0
Skip to Content
Bidwhistle
Temp Page
Pricing
About
English
Bidwhistle
Temp Page
Pricing
About
English
Temp Page
Pricing
About
English
Back

Cookie Notice

What we store on your device, why, and how you turn it off.

Bidwhistle OÜ · Registry code 17567745 · Sepapaja tn 6, 15551 Tallinn, Estonia
Version 1.0 · Effective 2 September 2026

1. About this notice

1.1 This notice explains the cookies and similar technologies we use on https://www.bidwhistle.com and in the Bidwhistle application, why we use them, and how you control them. It sits alongside our Privacy Notice at https://www.bidwhistle.com/legal/privacy, which explains everything else we do with personal data.

1.2 “We”, “us” and “our” mean Bidwhistle OÜ, an Estonian company, registry code 17567745, Sepapaja tn 6, 15551 Tallinn, Estonia. That registered office is a service address provided by the company administration provider we use, not premises we occupy.

1.3 We use very few cookies — at present, only ones that are strictly necessary. We use no advertising cookies and no third-party product analytics, we do not sell data to advertising networks, and we do not use a cookie wall — you can read this website and use the parts of it that do not need an account whether or not you accept anything beyond what is strictly necessary.

2. What cookies and similar technologies are

2.1 A cookie is a small text file a website asks your browser to store. The next time you visit, the browser sends it back, so the site can recognise your session or remember a setting. A first-party cookie is set by the site you are visiting; a third-party cookie is set by another organisation whose code runs on the page.

2.2 Cookies are not the only technology of this kind, and the law treats all of them the same way. We also mean:

TechnologyWhat it is
Local storage and session storageSpace in your browser where a site can keep information — often used instead of a cookie to hold a sign-in token or a preference. Local storage stays until it is cleared; session storage is dropped when you close the tab
Pixels and tracking pixelsA tiny invisible image or piece of code in a page or an email that tells the sender it was loaded, and when
Software development kits (SDKs)Third-party code built into an application that can read or write information on your device
Device or browser fingerprintingCombining details such as screen size, fonts and time zone to recognise a device without storing anything. We do not do this

2.3 Throughout this notice, “cookies” means all of the above. Storing information on your device, or reading information already there, needs your consent unless it is strictly necessary — which is why we ask.

3. How we ask for consent, and how to change your mind

3.1 We ask before we set anything non-essential. When you first visit, you see a banner. Nothing in the functional, analytics or marketing categories is set until you choose. Strictly necessary cookies are set without consent, because the law does not require consent for them and the Service cannot work without them.

3.2 The banner is fair. “Reject all” is as easy and prominent as “Accept all” — one click, same level, same styling. Nothing is pre-ticked. Continuing to scroll, closing the banner or carrying on browsing is not consent; if you do not choose, only strictly necessary cookies are set.

3.3 No cookie wall. We do not make access to the website conditional on accepting non-essential cookies.

3.4 Changing your mind is as easy as giving consent. Use the “Cookie settings” link in the footer of every page. You can switch any category off, and withdrawing consent takes effect immediately for future processing. Withdrawal does not make what we did beforehand unlawful. [CONFIRM — the consent banner and the footer “Cookie settings” panel to be built and verified before publication]

3.5 Your browser is another control. Every major browser lets you block or delete cookies and clear local storage. If you block strictly necessary cookies, you will not be able to sign in and parts of the Service will not work.

3.6 We keep a record of what you consented to and when, so we can show that consent was properly obtained. That record is used for nothing else.

4. The law, and why we ask everyone

4.1 Cookie rules come from the ePrivacy Directive as implemented in each EU and EEA country, and in the UK from the Privacy and Electronic Communications Regulations (“PECR”). The rule in both is the same: prior consent for anything that is not strictly necessary, plus the transparency and consent standards of the GDPR and UK GDPR.

4.2 The UK changed on 5 February 2026. The Data (Use and Access) Act 2025 created new exemptions from the consent requirement in the UK, which came into force on that date. Two matter here: low-risk analytics — statistical measurement used only to improve how a site works — and appearance and functionality cookies, such as remembering a display preference. In the UK these can now be set without consent, provided the user is given clear information and a straightforward way to object.

4.3 The EU and EEA did not change. Under the ePrivacy Directive, analytics cookies still require consent for visitors in the EU and EEA. The DUAA exemptions are UK-only.

