Cookie Policy
Last updated
DRAFT — requires legal review before launch. This is template seed copy from a public SaaS source; it has not been reviewed by counsel. Do not rely on it as legal advice.
1. What cookies are
Cookies are small text files placed on your device when you visit a website. Similar technologies — local storage, session storage, and SDK identifiers — work the same way for the purposes of this policy. We refer to all of these collectively as "cookies".
2. How we use cookies
Marketing Operator uses cookies for two purposes only:
Essential cookies
These cookies are required for the Service to function. They cannot be turned off without breaking core features (signing in, staying signed in, submitting forms safely).
- Authentication session — maintains your sign-in state between page loads. Set by NextAuth (
__Secure-next-auth.session-tokenin production,next-auth.session-tokenin development). HttpOnly, Secure, SameSite=Lax. Expires when you sign out, or after 24 hours of inactivity. - CSRF protection — a one-time token used to validate state-changing requests. Set by NextAuth (
__Host-next-auth.csrf-token). HttpOnly, Secure, SameSite=Lax. Expires at the end of your session. - Theme preference — stores your light/dark mode preference so the page does not flash the wrong theme on reload. Stored in
localStorageunder thethemekey. Persists until you clear browser storage.
These cookies are set without your consent because the Service is not usable without them. The legal basis under GDPR is "necessary for the performance of a contract" (Art. 6(1)(b)) and "strictly necessary" under the ePrivacy Directive Art. 5(3) exemption.
Analytics cookies
These cookies are set only after you opt in via the cookie consent banner.
- PostHog product analytics — measures feature adoption and helps us debug regressions. PostHog sets cookies in the
ph_namespace. Read PostHog's cookie list for the per-cookie purpose and lifetime. Data is hosted in the EU region (eu.i.posthog.com).
3. The consent banner
Our cookie banner is provided by Termly's Consent Management Platform. Termly detects your jurisdiction and shows the appropriate banner variant — opt-in for GDPR / UK / Switzerland regions, opt-out for California, notice-only for jurisdictions without specific cookie consent rules. Termly itself sets cookies in the uc-* namespace to remember your choice; these are essential to the consent system and are not subject to consent themselves.
If Termly's script is blocked (for example, by an ad-blocker) or fails to load, we fail closed: no analytics cookies are set, and no analytics data is sent. The Service continues to work normally with essential cookies only.
4. Managing your preferences
You can change your cookie preferences at any time:
- From your account settings — open
Settings → Privacy & Cookies → Manage cookie preferencesto reopen the Termly banner. - From your browser — most browsers allow you to block or delete cookies for specific sites. Blocking essential cookies will prevent you from signing in.
- Withdrawing consent — re-opening the consent banner and rejecting analytics has the same effect as clearing your initial choice.
Withdrawing consent stops new analytics cookies from being set and signals our analytics provider to opt you out. Existing analytics cookies on your device may persist until they expire or you clear your browser storage.
5. Third-party cookies
We do not embed third-party advertising or social-network tracking pixels in Marketing Operator. The only third-party cookies set are PostHog (after consent — see above) and Termly (essential consent management).
6. Changes
We may update this Cookie Policy from time to time. Material changes are announced in-app and by email to your registered address.
7. Contact
Questions about cookies? Email support@marketingoperator.ai.