Legal

Privacy Policy

Cookies and similar technologies we use, and how to control them.

Last updated: 25 March 2026

What this policy covers

This Cookie Policy explains how Marketing So High ("MSH," "we," "us") uses cookies and similar technologies on:
- marketingsohigh.com (our marketing website)
- app.marketingsohigh.com (the MSH product dashboard)

This policy works alongside our Privacy Policy. If you are a data subject in the EU, UK, EEA, or a jurisdiction with ePrivacy rules, you must consent to non-essential cookies before we set them.

What cookies are

A cookie is a small text file a website stores on your browser. Similar technologies include:
- Local storage — data stored in your browser (e.g., authentication tokens)
- Session storage — short-lived data cleared when you close the tab
- Pixels / beacons — small invisible images used for analytics
- Server-side session data — identified by a cookie in your browser

This policy covers all of them, even though we say "cookies" for short.

Cookie categories

1. Strictly necessary cookies (always on; no consent required)

These are essential for the Service to work. You cannot turn them off without breaking core functionality.

Name Purpose Duration Set by
msh-auth Authentication — keeps you logged in Session + 14 days (if "remember me") MSH
msh-csrf Protects against Cross-Site Request Forgery Session MSH
__Host-next-auth.csrf-token NextAuth CSRF protection Session MSH (via NextAuth)
sb-access-token Supabase session (refreshed automatically) Session Supabase
sb-refresh-token Supabase refresh token 30 days Supabase
__cf_bm Cloudflare bot protection (if enabled) 30 mins Cloudflare

Lawful basis: Strictly necessary — exempt from consent under ePrivacy Directive Art. 5(3).

2. Preference cookies (consent required)

Remember your choices so the Service feels consistent.

Name Purpose Duration
msh-theme Light/dark mode preference 1 year
msh-sidebar-state Dashboard sidebar expanded/collapsed 1 year
msh-locale Interface language 1 year
msh-last-org Last active workspace 1 year

Lawful basis: Consent (via cookie banner). Turning these off means your preferences reset each session.

3. Analytics cookies (consent required)

Help us understand how the product is used so we can improve it.

Name Purpose Duration Set by
_ga Google Analytics — distinguishes users (with IP anonymization enabled) 2 years Google
_ga_* Google Analytics session state 2 years Google
[TBD internal analytics] Product feature usage 1 year MSH

Lawful basis: Consent. We use Google Analytics 4 with IP anonymization enabled and Google Signals disabled — we do not combine your Google Analytics activity with your Google ad profile.

We do NOT use:
- Advertising cookies
- Cross-site tracking cookies
- Social media plugin cookies (Facebook Pixel, LinkedIn Insight, etc.)
- Remarketing / retargeting pixels

If these are ever added in the future, we'll update this policy and require fresh consent before activation.

Managing cookies

Cookie consent banner

When you first visit the site, a banner (powered by Complianz) asks for your consent. You can:
- Accept all — enables all cookie categories
- Accept only necessary — only strictly-necessary cookies are set
- Customize — enable/disable per category

Your choice is stored for 6 months, after which the banner re-appears.

Changing your preferences later

You can change your cookie choices at any time:
- Click the "Cookie Preferences" link in the website footer
- In the dashboard: Settings → Privacy → Cookie Preferences
- Or clear your browser's cookies for our domains and visit again

Browser-level controls

You can also manage cookies in your browser:
- Chrome: Settings → Privacy and security → Cookies
- Firefox: Settings → Privacy & Security → Cookies
- Safari: Preferences → Privacy → Cookies
- Edge: Settings → Cookies and site permissions

Note: blocking strictly necessary cookies will break login and other core features.

Global Privacy Control (GPC)

If your browser sends the Global Privacy Control signal (Sec-GPC: 1 header), we automatically treat it as an opt-out of non-essential cookies, per CPRA and equivalent laws. You don't need to click anything.

"Do Not Track" (DNT)

Some browsers send a "Do Not Track" signal. Industry consensus is that DNT is not a reliable standard, so most services (including ours) do not respond to it. We do respond to GPC (which replaced DNT in practice).

Third-party cookies and cross-border transfers

Some cookies are set by third-party services we embed (Google Analytics, Stripe checkout, Cloudflare). When they do, your data may be transferred to those providers' jurisdictions (typically the US). We rely on Standard Contractual Clauses for transfers from the EU/UK to non-adequacy countries — see our sub-processor list for each provider's details.

Cookies from pages embedded in MSH

If you embed external content in your MSH workspace (e.g., preview a YouTube video, view a tweet), that external content may set its own cookies. Those are governed by the respective provider's cookie policy, not ours.

Changes to this policy

We update this policy when our cookie usage changes. Material changes will be announced by email to registered users at least 30 days before they take effect. The latest version is always here.

Contact

Questions? Email privacy@marketingsohigh.com.


Change history

Date Version Change
2026-04-16 1.0 Initial dedicated cookie policy (previously covered in Privacy Policy Section 10)