4.4 So we ask everyone. We could ask EU visitors and not UK ones, but a single, honest, consent-first design is simpler for you, safer for us, and treats visitors in both places the same. We therefore ask for consent to analytics and functional cookies wherever you are, including in the UK, even though UK law would now let us set some of them without asking. If you are in the UK you can of course still object; you simply have the extra protection of being asked first. As things stand the question is largely academic: we set no analytics or marketing cookies at all (clause 6.2).

5. The categories we use

5.1 The banner splits cookies into four categories.

CategoryWhat it doesConsent needed?
Strictly necessarySigning you in and keeping you signed in, keeping your session secure, delivering the application and routing your requests, loading the Olivia assistant, preventing fraud on payment pages, and remembering your cookie choices. The Service cannot be provided without theseNo — exempt in the EU and the UK
FunctionalRemembering preferences that are not essential: interface settings, a dismissed message, a chosen view or language. We set none of these at presentYes, we would ask (UK law would now exempt some of these — see 4.2)
AnalyticsCounting visits and understanding which features are used, so we can fix what is broken and improve what is not. Aggregated; not used to target you. We use no third-party product analytics at present, so this category is currently emptyYes, we would ask (UK low-risk analytics is now exempt — we would ask anyway)
MarketingMeasuring campaigns or showing advertising. We use none of these. If we ever add one, we will update this notice and ask for consent before it is setYes — and we are not using any

These four categories describe what is stored on your device when you use our website and the Service. Tracking in the emails we send is a separate matter, dealt with at 6.1 and 7.2.

5.2 The banner keeps all four categories so that nothing can be added quietly later: if the analytics or functional categories ever hold anything, you will be asked before it is set. [CONFIRM — no third-party analytics provider is in use; update if one is introduced]

6. The cookies and similar technologies we use

6.1 The table below lists what our stack sets. The providers are settled and named; the individual cookie names and lifetimes are marked for verification, because platform providers change them from time to time and we will not guess. Every entry marked for confirmation must be checked against the live site before this notice is published.

NameProviderPurposeTypeDuration
[CONSENT RECORD NAME]Bidwhistle (first party)Stores your cookie choices so we do not ask again on every page, and so we can show that consent was properly obtainedStrictly necessary — cookie or local storage6 months [CONFIRM — cookie name and duration to be verified against the live site before publication]
[XANO AUTH TOKEN NAME]Xano — our application backend and authentication (London, United Kingdom)Keeps you signed in and authorises your requests. Usually held in browser local storage rather than as a cookieStrictly necessary — local storage or cookieUntil you sign out, or the token expires [CONFIRM — cookie name and duration to be verified against the live site before publication]
[WEWEB APPLICATION COOKIE NAME]WeWeb — delivery of the application interface, served via Amazon CloudFrontDelivers the interface and routes your requests correctly. No personal data rests with them; your session token stays in your own browserStrictly necessary — cookieSession [CONFIRM — cookie name and duration to be verified against the live site before publication]
[OLIVIA EMBED COOKIE OR STORAGE KEY NAME]Vercel — hosting of the Olivia assistant embedLoads the Olivia embed and carries the session context through your browser. Nothing is stored with the hostStrictly necessary — cookie or local storage, if any is set at allSession [CONFIRM — cookie name and duration, and whether the embed sets anything at all, to be verified against the live site before publication]
__stripe_midStripe — paymentsFraud prevention on payment and checkout pages; identifies the browser across a payment sessionStrictly necessary — third-party cookie1 year [CONFIRM — cookie name and duration to be verified against the live site before publication; set only on pages where Stripe’s code loads]
__stripe_sidStripe — paymentsFraud prevention on payment and checkout pages; identifies the current payment sessionStrictly necessary — third-party cookie30 minutes [CONFIRM — cookie name and duration to be verified against the live site before publication; set only on pages where Stripe’s code loads]
Email open and click pixelsResend — alert and transactional email, delivered via Amazon SES, eu-west-1 (Ireland)Tells us whether an email we sent was delivered, opened or clicked. This applies to email, not to the website, and nothing is stored on your deviceAnalytics — tracking pixelNot stored on your device [CONFIRM — whether open and click tracking is switched on in our email provider, to be verified before publication]

6.1.1 Everything in the table except the email pixels is strictly necessary: you cannot sign in, use the application, talk to Olivia or pay without it. We set no functional cookies at present, so there is currently nothing in that category to consent to.

