Cookie Policy
Version 2026-09-29
Draft for legal review. This text has not yet been reviewed by a UAE lawyer and may change.
We use only the cookies and browser storage needed to run the site securely. We do not use advertising or tracking cookies. If we ever add optional analytics or marketing cookies, they will only be set after you allow them in the cookie settings, which you can change at any time from the footer.
What we use
| Name | Purpose | Duration | Category |
|---|---|---|---|
__Host-mersy_session | Keeps you signed in (secure, HttpOnly — not readable by scripts) | Up to 30 days (12 hours for administrators) | Strictly necessary |
__Host-mersy_mfa | Remembers a sign-in waiting for two-step verification | 10 minutes | Strictly necessary |
__Host-mersy_csrf | Protects forms against cross-site request forgery | 7 days | Strictly necessary |
__Host-mersy_did | Random device identifier used for security and to prevent referral fraud | 12 months | Strictly necessary |
__Host-mersy_consent | Remembers your cookie choices | 6 months | Strictly necessary |
NEXT_LOCALE | Remembers your language | Session | Strictly necessary |
mersy_cart (local storage) | Keeps the contents of your bag on this device | Until you clear it | Strictly necessary |
When the security check (Cloudflare Turnstile) is shown on sign-up or sign-in, Cloudflare processes technical data to tell people from bots. It is strictly necessary for security and is covered by Cloudflare’s privacy policy.
When you pay, you are taken to our payment provider’s page, which sets its own cookies under its own policy.
Your choices
Strictly necessary cookies cannot be switched off in our settings because the site would not work securely without them. You can block or delete cookies in your browser, but you will not be able to sign in or check out.