Cookie policy
Cookie Policy of IuteCredit Bulgaria
Effective from: 30.09.2021
I. PURPOSE OF THIS COOKIE POLICY
1.1. This Cookie Policy describes how “IuteCredit Bulgaria” EOOD (“Iute“, “we“, “us“) uses cookies and similar technologies when individuals (“you“) visit our website [www.iute.bg](https://www.iute.bg) and the MyIute mobile application, in accordance with our Privacy Policy.
II. WHAT ARE COOKIES?
2.1. Cookies and similar technologies are small files or identifiers that can be stored on or accessed from your device when you use Iute’s digital services. They allow us or third-party service providers to recognise your browser, device or application, remember certain information, improve functionality, facilitate future use of our services and maintain the secure and efficient operation of our digital services.
III. TYPES OF COOKIES BY STORAGE DURATION
3.1. Iute uses various types of cookies, which may differ in terms of storage duration and purpose. According to storage duration, Iute uses the following categories of cookies:
– Session cookies are used to ensure the proper functioning of Iute’s digital services. They are stored temporarily on your device and are deleted when you log out, close the browser or application, or end the session.
– Persistent cookies are stored on your device for a limited period and may be used to remember your preferences, collect statistics, analyse the use of services and improve Iute’s digital services.
IV. TYPES OF COOKIES BY PURPOSE
4.1. According to the purpose of processing, Iute uses the following categories of cookies:
– Necessary cookies are mandatory for the proper functioning of Iute’s digital services. They provide basic functions such as secure login, navigation, authentication, form submission and security. Without these cookies, certain services requested by you cannot be provided.
– Functional cookies provide additional features and personalisation options. They allow us to remember your preferences, choices, settings and entered information. If you decline these cookies, some features may be less convenient and you may need to re-enter information or adjust your settings.
– Analytical cookies help us understand how you interact with Iute’s digital services. They allow us to collect statistics, measure performance, identify which features or pages are popular and which are used less frequently, and improve the user experience. If you decline these cookies, your use of our digital services will not be included in our analytical statistics.
– Advertising (targeting) cookies are used to provide more relevant information, offers and advertising for Iute’s products and services. They may also help us to measure and improve advertising campaigns, including on third-party websites or platforms. If you decline these cookies, the advertising you see may be less personalised.
V. THIRD-PARTY AND SERVICE PROVIDER COOKIES
5.1. Iute may use cookies and similar technologies provided by third-party service providers. These third parties may provide technical solutions, tools and features that help us to ensure functionality, analyse the use of our digital services, measure performance, improve the user experience and support advertising or personalised content where applicable.
5.2. Third-party cookies are cookies placed or accessed by a domain or service provider other than Iute. They may be used, for example, when you interact with content, tools or features provided by a third party through Iute’s digital services.
5.3. Data collected through cookies or similar technologies may be shared with Iute’s trusted partners and third-party service providers where this is necessary for the purposes described in this Cookie Policy. Third-party cookies and similar technologies may also be subject to the relevant third party’s own cookie or privacy policy.
VI. CONSENT AND COOKIE MANAGEMENT
6.1. Where required, Iute requests your consent before using functional, analytical and advertising cookies or similar technologies. Necessary cookies are mandatory for the proper functioning of Iute’s digital services and cannot be disabled through cookie settings.
6.2. Your cookie choices are stored for a period of one year, unless you change or withdraw your consent earlier. When you consent to a given category of cookies, you consent to all cookies in that category, as described in more detail in the Cookie List below.
6.3. Iute may periodically update the cookies and similar technologies used, for example in order to improve service quality, functionality, security, analytics or user experience. The Cookie List may be amended accordingly.
6.4. Where applicable, you may update your cookie preferences at any time by clicking:
6.5. You may remove stored cookies by clearing them in the settings of your browser, device or application. Please note that deleting or disabling cookies may affect the functionality and performance of Iute’s digital services.
6.6. The steps for managing cookies may vary depending on the browser, device or application you use. For guidance, please visit [www.allaboutcookies.org](https://www.allaboutcookies.org).
VII. PROCESSING OF PERSONAL DATA
7.1. Where personal data is processed through cookies or similar technologies, such processing is carried out in accordance with our Privacy Policy.
7.2. The Privacy Policy contains more information about how Iute processes personal data, about the rights you have under applicable data protection legislation, and about how you can exercise them.
VIII. CONTACT US
8.1. If you have any questions about this Cookie Policy or the use of cookies and similar technologies, you can contact us at [email protected].
