Every cookie this site puts on your device, who puts it there, how long it stays, and what it is for. The only banner appears from the cart onwards, and this page says why there is none anywhere else.
Cookies and local storage — Anthracite Brussels
Version 1.1 — 5 August 2026
This page lists every cookie and every piece of local storage this site puts on your device, who puts it there, how long it stays, and what it is for. It is not a summary: it is the list.
You will see a cookie banner from the cart onwards, and nowhere else. That is not laziness, it is the honest place for it. On the pages you can browse freely — the home page, the pricing, the service description, these legal pages — nothing at all is sent to anybody, so there is nothing to ask you. From the cart, one real choice appears, and only one: express payment wallets. The rest of what this site stores is what article 10/2, paragraph 2 of the Belgian law of 30 July 2018 calls strictly necessary to the service you asked for, and for that the law does not require your consent — asking for a permission we could not honour would be worse than not asking.
In one minute
- No advertising, no analytics, no audience measurement, no profiling. We run none, and we embed nobody who does it for us.
- On the pages you can browse freely — the home page, the pricing, the service description, the legal pages — the only things stored are three Odoo cookies that make the site work. Nothing is sent to any third party.
- When you pay, Stripe sets cookies. Stripe is our payment processor, and these cookies are how it detects fraud. They are the reason a card payment goes through.
- From the cart, a banner asks you one question: may we offer Apple Pay, Google Pay and Link? Say no and we do not offer them at all — card, Bancontact and bank transfer are untouched. That is the whole of what the banner decides.
- Even if you say yes, nothing reaches Apple or Google until you actually click the express payment button. Two steps, not one.
- Every cookie below is listed with its real duration, read from the browser, not from a vendor's documentation.
1. What this page covers
Belgian law does not talk about "cookies". It talks about storing information on your device, or
reading information already stored there — whatever the technique. So this page covers cookies,
localStorage, and anything else of the same nature.
The rule is article 10/2 of the law of 30 July 2018, which is what transposes article 5(3) of the ePrivacy directive in Belgium. It requires your consent, except where the storage has the sole purpose of carrying out a communication, or of providing a service you expressly requested, where it is strictly necessary for that purpose.
⚠️ If you are reading another Belgian cookie policy that cites "article 129 of the law of 13 June 2005", that article was repealed on 10 January 2022.
Everything listed below falls under that exception. That is our position, and we state the facts underneath it so you can check it yourself: open your browser's developer tools, look at the storage tab, and compare.
2. What is stored on every page
These three are set by Odoo, the software this site runs on. They are first-party — they go to
anthracite.brussels and nowhere else.
| Name | Set by | Domain | Duration | What it is for |
|---|---|---|---|---|
session_id |
Odoo | anthracite.brussels |
7 days | Your session. Without it, a cart is not a cart and a login is not a login. |
frontend_lang |
Odoo | anthracite.brussels |
365 days | The language you are reading in, so the next page comes back in the same one. |
tz |
Odoo | anthracite.brussels |
session | Your time zone, so dates and deadlines are shown in your own time and not ours. |
localStorage is empty on those pages. It gains two keys once you enter the shop, and both are first-party:
| Key | What it is for |
|---|---|
presence.lastPresence, presence.focus |
Whether this tab is the active one. Odoo uses it to stop polling a tab you are not looking at. |
web.lastConnectedUser |
Only if you have an account with us: which account was last used on this browser. |
No third party is contacted on these pages. Fonts are served from our own server. No analytics, no tag manager, no social button, no embedded video, no notification service.
A fourth cookie appears only once you have answered the banner, which only appears from the cart (section 4):
| Name | Set by | Domain | Duration | What it is for |
|---|---|---|---|---|
website_cookies_bar |
Odoo | anthracite.brussels |
999 days | Your answer to the banner, so we stop asking. It holds nothing but that answer and the moment you gave it. |
Yes — a cookie banner sets a cookie. There is no way around it: remembering that you said no requires remembering something. Erase it and the question comes back.
3. What is stored when you pay
Payments are handled by Stripe Payments Europe, Ltd. (Dublin, Ireland). We never see your card number: it goes from your browser to Stripe.
When you reach the payment page, Stripe's code loads and sets these:
| Name | Set by | Domain | Duration | What it is for |
|---|---|---|---|---|
__stripe_mid |
Stripe | anthracite.brussels |
365 days | Fraud prevention — it lets Stripe recognise a device across payments. |
__stripe_sid |
Stripe | anthracite.brussels |
~30 minutes | Fraud prevention, for the duration of one payment. |
m |
Stripe | m.stripe.com |
400 days | Fraud prevention, set by Stripe on its own domain — a third-party cookie. |
Why there is no consent request for these. You reached that page in order to pay. Fraud detection is not an extra we bolted on: it is part of how a card payment is accepted at all, and Stripe applies it to every merchant. This is the "service you expressly requested" exception.
Stripe is not our subcontractor. For the payment itself it acts as an independent controller, under its own privacy policy: https://stripe.com/privacy. What it does with these cookies is governed by that policy, not by ours.
