Cookie Policy
Last updated: July 10, 2026
1. What cookies and similar technologies are
Cookies are small text files that a website can store in your browser when you visit a page. Besides cookies, we also use similar technologies that serve comparable purposes without being, technically, cookies — in particular your browser's storage (localStorage and sessionStorage), where identifiers or preferences can be saved on your device.
Legally, all of these technologies — cookies and any information read from or written to your terminal device through localStorage/sessionStorage — fall under the same rule: they may be used without consent only if they are strictly necessary to deliver the service you asked for. Anything else (traffic analytics, marketing, conversion measurement) requires your prior consent.
This policy explains exactly what we use on La beauté de SEFORA's booking site, for what purpose, for how long, and what requires consent.
2. The categories of cookies and technologies we use
| Name | Provider | Category | Purpose | Storage duration | Consent required |
|---|---|---|---|---|---|
| __Secure-next-auth.session-token | La beauté de SEFORA (first-party) | Strictly necessary | Keeps your sign-in session active (account/booking) | Session / up to 30 days | No |
| __Host-next-auth.csrf-token | La beauté de SEFORA (first-party) | Strictly necessary | Anti-CSRF protection when submitting forms and signing in | Session | No |
| cookie-consent-cmmjg76zq00os110z0ev8n38f (in localStorage) | La beauté de SEFORA (first-party) | Strictly necessary | Remembers your consent choice so we don't ask on every visit | Persistent (until cleared) | No |
| thesalon_device_token (in localStorage) | La beauté de SEFORA (first-party) | Strictly necessary | Remembers this device so you skip SMS re-verification on your next booking | Persistent — up to 12 months, renewed on each booking | No |
| _pst (in sessionStorage) | La beauté de SEFORA (first-party) | Analytics | Session identifier for anonymous navigation and booking-funnel analytics | Session (cleared when the tab closes) | Yes |
| _pvid (in localStorage) | La beauté de SEFORA (first-party) | Analytics | Anonymous device identifier to detect returning visitors | Persistent (until cleared) | Yes |
| _putm (in sessionStorage) | La beauté de SEFORA (first-party) | Analytics | Stores the campaign source (UTM / click ID) for the session, for traffic attribution | Session | Yes |
| _porigin (in sessionStorage) | La beauté de SEFORA (first-party) | Attribution — contains no identifier | Keeps where this visit came from — the campaign your own link already named in the web address (utm_source / utm_medium / utm_campaign), the referring host — and, when that host is an AI assistant, which assistant it is — the entry path and the salon's own public id (which names the salon, never you) — for the booking you are making, so the salon can tell which campaign, or which site, brought it. It is written when the link named a campaign, and equally when it named none and the site you arrived from is all there is to keep; when there is neither, nothing is written. It creates no identifier: two people arriving from the same ad store byte-identical content, it cannot be read on a later visit, in another tab or on another device, and it is sent nowhere except this salon's own booking form | Session (cleared when the tab closes) | No — written before consent; see the section below |
| _plpsd (in sessionStorage) | La beauté de SEFORA (first-party) | Analytics | Remembers how far down a campaign landing page you scrolled, so the same figure is not reported twice in one session. Holds a number between 0 and 100 and nothing else — no identifier. Written only after you accept analytics, together with the script above | Session (cleared when the tab closes) | Yes |
| primer:booking-consent:<id> (in sessionStorage) | La beauté de SEFORA (first-party) | Strictly necessary | Keeps, in this tab only, the handle for the booking you have just sent, so the confirmation page can offer you the marketing subscription for it. It exists only because you completed a booking, it is never written to anyone who did not, and closing the tab removes it | Session (cleared when the tab closes) | No |
| Google Analytics 4 (_ga, _ga_*) | Analytics | Aggregate audience statistics (pages viewed, duration, conversions) | Up to 24 months | Yes | |
| Google Tag Manager | Analytics / Marketing | Container that loads the configured analytics and marketing tags | As per loaded tags | Yes | |
| Google Ads (gtag.js, conversions) | Marketing | Advertising conversion measurement and remarketing | Up to 24 months | Yes | |
| Meta / Facebook Pixel (_fbp) | Meta Platforms | Marketing | Conversion measurement and custom audiences for Facebook/Instagram ads | Up to 3 months | Yes |
| TikTok Pixel | TikTok | Marketing | Conversion measurement and TikTok ad optimization | Up to 13 months | Yes |
| Pinterest Tag | Marketing | Conversion measurement and Pinterest ad optimization | Up to 12 months | Yes |
Note: the third-party cookies and tags (Google, Meta, TikTok, Pinterest) are configured per salon. Not all of them may be active on this site — only those enabled by La beauté de SEFORA appear.
