COOKIE_PROTOCOL

COOKIE-
BELEID

> LAATSTE_UPDATE: 8/10/2026

Hoe we cookies en vergelijkbare technologieën gebruiken

🍪

Wat zijn Cookies

Cookies zijn kleine tekstbestanden die op je apparaat worden opgeslagen wanneer je onze website bezoekt.

Dit Beleid legt uit hoe Xeito cookies gebruikt, in overeenstemming met de AVG en de Spaanse LSSI.

📦

Soorten Cookies die we Gebruiken

Essentiële Cookies

Noodzakelijk voor het correct functioneren van de site. Kunnen niet worden uitgeschakeld.

Sessiebeheer en authenticatie

__Secure-better-auth.session_token — Authenticates your session after sign-in. Duration: 7 days (rolling). Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax, Domain=.xeito.ai. In local development the cookie is named better-auth.session_token (no __Secure- prefix) because it is served over HTTP.

__Secure-better-auth.session_data — Caches non-sensitive session metadata so we can avoid hitting the auth database on every request. Duration: matches the session token. Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax, Domain=.xeito.ai.

__Secure-better-auth.dont_remember — Set only when you sign in without "remember me", so the session ends when you close the browser. Duration: session. Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax.

better-auth.state_* / better-auth.pkce_* — Short-lived CSRF state and PKCE verifier cookies used during OAuth sign-in flows (Google, GitHub, LinkedIn) and email-verification redirects. Duration: 10 minutes. Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax. Deleted as soon as the OAuth round-trip completes.

Stripe (payment security — Stripe Payments Europe Ltd, Ireland)

__stripe_mid — Machine identifier for fraud detection. Duration: 1 year. Provider: Stripe. Set only on payment pages.

__stripe_sid — Session identifier for fraud detection. Duration: 30 minutes. Provider: Stripe. Set only on payment pages.

m — Device fingerprint for fraud prevention. Duration: 2 years. Provider: Stripe. Set only on payment pages.

Cloudflare (network security — Cloudflare, Inc., USA)

__cf_bm — Bot management and abuse prevention. Duration: 30 minutes. Provider: Cloudflare.

_cfuvid — Rate limiting to protect against abuse. Duration: Session. Provider: Cloudflare.

Analytische Cookies

Helpen ons te begrijpen hoe bezoekers de site gebruiken. Worden alleen geladen met je uitdrukkelijke toestemming.

_ga — Distinguishes unique users. Duration: 2 years. Provider: Google.

_ga_ZVXP12T53T — Maintains session state. Duration: 2 years. Provider: Google.

xeito-cookie-analytics — Stores your analytics consent choice. Duration: localStorage (no expiry). Provider: Xeito (first-party).

IP-anonimisering is ingeschakeld.

Functionele Cookies

Onthouden je voorkeuren en personaliseren je ervaring.

xeito-locale — Stores your language preference when you switch languages. Duration: 1 year. Provider: Xeito (first-party).

xeito-cookie-consent — Stores your cookie consent decision. Duration: localStorage (no expiry). Provider: Xeito (first-party).

Opgeslagen zoekopdrachten en werkvoorkeuren

Advertentiecookies

Advertenties draaien altijd op openbare blog- en marketingpagina's om Xeito gratis te houden. Standaard zijn ze niet-gepersonaliseerd (geen trackingcookies, geen toestemming vereist). Na je uitdrukkelijke toestemming via de cookiebanner kunnen Google AdSense en zijn partners advertentiecookies plaatsen om je interessegebaseerde advertenties te tonen. Premium-abonnees zien nooit advertenties.

Google AdSense (Google Ireland Limited / Google LLC)

NID — Used by Google to remember your preferences and show personalized ads. Duration: 6 months. Domain: .google.com.

IDE — Used by Google DoubleClick to measure ad effectiveness and show relevant ads. Duration: 13 months. Domain: .doubleclick.net.

ANID — Ad personalization identifier. Duration: 13 months. Domain: .google.com.

__gads, __gpi — Frequency capping and ad selection. Duration: 13 months. Domain: xeito.ai.

_gcl_* — Google Ads conversion tracking. Duration: 90 days. Domain: xeito.ai.

Advertentiecookies worden nooit geactiveerd op de geverifieerde app (app.xeito.ai) of op juridische pagina's zoals Pricing, Terms of Service of dit Cookie Policy. Advertentielevering wordt ook onderdrukt op dunne of programmatische pagina's volgens het AdSense-inhoudsbeleid.

⚙️

Cookiebeheer

Je kunt cookies beheren via de instellingen van je browser.

Het uitschakelen van bepaalde cookies kan de functionaliteit van de site beïnvloeden.

🔗

Cookies van Derden

Sommige diensten van derden kunnen cookies op je apparaat plaatsen:

Google Analytics voor webanalyse

Google AdSense voor advertenties (alleen op openbare blog- en marketingpagina's)

LinkedIn voor professionele netwerkfuncties

Betalingsverwerkers voor transactiebeveiliging

📧

Neem Contact Op

Als je vragen hebt over ons Cookiebeleid, neem dan contact met ons op: