We set a small number of cookies. Only the strictly necessary ones are set before you choose; everything else waits for your consent and nothing is loaded until you give it. This page says exactly what each one is for and how to change your mind.
A small file a website stores on your device to remember something — that you are signed in, which language you chose, that you already answered the cookie question.
We also use local storage, which works differently under the bonnet but does the same job from your point of view, so we treat it the same way and describe it here too.
On your first visit you get two buttons of equal weight: accept all, or essential only. Neither is pre-selected, neither is hidden behind a settings menu, and “essential only” is one click, not five.
Until you choose, no analytics or marketing script is loaded at all — not loaded and blocked, but never fetched. We record your answer so we do not ask again on every visit, including when the answer is no.
Set always, because the site cannot work without them. They keep your session, remember your language, record your cookie decision, and protect forms against abuse.
These do not require consent under UAE or EU rules because you cannot have the service without them. They expire within 12 months.
Set with your consent. They remember choices like the city you nominated or a message you dismissed, so you are not asked the same thing twice. Declining them costs you a little repetition and nothing else.
Set with your consent only. We use Google Analytics with IP anonymisation and advertising signals turned off, and PostHog on its EU host with session recording and autocapture disabled.
They tell us, in aggregate, which pages get read and where people stop — so we can fix what is confusing. We do not use them to identify you, and we do not watch individual sessions.
Set with your consent only. They let us tell whether an advert led to a reservation. Choose essential only and none are set, no advertising identifier is shared, and nothing about your visit leaves this site.
Stripe sets cookies on the checkout page to process your payment and detect fraud. These are strictly necessary for that transaction and are governed by Stripe’s own policy.
If you accept analytics, Google and PostHog set theirs under their own policies. We have configured both to collect as little as the measurement needs.
Session cookies go when you close the browser. The rest expire within 12 months, and your consent choice is re-asked after that in any case, so a decision you made a year ago is never assumed to still hold.
Clear this site’s data in your browser and the notice will appear again on your next visit, letting you answer differently. You can also block or delete cookies in your browser settings, though the strictly necessary ones going missing will make parts of the site behave oddly.
Withdrawing consent is as easy as giving it, which is the standard we hold ourselves to.
We honour Global Privacy Control where your browser sends it: it is treated as a refusal of analytics and marketing cookies, and you will not be asked again during that session.
If we add a cookie that needs consent, we will ask again rather than rely on an answer you gave about a different set. The date at the top shows the version you are reading.
privacy@hileila.com, or write to us at Office A, Innovation Business Center, RAK BANK ROC Office, Ground Floor, Al Rifaa, Sheikh Mohammed Bin Zayed Road, Ras Al Khaimah, United Arab Emirates. A person answers.