Draft — pre-launch. These legal documents are under revision and are not yet in force. Hail Pilot is a pre-launch service; the legal entity responsible for it will be identified here, with its registered name, before the Service accepts customer sign-ups. No account may be opened, and no data processing agreement executed, in reliance on this draft.

Cookie & Tracking Notice

Version: 2026-09-18.v1. Effective date: 18 September 2026. Operator: ABSOLUTE SERVICES (UEN 53464936W), a sole proprietorship registered in Singapore and owned by LEE KOK WAN. "Hail Pilot" is the name of the product and service operated by ABSOLUTE SERVICES ("Hail Pilot", "we", "us"). Registered address: 60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051.

This notice describes the cookies, browser storage and third-party scripts that hailpilot.com and the Hail Pilot application actually use today. It supplements the Privacy Policy at /legal/privacy. Terms in capitals have the meaning given in the Terms of Service at /legal/terms.

1. What this notice covers

1.1 It covers the public website at hailpilot.com, the sign-in and registration pages, and the signed-in application.

1.2 It does not cover the Seller Assistant browser extension. The extension has its own notice, the Seller Assistant Extension Privacy Notice at /legal/extension-privacy.

1.3 We describe only what is set or loaded by our own pages. Where a third party sets its own cookies through a script we load, we name the third party and say what we send it. That third party's own notice governs what it does with the data.

2. No consent prompt is shown today

2.1 We do not currently show a consent prompt before loading the scripts listed in Sections 4 to 6. Those scripts load when the page loads.

2.2 Singapore and Malaysian law do not require a consent prompt for cookies as such, but they do require us to tell you what we collect and why. This notice is that disclosure. You can block or remove any of the scripts and cookies below using the controls in Section 8.

2.3 The Service is not offered to persons in the European Economic Area or the United Kingdom.

3. Essential cookies

3.1 These cookies are set by our own servers and are required for you to sign in and use the Service. They are not used for advertising or analytics. Blocking them will stop sign-in from working.

CookieSet byWhat it doesAttributesLifetime
__Host-sessionapi.hailpilot.com, on sign-inHolds your session identifier. Only a hash of the identifier is stored on our servers.HttpOnly, Secure, SameSite=LaxDeleted on sign-out. Otherwise expires 7 days after sign-in. The server also ends a session after 8 hours without activity.
__Secure-session-existsapi.hailpilot.com, on sign-inA marker (value "1") that lets the application route you to the sign-in page or the dashboard without a server round-trip. Contains no session secret.Secure, SameSite=Lax, readable by page scriptsSame lifetime as __Host-session.
_csrfapi.hailpilot.com, on sign-inHolds a token that our pages send back in a request header so that another site cannot make changes in your account from your browser.Secure, SameSite=Lax, readable by page scriptsFor the session. Deleted on sign-out.
hp_localehailpilot.com, when you choose a languageRemembers your chosen display language (en, zh, ms, id, th or fil).Readable by page scripts1 year.

3.2 On a non-secure development build the first two cookies are named session and session_exists. On the live site the names above apply.

4. Website analytics

4.1 Plausible Analytics. Every page on hailpilot.com and in the application loads a script from plausible.io. Plausible states that it does not use cookies or store identifiers in your browser. Each page view sends your IP address, the page address, the referring page and your browser type to Plausible's servers, which are located in the European Union. We use the aggregated counts to see which pages are read. We also send Plausible a small number of named events (for example, that a public calculator was used) that contain no personal data.

4.2 Sentry. The application loads an error-monitoring script from Sentry when an error-reporting key is configured for the deployment. It sends error reports and, for a sample of 10 in 100 signed-in sessions, a replay of the session in which all text is masked and images and media are blocked. We have configured the script not to attach your IP address or user identifier to reports. Sentry processes this data in Germany.

4.3 [TO CONFIRM: PostHog] The public marketing pages are built to load a product-analytics script from PostHog, hosted in the United States, when a PostHog key is configured for the deployment. It is never loaded on the sign-in, registration or signed-in pages. If it is enabled, it sets its own cookies and records page views and interaction events. It is not gated by consent. [OPERATOR: confirm whether NEXT_PUBLIC_POSTHOG_KEY is set in production; delete this clause if it is not.]

