Cookie Policy
Last updated: August 1, 2026
What cookies Meeti Me sets, why, how long they last, and how to refuse or withdraw your consent at any time.
Table of Contents
1. What cookies are
A cookie is a small text file that a website asks your browser to store on your device. When you come back, the browser sends the file back, so the site can recognise your session, remember a choice you made, or count a page view.
Cookies are not the only technology of this kind. This policy uses the word "cookies" as a shorthand for all of them, including:
- Local storage and session storage, which hold data in your browser in much the same way as a cookie but are not automatically sent with every request;
- Software development kits and device identifiers used by our mobile applications, which perform the same functions as cookies do on the web;
- Pixels and web beacons, which are tiny transparent images used to record that a page or an email was opened.
A cookie can be a first party cookie, set by meeti.me itself, or a third party cookie, set by another domain whose content is loaded on our page. A cookie can be a session cookie, deleted when you close the browser, or a persistent cookie, which survives until it expires or you delete it.
Cookies cannot read other files on your device, they cannot run programs, and they do not carry viruses.
This policy forms part of our Privacy Policy and uses the same definitions. The Privacy Policy explains the wider picture: what personal information we collect, why, who processes it, and the fact that it is stored and processed outside Canada, in the European Union and the European Economic Area. Please read the two together.
2. How we use cookies and the consent model
Canadian law does not have a single dedicated cookie statute. PIPEDA and, for residents of Quebec, Law 25 require that we obtain meaningful consent for the collection and use of personal information, and that consent be express where the information is sensitive or where the person would not reasonably expect the use. This is how we apply that.
Strictly necessary cookies: no consent is sought, because none is required. These cookies exist only to deliver the service you asked for. Without them you cannot sign in, stay signed in, submit a booking, or pay. They collect nothing beyond what is needed for that function, and we do not use them to observe you. Refusing them is not possible while using the Platform, because they *are* the Platform.
Preference cookies: implied consent through your own action. When you choose a language or a region, we remember it. You asked for that.
Analytics cookies: implied consent, with a clear and easy opt out. We use one analytics tool, PostHog, hosted in the European Union. It tells us which features people use and where they get stuck. It does not build advertising profiles and it is not shared with any advertising network. Because the information is not sensitive, because the use is limited to improving our own product, and because we give you a prominent and continuously available way to say no, we rely on implied consent for analytics. Section 6 tells you exactly how to opt out, in one click, at any time.
Marketing cookies: express consent, opt in, or nothing. We would never set a marketing or advertising cookie without your prior express consent, given by an affirmative act. Today the question is academic: we do not use any marketing, advertising or cross site tracking cookies at all. We have not installed Google Analytics, Google Ads, the Meta or Facebook Pixel, or any similar advertising technology, and we do not participate in any advertising network. If that ever changes we will ask you first, through an opt in banner, and we will update this policy under section 8.
Our banner. The first time you visit, a banner tells you which categories we use and lets you accept or refuse the non essential ones before they are set. Refusing is exactly as easy as accepting: the two options carry equal prominence, and there is no dark pattern, no pre ticked box, and no penalty for saying no. Your choice is recorded in the `cookie-consent` cookie described below, and you can change it whenever you like.
3. The cookies we actually use
This is the complete list. It is not a template.
3.1 Strictly necessary
| Name | Set by | Purpose | Type | Retention | | --- | --- | --- | --- | --- | | `accessToken` | meeti.me (first party) | Holds the short lived token that authenticates each request once you have signed in. Without it you would have to re-enter your password on every page | HTTP cookie, HttpOnly, Secure, SameSite=Lax | 15 minutes from issue | | `refreshToken` | meeti.me (first party) | Lets us issue a new `accessToken` without asking you to sign in again, so your session survives a reload. Bound to the device and revoked when you sign out | HTTP cookie, HttpOnly, Secure, SameSite=Strict | 30 days, or until you sign out | | `cookie-consent` | meeti.me (first party) | Records which categories you accepted or refused, and the date and version of the banner you saw. This is the cookie that lets us honour a refusal. It is strictly necessary in the sense that we cannot respect your choice without remembering it | HTTP cookie, Secure, SameSite=Lax | 12 months, after which we ask you again |
3.2 Functional and preference
| Name | Set by | Purpose | Type | Retention | | --- | --- | --- | --- | --- | | `auth-hint` | meeti.me (first party) | A non sensitive flag telling the interface that a session probably exists on this device, so we can show the right screen immediately instead of flashing the signed out view. It contains no token and grants no access | HTTP cookie, Secure, SameSite=Lax, readable by the interface | 30 days | | `user-lang` | meeti.me (first party) | Remembers whether you chose English or French, so we do not have to guess from your browser each time | HTTP cookie, Secure, SameSite=Lax | 12 months | | `mp_region` | meeti.me (first party) | Remembers the marketplace region you were browsing, so the search results and the currency stay consistent between visits | HTTP cookie, Secure, SameSite=Lax | 12 months |
3.3 Analytics
| Name | Set by | Purpose | Type | Retention | | --- | --- | --- | --- | --- | | `ph_*` (for example `ph_phc_..._posthog`) | PostHog, EU hosted instance, loaded from our domain | Assigns a pseudonymous identifier so we can count distinct users and follow a journey through the product. See section 4 | First party cookie plus local storage | 12 months; the underlying event data is kept 12 months and then aggregated |
3.4 Payment
| Name | Set by | Purpose | Type | Retention | | --- | --- | --- | --- | --- | | `__stripe_mid`, `__stripe_sid` and related | Stripe (third party), on the checkout and billing pages only | Fraud prevention and payment session integrity. Stripe uses them to detect suspicious payment behaviour and to keep a payment session coherent. See section 5 | Third party cookies | `__stripe_mid`: 12 months. `__stripe_sid`: 30 minutes |
3.5 Marketing and advertising
None. We set no marketing cookies, we allow no advertising network onto the Platform, and we run no cross site tracking. This row exists so that you know the absence is deliberate.
