Skip to main content

Cookie Policy

Version 1.3 (2026-06)

What cookies and local storage are

Cookies are small text files that a website asks your browser to store on your device. They can serve useful purposes — such as remembering a setting between visits — but they can also be used to track people across the web. Local storage is a similar browser feature: a small space where a website can keep information on your device, except that it is never sent automatically with your requests.

This policy explains, in plain language, exactly what Goava ("we") stores in your browser when you visit goava.sa — and, just as importantly, what we do not.

We set no tracking cookies — the full inventory

We do not use advertising cookies, third-party tracking cookies, cross-site identifiers, browser fingerprinting, or any cookie that builds a profile of you. The complete and honest inventory of everything this website may store in your browser is the following:

NEXT_LOCALE — a functional cookie that remembers the selected site language (Arabic or English) so the site opens with the same selection on the next visit. It contains the language selection and nothing else.

payload-token — a session cookie used solely by Goava staff to sign in to the website's content administration area. It is HTTP-only, meaning scripts running in the page cannot read it. If you are not a member of our team and never sign in to the administration area, this cookie is never set in your browser.

umami.disabled — an optional flag stored in your browser's localStorage (not a cookie) that you can set yourself to switch off our anonymous analytics (see sections 3 and 4). We never set it for you; we only honour it if you do.

That is the entire list. This website stores nothing else in your browser.

Analytics without cookies

To understand how the site is used in aggregate — which pages are viewed and where visitors come from — we run a self-hosted analytics service on our own infrastructure. It is anonymous by design: it sets no cookies and stores no identifiers on your device.

Instead of an identifier, it computes a temporary, salted hash, and the salt rotates every day. Because the salt changes daily, the same visitor produces a different hash from one day to the next, so the system cannot identify you and cannot link your visits across days. What we see is aggregate page statistics only — never personal profiles — and this data is never shared with or sold to third parties.

How to opt out anyway

Even though our analytics cannot identify you, you may prefer that nothing be recorded at all. To opt out, set the umami.disabled flag in your browser's localStorage while on goava.sa. In most browsers: open the developer console and run localStorage.setItem("umami.disabled", "1"). From that moment on, your browser sends no analytics events to us.

To opt back in, remove the flag by running localStorage.removeItem("umami.disabled"). Clearing your browser data will also remove the flag.

If we ever add cookies

We have no plans to introduce tracking or marketing cookies. If that ever changes — for example, if a future feature genuinely requires a non-essential cookie — we will update this policy first and ask for your permission through a clear consent banner before any non-essential cookie is set. Until you agree, no such cookie will be placed, and simply continuing to browse will never be treated as consent.

Questions about this policy can be sent to us through the contact page on this website.