8.2. Iute may periodically update this Cookie Policy. Any changes will be published on this page, and you may be notified of material changes through the Iute website, mobile application or other appropriate channels.
Last updated: 23.07.2026
IX. COOKIE LIST
| Provider | Cookie Name | Type | Duration | Purpose |
| Iute | currentUser | Necessary | Session – until logout | Keeps you logged in and allows MyIute to display your profile information. |
| Iute | ic-csrf-token | Necessary | Session | Protects your account by helping to verify that requests made through MyIute are authentic. |
| Iute | 2fa_token, 2fa_phone, 2fa_* | Necessary | Until two-factor authentication is completed | Stores the information required to securely complete two-factor authentication. |
| Iute | passcodeExists, biometryFixed, biometric flags | Necessary | Until logout | Allows MyIute to recognise whether passcode or biometric protection has been set up on the device. |
| Iute | consents | Necessary | Persistent | Records your cookie and marketing choices so that we can apply them. |
| Iute | Session-handover blob | Necessary | Session | Allows your logged-in session to continue securely between the mobile application and the web service embedded within it. |
| Iute | appState | Necessary | Session | Maintains synchronisation between the mobile application and the embedded web service while you use MyIute. |
| Iute | hasRunBefore | Necessary | Until reinstallation | Determines whether MyIute is being opened for the first time so that the secure storage can be set up correctly. |
| Iute | frontendUrl | Necessary | Persistent | Connects MyIute to the correct Iute server environment. |
| Iute | deviceRegistrationHash / deviceHash in deviceInfo | Necessary | Until deleted | Creates a device-specific security value used to protect the passcode and document signing features. |
| Iute | certificateGenerated:{pin}, passcodeCertificateGenerated:{pin} | Necessary | Until the device’s secure storage is reset | Records that secure signing credentials have been created for your account on this device. |
| Iute | usingSecureKeyStore | Necessary | Persistent | Helps MyIute to securely use the current secure storage method. |
| Iute | PKI biometry private key + X.509 certificate | Necessary | Until logout or re-registration of biometrics | Enables secure document signing and in-depth customer identity verification through biometrics. |
| Iute | PKI passcode private key + X.509 certificate | Necessary | Until logout | Enables secure document signing and in-depth customer identity verification through your passcode. |
| Iute | Passcode hash – Argon2i | Necessary | Until the passcode is removed | Allows MyIute to verify your passcode without storing it in a readable form. |
| Iute | WKWebView Website Data Store – .default() | Necessary | Until uninstallation | Stores the web data required for the web-based parts of MyIute to function in the iOS application. |
| Iute | Android WebView cookies + DOM storage | Necessary | Until uninstallation | Stores the web data required for the web-based parts of MyIute to function in the Android application. |
| Iute | HTTP Basic Auth credentials | Necessary | For the duration of the installed test (staging) version | Protects access to the non-production test environment. |
| Google Firebase | FCM device token | Necessary | Until logout or token refresh by Firebase | Allows Iute to send targeted push notifications to your device. |
| Google Firebase | Firebase Installations – installation ID + auth tokens | Necessary | Until the application is reset | Supports Firebase services, including the creation and operation of push notification tokens. |
| Google reCAPTCHA Enterprise | reCAPTCHA Enterprise session token | Necessary | Session | Helps protect login and authentication processes from automated or fraudulent activity. |
| Cloudflare | __cf_bm | Necessary | 1 hour | Set by Cloudflare and supports bot management (Cloudflare Bot Management). |
| CookieYes | cookieyes-* | Necessary | 1 year | CookieYes sets this cookie for cookie consent solution management. |
| YouTube | VISITOR_PRIVACY_METADATA | Necessary | 6 months | YouTube sets this cookie to store the user’s cookie consent status for the current domain. |
| Google reCAPTCHA | rc::a | Necessary | No expiry | Set by the Google reCAPTCHA service to distinguish bots in order to protect the website from malicious spam attacks. |
| Google reCAPTCHA | rc::c | Necessary | Session | Set by the Google reCAPTCHA service to distinguish bots in order to protect the website from malicious spam attacks. |
| Iute Internal | utmData | Necessary | 1 month | Used for internal tracking of the visit source and is recorded only if the visitor submits a credit application. |
| Iute | locale | Functional | Persistent | Remembers your chosen language. |
| Iute | balance_visibility | Functional | Persistent | Remembers whether you have chosen to show or hide your account balance. |
