Cookie Policy
Information about cookies, browser storage and tracking technologies.
Last updated: 30 July 2026
1. Purpose of this policy
This Cookie Policy explains how the Arvenigrandhotel website uses cookies and related browser technologies. It should be read with the Privacy Policy. The current static website has been designed without third-party advertising, analytics pixels, embedded social-media trackers, remote fonts or external scripts.
2. Operator and contact
Legal entity: Arvenigrandhotel Pty Ltd
Address: 525 Collins Street, Melbourne VIC 3000, Australia
Privacy email: info@arvenigrandhotel.com
Telephone: +61 3 9123 6874
3. What cookies are
Cookies are small text files that a website or its service provider may place on a device. Similar technologies include local storage, session storage, pixels, software development kits and device identifiers. These technologies can support essential functions, remember preferences, measure usage or enable advertising, depending on how a site is configured.
4. Current website configuration
The supplied static version of this website does not intentionally set non-essential analytics, advertising or personalisation cookies. It contains no Google Analytics, Meta Pixel, remote font request, social-media embed or third-party marketing script. The address configuration is loaded from a local JSON file and is not used for tracking.
When the website is deployed, the hosting platform, content-delivery network, security provider or server may set strictly necessary cookies or create technical logs for load balancing, fraud prevention, rate limiting, session integrity or security. The operator should review the final hosting environment before publication because hosting configuration can introduce technologies that are not present in the source files.
5. Categories of cookies
- Strictly necessary: required for security, network management, accessibility, form protection or core service delivery. These cannot always be disabled through a consent tool.
- Functional: remember optional choices such as language or interface preferences.
- Analytics: measure how visitors use a site and help improve performance.
- Advertising: profile activity or measure advertising campaigns across sites or services.
Only the first category may be technically necessary in the current deployment, depending on the hosting provider. Functional, analytics and advertising technologies should remain disabled unless they are deliberately added with an appropriate legal basis and consent controls where required.
6. Legal basis and consent
In Australia, cookie use may involve obligations under the Privacy Act 1988 and the Australian Privacy Principles where information is personal information. Where the GDPR or ePrivacy rules apply, storing or accessing non-essential information on a user’s device generally requires valid consent unless a specific exemption applies. Consent should be informed, specific, freely given, unambiguous and as easy to withdraw as to give.
If non-essential cookies are introduced, they should not be activated before the required choice is made. Rejecting non-essential cookies should not prevent access to core informational content unless the technology is genuinely necessary for the requested service.
7. Cookie consent controls
Because the current source does not deploy non-essential cookies, a consent banner is not included. If analytics, advertising, embedded media or non-essential personalisation is added, the site operator should implement a consent interface that identifies purposes, offers accept and reject choices with comparable prominence, records the choice, permits later withdrawal and blocks non-essential technologies until consent where required.
A banner should not use pre-ticked boxes, misleading colours, forced consent for unrelated processing or language that makes refusal unnecessarily difficult.
8. Browser controls
Most browsers permit users to inspect, block or delete cookies. Blocking all cookies may affect services that rely on essential session or security features. Browser settings operate separately from any website consent interface and may not prevent all forms of storage or server-side logging.
Users should consult the help section of their browser for current instructions. The website does not link to external browser support pages in order to keep all project resources local.
9. Retention
Any cookie retention period should be limited to what is necessary for its purpose. Session cookies ordinarily expire when the browser session ends. Persistent cookies remain until their configured expiry or deletion. If non-essential cookies are added, the consent interface or an updated version of this policy should identify their provider, purpose and duration.
10. Third-party technologies
The current source contains no third-party tracking technology. If a third-party reservation engine, map, payment service, analytics platform or embedded content is added later, that provider may set its own cookies and process information under its own terms. The operator must assess the provider, configure privacy settings, update this policy and implement consent or other safeguards before deployment where required.
11. Do Not Track and global privacy signals
Browser “Do Not Track” signals are not implemented consistently across the industry. Where legally required or technically supported, the operator should assess recognised opt-out or global privacy signals and document how they are honoured. The current static website does not perform behavioural advertising.
12. Security
Cookie values should not contain unnecessary sensitive information. Security cookies should use appropriate attributes such as Secure, HttpOnly and SameSite where technically applicable. Access should be limited, and cookie identifiers should not be retained longer than needed.
13. Updates to this policy
This policy should be reviewed whenever hosting, analytics, advertising, booking, payment, map, embedded-media or security technologies change. The updated date will be revised when material changes are made.