Cookie Policy
Type: Cookie Policy · Version: 2026-04-17 · Published: 2026-04-17 11:25 UTC
════════════════════════════════════════════════════════════════
MAKRR — COOKIE POLICY
Version 1.0 · Effective 2026-04-17
Trashify Tech OÜ · Registry code 16495334
════════════════════════════════════════════════════════════════
AT A GLANCE
— We use cookies strictly to make the Service work (login, security,
saved preferences). These are set without asking.
— We ask your permission before setting anything else. You accept or
reject optional categories using the banner on your first visit,
and you can change your mind at any time.
— We do not sell or rent cookie data to third parties. We do not use
cookies to track you across other websites.
— The current consent version is 2026-03-05. If we add new cookies
or change the categories, the version bumps and we ask again.
────────────────────────────────────────────────────────────────
SECTION 1. WHAT COOKIES ARE
────────────────────────────────────────────────────────────────
Cookies are small text files that a website stores in your browser
so it can remember things between requests — for example, that you
are logged in. We also use a few related technologies (browser
local storage, similar identifiers) that behave like cookies;
everything in this Policy applies to them too.
Cookies fall into two kinds by who sets them:
(a) FIRST-PARTY cookies set by makrr.ai itself; and
(b) THIRD-PARTY cookies set by another service we have
integrated into our pages (for example, Google reCAPTCHA
on forms where we need to stop bots).
And two kinds by how long they last:
(a) SESSION cookies that disappear when you close the
browser; and
(b) PERSISTENT cookies with a set expiry.
────────────────────────────────────────────────────────────────
SECTION 2. THE COOKIES WE USE
────────────────────────────────────────────────────────────────
We split cookies into three categories. "Necessary" cookies are
set without asking. "Analytics" and "Marketing" cookies are only
set if you give consent through our banner.
--------------------------------------------------------------
2.1 Necessary (always on — no consent required)
--------------------------------------------------------------
These cookies are essential for the Service to function. Under
Article 5(3) of Directive 2002/58/EC (ePrivacy) and §103(3) of the
Electronic Communications Act of Estonia, strictly-necessary
cookies do not require prior consent.
Name: session
Set by: makrr.ai (first-party)
Purpose: authenticates your login and binds your session to
the server-side session store
Type: first-party, HTTP-only, secure (in production),
SameSite=Lax
Duration: ends when you close the browser, or on logout
Name: _csrf_token (held inside the session cookie)
Set by: makrr.ai (first-party)
Purpose: protects against cross-site request forgery on
state-changing requests
Type: part of the session cookie above
Duration: same as the session cookie
Name: cookie_consent
Set by: makrr.ai (first-party)
Purpose: records your choices from the cookie banner so we
do not ask you on every page load
Type: first-party, readable by the page (not HTTP-only),
SameSite=Lax
Duration: 12 months from the date of your choice, or until
you change it
Plus a small number of very short-lived cookies used for load
balancing and cross-site-request-forgery tokens that exist
only for the duration of a request.
--------------------------------------------------------------
2.2 Analytics (consent required — off by default)
--------------------------------------------------------------
If you accept the "Analytics" category in the cookie banner, we
may enable cookies that help us understand how the Service is used
so we can improve it. Analytics cookies are never used to identify
you to a third party and are never combined with your account data
for marketing.
CURRENT STATUS: At the date of this Policy, we have NOT
deployed an analytics tool. The category exists so that your
preference is recorded in advance — if we add an analytics
tool later, we will not enable it for you unless you have
consented to the Analytics category, and we will update this
Policy (with a new consent version and a fresh prompt)
before we do.
--------------------------------------------------------------
2.3 Marketing (consent required — off by default)
--------------------------------------------------------------
If you accept the "Marketing" category, we may set cookies that
personalise what we say to you in product or email campaigns.
CURRENT STATUS: As with Analytics, we have not deployed any
marketing cookies at the date of this Policy. Nothing changes
for you unless we add such cookies in the future, at which
point we will update this Policy and re-prompt under a new
consent version before they are enabled.