4. PostHog, our analytics provider
PostHog is the only product analytics tool on Meeti Me. It is used to answer questions like "do salons find the calendar settings" and "at which step do people abandon a booking".
- Where it runs. On PostHog's European Union hosted instance. Analytics data is not sent to the United States. As with the rest of our infrastructure, this means the data is processed outside Canada. Section 7 of the Privacy Policy explains what that means for you.
- What it records. A pseudonymous identifier, the pages and screens you viewed, the actions you took such as clicking or submitting a form, the approximate region derived from your IP address, and your browser and device type.
- What it does not do. It does not read your name, your bookings' content or a salon's client notes. We have disabled session recording of form fields. We do not use PostHog for advertising, we do not enrich its data with information bought from third parties, and PostHog is contractually prohibited from using the data for its own purposes.
- How to say no. Section 6. Opting out here does not degrade any feature.
5. Stripe, our payment processor
Stripe processes salon subscription payments in Canadian dollars. Stripe cookies are set only when you are on a checkout or billing page, and they are strictly necessary: without them, Stripe cannot distinguish a legitimate payment from a fraudulent one, and the payment will be declined.
We cannot switch these cookies off and continue to accept payment, and we do not offer a way to refuse them while paying. If you do not wish Stripe cookies to be set, do not use the paid subscription. Stripe acts as an independent controller for fraud prevention and is subject to its own privacy policy, which we encourage you to read.
Note that consumers do not pay us for a booking. Payment for the salon's service is arranged between you and the salon.
6. Managing and withdrawing your consent
You may change your mind at any time, and it costs you nothing.
Through the Platform. Open the Cookie settings link in the footer of meeti.me, on every page. It reopens the banner with your current choices shown. Turn analytics off, save, and the change takes effect immediately: the analytics script stops loading and existing PostHog cookies are cleared on your next page load. In our mobile applications, the same control lives under Settings, then Privacy.
Through your browser. Every major browser lets you block or delete cookies, either generally or site by site, and lets you refuse third party cookies. Look under Settings, then Privacy and security. Deleting cookies for meeti.me clears your choices too, so the banner will greet you again on your next visit.
Through Do Not Track and Global Privacy Control. We honour a Global Privacy Control (GPC) signal from your browser as a valid refusal of analytics, and we treat it as an opt out without requiring you to interact with our banner.
Marketing messages are separate. Cookie settings do not govern email or SMS. To stop commercial electronic messages, use the unsubscribe link in any message or write to meetime.company@gmail.com. See section 5 of our Privacy Policy.
If the controls do not work. If the cookie settings panel will not open or your choice does not appear to be saved, that is a bug and we want to hear about it. Write to meetime.company@gmail.com and we will fix it. Until we do, blocking cookies for meeti.me in your browser achieves the same result.
Questions or complaints. Write to our privacy officer at meetime.company@gmail.com, or to meetime.company@gmail.com. Where a representative has been designated for your region, you may also write to the privacy officer reachable at the address below. If we cannot resolve the matter, you may complain to the Office of the Privacy Commissioner of Canada and, if you reside in Quebec, to the Commission d'accès à l'information du Québec. Full contact details, and any supervisory authority designated for your region at Office of the Privacy Commissioner of Canada; for Quebec residents, the Commission d acces a l information du Quebec, 30 Victoria Street, Gatineau QC K1A 1H3, priv.gc.ca, are set out in section 13 of our Privacy Policy.
7. What happens if you refuse
We want you to be able to weigh the decision, so here is the honest consequence of each choice.
If you refuse analytics cookies, nothing about the Platform changes for you. Every feature works exactly as before, you see no additional prompts, and you are not treated differently in any way. The only effect is on us: we lose a small amount of information about how the product is used, which makes it slightly harder to find and fix rough edges. We accept that trade.
If you refuse or delete preference cookies, the Platform still works, but it forgets you. It may open in the wrong language until you change it again, and the marketplace may default to a region you were not browsing. You will have to re-set those choices on every visit.
If you block strictly necessary cookies, in practice by blocking all cookies for meeti.me in your browser, the Platform will not work. You will not be able to sign in, or you will be signed out on every page. You will not be able to complete a booking or a subscription payment. There is no workaround, because these cookies carry the authentication that protects your account.
If you block Stripe cookies on the checkout page, the payment will most likely be declined by Stripe's fraud systems. This is Stripe's decision, not ours.
What we will never do. We will not deny you access to the marketplace, degrade a feature, charge you a different price, or delay your booking because you refused analytics or preference cookies. Consent that is bought is not consent.
8. Changes to this policy
We may update this policy when we add or remove a cookie, change a provider, change a retention period, or when the law changes.
When we do, we update the version and effective date in the header, and we keep the earlier versions available. If we introduce a new category of cookie, and in particular if we ever introduce marketing or advertising cookies, we will ask for your express consent before setting them and we will reset the consent banner so that your earlier choice is not treated as covering something you never agreed to.
For other material changes we give notice at least 30 days in advance, through a notice in the Platform and, where you hold an account, by email.
The current version of this policy is 2026-08-01, in force from 2026-08-01. It is published by DOKUMENT.PL sp. z o.o., Aleja Stanow Zjednoczonych 51 lok. 222, 04-028 Warszawa, Poland.
---
This Cookie Policy exists in English and in French. The English and French versions are equally authoritative, and neither version prevails over the other.