Cookie Policy
Last updated: August 1, 2026
A list of the cookies and similar technologies used on the Meeti Me platform, together with the prior consent rule, the categories, the retention periods and the way to manage and withdraw consent.
Table of Contents
What cookies are
Cookies are small text files saved on your device by your browser while you use a website. They usually contain the name of the service they come from, a storage period and a unique identifier or another value.
This Policy covers not only cookies in the strict sense but all technologies with a similar effect, consisting in storing information on your terminal equipment or gaining access to information already stored there, in particular:
- browser local storage (localStorage) and session storage (sessionStorage),
- device identifiers in mobile applications,
- pixels and tracking tags in e-mail messages,
- authentication tokens stored in the secure system keystore of the device.
Throughout the rest of this document we refer to all of these technologies collectively as "cookies".
We use cookies in the Meeti Me service, available at meeti.me, and in the related applications. The entity that places cookies and gains access to them is DOKUMENT.PL sp. z o.o., with its registered office at Aleja Stanow Zjednoczonych 51 lok. 222, 04-028 Warszawa, Poland, NIP 5242982251, KRS 0001055336, REGON 526237551.
Cookies used by our providers are described in the tables in the "Cookie categories" section. We divide cookies into first-party cookies (placed in our domain) and third-party cookies (placed in the provider's domain).
The rules for processing personal data that may arise in connection with the use of cookies are described in the Meeti Me Privacy Policy.
Document version: 2026-08-01. Effective from: 2026-08-01.
The prior consent rule
We apply the prior consent rule (prior opt-in), which follows from art. 5(3) of Directive 2002/58/EC (ePrivacy) in conjunction with art. 4(11) and art. 7 GDPR, and from the national provisions applicable under law of Poland.
In practice this means:
- Before consent is given we do not load any cookies other than strictly necessary ones. Until you make your decision in the consent banner we do not run analytics scripts, we do not initialise the PostHog tool and we do not send any product events. Those scripts are loaded only after your consent has been recorded, and only within the scope of the categories you have accepted.
- Consent is voluntary and explicit. It requires an affirmative action, for example clicking the accept button. Continuing to browse the service, scrolling the page or closing the banner does not constitute consent.
- No consent box is pre-ticked. The toggles for categories other than strictly necessary are switched off by default.
- Refusing is as easy as consenting. The banner contains a "Reject all" button with the same visual weight, available in the same step as the "Accept all" button. We do not use mechanisms that make refusal more difficult.
- Consent is granular. You may consent separately for each category other than strictly necessary, using the "Customise settings" option.
- Consent may be withdrawn at any time, as easily as it was given. We describe how in the "Managing and withdrawing consent" section.
- Consent is not indefinite. Consent is valid for 12 months. After that period the banner will be displayed again. We will also ask you again if we add a new cookie category or a new provider.
- Consent is not a condition of using the service. Refusal does not block access to the platform or to the ability to make a booking.
Strictly necessary cookies do not require consent, because they are essential to provide the service explicitly requested by the user. They cannot be switched off in the service settings.
We keep a record of your decision as evidence that consent was given or refused, together with a timestamp, the version of this Policy and the scope of the categories selected.
Cookie categories
We use four cookie categories.
Strictly necessary
Essential for the correct operation of the service, user authentication, session maintenance and security. Without them the service cannot function. They do not require consent.
| Name | Provider | Purpose | Type | Retention period | | --- | --- | --- | --- | --- | | `accessToken` | Meeti Me (first-party) | Access token authenticating the logged-in user on every request to the API | HttpOnly, Secure, SameSite=Lax cookie | 15 minutes | | `refreshToken` | Meeti Me (first-party) | Refresh token allowing the session to be extended without logging in again and the session to be revoked on log-out | HttpOnly, Secure, SameSite=Strict cookie | 30 days | | `auth-hint` | Meeti Me (first-party) | Technical information for the interface that an active session exists in the browser, allowing the correct view to be displayed without a flash of the login screen. Contains no identifying data and no tokens | Cookie, Secure, SameSite=Lax | 30 days | | `cookie-consent` | Meeti Me (first-party) | A record of your cookie consent decision: the scope of the accepted categories, a timestamp and the Policy version. Necessary in order to respect your choice and as evidence of consent | Cookie, Secure, SameSite=Lax | 12 months | | `__stripe_mid`, `__stripe_sid` | Stripe | Payment fraud detection and transaction security in the salon subscription payment process. Set only on pages containing the payment form | Third-party cookie | `__stripe_mid` 12 months, `__stripe_sid` 30 minutes |
Functional
They remember your preferences and improve the way you use the service. Loaded only after consent to this category has been given.
| Name | Provider | Purpose | Type | Retention period | | --- | --- | --- | --- | --- | | `user-lang` | Meeti Me (first-party) | Remembering the selected interface language so that it does not have to be set again on every visit | Cookie, Secure, SameSite=Lax | 12 months | | `mp_region` | Meeti Me (first-party) | Remembering the selected marketplace region, which determines the list of salons presented, the currency and the applicable version of the legal documents | Cookie, Secure, SameSite=Lax | 12 months |
If you do not consent to functional cookies, the language and region will be determined from your browser settings for the current session and will not be remembered for the next visit.
