What cookies are
A cookie is a small text file that a website stores in your browser and reads back on later requests. Cookies let a site remember that you are signed in, keep your preferences and defend against forged requests. Similar technologies include local storage and session storage, which keep data in the browser without sending it to the server on every request. This policy covers all of them and applies to the WorkOSync website at workosync.com and to the web application.
Essential cookies versus analytics
Every cookie in the table above is strictly necessary: the service cannot sign you in, protect you from forged requests or remember your language without it. The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, for EU visitors, the ePrivacy rules and GDPR allow such cookies without consent, which is why WorkOSync does not show a cookie banner.
We set no analytics cookies, no advertising cookies and no social-media pixels, on either the website or the app. If we ever introduce a non-essential cookie we will ask for your consent first and update this policy.
First-party, cookieless analytics
We want to know how many people visit the site and which pages they read, without following anyone around the web. Our analytics are built into WorkOSync itself:
- A tiny same-origin script sends one request per page view to our own server. No third party receives it.
- To count unique visitors, the server computes a hash of your IP address and browser user agent together with a secret salt that rotates every day. The hash cannot be reversed to identify you, is different tomorrow, and is never joined with your account.
- We record the page, the referring site, the country (from a network header, not from a geolocation database), the device type and the time. We do not record your IP address in the analytics store.
- Known bots and crawlers are excluded, and the data is aggregated into daily totals.
Because this involves no cookie and no persistent identifier, it does not require consent, and “Do Not Track” or global privacy control signals do not change how it works, since it already tracks nothing across sites or sessions.
Third-party cookies
When you pay for a subscription, the card form is served by your chosen payment gateway (Stripe, Tap Payments, PayPal or Razorpay) inside a secure frame or on the gateway’s own page. The gateway may set its own cookies for fraud prevention under its own cookie and privacy policy. When you connect a third-party service to your company, such as WhatsApp Business or a bank feed, that service’s cookies are governed by its policy. We do not embed social-media widgets, video players or advertising networks on our pages.
How to control cookies
You can view, block and delete cookies in your browser settings. Every major browser lets you clear cookies for one site, block third-party cookies, or refuse cookies entirely:
- Chrome: Settings, Privacy and security, Third-party cookies and Site settings.
- Safari: Settings, Privacy, Manage Website Data.
- Firefox: Settings, Privacy and Security, Cookies and Site Data.
- Edge: Settings, Cookies and site permissions.
If you block the essential cookies listed above you will not be able to sign in to WorkOSync or submit forms on the website, because the service cannot tell that a request comes from you. Clearing local storage resets your language and layout preferences to the defaults.
Changes to this policy
We will update this page when we add, remove or change a cookie category and show the new effective date at the top. Material changes, such as any introduction of a non-essential cookie, will be announced in the app and by email to account owners before they take effect. Questions about cookies and privacy are covered in more detail in our Privacy Policy.
Contact
Questions about this document, or a request under it, can be sent to the address below. We reply within one working day, Sunday to Thursday.
Other addresses: privacy@workosync.com for data protection, support@workosync.com for billing and support, security@workosync.com for vulnerability reports.