4.4 [TO CONFIRM: Microsoft Clarity] The site is built to load a heat-map and session-recording script from Microsoft Clarity on public marketing pages only, never on signed-in pages, when a Clarity identifier is configured for the deployment. If it is enabled, it sets its own cookies. It is not gated by consent. [OPERATOR: confirm whether NEXT_PUBLIC_CLARITY_ID is set in production; delete this clause if it is not.]

5. Advertising and tag-management scripts

5.1 We do not load advertising or marketing tags on hailpilot.com or in the application. No Meta, LinkedIn or other advertising platform script is loaded by our pages.

5.2 [TO CONFIRM: Google Tag Manager] The public marketing pages are built to load Google Tag Manager when a container identifier is configured for the deployment; it is never loaded on the sign-in, registration or signed-in pages. If it is enabled, it may load further scripts from that container, and the consent signals it receives are set to "granted" by default. We will not use the container to load advertising tags. [OPERATOR: confirm whether NEXT_PUBLIC_GTM_ID is set in production and that the container carries no advertising tags; delete this clause if the identifier is not set.]

6. Security scripts

6.1 Cloudflare Turnstile. The sign-in and registration forms load a bot-detection widget from Cloudflare. It sends your IP address and browser signals to Cloudflare and returns a challenge token that our server verifies with Cloudflare before accepting the form. Cloudflare may set its own cookie for this purpose. Cloudflare processes this data at its global edge locations.

6.2 Cloudflare network. All requests to hailpilot.com and api.hailpilot.com pass through Cloudflare's network for DNS, content delivery and protection against attacks. Cloudflare sees your IP address and request headers for every request.

7. Browser storage that is not a cookie

7.1 Our pages store the following in your browser's local storage. Nothing in this list is sent to a third party. Each item stays until you clear your browser's site data or, where stated, until you take the action that removes it.

KeyWhat it holds
hp-themeYour chosen light or dark theme.
hp_sidebar_collapsed, hp_density_override, hp_layout_presetLayout preferences in the application.
hp_last_emailThe email address you last used to sign in, so the sign-in form can pre-fill it. Removed when you clear site data.
onboarding_dismissed, demo_banner_dismissed, onboarding_copilot_used, onboarding_evidence_downloaded, ai_tier_banner_dismissed, hp_passkey_nudge_dismissed, password_expiry_dismissed, cb-onboarding-carrier-skipped, cb-onboarding-notifications-ack, hailpilot-chat-open, hailpilot-chat-hiddenFlags that record which in-app tips and banners you have dismissed.
hp_miniapp_tokenA short-lived token used only when the application is opened inside Telegram.
deployment_skew_reloadA one-time flag that prevents a reload loop after we deploy a new version.

7.2 Our public pages store the following in session storage, which is deleted when you close the browser tab:

KeyWhat it holds
hp_utmCampaign parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term, ref) from the link you arrived on, so that a later sign-up can record where you came from.

7.3 Fonts are served from our own servers. No third-party font service is loaded.

8. Your controls

8.1 Block or delete cookies. Your browser lets you block all cookies, block third-party cookies, delete cookies when you close the browser, or delete them now. Blocking the cookies in Section 3 will prevent sign-in.

8.2 Block third-party scripts. Content-blocking browser extensions and the tracking-protection settings in most browsers will stop the scripts in Sections 4 and 5 from loading. The Service works without them.

8.3 Advertising platform controls. No advertising platform receives data from our pages, so there is no platform-side setting you need to change for our site.

8.4 Clear browser storage. Your browser's "clear site data" control removes everything in Section 7.

8.5 Global Privacy Control and Do Not Track. Our pages do not currently read these signals.

9. Changes to this notice

9.1 We will update this notice when we add, remove or change a cookie, script or storage key. Material changes are notified in the way described in the Terms of Service, and every version is listed on the legal changelog at /legal/changelog.

10. Contact

10.1 Questions about this notice go to our Data Protection Officer at business@hailpilot.com. The Privacy Policy explains how to make a complaint.

Cookie & Tracking Notice | Hail Pilot