Updated 2026-09-24

Cookie Policy

Last updated: 24 September 2026

About this policy

This policy explains which cookies and similar browser storage BookingsXP uses in three places:

  1. the marketing website at https://bookingsxp.com;
  2. the BookingsXP dashboard, when you sign in; and
  3. the booking widget and hosted booking pages that our customers put on their own websites.

The short version: the marketing site asks before it sets analytics cookies, the dashboard uses the cookies it needs to keep you signed in, and the embedded widget sets no cookies at all.

1. The marketing website

When you first visit, a banner asks you to accept or decline cookies. Your choice is saved in your browser's localStorage under cookie_consent, so we do not ask again on every page.

Before you choose, or if you decline

  • PostHog (product analytics) runs without cookies. It keeps its identifiers in memory only, so they disappear when you leave the page, and it does not record sessions. If you decline, PostHog stops measuring your visit.
  • Google tag: if a Google tag is configured on the marketing site, it loads with Google Consent Mode set to denied for advertising and analytics storage, so it does not set Google advertising or analytics cookies.
  • No attribution cookie is set.

If you accept

  • PostHog may set a first-party cookie and use localStorage so it can recognise you across visits, and it may record sessions with every form input masked.
  • Google tag: if one is configured, Consent Mode is updated to granted, so Google may set its advertising and analytics cookies (for example _gcl_au) to measure visits and ad conversions.
  • Attribution cookie: a small first-party cookie on .bookingsxp.com keeps the page you first landed on, the referring site and any campaign parameters for up to 90 days, so we can see which pages lead to sign-ups.

You can change your mind at any time by clearing this site's data in your browser (cookies and site storage), after which the banner will ask again. Declining or clearing does not affect the rest of the site.

BookingsXP's own marketing analytics are never loaded on embed or hosted booking pages.

2. The dashboard

When you sign in, we set strictly necessary first-party cookies to keep you signed in, protect your session and remember security steps such as two-factor authentication. They are required for the dashboard to work, so they are not covered by the consent banner. Session cookies end when you sign out or when the session expires.

The sign-in pages and the dashboard use the same PostHog and Google tag setup as the marketing site, and follow the choice you made in the cookie banner: cookieless until you accept, off if you decline.

3. The embedded widget and hosted booking pages

These rules apply to every BookingsXP widget, whether it is embedded inline, as a popup or floating button, through one of our packages or the WordPress plugin, or used on a hosted booking page at bookingsxp.com/book/....

No cookies

The widget does not set any cookies, on the customer's website or on bookingsxp.com.

Browser storage the widget uses

  • localStorage["bxp_attr"]: to credit a booking to the ad or page that brought the visitor, the widget keeps the first touch (landing page, referrer, UTM parameters and ad click IDs such as gclid, fbclid and msclkid) in the visitor's own browser for 90 days. A later visit that arrives from a new campaign replaces it. It is sent to BookingsXP with a booking so the source can be written into the booking notes in Microsoft Bookings.
  • sessionStorage["bxp_s"]: a simple flag that tells a new visit from a repeat one, so the widget can count visits. It is cleared when the browser tab is closed.

Cookies the widget reads

On the customer's page, the widget reads, but never sets, the Google Analytics and Meta cookies that the customer's own tags have already set (_ga, _fbp and _fbc). This lets the customer match bookings to visits in their own Google Analytics and Meta accounts.

If the visitor's browser sends Global Privacy Control (navigator.globalPrivacyControl), or the customer's site sets window.bxpConsent = false (for example, because the visitor declined the site's own cookie banner), the widget:

  • does not write bxp_attr or bxp_s (the embed script also removes any bxp_attr record already stored);
  • does not read _ga, _fbp or _fbc; and
  • reduces attribution to the current page and the referring site's origin.

The customer's own tags

Customers can have the widget send booking events to their own Google Tag Manager, Google Analytics, Google Ads, Meta Pixel or LinkedIn tags. Those tags, and any cookies they set, belong to the customer's website and are covered by the customer's own cookie policy and consent banner, not by this one.

Managing cookies and storage

Most browsers let you block or delete cookies and site data in their settings. Blocking cookies on bookingsxp.com may stop you from signing in to the dashboard. Clearing site data for a website that uses a BookingsXP widget removes bxp_attr and bxp_s; turning on Global Privacy Control stops the widget from storing them again.

Changes to this policy

We will update this page when the cookies or storage we use change, and change the date at the top.

Contact

Questions about this policy: hello@bookingsxp.com

Postal address: BookingsXP, 9th Floor, Tower D, Unitech Cyber Park, Sector 39, Gurugram, Haryana 122001, India