What this covers
This explains how Offpeek Ltd uses cookies, local storage, session storage and similar technologies on offpeek.ae, on our marketing pages, and inside the Offpeek application. Read it alongside our Privacy Policy.
Where a merchant embeds an Offpeek booking interface on its own website, that merchant is responsible for its own cookie notice and consent mechanism on its own domain. This policy covers our own pages.
The rules we follow
DIFC data protection rules govern the collection and use of personal data in digital services, and require transparency and, in practice, consent for anything that is not strictly necessary.
Where you are somewhere whose law requires consent before non-essential cookies are set, we obtain that consent first. Strictly necessary cookies are set without consent, because the service cannot be delivered without them.
A cookie notice that misdescribes what is actually set is a problem in itself, which is why we keep the list below accurate rather than generic.
What we use, and why
Strictly necessary. Authentication, session management, cross-site request forgery protection, load balancing, and storing booking and connection state while a flow is in progress. Consent is not required, because the service cannot operate without them.
Preferences. Remembering your language — Arabic or English — your timezone, and interface settings such as a collapsed panel. Set on your instruction; listed here for transparency.
Performance and error monitoring. Detecting, diagnosing and fixing errors and performance problems. Consent is required where the applicable law requires it. Session replay is off by default and is only ever enabled with consent.
Product analytics. Understanding which features are used, so we can improve them. Consent required.
Advertising and cross-site tracking. Not used. We do not deploy Meta Pixel, Google Ads conversion tracking, LinkedIn Insight Tag or anything equivalent. If that ever changes, we will update this page and ask for consent before anything is set.
The specific cookies we set
op_session | strictly necessary | maintains an authenticated session | expires at the end of your session. |
|---|---|---|---|
op_csrf | strictly necessary | protects against cross-site request forgery | session. |
op_lb | strictly necessary | routes your request to the right server | session. |
op_oauth_state | strictly necessary | holds state while a booking platform or calendar connection is authorised | up to 15 minutes. |
op_consent | strictly necessary | records your cookie choices so we do not ask again | 12 months. |
op_lang | preferences | remembers Arabic or English | 12 months. |
op_tz | preferences | remembers your timezone for slot display | 12 months. |
| [error monitoring cookie] | performance | correlates error reports to a session for diagnosis | [•]. |
| [analytics cookie] | product analytics | distinguishes users for feature-usage measurement | [•]. |
Local and session storage
The application uses browser local storage and session storage for the same strictly necessary purposes as the cookies above — holding authentication state, keeping a form draft while you complete it, and remembering interface preferences.
We do not use local storage to build a profile of you, and we do not read storage set by other sites.
Session replay
Where session replay is enabled, it records interactions with the interface so we can reproduce a reported fault.
It is off by default. It is enabled only with consent, only for the merchant account that consents, and only for as long as it takes to diagnose the fault.
Where it is enabled, we mask input fields containing customer names, telephone numbers, email addresses and any free-text field, so customer records do not appear in a replay.
Your choices
Where consent is required, we show a banner before anything non-essential is set. You can accept all, reject all, or choose by category — and rejecting is exactly as easy as accepting.
You can change your choices at any time through the Cookie settings link in the footer of every page.
You can also block or delete cookies in your browser. Blocking strictly necessary cookies will stop you signing in and using the application.
We keep a record of the consent you give, as evidence, for twelve months.
Third parties
Our error monitoring and product analytics providers are listed as sub-processors in our data processing terms, together with their locations.
Neither is approved to receive health information, and both are configured to exclude merchant customer records. We do not permit our providers to use data collected on our pages for their own purposes.
Changes
We update this page when what we set changes. The date at the top tells you when it was last reviewed. Where a change introduces a new category of non-essential technology, we will ask for consent again before it is set.
Contact
Questions about this policy: privacy@offpeek.ae
Data Protection Officer: dpo@offpeek.ae
You may also complain to the DIFC Commissioner of Data Protection at commissioner@dp.difc.ae.