Cookie Policy
Last updated: 2026-09-08
We use cookies and similar technologies to make the site work and, only with your consent, for analytics and marketing. This policy explains what we use, why, and how you can control your choice.
This is a translation for your convenience. The Romanian version of this document is the authoritative one; in case of any discrepancy, the Romanian text prevails.
What they are and the legal basis
Cookies are small files stored on your device; we also use pixels and server-side measurement events. Storing or reading information on your device for non-essential purposes happens only with your prior consent (Art. 4(5) of Law 506/2004 and Art. 6(1)(a) GDPR). Strictly necessary cookies do not require consent.
Categories
Necessary (always on): essential for the site to function and stay secure. Cannot be disabled.
Analytics (optional): helps us understand how the site is used (e.g. Hotjar, Google Analytics).
Marketing (optional): enables ad measurement and optimisation.
List of cookies and technologies
yab_sid, yes.abeauty.ro (first-party), identifies your questionnaire session to keep your answers, Necessary, 1 hour.
yab_consent, yes.abeauty.ro (first-party), stores your cookie choice, Necessary, 180 days.
yab_pixel_lead, yes.abeauty.ro (first-party, session storage), briefly hands off your submission to the confirmation step, Necessary, cleared at end of session.
yab_click, yes.abeauty.ro (first-party; set only with marketing consent), stores ad click identifiers (gclid, gbraid, wbraid, fbclid, ttclid, oppref) and campaign parameters (UTM) for conversion measurement, Marketing, 90 days.
Cloudflare Turnstile, Cloudflare, anti-bot protection at form submission; strictly necessary to secure the service, not used for analytics or advertising, Necessary, session / short-lived.
_fbp, _fbc, Meta (set by Meta Pixel, only with marketing consent), browser and click identifiers for ad measurement, Marketing, up to 90 days (typical).
_hjSession_*, _hjSessionUser_*, _hjFirstSeen and similar, Hotjar (first-party, set only with analytics consent), session recording and interaction heatmaps to understand site usage; text is masked, so questionnaire answers are not recorded, Analytics, from 30 minutes up to 12 months (typical).
Google Tag Manager (www.googletagmanager.com), a third-party container that manages the Google tags (Google Analytics 4 and Google Ads); it loads ONLY after consent (Google Consent Mode v2) and sets no tracking cookies of its own, Necessary for tag management (functional), not applicable.
_ga, _ga_* (Google Analytics 4, loaded via Google Tag Manager, only with analytics consent), pseudonymous browser/session identifiers for usage statistics, Analytics, up to 2 years (Chrome typically caps at ~400 days, Safari at 7 days).
_gcl_au and other _gcl_* cookies (Google Ads “Conversion Linker”, via Google Tag Manager, only with marketing consent), link ad clicks to conversions and enable remarketing, Marketing, up to 90 days.
Server-side measurement events (Google Analytics 4 via the Measurement Protocol, Meta Conversions API, Google Ads Enhanced Conversions, OpenAI Ads Conversions API), Google/Meta/OpenAI, conversion measurement, in addition to in-browser measurement, only with the corresponding consent, Analytics/Marketing, not applicable (no browser cookie).
Trustindex (Trustindex.io), a third-party widget that shows the Google-reviews badge on the homepage (the script is loaded from cdn.trustindex.io); on load it receives the visitor's IP. It is functional content, NOT used for analytics or advertising, and it sets no analytics/marketing cookies, Functional content, not applicable.
Note: durations are typical provider values and can be verified in your browser.
Server-side measurement
A significant part of the measurement happens on our servers, using the same identifiers and hashed contact data. In addition, after consent, we also load browser tags via Google Tag Manager (Google Analytics 4, with analytics consent; Google Ads, with marketing consent), and the Meta Pixel (with marketing consent) may also send a browser event. For OpenAI (ChatGPT Ads) we load NO script in your browser and set no cookie: those campaigns are measured entirely from our own servers, only with marketing consent. Google Tag Manager loads ONLY after consent (Google Consent Mode v2: all signals default to “denied” until your choice). Hashing does not anonymise the data, only pseudonymises it, so consent is still required.
Tracking in the emails we send you
The emails we send you through Brevo contain a tracking pixel (an invisible image loaded from Brevo’s servers) that tells us whether the message was opened. In addition, every link in the HTML version of the message is rewritten, so your click passes through Brevo’s servers first and only then reaches its destination. That is how we learn whether the email arrived, whether it was opened, and which link you clicked.
The practical consequence, which we would rather state plainly: the full address of the link you click reaches Brevo’s logs, together with the time of the click. That includes the link in the confirmation email that opens your data-management page. Brevo is our processor, acts only on our instructions under an Art. 28 GDPR contract, and hosts the data in the European Union.
The legal basis: for transactional messages (confirmations and notices about your request), our legitimate interest in making sure the messages actually arrive and in fixing it when they do not (Art. 6(1)(f) GDPR); you may object at any time under Art. 21. For marketing messages the basis is your consent (Art. 6(1)(a)), which you can withdraw as easily as you gave it. If you want to avoid the tracking, you can use an email client that blocks image loading, and open the plain-text version of the message, where links are not rewritten.
International transfers
Google, Meta and Cloudflare are in the US; transfers rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses. OpenAI (ChatGPT Ads) is also in the US, but it does not appear in the EU-US Framework list (checked on 7 September 2026), so for that recipient the transfer relies on the Standard Contractual Clauses in our contract with OpenAI. See the transfers section of the Privacy Policy.
How to change your choice
You can accept, reject or customise your choice from the consent banner. You can change your choice at any time, as easily as you gave it; withdrawal stops further collection. Analytics and marketing cookies do not load before your consent.
Duration and updates
We keep your choice for about 6 months, after which we ask again; we may re-ask sooner if we change the provider list. We may update this policy; the last-updated date is shown above.