Cookie & Tracking Notice
Version: 2026-09-18.v1. Effective date: 18 September 2026. Operator: ABSOLUTE SERVICES (UEN 53464936W), a sole proprietorship registered in Singapore and owned by LEE KOK WAN. "Hail Pilot" is the name of the product and service operated by ABSOLUTE SERVICES ("Hail Pilot", "we", "us"). Registered address: 60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051.
This notice describes the cookies, browser storage and third-party scripts that hailpilot.com and the Hail Pilot application actually use today. It supplements the Privacy Policy at /legal/privacy. Terms in capitals have the meaning given in the Terms of Service at /legal/terms.
1. What this notice covers
1.1 It covers the public website at hailpilot.com, the sign-in and registration pages, and the signed-in application.
1.2 It does not cover the Seller Assistant browser extension. The extension has its own notice, the Seller Assistant Extension Privacy Notice at /legal/extension-privacy.
1.3 We describe only what is set or loaded by our own pages. Where a third party sets its own cookies through a script we load, we name the third party and say what we send it. That third party's own notice governs what it does with the data.
2. No consent prompt is shown today
2.1 We do not currently show a consent prompt before loading the scripts listed in Sections 4 to 6. Those scripts load when the page loads.
2.2 Singapore and Malaysian law do not require a consent prompt for cookies as such, but they do require us to tell you what we collect and why. This notice is that disclosure. You can block or remove any of the scripts and cookies below using the controls in Section 8.
2.3 The Service is not offered to persons in the European Economic Area or the United Kingdom.
3. Essential cookies
3.1 These cookies are set by our own servers and are required for you to sign in and use the Service. They are not used for advertising or analytics. Blocking them will stop sign-in from working.
| Cookie | Set by | What it does | Attributes | Lifetime |
|---|---|---|---|---|
| __Host-session | api.hailpilot.com, on sign-in | Holds your session identifier. Only a hash of the identifier is stored on our servers. | HttpOnly, Secure, SameSite=Lax | Deleted on sign-out. Otherwise expires 7 days after sign-in. The server also ends a session after 8 hours without activity. |
| __Secure-session-exists | api.hailpilot.com, on sign-in | A marker (value "1") that lets the application route you to the sign-in page or the dashboard without a server round-trip. Contains no session secret. | Secure, SameSite=Lax, readable by page scripts | Same lifetime as __Host-session. |
| _csrf | api.hailpilot.com, on sign-in | Holds a token that our pages send back in a request header so that another site cannot make changes in your account from your browser. | Secure, SameSite=Lax, readable by page scripts | For the session. Deleted on sign-out. |
| hp_locale | hailpilot.com, when you choose a language | Remembers your chosen display language (en, zh, ms, id, th or fil). | Readable by page scripts | 1 year. |
3.2 On a non-secure development build the first two cookies are named session and session_exists. On the live site the names above apply.
4. Website analytics
4.1 Plausible Analytics. Every page on hailpilot.com and in the application loads a script from plausible.io. Plausible states that it does not use cookies or store identifiers in your browser. Each page view sends your IP address, the page address, the referring page and your browser type to Plausible's servers, which are located in the European Union. We use the aggregated counts to see which pages are read. We also send Plausible a small number of named events (for example, that a public calculator was used) that contain no personal data.
4.2 Sentry. The application loads an error-monitoring script from Sentry when an error-reporting key is configured for the deployment. It sends error reports and, for a sample of 10 in 100 signed-in sessions, a replay of the session in which all text is masked and images and media are blocked. We have configured the script not to attach your IP address or user identifier to reports. Sentry processes this data in Germany.
4.3 [TO CONFIRM: PostHog] The public marketing pages are built to load a product-analytics script from PostHog, hosted in the United States, when a PostHog key is configured for the deployment. It is never loaded on the sign-in, registration or signed-in pages. If it is enabled, it sets its own cookies and records page views and interaction events. It is not gated by consent. [OPERATOR: confirm whether NEXT_PUBLIC_POSTHOG_KEY is set in production; delete this clause if it is not.]
