Cookie Policy
Informative translation. In case of doubt, the Spanish version prevails.
Last updated: 1 October 2026
elpizzero uses the minimum cookies indispensable for the platform to function (session, basket, consent). We do not use our own analytics or tracking cookies. The only possible advertising element is the Meta Pixel, which a restaurant may activate on its own account and which is only loaded if you accept the «Marketing» category in the banner (see section 4.4).
You can change your preferences from your browser's settings at any time.
1. What cookies are
Cookies are small text files that are stored on your device (computer, tablet or mobile) when you visit a website. They make it possible to remember your actions and preferences (session, language, basket contents, etc.) for a period of time, so that you do not have to reconfigure them on each visit.
2. Legal basis
The use of cookies on elpizzero.com is governed by the following rules:
- General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679.
- Organic Law 3/2018 (LOPDGDD) — Protection of Personal Data and guarantee of digital rights.
- Law 34/2002 (LSSI-CE) — article 22.2 on storage and data-retrieval devices in terminal equipment.
- Directive 2002/58/EC (ePrivacy).
- Guide on the use of cookies of the Spanish Data Protection Agency (AEPD), current edition.
Strictly necessary cookies are installed on the basis of the legitimate interest of the controller (art. 6.1.f GDPR). For all the others, the legal basis is the user's explicit consent (art. 6.1.a GDPR).
3. Controller
Ángel Rives García (holder of elpizzero)
NIF: 15415960A
Address: Calle Redován 3, 03350 Cox (Alicante), España
Website: elpizzero.com
General contact: hola@elpizzero.com
Privacy contact (GDPR): privacidad@elpizzero.com
4. Types of cookies we use
4.1. Strictly necessary cookies
Essential for the site to function. They do not require prior consent under Art. 22.2 LSSI-CE and the AEPD Cookie Guide.
| Cookie | Provider | Duration | Purpose |
|---|---|---|---|
| ECOMSESSID | elpizzero.com | Session (7 days) | Server session identifier (PHP session). Necessary to keep the session open, for CSRF protection and for the processing of forms and orders. |
| elpz_remember | elpizzero.com | 1 year | Marks that the device is an order-reception APK and must keep the session open for one year (restaurant POS). It is only set when the user expressly requests it from the app. |
| elpz_remember_token | elpizzero.com | 1 year | «Remember me» token when logging in to the panel or the POS: it allows you to log back in without typing the password. It is only set if you tick that box when logging in, and it is deleted on logging out. |
| elp_cust_sess | elpizzero.com | 30 days | Session of your customer account: keeps the session open so that you can see your orders and your table account. It is only set if you log in with your email. |
4.2. Functional cookies
They enable enhanced functionality. Some are set only when the user performs a specific action (changing language, scanning a QR code, receiving an invitation).
| Cookie | Provider | Duration | Purpose |
|---|---|---|---|
| elp_locale | elpizzero.com | 30 days | Stores the language selected by the user in order to show the site in their preferred language on future visits. It is only set when the language selector is pressed. |
| elp_promo_code | elpizzero.com | 30 days | Remembers a promotional code scanned via QR so that it is applied automatically to the next order. It is only set when a promotion code is scanned. |
| elp_ptok | elpizzero.com | 3 days | Identifies your browser so that we can send you notifications of the status of your order (accepted, on its way, ready). It is only set if you agree to receive those notifications. |
| elp_redeem | elpizzero.com | Until the promotion expires | Marks that you have arrived with a scanned promotional code, so that the page is served without cache and the discount is applied correctly. It is only set when that code is scanned, and is deleted when it is used. |
| elp_invite | elpizzero.com | 30 days | Invitation token for new restaurants (referred by another restaurant on the platform). It is only set when an invitation link is opened. |
4.3. Analytics cookies
We do not use third-party measurement services (neither Google Analytics, nor Hotjar, nor Clarity). The menu of each restaurant does carry its own analytics so that the restaurant knows how many visits it receives: entry page, where you come from, device type and the steps of the order (viewing the menu, adding to the basket, completing the order). These data are not shared with anyone and are deleted after 26 months.
Without your permission we store nothing on your device: the visit is counted with a provisional identifier that is lost when the page is closed. Only if you accept the «Analytics» category in the banner do we store a random identifier in your browser (elp_visitor_<restaurante>, see 4.5), so as not to count you twice, and we also record an encrypted fingerprint (hash) of your IP and the browser type. If you refuse or withdraw permission, that identifier is deleted.
