Cookies and similar technologies we use, and how to control them.
Last updated: 25 March 2026
This Cookie Policy explains how Marketing So High ("MSH," "we," "us") uses cookies and similar technologies on:
- marketingsohigh.com (our marketing website)
- app.marketingsohigh.com (the MSH product dashboard)
This policy works alongside our Privacy Policy. If you are a data subject in the EU, UK, EEA, or a jurisdiction with ePrivacy rules, you must consent to non-essential cookies before we set them.
A cookie is a small text file a website stores on your browser. Similar technologies include:
- Local storage — data stored in your browser (e.g., authentication tokens)
- Session storage — short-lived data cleared when you close the tab
- Pixels / beacons — small invisible images used for analytics
- Server-side session data — identified by a cookie in your browser
This policy covers all of them, even though we say "cookies" for short.
These are essential for the Service to work. You cannot turn them off without breaking core functionality.
| Name | Purpose | Duration | Set by |
|---|---|---|---|
msh-auth |
Authentication — keeps you logged in | Session + 14 days (if "remember me") | MSH |
msh-csrf |
Protects against Cross-Site Request Forgery | Session | MSH |
__Host-next-auth.csrf-token |
NextAuth CSRF protection | Session | MSH (via NextAuth) |
sb-access-token |
Supabase session (refreshed automatically) | Session | Supabase |
sb-refresh-token |
Supabase refresh token | 30 days | Supabase |
__cf_bm |
Cloudflare bot protection (if enabled) | 30 mins | Cloudflare |
Lawful basis: Strictly necessary — exempt from consent under ePrivacy Directive Art. 5(3).
Remember your choices so the Service feels consistent.
| Name | Purpose | Duration |
|---|---|---|
msh-theme |
Light/dark mode preference | 1 year |
msh-sidebar-state |
Dashboard sidebar expanded/collapsed | 1 year |
msh-locale |
Interface language | 1 year |
msh-last-org |
Last active workspace | 1 year |
Lawful basis: Consent (via cookie banner). Turning these off means your preferences reset each session.
Help us understand how the product is used so we can improve it.
| Name | Purpose | Duration | Set by |
|---|---|---|---|
_ga |
Google Analytics — distinguishes users (with IP anonymization enabled) | 2 years | |
_ga_* |
Google Analytics session state | 2 years | |
| [TBD internal analytics] | Product feature usage | 1 year | MSH |
Lawful basis: Consent. We use Google Analytics 4 with IP anonymization enabled and Google Signals disabled — we do not combine your Google Analytics activity with your Google ad profile.
We do NOT use:
- Advertising cookies
- Cross-site tracking cookies
- Social media plugin cookies (Facebook Pixel, LinkedIn Insight, etc.)
- Remarketing / retargeting pixels
If these are ever added in the future, we'll update this policy and require fresh consent before activation.
When you first visit the site, a banner (powered by Complianz) asks for your consent. You can:
- Accept all — enables all cookie categories
- Accept only necessary — only strictly-necessary cookies are set
- Customize — enable/disable per category
Your choice is stored for 6 months, after which the banner re-appears.
You can change your cookie choices at any time:
- Click the "Cookie Preferences" link in the website footer
- In the dashboard: Settings → Privacy → Cookie Preferences
- Or clear your browser's cookies for our domains and visit again
You can also manage cookies in your browser:
- Chrome: Settings → Privacy and security → Cookies
- Firefox: Settings → Privacy & Security → Cookies
- Safari: Preferences → Privacy → Cookies
- Edge: Settings → Cookies and site permissions
Note: blocking strictly necessary cookies will break login and other core features.
If your browser sends the Global Privacy Control signal (Sec-GPC: 1 header), we automatically treat it as an opt-out of non-essential cookies, per CPRA and equivalent laws. You don't need to click anything.
Some browsers send a "Do Not Track" signal. Industry consensus is that DNT is not a reliable standard, so most services (including ours) do not respond to it. We do respond to GPC (which replaced DNT in practice).
Some cookies are set by third-party services we embed (Google Analytics, Stripe checkout, Cloudflare). When they do, your data may be transferred to those providers' jurisdictions (typically the US). We rely on Standard Contractual Clauses for transfers from the EU/UK to non-adequacy countries — see our sub-processor list for each provider's details.
If you embed external content in your MSH workspace (e.g., preview a YouTube video, view a tweet), that external content may set its own cookies. Those are governed by the respective provider's cookie policy, not ours.
We update this policy when our cookie usage changes. Material changes will be announced by email to registered users at least 30 days before they take effect. The latest version is always here.
Questions? Email privacy@marketingsohigh.com.
| Date | Version | Change |
|---|---|---|
| 2026-04-16 | 1.0 | Initial dedicated cookie policy (previously covered in Privacy Policy Section 10) |