1. What we use
The ardoiza.fr website, the app.ardoiza.fr customer area, the administration console reserved for the team and the websites hosted by ARDOIZA for its customers (addresses on the my-ardoiza.fr domain) only use cookies and browser storage that are strictly necessary for their operation and security. They are exempt from consent under Article 82 of the loi Informatique et Libertés (French Data Protection Act) and the guidelines of the CNIL (Commission nationale de l'informatique et des libertés, the French data protection authority). This is why no consent banner is displayed.
Restaurant menu pages, published at an address on the carte.ardoiza.fr domain, set no cookies and use no browser storage; only the anti-bot check of their booking request and gift card purchase forms involves Cloudflare (table below).
We use no advertising cookies, no third-party audience measurement tools, no social media pixels and no cross-site trackers.
2. List of cookies and storage
| Name | Set by | Purpose | Duration |
|---|---|---|---|
| __Host-ardz_session | ARDOIZA (customer area) | Keep you logged in to the customer area | 14 rolling days, 30 days at most from login; deleted when you log out or when the session is closed from the Security section |
| __Host-ardz_anon | ARDOIZA (customer area) | Protect public forms against cross-site request forgery (CSRF) before you log in | 24 hours |
| __Host-ardz_flash | ARDOIZA (customer area) | Show the confirmation or error message for an action once, on the next page | 1 minute, deleted as soon as it is shown |
| __Host-ardz_offre | ARDOIZA (customer area) | Remember the paid plan chosen on ardoiza.fr until your first login, so that you can be asked to confirm it | 7 days, deleted at your first login |
| __Host-ardz_etab | ARDOIZA (customer area) | Remember the venue selected in the customer area (Pro plan) | Browser session |
| __Host-ardz_lang | ARDOIZA (customer area) | Remember the chosen language (French or English) | 12 months |
| __Host-ardz_2fa | ARDOIZA (customer area) | Intermediate step of two-factor authentication | 5 minutes |
| __Host-ardz_lc | ARDOIZA (customer area) | Intermediate step of the code sent by email when logging in from an unusual address and browser (account without two-factor authentication) | 10 minutes, deleted as soon as you log in |
| __Host-ardz_2fa_act | ARDOIZA (customer area) | Prove that the activation of two-factor authentication was started with your password, from this session | 1 hour |
| __Host-ardz_td | ARDOIZA (customer area) | Remember a trusted device for two-factor authentication, if you asked for this | 30 days |
| __Host-ardz_kd | ARDOIZA (customer area) | Recognise a browser already used for this account (alert for a login from a new device; no code sent by email at login, once that code has been entered in this browser and until the next password change) | 12 months |
| __Host-ardz_console | ARDOIZA (administration console) | Keep a team member logged in to the console | 8 hours at most, 30 minutes without activity |
| __Host-ardz_console_anon | ARDOIZA (administration console) | CSRF protection for the console's login and invitation screens | 1 hour |
| Console local storage (localStorage and sessionStorage) | ARDOIZA (administration console) | Remember, for a team member, whether sound alerts are switched on and which requests have already been flagged | Until cleared in the browser; until the tab is closed for session storage |
| Assistant session storage | ARDOIZA (browser, sessionStorage) | Keep the current conversation with the automated assistant while you browse | Until the tab is closed |
| Order basket (sessionStorage) | ARDOIZA plugins (restaurant website) | Keep the contents of your basket while you browse and prevent an order from being sent twice | Until the tab is closed |
| ardoiza_lang | ARDOIZA plugins (restaurant website) | Remember the language you chose for the menu, ordering or booking; set only if you change language | Browser session |
| WordPress login cookies (wordpress_logged_in, wordpress_sec) and dashboard preference cookies (wp-settings) | WordPress (website hosted by ARDOIZA) | Keep the restaurant owner's session open in their website dashboard, after they arrive through the single-use login link, and remember their display preferences; never set for an ordinary visitor | Login: browser session, two (2) days at most; preferences: one (1) year |
| __cf_bm and Cloudflare security cookies | Cloudflare | Tell legitimate visitors apart from bots and protect against attacks; set only when the protection is triggered. The Cloudflare Turnstile anti-bot check, switched on since 1 October 2026 for the sign-up form, for the “Get some help” form and, on menu pages, for the booking request form and the gift card purchase form, loads its widget from challenges.cloudflare.com, which may rely on the same Cloudflare security cookies; according to Cloudflare's documentation, Turnstile sets no tracking cookie | Up to 30 minutes |
| Payment provider cookies | Stripe | Security and fraud prevention on the provider's payment pages and billing portal, only when you visit them | According to Stripe's policy |
Over https, the names of the customer area's cookies start with “__Host-”: the browser then only accepts them from app.ardoiza.fr, over a secure connection.
When a restaurant uses our plugins on its own WordPress website, with its own hosting provider, the cookies set by WordPress or by its other plugins (login, comments) are the restaurant's responsibility, not ARDOIZA's. The ARDOIZA plugins set no cookie other than the language cookie and use no storage other than the basket storage, both described above, and load no third-party tracking scripts. The free ARDOIZA PRO plugin, offered to the wordpress.org directory, sets no cookies and uses no browser storage. On websites hosted by ARDOIZA, comments are closed and no third-party tracking plugin is installed.
3. How to manage them
As these cookies are necessary, refusing them prevents you from logging in to the customer area or placing an order. You can nevertheless delete them at any time from your browser settings, which will log you out. Two-factor authentication, the code sent by email and the new device alert may then be requested again at your next login.
4. Changes
Should we ever use cookies that are not necessary (for example audience measurement that is not exempt), this policy would be updated and a prior consent mechanism would be put in place. For any question: [email protected].