--------------------------------------------------------------
2.4 Third-party services we integrate
--------------------------------------------------------------
Some third-party services set their own cookies when we load them
on a page. Where the third-party cookie is strictly necessary for
a security or fraud-prevention function, we treat it as a
Necessary cookie under clause 2.1.
Google reCAPTCHA v3
Set by: Google LLC on auth pages (login, registration,
password reset)
Purpose: distinguishing human users from bots to prevent
account abuse and fraud
Category: treated as Necessary because blocking bots is
required to secure the Service
Information flow: reCAPTCHA may set cookies on the
google.com and recaptcha.net domains and
transmit interaction signals to Google. See
Google's Privacy Policy and reCAPTCHA Terms.
Stripe
Set by: Stripe Payments Europe Ltd on pages that load
Stripe Checkout or Elements (billing,
checkout)
Purpose: fraud prevention and checkout functionality
Category: treated as Necessary on the checkout flow
Information flow: Stripe sets cookies on stripe.com. See
Stripe's Privacy Policy.
We do not use advertising cookies, cross-site trackers, or
social-media "like" / share buttons that load third-party
scripts.
────────────────────────────────────────────────────────────────
SECTION 3. YOUR CHOICE
────────────────────────────────────────────────────────────────
3.1 The banner. On your first visit, a banner gives you three
options:
— Accept all
— Accept only necessary
— Choose categories (tick Analytics and Marketing individually)
3.2 Changing your mind. You can change your cookie preferences
at any time:
— by clicking the "Cookies" link in the footer of any page;
— or by clearing the cookie_consent cookie in your browser,
which will cause the banner to reappear on your next visit;
— or by emailing privacy@makrr.ai.
Opt-outs take effect immediately. Data already collected before
you opt out is not retroactively deleted; contact us if you want
retrospective deletion under GDPR Article 17.
3.3 Browser-level control. You can also block or delete cookies
directly in your browser. Blocking all cookies from makrr.ai will
prevent the Service from working — for example, you will not be
able to stay logged in. Information on managing cookies in common
browsers:
— Chrome: https://support.google.com/chrome/answer/95647
— Firefox: https://support.mozilla.org/kb/enhanced-tracking-protection-firefox-desktop
— Safari: https://support.apple.com/en-gb/guide/safari/sfri11471/mac
— Edge: https://support.microsoft.com/microsoft-edge/view-cookies-in-microsoft-edge
────────────────────────────────────────────────────────────────
SECTION 4. CONSENT RECORDS
────────────────────────────────────────────────────────────────
When you make a choice on the banner, we record:
— the consent version (currently 2026-03-05);
— whether you accepted necessary, analytics, marketing;
— the source of the consent (banner, settings page, support);
— the timestamp;
— your user identifier, if you are logged in.
This record is kept for three (3) years from the date of your
most recent choice (or withdrawal), as evidence of consent under
Article 7(1) GDPR.
────────────────────────────────────────────────────────────────
SECTION 5. "DO NOT TRACK" AND GLOBAL PRIVACY CONTROL
────────────────────────────────────────────────────────────────
Our Service does not currently respond to browser "Do Not Track"
signals, because there is no consensus on how they should be
interpreted. We do respond to the Global Privacy Control (GPC)
signal where sent: a GPC header is treated as a withdrawal of
consent for Analytics and Marketing categories.
────────────────────────────────────────────────────────────────
SECTION 6. VERSIONING
────────────────────────────────────────────────────────────────
Each material change to this Policy bumps the consent version. On
the next page load, the banner reappears and you re-choose. Minor
edits (typos, contact-detail updates, clarifications) do not bump
the version.
────────────────────────────────────────────────────────────────
SECTION 7. CONTACT
────────────────────────────────────────────────────────────────
Trashify Tech OÜ
Registry code: 16495334
Registered office: Gonsiori tn 29-3, Kesklinna linnaosa,
10147 Tallinn, Harju maakond, Estonia
Privacy: privacy@makrr.ai
Legal: legal@makrr.ai
Supervisory authority: Estonian Data Protection Inspectorate
(Andmekaitse Inspektsioon) — info@aki.ee —
www.aki.ee
════════════════════════════════════════════════════════════════
Version 1.0 · Effective 2026-04-17 · Consent version 2026-03-05
════════════════════════════════════════════════════════════════