Merco · Legal
Cookies and browser storage
Preparation draft · 27 September 2026 · 2026-09-27-draft-2
01Necessary storage
Authentication, security and a workspace selection you request use necessary storage. Rejecting optional storage leaves these functions available.
- Auth.js session, CSRF and callback cookies: sign-in and protection. Exact deployed names and lifetimes must be confirmed before publication.
- merco_active_org: your selected organisation, HttpOnly, SameSite=Lax, maximum one year.
- _merco_imp_uid and _merco_imp_name: authorised staff support sessions, maximum four hours.
- merco_privacy: signed HttpOnly preference/map choices and random receipt identifier, six months; no advertising profile. merco_privacy_denied: necessary six-month withdrawal marker if a save fails.
- merco_legal: signed user-bound acceptance check, two hours; acceptance history is stored separately on the server.
02Optional interface preferences
Optional local/session storage for density, sidebar state, layouts, dismissed introductions, animations and previous visits is read or written only after a saved affirmative preference choice. Refusing leaves the core service usable. Withdrawal removes these Merco entries in this browser. Other devices keep their own choice. Local storage has no automatic browser expiry; session storage normally ends with the browser session.
- dash-density; sidebar-collapsed; merco.casedesk.layout.v4
- merco.overview.lastVisit and merco.overview.window
- merco:onb:*, merco:ms:*, merco:appstat:*
- merco:pwa-install-dismissed; merco:supplier-kbd-intro-seen; merco:booted
03Optional external maps
Mapbox maps start only after your separate affirmative map choice. Mapbox receives IP, device and map-request data. The installed SDK can use mapbox.eventData.* local-storage entries for telemetry identifiers and dispatch state; that storage has no automatic browser expiry. Additional performance metrics are disabled. Withdrawal stops the maps and removes these entries; a reload stops remaining SDK queues. Lists, forms and uploads remain available without the external map. See the privacy notice and provider register for processing and transfers.
04External features
The application currently has no general Google Analytics or advertising-pixel integration. Security logs and in-product usage signals still exist. Payment features may send IP/device information to their providers. Their deployed storage behaviour must be audited before production activation. Optional tracking or embeds must not start before valid consent. The preference choice does not authorise additional tracking categories.
05Change your choice
Use Cookie settings in the footer or Settings → Privacy to accept, reject or withdraw with the same simple steps. Choice evidence records a random receipt ID, time, language, version, notice hash and both choices; no IP address or browser fingerprint is collected for that evidence. Evidence expires after twelve months. A failed save does not enable optional browser storage.
Clearing browser storage does not delete account or order records. Use a privacy request for server-side data. Optional email marketing is a separate choice.