Cookie Policy

Type: Cookie Policy · Version: 2026-04-17 · Published: 2026-04-17 11:25 UTC
════════════════════════════════════════════════════════════════ MAKRR — COOKIE POLICY Version 1.0 · Effective 2026-04-17 Trashify Tech OÜ · Registry code 16495334 ════════════════════════════════════════════════════════════════ AT A GLANCE — We use cookies strictly to make the Service work (login, security, saved preferences). These are set without asking. — We ask your permission before setting anything else. You accept or reject optional categories using the banner on your first visit, and you can change your mind at any time. — We do not sell or rent cookie data to third parties. We do not use cookies to track you across other websites. — The current consent version is 2026-03-05. If we add new cookies or change the categories, the version bumps and we ask again. ──────────────────────────────────────────────────────────────── SECTION 1. WHAT COOKIES ARE ──────────────────────────────────────────────────────────────── Cookies are small text files that a website stores in your browser so it can remember things between requests — for example, that you are logged in. We also use a few related technologies (browser local storage, similar identifiers) that behave like cookies; everything in this Policy applies to them too. Cookies fall into two kinds by who sets them: (a) FIRST-PARTY cookies set by makrr.ai itself; and (b) THIRD-PARTY cookies set by another service we have integrated into our pages (for example, Google reCAPTCHA on forms where we need to stop bots). And two kinds by how long they last: (a) SESSION cookies that disappear when you close the browser; and (b) PERSISTENT cookies with a set expiry. ──────────────────────────────────────────────────────────────── SECTION 2. THE COOKIES WE USE ──────────────────────────────────────────────────────────────── We split cookies into three categories. "Necessary" cookies are set without asking. "Analytics" and "Marketing" cookies are only set if you give consent through our banner. -------------------------------------------------------------- 2.1 Necessary (always on — no consent required) -------------------------------------------------------------- These cookies are essential for the Service to function. Under Article 5(3) of Directive 2002/58/EC (ePrivacy) and §103(3) of the Electronic Communications Act of Estonia, strictly-necessary cookies do not require prior consent. Name: session Set by: makrr.ai (first-party) Purpose: authenticates your login and binds your session to the server-side session store Type: first-party, HTTP-only, secure (in production), SameSite=Lax Duration: ends when you close the browser, or on logout Name: _csrf_token (held inside the session cookie) Set by: makrr.ai (first-party) Purpose: protects against cross-site request forgery on state-changing requests Type: part of the session cookie above Duration: same as the session cookie Name: cookie_consent Set by: makrr.ai (first-party) Purpose: records your choices from the cookie banner so we do not ask you on every page load Type: first-party, readable by the page (not HTTP-only), SameSite=Lax Duration: 12 months from the date of your choice, or until you change it Plus a small number of very short-lived cookies used for load balancing and cross-site-request-forgery tokens that exist only for the duration of a request. -------------------------------------------------------------- 2.2 Analytics (consent required — off by default) -------------------------------------------------------------- If you accept the "Analytics" category in the cookie banner, we may enable cookies that help us understand how the Service is used so we can improve it. Analytics cookies are never used to identify you to a third party and are never combined with your account data for marketing. CURRENT STATUS: At the date of this Policy, we have NOT deployed an analytics tool. The category exists so that your preference is recorded in advance — if we add an analytics tool later, we will not enable it for you unless you have consented to the Analytics category, and we will update this Policy (with a new consent version and a fresh prompt) before we do. -------------------------------------------------------------- 2.3 Marketing (consent required — off by default) -------------------------------------------------------------- If you accept the "Marketing" category, we may set cookies that personalise what we say to you in product or email campaigns. CURRENT STATUS: As with Analytics, we have not deployed any marketing cookies at the date of this Policy. Nothing changes for you unless we add such cookies in the future, at which point we will update this