| Iute | referralCode | Functional | Persistent | Remembers a referral code received via a link. |
| Iute | educationSurveyCompleted, loyalty*, quickActions*, welcomeBottomSheetSeen, iuteMarketPromoSeen and other show-once flags | Functional | Persistent | Prevents MyIute from re-displaying onboarding steps, promotions or messages that you have already completed, seen or dismissed. |
| Iute | consents.optional_cookies | Functional | Persistent | Records your choice to accept or decline optional cookies and similar technologies. |
| Iute | IuteMarket cart keys (5 keys) | Functional | Until the order is completed | Saves the items in your IuteMarket shopping cart. |
| Iute | Multi-step form / wizard state keys (about 28) | Functional | Session | Saves your progress when filling in credit, identity verification (KYC) or profile forms. |
| Iute | notification_permission_status | Functional | Persistent | Remembers whether you have allowed MyIute to send push notifications. |
| Iute | notification_analytics_events | Functional | Persistent | Temporarily stores notification permission events until MyIute is able to send them. |
| Iute | permissions_handler_asked (per permission) | Functional | Persistent | Remembers permissions that you have permanently declined so that MyIute does not repeatedly request them. |
| Iute | trackingAuthorizationStatus | Functional | Persistent | Remembers your choice under App Tracking Transparency on iOS. |
| Iute | version_preference | Functional | Persistent | Makes the MyIute version number accessible in iOS device settings. |
| Iute | Temporary downloaded PDFs / images | Functional | Until logout / next launch | Temporarily stores downloaded contracts, statements and images so that you can view or sign them. |
| WordPress | wp-wpml_current_language | Functional | Session | Supports internal translation preview in development and testing environments. |
| YouTube | VISITOR_INFO1_LIVE | Functional | 6 months | A YouTube cookie for measuring connection speed, which determines whether the user receives the new or old player interface. |
| YouTube | ytidb::LAST_RESULT_ENTRY_KEY | Functional | No expiry | Used by YouTube to store the last search result selected by the user, in order to provide more relevant results in the future. |
| PostHog | ph_phc_{project-token}_posthog | Analytical | Cookie: 1 year; localStorage: persistent | Helps us understand how MyIute is used, remembers feature and experiment settings, and supports session analysis when activated. |
| PostHog | myiute_ph_country_props_v1_{country} | Analytical | Persistent | Associates analytical information with the relevant country version of MyIute. |
| PostHog | Anonymous-flow experiment variant cache | Analytical | Persistent | Ensures that you continue to see the same version of an experiment on the website or application. |
| Google Analytics 4 / Google Tag Manager | _ga | Analytical | 2 years | Distinguishes returning browsers for the purposes of aggregated usage statistics. |
| Google Analytics 4 / Google Tag Manager | _gid | Analytical | 24 hours | Distinguishes activity within a short period for the purposes of aggregated usage statistics. |
| Google Analytics 4 / Google Tag Manager | _gat | Analytical | 1 minute | Limits the number of requests sent to Google Analytics within a short period. |
| Google Analytics 4 / Google Tag Manager | _ga_{stream-id} | Analytical | 2 years | Supports Google Analytics session and measurement settings. |
| Google Tag Manager | dataLayer | Analytical | Session | Temporarily stores event information before it is sent to the activated Google Tag Manager tools. |
| Hotjar | _hjSession_{site-id} | Analytical | 30 minutes | Groups activity during a single visit for the purposes of heatmaps and session analysis. |
| Hotjar | _hjSessionUser_{site-id} | Analytical | 1 year | Recognises a returning browser for the purposes of usage analysis. |
| Hotjar | _hjFirstSeen, _hjAbsoluteSessionInProgress, _hjIncludedInSessionSample | Analytical | Session to 1 year | Manages sampling and session recording settings when Hotjar is activated. |
| Iute | iute_tracking_session_id | Analytical | Session | Links actions within the same MyIute session for the purposes of internal usage analysis. |
| Sentry | Breadcrumbs and session ID | Analytical | Until sent | Helps Iute to identify and resolve technical errors and performance issues with the web service. |
| Sentry | Sentry envelopes | Analytical | Until sent | Temporarily stores crash and error reports so that they can be sent to Iute’s technical monitoring service. |
| Google Firebase Analytics | Event queue, session ID and user properties | Analytical | Persistent | Helps us understand how the Android application is used and to improve its performance. |
| Google Firebase Crashlytics | Crash reports | Analytical | Until sent | Helps Iute to identify, investigate and resolve application crashes. |
| New Relic | New Relic agent storage | Analytical | Until sent | Helps Iute to monitor errors, performance and network activity of the Android application. |