6.2 We set no marketing or advertising cookies, there is no advertising network code on our site, and we use no third-party product analytics. [CONFIRM — no third-party analytics provider is in use; update if one is introduced]

6.3 If we add, remove or materially change a cookie, we update this table and — where the change needs consent — ask you again before the cookie is set.

7. Third-party cookies

7.1 Some cookies are set by providers whose code runs on our pages. They act as our processors for this purpose, but they also publish their own privacy information, and you should read it if you want the detail:

ProviderRoleWhere to read their policy
StripePayments and payment fraud prevention, on checkout and payment pages[LINK — Stripe privacy policy; CONFIRM — link to be verified before publication]
WeWebDelivery of the application interface, served via Amazon CloudFront[LINK — WeWeb privacy policy; CONFIRM — link to be verified before publication]
XanoApplication backend and authentication[LINK — Xano privacy policy; CONFIRM — link to be verified before publication]
VercelHosting of the Olivia assistant embed[LINK — Vercel privacy policy; CONFIRM — link to be verified before publication]
AnamOlivia’s avatar, voice and speech-to-text, which run in the Olivia embed while you are in a conversation[LINK — Anam privacy policy; CONFIRM — link to be verified before publication]

7.2 Resend, our email provider, sets the open and click pixels in the emails we send, delivered through Amazon SES in Ireland. That is email, not the website, and nothing is stored on your device. [LINK — Resend privacy policy; CONFIRM — link to be verified before publication]

7.3 Our full sub-processor list, including where each provider is located and what it does, is at https://www.bidwhistle.com/legal/sub-processors. International transfers are explained in the Sending personal data outside the EEA and the UK section of our Privacy Notice — including the fact that a conversation with Olivia may be processed outside the EEA and the UK.

8. Do Not Track and Global Privacy Control

8.1 Do Not Track (DNT). Browsers can send a “Do Not Track” header, but there is no agreed standard for what a website must do with it. We do not rely on it, and it does not change what we set — because we do not set anything non-essential without your consent in the first place.

8.2 Global Privacy Control (GPC). GPC is a signal your browser or an extension can send to say you object to your data being sold or shared and, in some jurisdictions, to non-essential tracking. We treat a GPC signal as an objection to non-essential cookies: if we receive one, we do not set functional, analytics or marketing cookies unless you afterwards give consent through the banner or the “Cookie settings” panel. [CONFIRM — GPC signal handling to be implemented and tested before publication]

9. How long consent lasts, and when we ask again

9.1 Your choice is stored for 6 months. After that we ask again, so consent stays a current decision rather than something you agreed to once.

9.2 We will also ask again, before that six months is up, if:

  • we add a cookie in a category you have not agreed to, or a new purpose;
  • we change analytics or other providers in a way that changes what is stored on your device; or
  • you clear your browser storage, which deletes the record of your choice.

9.3 Your consent applies to this browser on this device. If you use another browser or device, you will be asked there too.

10. Children

10.1 The Service is for business use and is not intended for anyone under 18. We do not knowingly set cookies for the purpose of profiling children.

11. Changes to this Cookie Notice

11.1 We update this notice when our cookies change. The version number and issue date at the top tell you which version you are reading.

11.2 Where a change means storing something new on your device that is not strictly necessary, we ask for your consent before the change takes effect — a new version of this notice is not, by itself, consent.

12. How to contact us

Bidwhistle OÜ · Registry code 17567745 · Sepapaja tn 6, 15551 Tallinn, Estonia

12.1 Questions about cookies, or about anything in this notice: privacy@bidwhistle.com.

12.2 We have no UK establishment, so Article 27 of the UK GDPR requires us to appoint a representative in the United Kingdom, whom you can contact instead about UK GDPR matters. [UK ARTICLE 27 REPRESENTATIVE — to be appointed; name, address and contact email to be inserted]

12.3 If you are unhappy with our answer, our Complaints Policy (https://www.bidwhistle.com/legal/complaints) explains how to complain to us. You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia, +372 627 4135, info@aki.ee, www.aki.ee — and, if you are in the UK, to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, 0303 123 1113, www.ico.org.uk.

12.4 Related documents: our Privacy Notice (https://www.bidwhistle.com/legal/privacy), our Sub-processors page (https://www.bidwhistle.com/legal/sub-processors) and our Website Terms of Use (https://www.bidwhistle.com/legal/website-terms).


support@bidwhistle.com

© 2026 Bidwhistle

Terms of Service
Privacy Policy
Cookie Notice