MazeCFO

Legal

Cookie policy

MazeCFO sets one cookie. There is no analytics, advertising, or third-party tracking, which is why you are not being asked to accept anything.

Draft pending legal review. This document describes how the platform actually operates, but it has not been reviewed by qualified counsel and is not yet a binding agreement. It must not be relied upon until this notice is removed.

1The cookie we set

Name__Host-mazecfo_session
PurposeKeeps you signed in. It holds an opaque identifier, not your identity or any data about you.
TypeStrictly necessary. The service cannot authenticate you without it.
LifetimeUntil you sign out, or until the session expires — 12 hours by default, 30 days if you chose to stay signed in.
FlagsHttpOnly, Secure, SameSite=Lax, and the __Host- prefix, which forbids a Domain attribute so no subdomain can write it.
Third partyNo.

2What we do not set

No analytics cookies. No advertising or retargeting cookies. No social media pixels. No third-party scripts of any kind — the Content Security Policy would block them, and it is enforced rather than advisory.

3Why there is no consent banner

Consent is required for cookies that are not strictly necessary. The only cookie here is the one that keeps you signed in, which is strictly necessary by definition — so there is nothing to consent to, and a banner asking you to would be theatre.

If that ever changes, a banner will appear and this page will be updated before it does.

4Controlling cookies

You can block or delete cookies in your browser. Blocking this one means you cannot stay signed in, because there is no other mechanism holding the session.

5Contact

Questions: contact us. See also the privacy policy.