Legal
Cookie policy
MazeCFO sets one cookie. There is no analytics, advertising, or third-party tracking, which is why you are not being asked to accept anything.
1The cookie we set
| Name | __Host-mazecfo_session |
|---|---|
| Purpose | Keeps you signed in. It holds an opaque identifier, not your identity or any data about you. |
| Type | Strictly necessary. The service cannot authenticate you without it. |
| Lifetime | Until you sign out, or until the session expires — 12 hours by default, 30 days if you chose to stay signed in. |
| Flags | HttpOnly, Secure, SameSite=Lax, and the __Host- prefix, which forbids a Domain attribute so no subdomain can write it. |
| Third party | No. |
2What we do not set
No analytics cookies. No advertising or retargeting cookies. No social media pixels. No third-party scripts of any kind — the Content Security Policy would block them, and it is enforced rather than advisory.
3Why there is no consent banner
Consent is required for cookies that are not strictly necessary. The only cookie here is the one that keeps you signed in, which is strictly necessary by definition — so there is nothing to consent to, and a banner asking you to would be theatre.
If that ever changes, a banner will appear and this page will be updated before it does.
4Controlling cookies
You can block or delete cookies in your browser. Blocking this one means you cannot stay signed in, because there is no other mechanism holding the session.
5Contact
Questions: contact us. See also the privacy policy.