| SEON | SEON anti-fraud agent storage | Analytical | Determined by the provider | Helps to identify potentially fraudulent activity through device and browser risk signals. |
| CredoLab | CredoLab behavioural biometrics | Analytical | Determined by the provider | Collects behavioural information during a credit application to support creditworthiness assessments and fraud prevention. |
| YouTube | YSC | Analytical | Session | Set by YouTube to track views of embedded videos on YouTube pages. |
| OptinMonster | _omappvp | Analytical | 1 year | Set to distinguish new and returning users and is used together with the _omappvs cookie. |
| OptinMonster | _omappvs | Analytical | 20 minutes | Used together with the _omappvp cookie to determine whether the visitor has visited the website before or is a new visitor. |
| Google Analytics 4 | _ga_* | Analytical | 1 year and 1 month | Google Analytics sets this cookie to store and count page views. |
| Google Analytics 4 | _ga | Analytical | 1 year and 1 month | Google Analytics sets this cookie to calculate visitor, session and campaign data and to track site usage for the analytics report. The information is stored anonymously by assigning a randomly generated number to recognise unique visitors. |
| PostHog | dmn_chk_* | Analytical | Under 1 minute | Set to track user activity on the website. |
| Microsoft Clarity | _clck | Analytical | 1 year | Microsoft Clarity sets this cookie to retain the Clarity User ID and settings for this website, so that actions during subsequent visits are linked to the same user ID. |
| Microsoft Clarity | _clsk | Analytical | 1 day | Microsoft Clarity sets this cookie to store and consolidate a user’s page views into a single session recording. |
| Iute | utm (11 marketing parameters) | Advertising | 30 days | Records the last campaign or referral source so that Iute can measure whether marketing activity led to a credit application or other action. |
| Branch.io | Branch session, deep-link parameters and install referrer | Advertising | Persistent | Allows links to open the correct content in MyIute and helps to measure the source of application installations. |
| Meta / Facebook SDK | Access tokens, app-event cache and install-attribution storage | Advertising | Persistent | Helps to measure whether a Meta/Facebook campaign led to an application installation or activity within it. |
| Google Ads – On-Device Conversion | Conversion-tracking blob | Advertising | Persistent | Helps to measure whether a Google Ads campaign led to an action in the iOS application. |
| Google Play Install Referrer | Install-referrer string | Advertising | Persistent | Records the installation source reported by Google Play. |
| Samsung Galaxy Store Install Referrer | Install-referrer string | Advertising | Persistent | Records the installation source reported by Samsung Galaxy Store. |
| PostHog | _posthog | Advertising | 1 year | PostHog’s main cookie for storing data. |
| Adform | C | Advertising | 1 month | Checks whether the user’s browser supports cookies. |
| YouTube | __Secure-YNID | Advertising | 6 months | A YouTube cookie for protecting user security and preventing fraud, particularly during login. |
| YouTube | __Secure-ROLLOUT_TOKEN | Advertising | 6 months | Set by YouTube to manage the gradual rollout of new features and experiments, so that the user has a consistent experience during a given experiment. |
| YouTube | __Secure-YEC | Advertising | Expires immediately | No description available from the provider. |
| Google Tag Manager | _gcl_au | Advertising | 3 months | Google Tag Manager sets this cookie to measure advertising effectiveness on websites using its services. |
| Adform | uid | Advertising | 2 months | A unique user identifier used to recognise the user across different sections of the website and to display relevant advertising. |
| Meta | _fbp | Advertising | 3 months | Facebook sets this cookie to store and track interactions. |
| Google DoubleClick | test_cookie | Advertising | 15 minutes | doubleclick.net sets this cookie to determine whether the user’s browser supports cookies. |
| Microsoft Bing | _uetsid | Advertising | 1 day | Bing Ads sets this cookie to engage with a user who has previously visited the website. |
| Microsoft Bing | _uetvid | Advertising | 1 year | Bing Ads sets this cookie to engage with a user who has previously visited the website. |
| Microsoft Bing | MUID | Advertising | 1 year | Bing sets this cookie to recognise unique browsers visiting Microsoft sites. It is used for advertising, site analytics and other operations. |
| Google Ads | _gcl_ag | Advertising | 3 months | Stores the Google Click ID (GCLID) from an ad click and is used to attribute conversions to the relevant click in Google Ads. |
| Google DoubleClick | IDE | Advertising | 1 year | Google DoubleClick IDE cookies store information about how the user uses the website in order to display relevant advertisements based on their user profile. |