Skip to content
Baytakبَيْتَك
Legal

Cookie Policy

Effective: 30 May 2026  ·  Last updated: 15 July 2026  ·  support@baytakapp.com

1. Introduction

This Cookie Policy explains what cookies are, how Baytak ("we", "us", "our") uses them on baytakapp.com and any sub-domains (the "Platform"), and what rights you have regarding their use.

By using the Platform you acknowledge this policy. Strictly necessary cookies are set automatically because the Platform cannot function without them. We do not set any optional, tracking, analytics, or advertising cookies, and we do not require your consent for the cookies described below because they are all strictly necessary for service delivery.

2. What Are Cookies?

Cookies are small text files placed on your device by a website. They allow the website to recognise your device between page visits and server round-trips. Cookies cannot run programs or deliver viruses.

3. Cookies We Use

Baytak uses only strictly necessary cookies. We set no analytics cookies, no advertising cookies, no tracking pixels, and no third-party cookies of any kind beyond those required for authentication.

3.1 Authentication Session Cookies (Supabase SSR)

Cookie name patternPurposeTypeDuration
sb-[project-ref]-auth-tokenStores your encrypted JWT access token. Allows the server to confirm you are signed in without requiring you to log in on every page load.Strictly necessaryUntil your session expires (default 1 hour, auto-renewed on activity)
sb-[project-ref]-auth-token.0, .1 …Chunk cookies used when the JWT exceeds the 4 KB browser cookie limit. Same purpose as above.Strictly necessarySame as above

3.2 Preference Cookies

Cookie namePurposeTypeDuration
baytak_localeRemembers your chosen display language (English or Arabic). Contains only the value "en" or "ar" — no personal data.Strictly necessary400 days

What these cookies contain: An encrypted JSON Web Token (JWT) issued by Supabase. The token encodes only your internal user ID, session ID, and expiry timestamp. It does not contain your phone number, name, address, or any booking data.

How they are set: Authentication cookies are set server-side via Set-Cookie response headers with HttpOnly, Secure, and SameSite=Lax flags — they are not accessible from JavaScript. The baytak_locale preference cookie is set with Secure and SameSite=Lax but not HttpOnly, as it holds only the non-sensitive value "en" or "ar".

No personal cleaning, booking, or location data is ever stored in a cookie.

4. What We Do NOT Use

  • Analytics cookies — we do not use Google Analytics, Mixpanel, Hotjar, or any equivalent service
  • Advertising / retargeting cookies — none
  • Social media tracking pixels — none (social icons in the footer are plain HTML links with no tracking scripts)
  • Third-party cookies — the only external service that reads these cookies is Supabase, acting as our authentication and database processor under a Data Processing Agreement
  • Fingerprinting — we do not use browser or device fingerprinting of any kind

5. Browser-Level Storage (Not Cookies)

We do not use localStorage, sessionStorage, or IndexedDB to store personal data. No personal data is persisted in the browser beyond the session cookies described above.

6. Legal Basis

Our use of strictly necessary authentication cookies is based on our legitimate interest in providing a secure, functioning service that requires user authentication (Article 6(1)(f) GDPR, where applicable). Because these cookies are essential to the service you have explicitly requested, they do not require prior consent under applicable Jordanian and international e-privacy law.

7. Your Rights and Controls

7.1 Browser controls

You may block or delete cookies at any time through your browser settings. Note that deleting or blocking authentication cookies will sign you out and prevent you from accessing your dashboard or booking history.

7.2 Account deletion

Deleting your account (available in the Dashboard → Account section) removes all your personal data from our servers. Any authentication cookies remaining in your browser will immediately become invalid.

7.3 Session expiry

Your session cookies expire automatically when you sign out or when your session times out. Closing your browser does not necessarily clear session cookies; use Sign Out to explicitly invalidate your session.

8. Changes to This Policy

We may update this policy when we change our technical infrastructure. The "Last updated" date at the top of this page will reflect any changes. Material changes will be communicated via in-app notice.

9. Contact Us

For questions about this Cookie Policy or our privacy practices:

Email: support@baytakapp.com

Address: Amman, Jordan

This Cookie Policy applies exclusively to baytakapp.com. It does not cover third-party websites linked from our Platform.