Analytics
They allow us to understand how users use the platform, which features cause difficulty and where errors occur. Loaded only after consent to this category has been given. Until consent is given, the PostHog script is not downloaded or initialised at all.
| Name | Provider | Purpose | Type | Retention period | | --- | --- | --- | --- | --- | | `ph_phc_*` | PostHog | The main product analytics file. It stores a pseudonymised device identifier and a session identifier, allowing unique users to be counted and in-product journeys to be analysed | Third-party cookie, hosted in the European Union | 12 months | | `ph_opt_out` | PostHog | A record of opting out of analytics, thanks to which the tool does not collect events after consent has been withdrawn | Third-party cookie | 12 months |
PostHog analytics runs on infrastructure hosted within the territory of the European Union. The IP address is truncated and events are linked to a pseudonymised identifier, not to your name, e-mail address or telephone number. We do not use analytics data for advertising profiling and we do not transfer it to advertising networks.
Marketing
These would serve to run advertising activities, measure campaign effectiveness and personalise advertising messages.
We currently do not use any cookies in the marketing category. The Meeti Me platform has no Google Analytics, Google Ads, Facebook Pixel or any other third-party advertising tools installed. The category remains in the consent banner in order to preserve transparency should it be introduced in the future. If such tools are ever deployed, we will update this Policy and ask you for consent again before they are launched.
Cookies in mobile applications
In the Meeti Me mobile applications we do not use cookies in the browser sense. Authentication tokens are stored in the secure system keystore of the device, and language and region preferences in the local application storage. Their function and retention periods correspond to the strictly necessary and functional cookies described above.
Product analytics in the mobile applications is started only after consent has been given on the application's privacy settings screen. We do not use advertising device identifiers (IDFA, GAID) and we do not use cross-app tracking.
Managing and withdrawing consent
You may withdraw or change your consent at any time, as easily as it was given. This does not require contacting us, giving reasons or any additional step.
On the website. Click the "Cookie settings" link permanently available in the footer of every meeti.me page. The same choice window you saw on your first visit will open, showing the current state of your consents. You may switch on or off each category other than strictly necessary, or withdraw all consents with a single click. The change takes effect immediately: the scripts corresponding to the withdrawn categories stop running and the related cookies are deleted.
In the mobile application. Go to Settings, then Privacy, and change the analytics settings.
In your browser. You may also delete the stored cookies yourself or block them from being saved in your browser settings. You will find the relevant instructions in your browser's documentation, usually in the section on privacy and site data. Please note that deleting the `cookie-consent` file will cause the banner to be displayed again on your next visit, because we will have lost the information about your earlier decision.
Global signals. We honour the Global Privacy Control (GPC) signal sent by the browser. We treat its presence as the absence of consent to categories other than strictly necessary.
Contact. If you encounter a problem withdrawing consent, write to meetime.company@gmail.com. For technical matters concerning the operation of the service, meetime.company@gmail.com will help. If we have appointed a data protection officer, you may contact them at meetime.company@gmail.com.
Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
Consequences of refusing or withdrawing consent
Refusing consent to cookies other than strictly necessary does not limit access to the platform. You can still browse salon offers, create an account, log in, make a booking, manage appointments and use the salon account and pay for the subscription.
The consequences are as follows:
- No consent to functional cookies. The selected language and region will not be remembered between visits. On each visit the settings will be determined from your browser configuration, which may mean having to select them again. If you are logged in, the preferences saved in your account profile will still be applied, because we store them server-side as part of performance of the contract.
- No consent to analytics cookies. We do not collect data on how the service is used. This does not affect any feature available to the user. It does however mean that we detect errors and usability problems more slowly.
- No consent to marketing cookies. Currently without effect, because we do not use such files.
- Blocking strictly necessary cookies in your browser settings. This will make it impossible to log in and maintain a session, and the subscription payment process may not work correctly. This is not, however, a result of our settings but of your browser configuration.
We do not use so-called cookie walls. Access to the content of the service is not conditional on consent to cookies other than strictly necessary.
Legal basis and your rights
The legal basis for storing and reading cookies other than strictly necessary is your consent, that is art. 6(1)(a) GDPR in conjunction with art. 5(3) of Directive 2002/58/EC.
The legal basis for the use of strictly necessary cookies is the performance of the contract for the provision of services by electronic means (art. 6(1)(b) GDPR) and our legitimate interest in ensuring the security of the platform (art. 6(1)(f) GDPR). Strictly necessary cookies are exempt from the consent requirement under art. 5(3) of Directive 2002/58/EC.
In relation to the personal data arising in connection with cookies, you have all the rights described in the Privacy Policy, including the right of access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent.
You also have the right to lodge a complaint with the supervisory authority competent for your region:
- Supervisory authority: Prezes Urzedu Ochrony Danych Osobowych (UODO)
- Address: ul. Stawki 2, 00-193 Warszawa, Poland
- Website: uodo.gov.pl
The courts competent in matters covered by this Policy are courts competent for the seat of the operator, without prejudice to the consumer right to sue at their place of residence, provided that you may also pursue your rights before the court of the Member State of your habitual residence.
Changes to the Cookie Policy
We may update this Policy in connection with technical changes in the service, the addition or removal of a provider or a change in the law.
If a change consists in the introduction of a new cookie category, a new provider or a new processing purpose, we will ask you to give consent again before such files are launched. Existing consent does not extend to new purposes or to new providers.
We will give notice of material changes at least 14 days in advance by means of a message in the service, and to users holding an account also by e-mail. Housekeeping and editorial changes are published without prior notice.
The current version of the Policy is always available at meeti.me and is marked with the number 2026-08-01 and the effective date 2026-08-01. We make previous versions available on request sent to meetime.company@gmail.com.
Binding version
This document has been drawn up in the following language versions: Polish (pl), English (en) and Ukrainian (uk).
For the PL (Poland) region, the Polish (pl) language version of this document is binding. For the EU (other states of the European Economic Area) region, the English (en) language version is binding. The Ukrainian (uk) version is for information and convenience only. In the event of any discrepancy, the version binding for the given region prevails.