4.4 [TO CONFIRM: Microsoft Clarity] The site is built to load a heat-map and session-recording script from Microsoft Clarity on public marketing pages only, never on signed-in pages, when a Clarity identifier is configured for the deployment. If it is enabled, it sets its own cookies. It is not gated by consent. [OPERATOR: confirm whether NEXT_PUBLIC_CLARITY_ID is set in production; delete this clause if it is not.]
5. Advertising and tag-management scripts
5.1 We do not load advertising or marketing tags on hailpilot.com or in the application. No Meta, LinkedIn or other advertising platform script is loaded by our pages.
5.2 [TO CONFIRM: Google Tag Manager] The public marketing pages are built to load Google Tag Manager when a container identifier is configured for the deployment; it is never loaded on the sign-in, registration or signed-in pages. If it is enabled, it may load further scripts from that container, and the consent signals it receives are set to "granted" by default. We will not use the container to load advertising tags. [OPERATOR: confirm whether NEXT_PUBLIC_GTM_ID is set in production and that the container carries no advertising tags; delete this clause if the identifier is not set.]
6. Security scripts
6.1 Cloudflare Turnstile. The sign-in and registration forms load a bot-detection widget from Cloudflare. It sends your IP address and browser signals to Cloudflare and returns a challenge token that our server verifies with Cloudflare before accepting the form. Cloudflare may set its own cookie for this purpose. Cloudflare processes this data at its global edge locations.
6.2 Cloudflare network. All requests to hailpilot.com and api.hailpilot.com pass through Cloudflare's network for DNS, content delivery and protection against attacks. Cloudflare sees your IP address and request headers for every request.
7. Browser storage that is not a cookie
7.1 Our pages store the following in your browser's local storage. Nothing in this list is sent to a third party. Each item stays until you clear your browser's site data or, where stated, until you take the action that removes it.
| Key | What it holds |
|---|---|
| hp-theme | Your chosen light or dark theme. |
| hp_sidebar_collapsed, hp_density_override, hp_layout_preset | Layout preferences in the application. |
| hp_last_email | The email address you last used to sign in, so the sign-in form can pre-fill it. Removed when you clear site data. |
| onboarding_dismissed, demo_banner_dismissed, onboarding_copilot_used, onboarding_evidence_downloaded, ai_tier_banner_dismissed, hp_passkey_nudge_dismissed, password_expiry_dismissed, cb-onboarding-carrier-skipped, cb-onboarding-notifications-ack, hailpilot-chat-open, hailpilot-chat-hidden | Flags that record which in-app tips and banners you have dismissed. |
| hp_miniapp_token | A short-lived token used only when the application is opened inside Telegram. |
| deployment_skew_reload | A one-time flag that prevents a reload loop after we deploy a new version. |
7.2 Our public pages store the following in session storage, which is deleted when you close the browser tab:
| Key | What it holds |
|---|---|
| hp_utm | Campaign parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term, ref) from the link you arrived on, so that a later sign-up can record where you came from. |
7.3 Fonts are served from our own servers. No third-party font service is loaded.
8. Your controls
8.1 Block or delete cookies. Your browser lets you block all cookies, block third-party cookies, delete cookies when you close the browser, or delete them now. Blocking the cookies in Section 3 will prevent sign-in.
8.2 Block third-party scripts. Content-blocking browser extensions and the tracking-protection settings in most browsers will stop the scripts in Sections 4 and 5 from loading. The Service works without them.
8.3 Advertising platform controls. No advertising platform receives data from our pages, so there is no platform-side setting you need to change for our site.
8.4 Clear browser storage. Your browser's "clear site data" control removes everything in Section 7.
8.5 Global Privacy Control and Do Not Track. Our pages do not currently read these signals.
9. Changes to this notice
9.1 We will update this notice when we add, remove or change a cookie, script or storage key. Material changes are notified in the way described in the Terms of Service, and every version is listed on the legal changelog at /legal/changelog.
10. Contact
10.1 Questions about this notice go to our Data Protection Officer at business@hailpilot.com. The Privacy Policy explains how to make a complaint.