Cookies
Which cookies and local storage Dutchbeard uses and what for.
Last updated: 16 May 2026This is a translation provided for convenience. In case of any discrepancy, the Dutch version prevails.
Which cookies and similar techniques I use within the Dutchbeard services, and why.
In this statement, "Dutchbeard services" means: this account portal
(account.dutchbeard.nl), the associated apps (including RailBox and
Dienstkaartje.nl) and all other websites and applications that I offer under
the name Dutchbeard.
Within the Dutchbeard services I use only functional storage and, for measuring general usage, an anonymous count on a self-hosted server. No third-party tracking, advertising or social media cookies.
1. What are cookies and similar techniques?
A cookie is a small text file that a website places on your device to
remember information between pages or visits. Besides cookies there are
similar techniques that store data within your browser, such as
localStorage and sessionStorage. In this statement I refer to
both together as "storage", because under the law (the Dutch
Telecommunications Act and the GDPR) they are treated in virtually the
same way.
2. Which storage I use
All storage that I place falls into one of the following categories:
- Login session. An HttpOnly cookie on the API domain containing the part of your login credentials with which a session can be renewed. This cookie is not readable by scripts in your browser and is only sent to the Dutchbeard API. Purpose: to keep you logged in between pages and between different Dutchbeard services. Lifetime: until your session expires or is revoked, or sooner if you log out.
- Access token in working memory. On every page load the portal requests a new short-lived access token, which stays only in your browser's memory for the duration of the visit. It disappears as soon as you close the tab.
- Preferences. For example your chosen theme (light or dark),
stored in
localStorageof the relevant Dutchbeard domain. Purpose: to remember your preference between visits. Lifetime: until you clear the domain's storage or change the preference. - Anti-bot protection. On the login and registration screen I use a lightweight proof-of-work challenge to counter automated login attempts. No personal data is recorded in the process; only a short-lived computation result.
- App-specific storage. Some Dutchbeard apps (such as RailBox) store additional preferences or caches in order to work offline or faster. This storage stays within the domain of that app and, insofar as it is additional, is explained in the app itself.
All of this storage is strictly necessary for the functioning of the Dutchbeard services or serves a preference actively chosen by you. Under the Telecommunications Act, no consent requirement applies to this.
3. Anonymous visitor statistics
In order to see how heavily the Dutchbeard services are used, I keep an anonymous count of page views and general visitor statistics (such as device type and browser language) on a self-hosted server. In doing so:
- no personal data that can be traced back to you is recorded;
- no profile of you is built and no behaviour is linked across different sessions;
- the measurements are not shared with third parties and are not linked to your Dutchbeard ID;
- the data is used solely to make decisions about the capacity, functionality and quality of the Dutchbeard services.
Under Dutch cookie law, privacy-friendly statistics of this kind fall under the exemption for analytics, and no consent is required for them.
4. No third-party tracking
I use no third-party advertising, social media or cross-site tracking cookies on any Dutchbeard domain. There is no tracking pixel, no fingerprinting script and no profiling for advertising purposes.
5. Third-party cookies for payments
If you top up credits or make a donation, you are temporarily redirected to the payment environment of Stripe. At that moment Stripe may place cookies on its own domain, for example to detect fraudulent transactions. These cookies fall under Stripe's policy; I have no influence over them. See section 5 (Sharing with third parties) of the Privacy Statement and section 5 (Payments) of the Terms and Conditions for the associated processing.
6. Your choices
- Clearing storage. You can clear cookies and
localStorageat any time via your browser settings. Please note that you will then have to log in again and that app-specific preferences (such as theme) will be lost. - Logging out. By logging out in the portal, I end your session cookie and the short-lived access token is removed from working memory.
- Ending other sessions. In the portal you can see per session which devices are currently logged in and revoke them individually or all at once.
- Notifications. Push notifications do not work via cookies, but via a separate push token. You can disable these at any time in the portal or in the relevant app.
7. Changes to this statement
I may amend this cookie statement from time to time, for example if I introduce new features or if regulations change. The date at the top of this document indicates when the statement was last amended. In the event of material changes, I will inform registered users reasonably in advance, for example by email or via a notification in the portal.
8. Contact
Do you have questions about this cookie statement? Please contact me at brievenbus@dutchbeard.nl.
Language
This English text is a translation provided for convenience. The Dutch version of this document is the legally binding one; in the event of any discrepancy between the two versions, the Dutch version prevails.
