Cookie Policy
Last updated: 27 May 2026
This policy explains the cookies and similar technologies we set on the BYBU Aesthetics & Wellness website, why we set them, how long they last, and how you can manage them. It sits alongside our Privacy Policy.
1. What is a cookie?
A cookie is a small text file a website saves on your device when you visit. We also use similar technologies — for example, local storage and pixels — which we treat the same way as cookies in this policy. Some cookies are essential for the site to work; others help us understand how the site is used or are set by third parties we work with.
2. Your choices
Strictly necessary cookies are set without asking — the site cannot work without them and the law allows this. For everything else (analytics, optional features) we ask for your consent before they are set, and you can change your mind at any time by:
- Using the consent toggle in the site footer or your account settings;
- Clearing cookies in your browser and refusing the banner next time; or
- Emailing info@bybuaesthetics.com and asking us to record your preference.
You can also choose "Allow necessary cookies only" at the banner — this leaves analytics and marketing cookies switched off, and only the strictly necessary cookies in the table below stay on.
We honour the Global Privacy Control (GPC) and Do-Not-Track browser signals — if your browser sends either, we treat it as a refusal of optional cookies.
3. Cookies we set on our own domain
| Name | Purpose | Category | Duration |
|---|---|---|---|
bybu_client_session | Keeps you signed in to your account. | Strictly necessary | Session (cleared on sign-out or browser close) |
bybu_csrf | Protects forms from cross-site request forgery attacks. | Strictly necessary | Session |
bybu_consent | Remembers your cookie preferences so we do not ask every visit. | Strictly necessary | 12 months |
4. Third-party cookies and similar technologies
We use a small number of third parties to run the site. Where they set cookies on your device, they are listed below.
| Provider | Purpose | Category | Duration |
|---|---|---|---|
Stripe (__stripe_mid, __stripe_sid and similar) | Process payments and detect payment fraud. Only set when you reach the wellness checkout. | Strictly necessary (payment) | Up to 1 year |
Vercel (_vercel_*) | Hosting, edge routing, and request integrity for the website. | Strictly necessary | Session to 1 year |
PostHog (ph_*) | Privacy-friendly product analytics. Helps us see which pages people use and where the site breaks. IP addresses are truncated and we do not use PostHog for advertising. Only set after you consent. | Analytics (consent) | Up to 12 months |
| Marketing partners (e.g. Meta Pixel, Google Ads, TikTok Pixel) | Help us measure how people find us and show more relevant adverts on other sites. Not currently active — only set after you choose "Approve cookies". We will update this table with the exact provider list before any marketing cookie goes live. | Marketing (consent) | Up to 13 months |
Stripe sets its own cookies inside its embedded checkout iframe under Stripe's cookie policy. They are required for the payment to clear; if you block them, checkout will not work.
5. Marketing and analytics — what stays off unless you approve
- Marketing and analytics cookies are only set if you choose "Approve cookies" at the banner. If you choose "Allow necessary cookies only", none of them are written.
- We do not use cross-site tracking or fingerprinting beyond what is technically required to run the site.
- We do not sell, rent, or share data collected through cookies with data brokers.
6. Managing cookies in your browser
You can clear or block cookies in your browser settings at any time. Doing so will sign you out of your account and you will need to sign in again. If you block third-party cookies entirely, Stripe checkout may not load — you can allow third-party cookies for the checkout page or use a different browser when paying.
Most browsers offer step-by-step instructions:
7. Changes
If we add or remove a cookie or change what an existing one does, we will update this page and the "Last updated" date above. Material changes that introduce a new third-party cookie will also trigger a fresh consent prompt.
8. Contact
Questions about cookies? Email info@bybuaesthetics.com.