BelioReservations
Legal

Cookie Policy

Last updated: 30 July 2026

This Cookie Policy explains how Belio Reservations uses cookies and similar technologies (local storage, pixels/tags). It should be read with our Privacy Policy. It reflects GDPR, the ePrivacy Directive, and AEPD guidance for Spain: non-essential cookies require prior opt-in; rejecting is as easy as accepting; and you can withdraw consent at any time.

1. What are cookies?

Cookies are small text files stored on your device. Similar technologies include local/session storage. Some are strictly necessary; others (analytics) are optional and blocked until you consent.

2. How we obtain consent

On your first visit we show a cookie banner with three equal options: Accept all, Reject, and Customise. Analytics scripts (Google Tag Manager) do not load until you opt in. Your choice is stored locally (consent record) with a version and timestamp.

You can change or withdraw consent later via the cookie banner (shown again when you clear your consent record or when we update this policy) or by reviewing the options described in this Cookie Policy. Withdrawing analytics consent stops GTM/measurement tags and clears known Google Analytics cookies where possible.

3. Categories we use

Strictly necessary (always on). Required to provide the service you request and for security. Legal basis: Art. 6(1)(b)/(f) GDPR and the ePrivacy exception for cookies strictly necessary for a service requested by the user. Examples:

  • Authentication session cookies (Auth.js / NextAuth) when you sign in to the dashboard.
  • Language preference cookies (belio_guest_locale, belio_owner_locale).
  • Cookie consent record in local storage (belio_cookie_consent).
  • Lightweight UX flags such as returning-user welcome state (belio_returning / related local storage).
  • Cloudflare Turnstile on registration, password, and public booking forms — security / bot protection that may use Cloudflare cookies or storage as described in Cloudflare's documentation.

Analytics (opt-in only). Google Tag Manager (GTM) and measurement tags configured in your GTM container (for example Google Analytics 4). These may set cookies such as _ga / _gid and send device/usage data to Google. Legal basis: consent (Art. 6(1)(a) GDPR). Default state: denied (Google Consent Mode v2). We do not load GTM until analytics is accepted.

Advertising / social. We do not currently deploy Meta, TikTok, or similar advertising cookies on Belio. If that changes, we will add a separate opt-in category and update this policy before enabling them.

4. Cookie / storage reference

NameCategoryPurposeDuration
Auth.js session cookiesNecessaryKeep dashboard users signed inSession / up to ~8 hours
belio_guest_locale / belio_owner_localeNecessaryRemember UI languageUp to 1 year
belio_cookie_consentNecessaryStore consent choicesUntil cleared / policy version change
belio_returning (+ related local storage)NecessaryReturning-user welcome UXPersistent until cleared
Cloudflare TurnstileNecessary (security)Bot protection on formsPer Cloudflare
_ga, _gid, related GA/GTMAnalyticsUsage measurement via GTMPer Google (often up to 2 years)

5. Browser controls

You can also delete or block cookies in your browser. Blocking strictly necessary cookies may break sign-in or language preferences. Browser controls do not replace the Belio banner for analytics opt-in on this site.

6. Changes

We may update this Cookie Policy. When consent requirements change, we bump the consent version so the banner can ask again. Last updated date appears at the top of this page.

7. Contact

Questions: info@belio.studio. Supervisory authority in Spain: AEPD (aepd.es).

Cookie Policy | Belio