COOKIE POLICY

ALLINDUBAI LEGAL

COOKIE POLICY

Website Tracking & Consent Master

Legal entity

All In Concierge Services FZE LLC

Licence No.

2621219432888

Registered address

CWS-1V-228138, 26th Floor, Amber Gem Tower, Ajman, UAE

Website

https://allindubai.net/

Effective date

September 2026


IMPORTANT

This master policy is intentionally technology-neutral. Before publication, the developer must inventory the actual cookies, SDKs, pixels, analytics and advertising tools used on AllInDubai.net and update the cookie table and consent configuration accordingly. Non-essential tracking must not be enabled merely because it is mentioned in this draft.

 

PLEASE READ THIS COOKIE POLICY TOGETHER WITH OUR PRIVACY POLICY. This Policy explains how AllInDubai may use cookies and similar technologies on AllInDubai.net and how visitors can control non-essential technologies where applicable.

1. Who We Are

AllInDubai is operated by All In Concierge Services FZE LLC ("AllInDubai", "we", "us" or "our"). This Cookie Policy applies to https://allindubai.net/ and related customer-facing web pages operated by us.

2. What Are Cookies and Similar Technologies?

Cookies are small data files stored on or accessed from a user's browser or device. Similar technologies may include local storage, pixels, tags, SDKs, identifiers and server-side event technologies. They can support core Website functions, remember preferences, measure Website usage, improve security, or support advertising and remarketing.

Not every technology described in this Policy will necessarily be active on the Website. The technologies actually used may change as the Website and its vendors change.

3. Our Cookie Categories

3.1 Strictly Necessary Cookies

These technologies are required for core Website operation, security, fraud prevention, session management, load balancing, booking flows, payment handoff, consent storage or other functions that cannot reasonably be provided without them. Where applicable law permits, these may operate without optional marketing consent.

3.2 Preference / Functional Cookies

These may remember language, region, interface choices or other optional preferences so the Website can provide a more convenient experience.

3.3 Analytics / Performance Cookies

These may help us understand how visitors use the Website, which pages are visited, where traffic comes from, whether errors occur and how Website performance can be improved. Where consent is required, these technologies will remain disabled until the relevant consent is obtained.

3.4 Advertising / Remarketing Cookies and Pixels

If enabled, advertising technologies may help measure campaigns, build audiences, limit repeated advertising or show more relevant advertising on third-party platforms. Where applicable law requires consent, these technologies will not be activated until the visitor has made the relevant choice.

3.5 Third-Party Embedded Content

Maps, video players, social-media embeds, chat tools or other third-party features may place or access technologies when loaded. Where practical and legally required, optional embedded technologies should be blocked until the relevant consent category is enabled.

4. Consent and Your Choices

Where AllInDubai relies on consent for non-essential cookies or similar technologies, the Website will seek a clear user choice before activating those technologies. A visitor should be able to accept available optional categories, reject non-essential technologies, or manage preferences through the cookie interface.

A user's refusal of non-essential cookies should not prevent access to ordinary Website content or booking functionality except where a particular optional feature genuinely depends on the relevant technology.

Where consent is the legal basis, AllInDubai should be able to demonstrate the consent choice and provide a practical way to withdraw or change it. Withdrawal should be respected for future optional processing.

5. Cookie Preference Centre

Where implemented, the Website's Cookie Settings or preference centre allows visitors to review and change available cookie categories. Strictly necessary technologies may be shown as always active where they are genuinely necessary.

Changing preferences does not necessarily delete cookies already stored on the device. Visitors may also use browser controls to delete stored cookies, although deleting strictly necessary cookies may affect Website functionality.

6. Browser Controls and Do-Not-Track Signals

Most browsers allow users to block, restrict or delete cookies. Browser settings vary by provider and device. Blocking all cookies may cause parts of the Website, including security or booking functions, to operate incorrectly.

Where legally or technically required, AllInDubai will assess recognized browser or platform privacy signals and update its practices as applicable.

7. Third-Party Technologies

If AllInDubai uses third-party analytics, advertising, payment, communications, maps, video or social-media technologies, those providers may process data under their own privacy terms. The Website should disclose the relevant active vendors in the cookie preference interface or cookie inventory where appropriate.

The presence of a vendor in an internal implementation plan does not authorize that vendor to be activated without the necessary technical and legal review.

8. Data Generated Through Cookies

Depending on the technology, cookie-related data may include IP address, browser/device information, identifiers, page views, clicks, referring source, approximate location derived from IP, session timestamps, campaign parameters and conversion events.

AllInDubai should avoid sending directly identifying or sensitive customer information to analytics or advertising tools unless there is a clear lawful purpose, appropriate configuration and any required consent.

9. Retention

Cookie duration varies by purpose and provider. Session cookies may expire when the browser session ends, while persistent cookies may remain for a defined period. AllInDubai will seek to avoid retaining cookie-derived data longer than reasonably necessary for the relevant purpose and legal requirements.

The live cookie preference interface should state or link to the actual duration of active cookies where reasonably practicable.

10. International Processing

Some technology vendors may process cookie-related data outside the UAE. Any cross-border processing must be addressed consistently with the AllInDubai Privacy Policy and applicable UAE data-protection requirements.