4. Your one choice: express payment (Apple Pay, Google Pay, Link)
This is the one place where a third party learns something about you. Getting there takes two deliberate acts from you, and this is the only section of this page where you have anything to decide.
4.1 The banner, and what it actually decides
From the moment you have something in your cart, a banner appears at the bottom of the page with two buttons:
| Button | What it does |
|---|---|
| Only essentials | We do not offer the express payment button at all. Apple and Google are never contacted. Card, Bancontact and bank transfer work exactly as before — you lose nothing but the wallets. |
| Allow express payment | The express payment button appears. Nothing is sent yet: see 4.2. |
We show it from the cart and not before, because before the cart there is nothing to decide — those pages contact nobody. And we do not ask you about the Stripe cookies of section 3, because they are strictly necessary to the payment you came to make: a permission we could not honour is not a permission, it is theatre.
Your answer is kept in the website_cookies_bar cookie (section 2). You can change it at any time
from this page — a small button appears here once you have answered.
4.2 What happens if you then click the express payment button
Before the click, nothing at all is loaded from Stripe, Apple or Google on the cart. That is deliberate, and it is a change we made on purpose: until 3 August 2026, this site loaded Stripe and contacted Google as soon as the cart page appeared, before anyone had asked for anything. We measured it, and we stopped it.
After the click, in this order:
- Stripe's library is downloaded from
js.stripe.com; - it asks your browser whether a wallet is available;
- to answer that question, your browser contacts Apple or Google. Your IP address, your browser's user agent, and the address of the page are sent to them by that request.
If it is Google, pay.google.com sets a cookie:
| Name | Set by | Domain | Duration | What it is for |
|---|---|---|---|---|
NID |
.google.com |
183 days | Google's own cookie, set by its payment interface. It is governed by Google's policy, not ours. |
Google's privacy policy: https://policies.google.com/privacy. Apple's: https://www.apple.com/legal/privacy/.
Two things we owe you in plain words. First, this happens even if no wallet turns out to be available — the question cannot be asked without contacting them. Second, under the case law of the Court of Justice (Fashion ID, C-40/17), a site that embeds a third party's code is jointly responsible for the collection and transmission it triggers. We are not hiding behind Stripe. That is exactly why the button is there: so that this transmission follows a choice of yours, instead of a page load.
If you never click it, none of this ever happens. Bancontact, card and bank transfer are on the payment page and involve neither Apple nor Google.
5. If you order the service
The order funnel is on the same site and stores nothing beyond section 2 above. What we do with the accounting data you entrust to us is a different question, governed by a different text: the data processing agreement, which you accept before we read anything at all.
6. Transfers outside the European Union
Stripe Payments Europe is Irish. Google LLC and Apple Inc. are American, and both are certified under the EU–US Data Privacy Framework (adequacy decision of 10 July 2023). A transfer to them therefore rests on that decision today. We do not control it, and we say so rather than promise otherwise.
7. How to refuse, and how to erase
- Refuse the wallets: answer Only essentials in the banner, and the express payment button is not even offered. If you already answered otherwise, come back to this page and change your answer, or simply never click the button. There is nothing else to refuse — the rest is what makes the page work and what makes a payment go through.
- Erase everything: your browser's settings will delete cookies and local storage for this site. Nothing here survives that, and nothing here is restored behind your back.
- Block in advance: a browser set to refuse third-party cookies will still let you use this site and pay by card; only the wallets may stop working.
Erasing session_id logs you out and empties your cart. That is the only consequence.
8. Who is responsible, and how to reach us
The controller is Charbon Cinéma SRL, trading as Anthracite Brussels — rue Berthelot 172, 1190 Forest, Belgium — company number BE 0669.654.643.
Write to support@anthracite.brussels for any question about this page, or to exercise your rights of access, rectification, erasure, restriction, objection and portability under articles 15 to 22 of the GDPR.
You may also lodge a complaint with the Belgian Data Protection Authority, rue de la Presse 35, 1000 Brussels — https://www.autoriteprotectiondonnees.be.
9. Versions of this page
Each version of this page is numbered, dated, and kept. If you need to know what this page said on the day you visited, ask us and we will send you that version.
| Version | Date | What changed |
|---|---|---|
| 1.1 | 5 August 2026 | A consent banner now appears from the cart onwards, asking one question: may we offer Apple Pay, Google Pay and Link? Answering "Only essentials" removes the express payment button altogether. Version 1.0 said this site had no banner and that the day it got one, this page would change first. This is that change. The website_cookies_bar cookie is added to section 2. |
| 1.0 | 3 August 2026 | First version. Published together with the change that stopped the cart from contacting Stripe and Google before any click, and with the removal of Google Fonts and the Firebase notification library from every page. |
This page exists in English, French and Dutch. In the event of divergence, the English version prevails. It is written to be read, not to be survived: if any line of it does not match what your browser actually does, tell us — that is a defect, and we will fix it.