Policy and re-prompt under a new consent version before they are enabled. -------------------------------------------------------------- 2.4 Third-party services we integrate -------------------------------------------------------------- Some third-party services set their own cookies when we load them on a page. Where the third-party cookie is strictly necessary for a security or fraud-prevention function, we treat it as a Necessary cookie under clause 2.1. Google reCAPTCHA v3 Set by: Google LLC on auth pages (login, registration, password reset) Purpose: distinguishing human users from bots to prevent account abuse and fraud Category: treated as Necessary because blocking bots is required to secure the Service Information flow: reCAPTCHA may set cookies on the google.com and recaptcha.net domains and transmit interaction signals to Google. See Google's Privacy Policy and reCAPTCHA Terms. Stripe Set by: Stripe Payments Europe Ltd on pages that load Stripe Checkout or Elements (billing, checkout) Purpose: fraud prevention and checkout functionality Category: treated as Necessary on the checkout flow Information flow: Stripe sets cookies on stripe.com. See Stripe's Privacy Policy. We do not use advertising cookies, cross-site trackers, or social-media "like" / share buttons that load third-party scripts. ──────────────────────────────────────────────────────────────── SECTION 3. YOUR CHOICE ──────────────────────────────────────────────────────────────── 3.1 The banner. On your first visit, a banner gives you three options: — Accept all — Accept only necessary — Choose categories (tick Analytics and Marketing individually) 3.2 Changing your mind. You can change your cookie preferences at any time: — by clicking the "Cookies" link in the footer of any page; — or by clearing the cookie_consent cookie in your browser, which will cause the banner to reappear on your next visit; — or by emailing privacy@makrr.ai. Opt-outs take effect immediately. Data already collected before you opt out is not retroactively deleted; contact us if you want retrospective deletion under GDPR Article 17. 3.3 Browser-level control. You can also block or delete cookies directly in your browser. Blocking all cookies from makrr.ai will prevent the Service from working — for example, you will not be able to stay logged in. Information on managing cookies in common browsers: — Chrome: https://support.google.com/chrome/answer/95647 — Firefox: https://support.mozilla.org/kb/enhanced-tracking-protection-firefox-desktop — Safari: https://support.apple.com/en-gb/guide/safari/sfri11471/mac — Edge: https://support.microsoft.com/microsoft-edge/view-cookies-in-microsoft-edge ──────────────────────────────────────────────────────────────── SECTION 4. CONSENT RECORDS ──────────────────────────────────────────────────────────────── When you make a choice on the banner, we record: — the consent version (currently 2026-03-05); — whether you accepted necessary, analytics, marketing; — the source of the consent (banner, settings page, support); — the timestamp; — your user identifier, if you are logged in. This record is kept for three (3) years from the date of your most recent choice (or withdrawal), as evidence of consent under Article 7(1) GDPR. ──────────────────────────────────────────────────────────────── SECTION 5. "DO NOT TRACK" AND GLOBAL PRIVACY CONTROL ──────────────────────────────────────────────────────────────── Our Service does not currently respond to browser "Do Not Track" signals, because there is no consensus on how they should be interpreted. We do respond to the Global Privacy Control (GPC) signal where sent: a GPC header is treated as a withdrawal of consent for Analytics and Marketing categories. ──────────────────────────────────────────────────────────────── SECTION 6. VERSIONING ──────────────────────────────────────────────────────────────── Each material change to this Policy bumps the consent version. On the next page load, the banner reappears and you re-choose. Minor edits (typos, contact-detail updates, clarifications) do not bump the version. ──────────────────────────────────────────────────────────────── SECTION 7. CONTACT ──────────────────────────────────────────────────────────────── Trashify Tech OÜ Registry code: 16495334 Registered office: Gonsiori tn 29-3, Kesklinna linnaosa, 10147 Tallinn, Harju maakond, Estonia Privacy: privacy@makrr.ai Legal: legal@makrr.ai Supervisory authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — info@aki.ee — www.aki.ee ════════════════════════════════════════════════════════════════ Version 1.0 · Effective 2026-04-17 · Consent version 2026-03-05 ════════════════════════════════════════════════════════════════