SahraSafarCookie Policy
SAHRASAFAR GROUP INC — Online Travel Agency
1. INTRODUCTION
This Cookie Policy explains how SAHRASAFAR GROUP INC uses cookies and similar technologies on https://www.sahrasafar.com and related applications. Read this alongside our Privacy Policy and Terms and Conditions.
2. WHAT ARE COOKIES AND SIMILAR TECHNOLOGIES?
Cookies are small text files stored on your device by websites. Similar technologies we use include:
- sessionStorage — browser storage cleared automatically when you close the tab. Used for temporary data like checkout form state. - localStorage — browser storage that persists until manually cleared. Used for preferences like language and currency. - Device Fingerprinting — generates a unique device identifier from browser and device attributes for fraud prevention only. No data is shared with any external fingerprinting company. - Server-Side Session Tokens — unique identifiers stored on our servers to maintain your authenticated session.
3. COOKIES AND TECHNOLOGIES WE USE
3.1 Strictly Necessary (No Consent Required)
Essential for the Platform to function. Cannot be disabled.
| Technology | Purpose | Storage | Duration |
|---|---|---|---|
| Session token | Maintains your login state | Server-side + cookie | Session |
| CSRF token | Protects against cross-site request forgery | Cookie | Short-lived |
| Cookie consent preference | Remembers your cookie choices | localStorage | 12 months |
| OTP session state | Manages one-time password authentication flow | Session | Session |
*Legal basis: Strictly necessary for service provision — consent not required.*
3.2 Security and Fraud Prevention
Protect the Platform and users from fraud and abuse.
| Technology | Purpose | Storage | Duration |
|---|---|---|---|
| Device fingerprint | Fraud detection and account protection | Cookie + localStorage + server-side | Up to 1 year client-side; up to 3 years server-side |
| Fraud risk scoring | IP geolocation, fraud risk assessment, and local currency/airport display | localStorage + third-party cookies | Session; server-side up to 12 months |
| Payment fraud signals | Payment fraud detection by our payment processor | Third-party managed | Per provider's policy |
| Abuse prevention | Monitors for anomalous activity patterns | Server-side | Up to 12 months |
| Bot detection | Automated bot detection to protect the platform | Server-side | Up to 3 years |
*Legal basis: GDPR Art. 6(1)(f) legitimate interests; essential security measures, not used for advertising.*
3.3 Functional (Enhance Your Experience)
Remember your choices and personalize the Platform.
| Technology | Purpose | Storage | Duration |
|---|---|---|---|
| Language preference | Remembers your selected language | localStorage | Until cleared |
| Currency preference | Remembers your display currency | localStorage | Until cleared |
| Region preference | Remembers your selected region for deals/offers | localStorage + cookie | Until cleared |
| Recent searches | Stores recent searches for quick access | localStorage | Until cleared |
| Sign-in prompt state | Tracks whether sign-in prompts were dismissed | localStorage | Until cleared |
| AI assistant session | Maintains conversation state and travel plans | Server-side | Until you delete or account deletion |
| Third-party sign-in | Maintains sign-in session with Google/Apple | Session | Session or per provider |
*Legal basis: Consent or legitimate interests. Disabling may degrade personalization.*
3.4 Temporary Checkout Data
| Technology | Purpose | Storage | Duration |
|---|---|---|---|
| Passenger form data | Temporarily caches passenger details during checkout to prevent data loss if a fare expires | sessionStorage (your device only) | Automatically deleted when tab is closed |
This data never reaches SahraSafar's servers. It exists only in your browser tab and is permanently removed when you close the tab.
*Legal basis: Strictly necessary for service provision during an active checkout session.*
3.5 Analytics
As of the effective date, SahraSafar does NOT use third-party analytics cookies. Any internal analytics rely on server-side logs and aggregated, anonymized data — no cookies placed on your device.
If we introduce analytics cookies in the future, this policy will be updated and your consent obtained before activation.
3.6 Marketing and Advertising
SahraSafar does NOT use any marketing, advertising, retargeting, or cross-site tracking cookies.
If introduced in the future, this policy will be updated and explicit consent obtained.
4. THIRD-PARTY COOKIES
Some integrated services may set their own cookies:
- Stripe — payment processing and fraud prevention, governed by Stripe's privacy policy. - Google Sign-In — authentication cookies, governed by Google's privacy policy. - Apple Sign-In — authentication cookies, governed by Apple's privacy policy. - MaxMind — geolocation and fraud risk scoring, governed by MaxMind's privacy policy. - Mapbox — mapping services, governed by Mapbox's privacy policy.
We do not control third-party cookies. You can manage or block them through your browser settings (see Section 5).
5. YOUR CHOICES
5.1 Cookie Consent Banner
On first visit, you can: Accept All; Reject Non-Essential; or Customize by category. Change preferences anytime via the cookie settings link in the website footer.
5.2 Browser Controls
Manage cookies via browser settings (view, delete, block). Blocking essential cookies may prevent login or checkout.
5.3 Device Controls
Mobile devices offer tracking controls in system settings (e.g., iOS Limit Ad Tracking, Android opt-out of personalized ads).
6. DO NOT TRACK
The Platform does not respond to DNT signals. Use the controls above to manage preferences.
7. LEGAL FRAMEWORK
This policy complies with: the EU ePrivacy Directive (2002/58/EC); GDPR (Regulation 2016/679); UK GDPR and Privacy and Electronic Communications Regulations (PECR); Saudi PDPL; CCPA/CPRA; India DPDP Act 2023; and the UK Digital Markets, Competition and Consumers Act 2024 (DMCCA). Non-essential cookies require opt-in consent where required by applicable law. Strictly necessary cookies are exempt from consent requirements under ePrivacy Directive Article 5(3).
8. CHANGES
Material changes trigger an updated "Last Updated" date and re-display of the consent banner. Where required, renewed consent is obtained.
9. CONTACT
SAHRASAFAR GROUP INC Email: legal@sahrasafar.com (for data/privacy requests) | support@sahrasafar.com (general) Website: https://www.sahrasafar.com
*By continuing to use SahraSafar after being presented with our cookie consent mechanisms, you acknowledge this Cookie Policy.*