3. The _pvid and _pst device identifiers are non-essential
We want to be explicit: the anonymous identifiers _pvid (in localStorage) and _pst (in sessionStorage), together with _putm and the scroll watermark _plpsd, are NOT strictly necessary for the site to function. They are used solely for traffic and navigation analytics.
Therefore, the script that creates and writes these identifiers to your device loads ONLY after you have given consent. Before consent, no _pvid, _pst, _putm or _plpsd is written to your browser.
The one NON-ESSENTIAL thing written before consent is _porigin (in sessionStorage): where this visit came from — the campaign your own link already named in the web address, or, when it named none, simply the site that sent you here (and, when that site is an AI assistant, which one) — kept for this tab only so the booking you are about to make can be credited to what actually brought you. It contains no identifier of any kind — see its row in the table above and the section below.
Everything else that is written without asking you first is strictly necessary and is marked as such in the table: your sign-in session, your consent choice itself, the device token that spares you an SMS, and primer:booking-consent:<id> — the handle for a booking you have just sent, which exists only because you sent it and which the tab removes when you close it.
4. Strictly necessary cookies (no consent needed)
The following technologies are indispensable for the site to work and for you to complete a booking securely. For these, the law does not require consent, and disabling them would prevent the service from functioning:
- Session cookie (__Secure-next-auth.session-token) — keeps you signed in while you use your account or complete a booking;
- Anti-CSRF cookie (__Host-next-auth.csrf-token) — protects forms against cross-site request forgery;
- Consent storage (cookie-consent-cmmjg76zq00os110z0ev8n38f in localStorage) — remembers your own cookie choice so we don't ask again on every visit.
5. No non-essential cookie or tracker runs before consent — with one declared exception
On this site, non-essential cookies and technologies (analytics and marketing) are NOT activated before you give consent. Until you accept, the analytics and marketing scripts (Google, Meta, TikTok, Pinterest) and the device identifiers (_pvid, _pst, _putm) and the scroll watermark (_plpsd) are not loaded and write nothing to your device. For Google services, the default consent state is set to “denied” (consent mode) until you accept.
The one exception, stated plainly: _porigin (in sessionStorage) is written when you arrive. It is neither analytics nor marketing and it recognises nobody. It holds only what this page load already carried: the campaign your own link named in the web address (utm_source / utm_medium / utm_campaign), the site you came from — and, when that site is an AI assistant, which assistant it is — the page you landed on and the salon's own public id, which names the salon, never you — for the length of this tab, so that the booking you make can be credited to what brought you. It is written when your link named a campaign, and equally when it named none and the site you came from is all there is to keep; if you arrived from nowhere we can name — you typed the address in, or followed a link from this same site — nothing at all is written. It mints no identifier, it is not read on a later visit, in another tab or on another device, it is never combined with anything else, and it leaves your browser only together with the booking you send to this salon. You can clear it at any time by closing the tab.
6. How consent works
On your first visit, we show a consent banner at the bottom of the page. From there you can:
- Accept — enables the analytics and marketing cookies and technologies described above;
- Reject / dismiss — the site remains fully functional using only the strictly necessary technologies; no non-essential tracker is loaded.
Your choice is stored locally on your device so you don't have to repeat it on every visit.
7. How to withdraw or change your consent at any time
You can change your mind at any time. You have the right to withdraw your consent as easily as you gave it:
- Use the “Cookie settings” link available on the site — it reopens the consent banner, where you can re-enable or disable the non-essential categories;
- Alternatively, you can clear the site's cookies and storage from your browser settings; on your next visit we will ask you again.
Withdrawing consent stops the loading of non-essential technologies going forward. It does not affect the lawfulness of processing carried out before withdrawal.
8. Who we are and how to contact us
This booking site is operated by:
- La beauté de SEFORA
- Strada Soporului 8A, 400482 Cluj-Napoca
- România
- Email: contact@labeautedesefora.ro
- Phone: +40730488564