11. Updates to This Policy

We may update this Cookie Policy when our Website, vendors, legal requirements or tracking technologies change. The current version and effective date will be published on the Website. If a change materially affects consent choices, the Website should request a fresh choice where required.

12. Contact

Questions concerning cookies or privacy may be submitted through the current privacy/customer-support contact details published on AllInDubai.net. Before launch, AllInDubai should designate and publish an active privacy contact channel.

Last updated: September 2026.

 

INTERNAL - DEVELOPER IMPLEMENTATION INSTRUCTIONS

NOT FOR PUBLICATION ON THE CUSTOMER-FACING COOKIE POLICY PAGE

A. Before Any Tracking Goes Live

• Create a complete inventory of every cookie, pixel, SDK, tag, local-storage key and server-side marketing event actually used on the production Website. Record vendor, purpose, category, domain, duration and whether data leaves the UAE.

• Do not copy a generic cookie list from another Website. The published list must reflect AllInDubai's actual production configuration.

• Classify each technology as Strictly Necessary, Functional/Preferences, Analytics/Performance, or Advertising/Remarketing. If a tool is not necessary for core booking/security, default to treating it as optional until reviewed.

• Confirm the final stack before launch: CMS, hosting/CDN, payment processor, chat/WhatsApp widget, Google services, Meta services, maps, video embeds, CRM forms and any booking plugins.

B. Consent Banner - Required Behaviour

• On a visitor's first relevant visit, show a clear cookie banner before non-essential tags fire.

• Banner must provide equally understandable choices to Accept optional cookies, Reject non-essential cookies, and Manage/Customize preferences. Do not make rejection materially harder than acceptance.

• Do not use pre-ticked optional categories. Strictly Necessary may be locked on only where genuinely necessary.

• Do not fire Analytics, Meta Pixel, Google Ads/remarketing, TikTok or other optional advertising/measurement tags before the relevant consent category is granted where consent is required.

• Do not treat scrolling, inactivity or continued browsing as affirmative consent where affirmative consent is required.

• After a user changes or withdraws consent, stop future optional tag firing for the affected categories.

C. Consent Evidence

• Store a consent record containing: anonymous/appropriate visitor identifier, timestamp, consent categories, banner/policy version, locale, and source/page where the choice was made.

• Do not store more personal data than necessary merely to prove cookie consent.

• Version the cookie configuration so AllInDubai can show what choices and vendors existed when consent was recorded.

• Define a reasonable re-consent trigger when the vendor list or purposes materially change.

D. Cookie Settings Control

• Add a permanent 'Cookie Settings' or equivalent control in the Website footer so visitors can reopen preferences at any time.

• Also link 'Cookie Policy' and 'Privacy Policy' from the footer.

• Preference centre must clearly separate categories and explain each category in plain language.

• Changing preferences must update the consent platform and tag manager immediately for future page loads/events.

E. Google / Meta / Advertising Implementation

• If Google Analytics, Google Ads, Meta Pixel, Conversion API or similar tools are used, map each tag/event to the correct consent category before launch.

• Do not send passport details, Emirates ID, health information, children's data, full phone numbers, email addresses or other sensitive/direct identifiers in analytics event names, URLs, custom dimensions or advertising parameters unless specifically reviewed and lawful.

• Audit URLs so query parameters do not leak names, email, phone, booking notes or payment information into analytics/referrer logs.

• For server-side conversion APIs, consent rules must also be enforced server-side; blocking only the browser pixel is not sufficient if the server still sends the event.

F. Third-Party Embeds

• Review Google Maps, YouTube/Vimeo, Instagram/TikTok embeds, live chat and similar widgets for tracking behaviour.

• Where optional consent is required, use a blocked placeholder until the visitor enables the relevant category.

• Do not allow embedded vendors to bypass the site's consent state through custom scripts.

G. Payments and Essential Technologies

• Payment security/session cookies may be treated as necessary only where genuinely required to complete or protect the transaction.

• Do not load advertising trackers inside sensitive payment or identity-document pages unless specifically justified and lawfully configured.

• Never put card data, CVV, passport numbers or sensitive booking notes into cookies or browser local storage.

H. Testing Before Launch

• Test in a clean browser: before consent, after Reject All, after Analytics only, after Advertising consent, and after consent withdrawal.

• Use browser developer tools/tag diagnostics to confirm optional network requests do not occur before the corresponding consent.

• Test desktop and mobile, logged-in/logged-out flows, landing pages, booking pages, payment handoff, confirmation pages and embedded widgets.

• Retest after every major plugin, tag-manager, marketing or Website update.

I. Publication Checklist

• Replace any generic descriptions with the actual active cookie/vendor inventory before public launch.

• Insert the real privacy/support contact details once created.

• Keep the public Cookie Policy synchronized with the live consent platform and Privacy Policy.

• Have UAE-qualified counsel review the final production setup, particularly if extensive advertising profiling, cross-border transfers, sensitive data or new tracking technologies are introduced.

J. Legal Framework Considered

This draft was prepared with reference to the UAE personal-data protection framework, including Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data. In particular, where processing relies on consent, the controller must be able to prove that consent and consent must be clear, simple, unambiguous and easily accessible. The final technical implementation must be reviewed against the actual technologies and processing activities in production.