4.4. Marketing and advertising cookies
By default none is loaded. We do not use the Google Ads Tag, TikTok Pixel or any other advertising tag, and we do not sell or share your data with third parties for advertising purposes.
The platform does offer each restaurant the possibility of activating the Meta Pixel (Facebook/Instagram) to measure its own campaigns. When a restaurant activates it, the pixel is only loaded if you accept the «Marketing» category in the cookie banner. If you do not accept it, the script is not even inserted into the page and none of these cookies is set:
| Cookie | Provider | Duration | Purpose |
|---|---|---|---|
| _fbp | Meta Platforms (written on the domain of this site) | 3 months | Identifies your browser in order to attribute to the restaurant's campaign the visits and orders that arrive from Facebook or Instagram. |
| _fbc | Meta Platforms (written on the domain of this site) | 3 months | Stores the identifier of the advertisement through which you arrived, in order to attribute the purchase to that advertisement. |
You can withdraw this consent whenever you wish from «⚙️ Manage consent». Meta processes those data as an independent controller: Meta privacy policy.
4.5. Local storage (localStorage)
For your convenience, we store some data in your browser's local storage (localStorage). Unlike cookies, these data are not sent to the server automatically (except the analytics identifier if you have accepted it, and your contact details when you place an order): they live on your device and you delete them from the browser settings or from the «Delete my data» button that you will see on the order form if you have stored data.
| Key | Persistence | Purpose |
|---|---|---|
| elp_gdpr_consent_v1 | 180 days | Stores your preferences in the cookie banner (categories accepted and date). After 180 days it is deleted and the banner asks you again. |
| elp_visitor_<restaurante> | For as long as you have accepted «Analytics» (at most, 180 days) | Random identifier for the menu's own analytics (4.3), so as not to count the same visit twice. It is only stored if you accept the «Analytics» category. |
| elp_customer_v1 | Permanent (until you delete it) | Remembers your name, email, telephone and address to autocomplete the form in future orders. You can delete it with the «Delete my data» button that appears above the form. |
| cart_<restaurante> · elp_cart_<restaurante> | For the duration of the purchase | Stores what you have in the basket so that it is not lost if you reload the page or come back later. |
| elp_corte_resuelto | Temporary | Remembers that you have already dealt with a connection-loss notice, so as not to repeat it. |
| fb_purchase_<pedido> | Permanent (until you delete it) | Prevents the same purchase from being counted twice in the Meta Pixel. It is only written if the restaurant has the pixel active and you have accepted the «Marketing» category. |
| elp_retry_pkg | Temporary (until successfully sent) | Stores the last order if the network drops just as it is sent, so as to retry when you have a connection again and avoid losing the order. |
5. Third-party cookies
The site may use the following external services, which may set their own cookies:
- Google Fonts (fonts.googleapis.com) — web fonts. Google states that it does not use tracking cookies with this service.
- OpenStreetMap / Leaflet (tile.openstreetmap.org) — map tiles of the delivery zone. OSM privacy policy.
- Payment gateway (Stripe, Redsys or another engaged by the restaurant) — only when a card payment is made. Card data are handled exclusively by the provider.
- CDN (cdn.jsdelivr.net, unpkg.com, cdnjs.cloudflare.com) — distribution of JS and CSS libraries.
- Meta Pixel (connect.facebook.net) — only if the restaurant has activated it and you have accepted the «Marketing» category. See section 4.4.
6. How to manage your cookies
6.1. From your browser
You can configure your browser to block, delete or notify you about the installation of cookies. Direct links:
If you disable the strictly necessary cookies, some functions (session, basket, submission of forms) will no longer work properly.
6.2. Withdrawing consent
You can withdraw or change your consent at any time from the «⚙️ Manage consent» link that you will find in the footer, or by deleting the key elp_gdpr_consent_v1 from your browser's local storage (DevTools → Application → Local Storage). On your next visit the cookie banner will be shown to you again.
7. International transfers
Some third-party services (Google Fonts, CDN) may transfer data outside the European Economic Area. These transfers are covered by the European Commission's Standard Contractual Clauses (SCC) or by adequacy decisions in force.
8. Retention period
Cookies last for the duration indicated in each table. Your consent preference is kept for 180 days (in accordance with the AEPD's recommendation), after which you will be asked again.
9. User rights
For further detail on your rights regarding data protection, see our Privacy Policy. To exercise them, write to privacidad@elpizzero.com.
You have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD): www.aepd.es.
10. Updates
This policy may be updated to reflect changes in the services used or in the applicable regulations. The date of the last modification is shown at the beginning of the document. If the changes are substantial, your consent will be requested again.