Legal
Cookie policy
Every cookie this site sets, and why. The list is short because the product has no analytics, no advertising and no tracking of any kind.
Last updated: 20 August 2026
The Thai and Chinese versions of this page are translations for convenience: the English text is the one a Thai lawyer reviewed, and if a translation and the English ever differ, the English is what applies — you can ask us for the English text at any time. The sentences about what your browser keeps on your own device were updated on 8 September 2026, and the company that serves our map tiles was corrected on 9 September 2026 — both after that review.
1. The short version
We set cookies for three reasons only: to keep you signed in, to remember whether you were last using the site as a renter or as an owner, and to remember a map language if you pick one. There is no analytics, no advertising, no tracking pixel and no third-party cookie anywhere in this product. Your browser keeps three small things on your own device — the homes you recently looked at, which prompts you have closed, and, if you are an owner, a listing you are halfway through writing — and none of that is sent to us, apart from one thing: when a save was interrupted, the listing form sends back its random reference number to check whether that save had already gone through.
2. Cookies we set
Strictly necessary — signing in
These are set by Auth.js, the sign-in library the site uses. Without them you cannot stay signed in, and the sign-in form cannot protect itself against forged submissions.
| Cookie | What it does | How long |
|---|---|---|
authjs.session-token | Your signed-in session, held as a signed token. On the live site it carries a __Secure- prefix and is only sent over HTTPS. Not readable by scripts in your browser. | Until it expires or you sign out |
authjs.csrf-token | Proves a sign-in request came from our own page rather than somebody else’s. | Session |
authjs.callback-url | Remembers the page you were on so signing in returns you to it instead of dumping you on the home page. | Session |
authjs.pkce.code_verifier | Set only while you are signing in with Google or LinkedIn, alongside authjs.state and authjs.nonce. They tie the round trip to that provider back to your browser so it cannot be hijacked. | Minutes |
Functional — two cookies of our own
| Cookie | What it does | How long |
|---|---|---|
xx_mode | Remembers whether you last chose the renting side or the owner side, so the first paint of the next page already shows the right header instead of flickering — and so you come back to the same side the next time you sign in. It holds one word: “tenant” or “owner”. It is not readable by scripts, it is deleted whenever anybody signs out on this browser, and every page checks it against your own account, so it can never give you a side your account does not have. | Up to one year |
xx_map_lang | Written only at the moment you tap a language on a map, so map place names stay in the language you picked. It holds one short language code and nothing else, and it is not tied to your account. | Up to one year |
It is set when you switch sides or open one side’s console (the owner pages or the renting dashboard), and only if your account holds both roles. A cookie can never grant you a role your account does not have — the server checks the account, not the cookie.
Your cookie choice itself
| Cookie | What it does | How long |
|---|---|---|
xx_consent | Remembers that you have seen the cookie notice, and — if we ever add a cookie you can refuse — which ones you allowed. It holds a version number, the date you chose, and yes/no per optional category. Nothing about you, and nothing that identifies you. Without it the notice would reappear on every page you open. | Up to one year |
You can change your answer at any time: Cookie settings sits in the footer of every page. The panel there lists exactly what is on this page, and it is the same list — if the two ever disagree, the panel is generated from the code and this page is not, so trust the panel and tell us.
What we do not set
- No analytics cookie. There is no Google Analytics, no Plausible, no Vercel Analytics, no session recording.
- No advertising or remarketing cookie, and no social tracking pixel.
- No currency cookie, and no cookie for the site's own language — that lives in the web address, and your preference, if you set one, on your account. The one language cookie is xx_map_lang above, written only if you tap a language on a map.
- localStorage and sessionStorage hold only what your own browser needs, and nothing in them is sent to our servers: the homes you recently looked at (the last 50, on this device only), whether you have closed the LINE invitation or the LINE sign-in strip and whether automatic LINE sign-in has already been tried in this visit, and — for owners — the listing you are halfway through writing, autosaved on this device so a crash or a reload does not lose it. That draft is deleted when you save the listing, when you sign out, and the next time you use the site once it is more than seven days old. Clearing your browser data removes all of it.
3. Things that are not cookies but still reveal your IP
A cookie policy that stops at cookies would leave out the part most people would actually want to know. While you use the site, your browser talks directly to a few other companies, and each of those requests carries your IP address.
| When | Who your browser talks to |
|---|---|
| Any page with a listing photo, video or 360° tour | Our media host media.xinxinhomes.com, which sits on Cloudflare. They see the request and your IP address. |
| The map on the search page | OpenFreeMap. Map tiles are fetched by your own browser from tiles.openfreemap.org, so OpenFreeMap sees your IP address and which part of the map you are looking at. The map only loads when you open the map view. |
| Anywhere a profile photo from Google or LinkedIn sign-in is shown | Google or LinkedIn. Those photos are not copied onto our servers — your browser fetches them from the original host, which discloses your IP to that company. |
| Every page | Our host, Vercel, which sees all request traffic including IP addresses. |
None of these set a cookie of ours, and we do not receive anything back from them about you. The privacy policy lists every company involved in the product and what each one gets.
4. Controlling cookies
You can block or delete cookies in your browser settings. Blocking the sign-in cookies will stop you being able to sign in at all — there is no way around that, because a session has to be remembered somewhere. Blocking or clearing xx_mode costs you nothing except that the site will show you the renting side by default.
What we cannot claim yet
You see a short notice, not a permission wall. Every cookie listed above is either strictly necessary for signing in or a single preference you set yourself, and we set nothing at all for analytics or advertising — so there is nothing here for you to refuse. Demanding your consent for a sign-in cookie would imply we track you when we do not, and it would train you to click through the choices that actually matter elsewhere. So we tell you what we store, once, and let you get on with it.
You can reopen that panel whenever you like — Cookie settings is in the footer of every page, and it lists exactly what is on this page. If we ever add something you can refuse, it will be off until you switch it on, and the notice will ask you a real question instead of telling you something.
5. Changes
If we ever add a cookie, this page changes at the same time. If we add anything that tracks you across sites, we will ask you first. Questions go to privacy@xinxinhomes.com.
Questions about this page
Write to privacy@xinxinhomes.com. The other pages in this set are privacy, terms and cookies.

