Cookie Policy

1. Introduction

This Cookie Policy ("Policy") explains how DLF Club and Hospitality and its affiliates (hereinafter referred to as "DLF", "we", "us", or "our") use cookies and similar technologies when you access or interact with our mobile application, the DLF Hospitality App ("Platform").

Cookies help us improve the Platform's performance, enhance user experience, and analyse traffic patterns. This Policy provides detailed information about the types of cookies we use, their purposes, your rights regarding their use, and how you can manage your preferences or withdraw consent.

To the extent that information collected through cookies and similar technologies constitutes personal data under applicable law, including the Digital Personal Data Protection Act, 2023, DLF processes such information in accordance with this Cookie Policy, our Privacy Policy, and applicable laws.

2. What are Cookies?

Cookies are small text files that a website or application places on your device when you access or use it. These files store information about your in-app activities and preferences, enabling features such as secure logins, personalised settings, and analytical insights.

In addition to cookies, we may deploy similar technologies such as web beacons or pixel tags in limited circumstances. However, the primary technologies utilised on our Platform are cookies and local storage-based authentication mechanisms, as described in this Policy.

3. How DLF Uses Cookies

DLF uses cookies and similar technologies to:

  • Enable core app functionality (e.g., secure sessions, bot protection, and security controls);
  • Understand user behaviour through analytics and usage statistics; and
  • Optimise app performance and measure engagement.

These cookies and similar technologies enable us to understand how users navigate our Platform and interact with its features, allowing us to make informed decisions to improve our services.

We engage third-party service providers to analyse Platform usage and provide security services on our behalf. These third parties may collect aggregated data regarding Platform usage. Such cookies are activated only upon receiving explicit user consent, except where strictly necessary for security purposes.

Our use of cookies is categorised into different types as elaborated in Section 4 (Types of Cookies We Use) below.

We ensure that personal data collected via cookies is processed in accordance with user consent preferences, except where such cookies are strictly necessary for the functioning or security of the Platform. Users are provided with clear options to manage their cookie preferences and may opt in or out of specific categories of non-essential cookies at any time. Our systems maintain a record of the cookie categories authorised by each user to ensure adherence to their stated preferences.

First-party cookies and technologies are those set directly by DLF when you access or interact with our Platform.

Third-party cookies are set by domains other than ours, typically through integrations with external service providers such as analytics platforms and security services. These cookies are used to: (a) analyse user engagement and Platform usage statistics; (b) measure app performance and track user interactions; and (c) provide bot protection, traffic management, and security controls.

DLF only deploys third-party cookies after obtaining your explicit consent, in accordance with applicable laws, except for strictly necessary security cookies. You are always given the choice to accept, reject, or manage the use of non-essential cookies through: (a) the in-app consent screen displayed when you first access the Platform; (b) the cookie preference settings available within the Platform; or (c) your device-level privacy settings.

4. Types of Cookies We Use

A. Strictly Necessary / Security Cookies

These cookies and technologies are essential for the Platform to function properly. They enable basic features such as secure sessions, bot protection, traffic management, rate limiting, and security controls. These are required to deliver the requested service or resource. If these cookies are not enabled, the functionality and security of our Platform may be impacted. The strictly necessary cookies that we deploy are set out in the table below.

Technology / SDK / Identifier Platform Description Retention Period
Session Authentication Token

(confirm technical name with client)
Android & iOS Used for application session management and authenticated access. If disabled or rejected, the user session and authenticated access may not function correctly. Session-based (cleared on logout / app close)
Firebase Remote Config Android Retrieves configuration values from Firebase to manage app settings and feature flags remotely. Persistent
Google Firebase Core iOS Core Firebase SDK infrastructure; access depends on the Firebase services enabled by the application. Required for all Firebase service integrations to function. Persistent
Google Firebase Installations iOS Collects a Firebase Installation ID and installation metadata required for Firebase service initialisation and linking of Firebase features to the device installation. Persistent until app uninstall

B. Analytics Cookies (Third-Party)

These cookies and similar technologies help us understand how users interact with the Platform by collecting information on app usage events, in-app behaviour, and engagement metrics. The information collected is used to improve functionality, user experience, and app stability. All Analytics Cookies are activated only after obtaining your consent. If you choose to disable or disallow these cookies, we may not be able to monitor and improve the performance and stability of our Platform effectively. The Analytics Cookies that we deploy are set out in the table below.

Technology / SDK / Identifier Platform Description Retention Period
Google Firebase Analytics Android Collects app usage events and technical identifiers depending on implementation. Used to understand how users interact with the Platform, measure engagement, and track in-app behaviour. Up to 14 months (Google's default retention for Firebase Analytics data) —
Google Firebase Crashlytics (Android) Android Collects crash diagnostics and device/app technical information to identify, prioritise, and resolve app stability issues. 90 days (Google's standard Crashlytics retention)
Google Firebase Crashlytics iOS Collects crash diagnostics and device/app technical information to identify, prioritise, and resolve app stability issues. 90 days (Google's standard Crashlytics retention)
Google Firebase Messaging iOS Collects push notification device registration tokens and messaging metadata for the purpose of delivering push notifications to the user's device. Until app uninstall or token refresh.

5. Third-Party Services and Tools

In addition to the cookies and similar technologies listed above, the following third-party services are integrated with our Platform and may receive certain user data through the Platform:

Third-Party Service Platform Purpose / Data Collected
Google Firebase Analytics Android Collects app usage events and technical identifiers to measure user engagement and in-app behaviour.
Google Firebase Crashlytics Android Collects crash diagnostics and device/app technical information for app stability monitoring.
Google Firebase Crashlytics iOS Collects crash diagnostics and device/app technical information for app stability monitoring.
Google Firebase Messaging iOS Collects push notification device registration tokens and messaging metadata for push notification delivery.
Firebase Remote Config Android Retrieves remote configuration values for app feature management.
Google Firebase Core / Installations / Data Transport iOS Core Firebase SDK infrastructure — collects Firebase Installation ID, installation metadata, and supports data transport for all enabled Firebase services.

6. How to Manage or Withdraw Your Consent

You have the right to accept or decline cookies and similar technologies when using our Platform. You may also withdraw your consent at any time through the following means: (a) the consent management settings available within the Platform; or (b) device-level controls, including adjusting your device settings (such as limiting ad tracking on iOS or opting out of personalised ads on Android) to restrict the use of certain tracking technologies.

Please be aware that disabling certain cookies may affect Platform performance or prevent certain features from functioning correctly.

Please note that your cookie and tracking preferences and consent choices may be retained in our records for compliance purposes. Withdrawal of consent shall not affect the lawfulness of any processing undertaken prior to such withdrawal.

7. Grievances and Contact Information

If you have any questions, grievances, or concerns regarding our use of cookies or similar technologies, or regarding this Policy, you may contact the designated Grievance Officer, whose details are set out below:

Email: grievance.hospitality@dlf.in

8. Review and Updates to this Policy

We may update this Policy periodically to reflect changes in legal, technological, or operational practices. We will notify you of significant changes, where required under applicable law, and will update the "Last Updated" date at the top of this Policy. Changes to this Policy shall become effective upon being posted on the Platform.

The latest version of this Policy shall always remain available on our Platform.