What ihjiz.co and app.ihjiz.co store in your browser, which third parties they load, and what you can do about it. The short version: this website sets no cookies at all, the app sets only what it needs to keep you signed in and safe, and neither uses advertising or analytics trackers.
1.This website (ihjiz.co)
The marketing site is a set of static pages. It sets no cookies. It keeps two preferences in your browser's local storage, which never leave your device:
| Key | Purpose | Lifetime |
|---|---|---|
| ihjiz-theme | Whether you chose light or dark mode. | Until you clear site data |
| ihjiz-landing-lang | Not used by the live site; reserved. | — |
Because there is nothing to consent to, the site shows no cookie banner. If we ever add analytics, we will add a consent prompt first and update this page.
2.The app (app.ihjiz.co)
The application uses only strictly necessary cookies and storage. None of them is used for tracking or advertising.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| _csrf | Cookie | Protects forms and API calls against cross-site request forgery. Contains a random token, nothing about you. | Session |
| Sign-in session | Cookie (HttpOnly, Secure, SameSite=Lax) | Holds the server-side session during sign-in with Google, Facebook or another identity provider. | Session |
| Sign-in state | Browser storage | Keeps you signed in between visits and lets the app refresh your session. Cleared when you sign out. | Until sign-out or expiry |
| ihjiz_theme_mode, ihjiz_language | Browser storage | Your colour mode and interface language. | Until you clear site data |
| Table and view preferences | Browser storage | Column widths, chosen views, collapsed panels, so screens look the way you left them. | Until you clear site data |
On the staff mobile app, the sign-in token is stored in the operating system's secure keystore rather than in browser storage, and can be protected with the device's biometrics.
3.Cookies set by businesses' booking pages
A business's public booking page and embedded widget run on the same app and follow the same table above. If a business embeds the widget on its own website, that website's own cookies and analytics apply to the page around the widget; the widget itself sets nothing beyond what section 2 lists.
4.Third-party requests
Some pages load resources from other companies. When they do, your browser sends those companies your IP address and standard request headers, and they may set cookies under their own policies. We keep this list short and link each policy.
| Provider | Where | What for |
|---|---|---|
| Google Fonts | Website and app | Typefaces. Google privacy policy. |
| Adobe Fonts (Typekit) | App | Typefaces. Adobe Fonts privacy. |
| Cloudflare cdnjs | App | Open-source script and style libraries. Cloudflare privacy policy. |
| OpenStreetMap | App, where a business shows a map | Map tiles. OSMF privacy policy. |
| Stripe, HyperPay, Tap, PayPal | App, only while you pay | Payment forms and fraud prevention. Card details go directly to the provider. Each provider's policy is shown at checkout. |
5.Managing cookies
You can clear or block cookies and site data in your browser settings. Blocking the strictly necessary items in section 2 will stop you signing in to the app. Because we use no optional cookies, there is nothing else to switch off.
6.Changes and contact
We update this page when the cookies or providers change, and change the date at the top. Questions: privacy@ihjiz.co. For how we handle personal data more broadly, see the Privacy Policy.