What is a cookie?
A cookie is a small text file a website asks your browser to remember between visits. Hesett also uses two related technologies — localStorage and sessionStorage — which store small amounts of data in your browser. For simplicity, we refer to all of these as “cookies” below.
How we use them
We use cookies for three reasons, in this order of importance: (1) to make the Service work at all, (2) to remember your preferences between visits, and (3) to understand how the Service is used in aggregate so we know what to improve.
We do not use cookies to advertise to you, to build a profile of you across other websites, or to share your behaviour with data brokers.
Essential cookies
These cookies are required for the Service to function. Without them, you would not be able to sign in, place an order, or check out. They cannot be switched off.
| Name | Purpose | Duration | Set by |
|---|---|---|---|
| hesett_session | Keeps you signed in across pages. | 30 days | Hesett |
| hesett_table | Remembers the table you scanned in the web app session. | Session | Hesett |
| hesett_csrf | Protects against cross-site request forgery. | Session | Hesett |
| __stripe_mid, __stripe_sid | Stripe fraud detection during checkout. | 1 year / 30 minutes | Stripe |
| cf_clearance | Cloudflare bot challenge for abuse protection. | 30 minutes | Cloudflare |
Preferences
These cookies remember small choices so the Service feels personal between visits — your menu language, your allergen profile, dark or light mode. You can clear them at any time without losing your account.
| Name | Purpose | Duration | Set by |
|---|---|---|---|
| hesett_lang | Stores your chosen menu language so the menu opens in the same one next time. | 1 year | Hesett |
| hesett_allergens | Stores your allergen profile locally so menus pre-filter without a network call. | 1 year | Hesett |
| hesett_theme | Light or dark mode preference. | 1 year | Hesett |
Analytics
We use a single privacy-respecting analytics tool (currently Google Analytics 4 with IP anonymisation and disabled ad-personalisation features) to understand which pages people use, in aggregate. Analytics cookies are loaded only after you accept them in the cookie banner — declining them does not break anything.
| Name | Purpose | Duration | Set by |
|---|---|---|---|
| _ga, _ga_* | Aggregated usage analytics (de-identified). Loaded only after you consent. | 13 months |
Third-party cookies
A handful of cookies are set by services we use to operate Hesett — currently Stripe (payments and fraud detection) and Cloudflare (security). Their cookies are governed by their respective privacy policies:
Your choices
- You will see a cookie banner the first time you visit hesett.com. You can change your choices any time at Settings → Privacy in the mobile app, or from the “Cookie preferences” link at the bottom of any web page.
- You can block or delete cookies in your browser settings. Note that blocking essential cookies will break sign-in and checkout.
- You can request that we delete the data we hold about you — see the Privacy Policy.
Changes
When we add or remove a cookie that affects you, we update this page and refresh the “Last updated” date. Material changes are also announced via the cookie banner.
Contact
Questions? support@hesett.com.