Cookie policy.
Sabee uses a small, clearly defined set of cookies — strictly necessary ones on the marketing site, and a few more once you sign in to the platform. This policy explains what they are, exactly which ones we set, why, and how you can control them. Last updated 15 May 2026.
On this page
1. What is a cookie
A cookie is a small text file that a website places on your device — computer, tablet or phone — when you visit. Cookies let a website recognise your device across pages and visits, remember your preferences, and maintain a logged-in session. Similar technologies include local storage, session storage and, in a small number of cases, pixel-based confirmation of email delivery; Sabee uses each of these for the same narrow, functional purposes described in this policy, and treats them under the same rules as a cookie for the purposes of this document. This policy covers both sabee.esesun.com, our public marketing site, and app.sabee.esesun.com, the platform you use once you have an account.
Cookies are generally described as either "session" cookies, which are deleted automatically when you close your browser, or "persistent" cookies, which remain on your device for a defined period so that a site can recognise you on a return visit. They are also described by who sets them: "first-party" cookies are set by the site you are visiting (in this case, Sabee), while "third-party" cookies are set by a domain other than the one you are visiting, typically because that page embeds content or a script from another provider. As explained in Section 4, Sabee's use of genuine third-party cookies is limited to a small number of specific, disclosed cases inside the platform, and none appear on the public marketing site.
2. Cookies on the marketing site
sabee.esesun.com sets only strictly necessary cookies. None of them are used for advertising, cross-site tracking or profiling. The table below lists every cookie the marketing site sets.
| Cookie | Purpose | Duration | Category |
|---|---|---|---|
| sb_session | Maintains your session while browsing the marketing site, including form progress on multi-step pages such as the access request form | Session (deleted on browser close) | Strictly necessary |
| sb_prefs | Stores minor UI preferences such as a dismissed banner or expanded FAQ item | 12 months | Strictly necessary |
| csrf-token | Prevents cross-site request forgery when you submit the contact or access-request form | Session | Strictly necessary |
| sb-locale | Remembers your selected language if you change it from the browser default | 12 months | Strictly necessary |
| sb-theme | Remembers your selected colour theme, light or dark | 12 months | Strictly necessary |
We do not set marketing cookies, advertising cookies, retargeting pixels or third-party analytics cookies on sabee.esesun.com. We do not embed Facebook, LinkedIn, TikTok, Google Ads or any comparable third-party tracking pixel. Because every cookie above is strictly necessary for the site to function, no consent banner is required and none is shown; you can still control or delete these cookies at any time using your browser settings, described in Section 6.
We deliberately keep the marketing site's cookie footprint this small because most of what a marketing cookie would normally be used for — remembering that you asked a sales question, or which page you looked at last — is not something we think is worth the privacy trade-off for a page whose only job is to explain the product and let you request access. If a future feature genuinely requires a new cookie category (for example, a comparison tool that remembers which competitor you are comparing against), we will update this table, bump the version number in Section 9, and, if the new cookie is not strictly necessary, add a consent mechanism before it is set — something we do not currently need because nothing on this list falls outside that category today.
3. Cookies inside the platform
Once you sign in at app.sabee.esesun.com, the Platform sets additional cookies required for authentication, security and application state. These are covered by your acceptance of the Terms of Service at sign-in, and every one of them is strictly necessary for the Platform to operate — none are used for advertising. The table below sets out the categories used inside the app.
| Category | Example cookie | Purpose | Duration |
|---|---|---|---|
| Session | sb_app_session | Keeps you signed in and associates requests with your user account and tenant | 8 hours idle timeout, 30 days with "remember this device" |
| Security | sb_mfa_verified | Records that multi-factor authentication has been completed for the current session | Session |
| XSRF protection | sb_xsrf | Cross-site request forgery token validated on every state-changing request | Session |
| Feature flags | sb_flags | Stores which beta or staged features are enabled for your tenant so the UI renders consistently | 30 days |
| Workspace preference | sb_last_property | Remembers the last property selected in a multi-property tenant | 90 days |
These platform cookies exist to let the application function correctly for a signed-in user working across dozens of screens in a single day — a front-desk shift, for instance, might touch the booking calendar, the folio view, the housekeeping board and the messaging inbox without ever needing to log in again. None of the cookies in this table are configurable on or off individually, because each one supports a function (staying signed in, confirming your device passed multi-factor authentication, protecting a form submission from forgery) that the platform cannot safely operate without.
4. Third-party services
No third-party cookies are set on the marketing site. Inside the Platform, two categories of third-party service may set their own cookies, strictly to deliver a feature you use directly: (a) the Stripe-hosted iframe used when you enter or update a payment method, which sets its own cookies under Stripe's privacy policy to secure the payment flow; and (b) optional Datadog Real User Monitoring, which a customer administrator may enable in account settings to help our support team diagnose performance issues reported by that tenant. Datadog RUM is off by default and can be disabled at any time from the tenant's admin settings.
We deliberately keep this list short. Sabee does not embed a live chat widget, a marketing automation snippet, or a session-replay tool inside the authenticated platform, because those categories of tool typically set their own tracking cookies and we have not found a case where the benefit outweighs adding another party with access to screens that may show guest personal data. If we ever do add a new embedded third-party tool to the platform, we will update this section, extend the Data Processing Addendum's sub-processor annex if the tool would process personal data, and give customers the standard 30-day notice described there before it goes live for any tenant.
