← All legal documents

Draft — not yet finalized. This document still contains unresolved placeholder text and has not been approved for publication: [EFFECTIVE DATE].

Cookie & Tracking Policy — 8055 Stays

Operated by HASU AURORA PRIVATE LIMITED

Effective date: [EFFECTIVE DATE] · Last updated: 18 August 2026


1. What this Policy covers

This Policy explains how 8055 Stays uses cookies, local storage, and similar tracking technologies (including mobile SDK identifiers) across our Guest and Host web and mobile apps.

A cookie is a small text file a website stores on your device. We also use equivalent browser storage (localStorage / sessionStorage) and, in the mobile apps, on-device storage and SDK identifiers. We group all of these as "cookies and similar technologies" below.


2. Our approach: strictly necessary by default, analytics on opt-in

We keep tracking to a minimum:


3. Categories of cookies and storage we use

3.1 Strictly necessary (always active)

Purpose Technology Set by Notes
Authentication & sessions Session cookie / secure token Better Auth (our Auth Worker) Keeps you signed in; stores a session reference, not your password.
Security & abuse prevention Cookie / token, rate-limit keys HASU AURORA Protects against fraud, CSRF, and abuse.
Consent state Local storage HASU AURORA / PostHog SDK Remembers your analytics choice so we don't ask every visit.
Preferences Local storage HASU AURORA Language, currency, time zone, and similar UI settings.

These do not require consent because they are essential to provide a service you have requested.

3.2 Analytics (only after you opt in)

Purpose Technology Set by Notes
Product analytics PostHog cookies / local storage PostHog Named product events + a stable internal user ID. US region.
Safe exception capture PostHog PostHog Allowlisted error class + generic message only.

When analytics is enabled, we deliberately disable session replay, heatmaps, automatic click/pageview/page-leave capture, dead-click collection, and performance capture. URL query strings and fragments are stripped before events leave your device, and you are identified only by a stable internal user ID — never by name, email, message content, payment data, or identity documents.

3.3 Third-party features you interact with

Feature Provider When it applies
Social sign-in Google, Apple Only if you choose to sign in with Google or Apple; the provider may set its own cookies during that flow.
Maps Google Maps Platform (web) When a page shows an interactive map; Google may set cookies to render maps.
Payments (planned) Razorpay / Cashfree On checkout, once payments are live; the provider sets cookies needed to process payment securely.

These providers act under their own cookie/privacy policies for the cookies they set. Links are in Section 6.


4. Mobile apps (iOS & Android)

The mobile apps do not use browser cookies but use equivalent technologies:

Device permissions (camera, photos, location, notifications) are separate from cookies and are covered in your device's permission settings.


5. How to control cookies


6. Third-party policies


7. Changes and contact

We will update this Policy when our use of cookies changes and post a new "Last updated" date. Questions: support@hasuaurora.com.