# Cookie Policy and Data Collection Practices **Publisher:** Sabre **Published:** n/a **Category:** Travel tech **Type:** Policy paper **Access:** Free **Official source:** https://www.sabre.com/about/privacy/cookie-policy **Canonical:** https://tourismintel.ai/reports/cookie-policy ## At a glance - Sabre deploys four categories of cookies: strictly necessary (security, compliance), performance/analytics, social media, and targeting/advertising. - Strictly necessary cookies include bot-detection tools (Imperva, Incapsula) and consent management (OneTrust); most first-party, lifespan 29 days to 364 days. - Users can manage most cookies via browser settings or site controls; strictly necessary cookies cannot be disabled without degrading site functionality. - Third-party advertising cookies persist 89–395 days, enabling cross-site tracking and interest profiling for real-time bidding and retargeting campaigns. ## What the report covers Sabre's cookie policy discloses tracking and data-collection practices on its website (sabre.com). The policy itemises 12 strictly necessary cookies (for site function, security, and consent) and 45+ non-essential cookies (analytics, social media, and advertising). Sabre uses both first-party cookies and third-party integrations from analytics, social media, and programmatic advertising platforms. The policy explains cookie types, lifespans, purposes, and user control options, and was last updated 3 June 2026. ## Key findings Sabre implements multiple layers of security cookies under 'strictly necessary' classification. These include bot-detection via Imperva (reese84, 29-day lifespan; x-d-token, seconds) and Incapsula DDoS protection (session and 364-day persistent cookies). Load-balancing cookie GCLB ensures consistent server routing across sessions. OneTrust compliance cookies (OptanonAlertBoxClosed, OptanonConsent, both 364 days) manage cookie consent notices and store user preferences. The source specifies these cannot be disabled without site malfunction. Performance and analytics cookies enable behavioural tracking and engagement measurement. Google Analytics cookies (_ga, _ga_xxxxxxxxxx, each 399 days) assign unique client identifiers and track sessions. Hotjar cookies (_hjSessionUser, 364 days; _hjSession, session-based) monitor user interaction patterns. Pardot (marketing automation) and StackAdapt (programmatic ads) cookies monitor campaign data. The policy notes disabling these impairs service functionality and prevents performance monitoring. Social media and targeting cookies facilitate cross-site profiling and ad personalisation. LinkedIn cookies (bcookie, bscookie, AnalyticsSyncHistory, li_sugr, UserMatchHistory) enable content sharing and identity matching; lifespans range from 30 to 364 days. Facebook (_fbp, 89 days) and Google Ad Manager cookies support real-time bidding. Rubicon Project cookies (audit, khaos, audit_p, khaos_p; 364 days and 89 days) enable programmatic advertising. StackAdapt, LiveRamp, and Demandbase cookies persist 364–395 days for audience targeting. Third-party advertising networks dominate non-essential cookie volume. Casale Media (CMID, CMPRO, CMPS; 364 and 89 days), Rubicon Project, and Tremor Video (tv_UIDM, tvid; 365–399 days) track users across multiple sites for ad delivery. Vimeo and CloudFlare provide session-based bot-management cookies. The policy discloses that disabling targeting cookies does not block ads but reduces relevance. No metrics quantify user consent rates or cookie rejection frequency. ## Key numbers | Metric | Value | Note | |---|---|---| | Strictly necessary cookies deployed | 12 | First-party and third-party (Vimeo, CloudFlare); lifespans from seconds to 364 days | | Google Analytics cookie persistence | 399 days | _ga and _ga_xxxxxxxxxx; first-party, standard lifespan for session and visitor tracking | | LinkedIn cookie persistence (persistent variant) | 364 days | bcookie and bscookie third-party cookies for social sharing and tracking | | Programmatic advertising cookie persistence | 364–395 days | StackAdapt, LiveRamp, Rubicon Project, Demandbase, Tremor Video cookies for targeting | | OneTrust compliance cookies persistence | 364 days | OptanonAlertBoxClosed and OptanonConsent; store user consent preferences and suppress notice repeat-display | | Imperva bot-detection cookie lifespan | 29 days | reese84; detects bot traffic and mitigates DDoS attacks | ## Why it matters **DMOs & destinations** — Sabre's extensive third-party cookie network—spanning analytics (Google, Hotjar), social media (LinkedIn, Facebook), and programmatic advertising (StackAdapt, Rubicon)—enables precise visitor-behaviour tracking and retargeting. DMOs should understand how travel-distribution platforms profile their potential customers and what consent disclosures may be required under local privacy law. Cross-site tracking via persistent cookies (364+ days) allows attribution of destination interest across touchpoints. **Hotels & hospitality** — Hotels using Sabre's retailing and distribution infrastructure inherit these cookie practices. The reliance on 15+ third-party data partners—including programmatic ad exchanges and audience-targeting platforms—affects how guest behaviour is tracked and monetised. Hoteliers should audit consent flows and understand data-sharing arrangements, especially where GDPR, CCPA, or emerging privacy laws govern. Bot-detection and load-balancing cookies (Imperva, Incapsula) protect booking systems but add latency considerations. **Travel tech & distribution** — This policy exemplifies modern travel-tech compliance strategy: layered cookie categorisation, third-party partnerships for analytics and ads, and user control mechanisms. The scale of integrations (Pardot, Hotjar, StackAdapt, LinkedIn, Rubicon) shows how distribution platforms monetise visitor data. Tech teams should note OneTrust consent management, Vimeo/CloudFlare third-party dependencies, and session-management patterns. Persistent cookies (364–399 days) enable sophisticated user-journey mapping across bookings and searches. ## Methodology and limits This brief summarises Sabre's published cookie policy, updated 3 June 2026, available at sabre.com/about/privacy/cookie-policy. The source is a declarative policy document, not an empirical study or survey. It itemises individual cookies by name, host, lifespan, first/third-party status, and stated function. No quantitative data on user consent rates, cookie rejection frequency, or performance impact is provided. The brief reflects only publicly disclosed information; Sabre's full data-sharing and processing terms are referenced to a separate Privacy Policy, not reproduced here. --- © Sabre for the original report. This brief is an original editorial summary by TourismIntel (https://tourismintel.ai). Read the original: https://www.sabre.com/about/privacy/cookie-policy