Skip to content
BAYZO

Your data

Cookie Policy

This policy lists every cookie Bayzo sets, what each one does, and how long it lasts. There are five, they are all first-party, and none of them is for advertising. You will not find a consent banner on Bayzo because there is nothing here to consent to beyond what the service needs to work.

1. What a cookie is here

A cookie is a small value stored by your browser and returned to us on your next request. Bayzo uses them for three jobs only: keeping you signed in, stopping abuse, and remembering three choices you made. We also read a small amount of local storage in the installed app for the same preference purposes.

2. The cookies we set

bayzo_session — signed proof that you are signed in, and as whom. Set when you complete sign-in, removed when you sign out. Lasts 30 days. Strictly necessary; without it, every page would forget you.

bayzo_csrf — an anti-forgery token, checked on every form submission and action so that another site cannot make your browser act on your behalf. Lasts as long as your session. Strictly necessary and a security control.

bayzo_anon — a signed random identifier for a visitor who is not signed in. It carries no personal data and is not linked to an account; it exists so that rate limits, saved-listing state and contact-event counting work for a signed-out visitor. Lasts 12 months. Necessary for abuse prevention.

bayzo_location — the governorate you selected in the location control, so that results are scoped where you left them. It is a place name, not a coordinate, and it is never derived from GPS. Lasts 12 months. A preference.

bayzo_currency — the currency you chose to see prices in. Lasts 12 months. A preference.

Language is not a cookie. It is in the address of every page — /ar/… or /en/… — so the page you are on says which language it is in, and a link you share opens in the language you were reading. When you arrive without a language in the address we choose one from your browser's own language setting for that request only, and store nothing.

One further cookie, bayzo_impersonator, exists only inside our staff console and is set only when a support administrator is acting on an account with authorisation. It is never set on a normal visit, and its presence is recorded in our audit trail.

3. What we do not set

  • No advertising or retargeting cookies.
  • No third-party analytics cookies. Usage measurement is first-party and server-side; it does not set a cookie of its own beyond bayzo_anon.
  • No social media pixels or share-button trackers.
  • No cross-site identifiers, fingerprinting, or data sold to anyone.

Our own analytics is described in section 2 of the Privacy Policy.

4. Third parties you may still meet

Two things on Bayzo take you somewhere else, and what happens there is governed by that service:

  • WhatsApp, when you tap a contact button. Meta's terms and privacy policy apply from that point.
  • Google Play, if you installed the Android app. Google's own policies apply to the store and to push delivery.

Neither can read the cookies listed above; they are ours and are scoped to our domain.

5. Controlling them

You can delete cookies and block them in your browser settings, and you can clear the app's storage in your device settings. Blocking bayzo_session and bayzo_csrf will sign you out and prevent you from publishing, saving or reporting anything — those two are what make an authenticated action possible at all. Blocking the two preference cookies costs you nothing but the preference: Bayzo will simply open scoped to all of Syria, in the default currency, each time.

Nothing on Bayzo requires you to accept a cookie in order to browse.

6. Changes

If we add a cookie, it is listed here before it is set, and the effective date at the top of the page changes. If we ever add a category that requires consent — we have no plan to — it will be opt-in, not a banner that assumes agreement.

Write to the legal mailbox and a person will answer.