party | Remember that you dismissed the app install prompt. | Persistent | Preferences |
reservo-calendar-hour-range, reservo-calendar-zoom | First party | Remember the time range and zoom level of the management calendar (club accounts only). | Persistent | Preferences |
Keys prefixed with ph_ (PostHog) | Third party — PostHog | Product analytics state on the device (identifier, session properties). Only if you accept analytics. | 12 months ([PENDING: confirm]) | Analytics (consent) |
__ph_opt_in_out_[token] (PostHog) | Third party — PostHog | Remember that you rejected analytics so you are not measured again. It is kept on purpose: it is precisely what makes your refusal effective. | Persistent | Technical (necessary) |
4.3 sessionStorage (cleared when the tab is closed)
| Key | Ownership | Purpose | Duration | Category |
|---|---|---|---|---|
pwa-hard-recover-attempted | First party | Prevent a reload loop when the installed app tries to recover from a load error. | Until the tab is closed | Technical (necessary) |
4.4 Cookieless performance measurement (Cloudflare Web Analytics)
We use Cloudflare Web Analytics to measure site performance. Unlike everything above, it neither writes nor reads anything on your device: no cookies, no localStorage, no sessionStorage, no fingerprinting techniques, and it creates no identifier that could track you across visits or across sites.
It works through a script (static.cloudflareinsights.com/beacon.min.js) that sends aggregate metrics for each page load: load times, referring page, device and connection type, and the country inferred from your IP address.
That is why it does not require your consent: Article 22.2 of the LSSI-CE requires consent to store information on your device or to retrieve information already stored there, and neither happens here. We disclose it anyway, for transparency.
This measurement is active both on the public website and inside the application. The lawful basis for the associated processing is the legitimate interest in understanding and improving the performance of the service (Art. 6(1)(f) GDPR); you will find the details in the privacy policy.
[PENDING: review this inventory against the code before each publication. It must be updated whenever any cookie or storage key is added, removed or changed.]
5. How to manage or withdraw your consent
- From this page: the “Cookie preferences” button at the end of this page brings the banner back so you can change your decision, whether or not you have an account. This page is linked from the footer of every page.
- From your account: if you are signed in, “Profile → Privacy” gives you the same control.
- What happens when you reject: capture stops immediately and PostHog’s identifier is cleared from your device. A single key (
__ph_opt_in_out_[token]) is kept on purpose to record your refusal: it is precisely what prevents you from being measured again. - From your browser: you can block or delete the site’s cookies and local storage from your browser settings. Note that if you delete the technical storage your session will end and your preferences will be lost.
Instructions for the most common browsers:
Withdrawing consent does not affect the lawfulness of processing carried out before it was withdrawn.
6. International transfers
First-party storage (Reservo cookies, localStorage and sessionStorage) does not involve international data transfers.
Product analytics is provided by PostHog as a processor, with data processing on servers within the European Union. [PENDING: confirm the contracted instance (EU) and, where applicable, the Chapter V GDPR safeguards that apply.]
Performance measurement (section 4.4) is provided by Cloudflare, Inc. (United States) as a processor. Although it stores nothing on your device, it does process your IP address transiently in order to infer the country. [PENDING: confirm the data processing agreement (DPA) with Cloudflare and the applicable Chapter V GDPR transfer basis.]
Payments are processed by Stripe (section 4.1). [PENDING: confirm the contracting Stripe entity, the processing agreement and, where applicable, the transfer basis that applies.]
7. Personal data and your rights
Where the use of cookies involves the processing of personal data, that processing is governed by the privacy policy, where you will find information about the controller, the purposes, the retention periods and how to exercise your rights of access, rectification, erasure, objection, restriction and portability, as well as the right to lodge a complaint with the Spanish Data Protection Agency.
8. Changes to this policy
We may update this policy to adapt it to legal, technical or service changes, or when the cookie inventory changes. Each version is identified by a version number and a last updated date, shown at the top of the document. Where changes affect cookies that require consent, you will be asked again.
Cookie preferences
You can change your decision about product analytics at any time, whether or not you have an account.