5. First-party analytics
On the marketing site we use Fathom Analytics, a privacy-respecting analytics service that operates without cookies and without collecting personal data, recording only aggregated, anonymised metrics such as page views, referrer domains and country-level location derived from IP address, with the IP address itself never stored. Because this analytics method does not use cookies or process personal data, no consent is required under GDPR or the ePrivacy Directive. We do not run Google Analytics, Adobe Analytics, Mixpanel, Amplitude, Hotjar or any comparable cookie-based analytics tool on the marketing site.
Fathom's aggregation happens server-side before any data reaches our dashboards: individual visits are counted and then discarded, so we can see that a page received a certain number of views from a certain country in a given hour, but we cannot reconstruct an individual visitor's path through the site, replay their session, or connect a visit to a specific person. This is a deliberate architectural choice, not a configuration setting we could turn off — Sabee's own product decisions are informed by aggregate trends (which pages get read before someone requests access, for example) rather than by tracking any single visitor.
6. Browser controls
Every modern browser lets you view, delete or block cookies, and most let you set exceptions per site. In Chrome, open Settings → Privacy and security → Cookies and other site data. In Firefox, open Settings → Privacy & Security → Cookies and Site Data. In Safari, open Preferences → Privacy → Manage Website Data. In Edge, open Settings → Cookies and site permissions → Manage and delete cookies and site data. If you block cookies on sabee.esesun.com, the marketing site will still load, but your language and theme preferences will not persist between visits, and the access-request and contact forms may not submit correctly because the CSRF token cannot be set. If you block cookies on app.sabee.esesun.com, you will not be able to remain signed in, since the session cookie is required for authentication.
7. Do Not Track and Global Privacy Control
We honour the "Do Not Track" browser header and the Global Privacy Control signal where present: when either is set, our first-party analytics on the marketing site does not record the visit at all, and no additional cookie is set to remember the preference, since the check happens at the request level on every page load. Do Not Track has no effect inside the Platform, since the cookies set there are strictly necessary for the service you have subscribed to and cannot be selectively disabled without breaking sign-in.
7b. Extended in-app cookie table
The categories in Section 3 above are a summary; the fuller enumeration below captures every cookie the authenticated Sabee platform may set for a signed-in user. Each cookie is first-party (set from a *.sabee.esesun.com domain), strictly necessary for the function it supports, and subject to the retention and deletion behaviour set out in the Privacy Policy. The names below are indicative and may be prefixed or suffixed by an environment identifier (for example sb_app_session_prod versus sb_app_session_staging) on non-production tenants.
| Cookie name | Purpose | Duration | First-party |
|---|---|---|---|
| sb_app_session | Primary authenticated session token binding your browser to a user record and tenant | 8 hours idle, up to 30 days with device trust | Yes |
| sb_mfa_verified | Confirms multi-factor authentication was completed for the current session and device | Session | Yes |
| sb_xsrf | Anti-forgery token echoed on every state-changing request to protect against XSRF attacks | Session | Yes |
| sb_device_trust | Marks a browser as a trusted device to reduce MFA challenges on repeat sign-ins | 30 days | Yes |
| sb_flags | Feature-flag payload keyed to your tenant, used to render staged and beta UI consistently between requests | 30 days | Yes |
| sb_last_property | Remembers the last property you had selected within a multi-property tenant so the tape chart reopens where you left off | 90 days | Yes |
| sb_ui_prefs | Stores non-essential UI preferences such as expanded sidebar sections, saved column layouts and default calendar zoom | 12 months | Yes |
| sb_locale | Records the interface language you selected inside the app; falls back to browser default when absent | 12 months | Yes |
| sb_theme | Records your chosen colour theme (light or dark) so the dashboard renders consistently between visits | 12 months | Yes |
Beyond the strictly necessary cookies listed here, the authenticated platform does not set marketing, retargeting or cross-site tracking cookies of any kind. If a customer administrator opts in to Datadog Real User Monitoring under Section 4, Datadog may set its own first-party cookie on the tenant subdomain to correlate a single user's performance events; that cookie is described in Datadog's own privacy documentation and can be removed by disabling RUM in tenant admin settings.
8. Changes to this policy
We update this policy whenever our cookie use changes, for example if we add a new strictly necessary cookie for a new feature. The "last updated" date at the top of this page always reflects the current version. Material changes affecting customers are noted in our product changelog and, where the change affects the platform's authentication cookies, communicated directly to tenant administrators by email at least 14 days before the change takes effect. Historical versions of this policy are retained internally for at least 24 months so that any question about which cookie rules applied on a specific date can be answered precisely, both for our own compliance records and for any customer or regulator that asks.
9. Version and contact
Questions about cookies or this policy can be sent to privacy@sabee.esesun.com. Postal address: Sabee Cloud OU, Rotermanni 8, 10111 Tallinn, Estonia. For questions about the DPA and the underlying processing that these cookies support, see the Data Processing Addendum; for questions about the categories of personal data associated with the session cookies documented above, see Section 3 of the Privacy Policy. The Sabee data protection officer can be reached at the same postal address, marked to the attention of the DPO.
v3.1 Last updated 26 July 2026.