Last updated: September 24, 2026

Cookie Policy

Every cookie Markuva sets, how long it lives, and what it is for

This page lists the cookies and similar identifiers that exist in Markuva's code today. Categories marked as requiring consent are only set after you accept them in the cookie banner; you can change your choice at any time in Settings.

Essential (no consent required)

CookieDurationPurpose
sb-*-auth-tokenSession / up to 1 yearKeeps you signed in (Supabase Auth).
locale1 yearRemembers your language.
markuva_consent_v21 yearStores your cookie choice for each category (the legacy markuva_consent is migrated and removed).
markuva_ref30 daysReferral code from an invitation link, so the person who invited you gets credit.
_la1 hourThrottles the update of your last-activity timestamp.
__mk_signup10 minutesSet once when your account is created, read by the next page to record the signup, then deleted.

First-party attribution (no consent required)

CookieDurationPurpose
markuva_attr400 daysSet by our server: campaign parameters (utm_*), click identifiers (gclid, fbclid, msclkid), landing page, referring site and date of your first and most recent arrival. Used only to measure where our own signups and purchases come from. Not sent to third parties when written.
markuva_utm1 hourLegacy copy of campaign parameters kept across the Google sign-in redirect.
markuva_pages24 hoursLegacy copy of landing page and referring site kept across the sign-in redirect.

Analytics (requires consent)

CookieDurationPurpose
_ga, _ga_*2 yearsGoogle Analytics 4 — distinguishes visitors and sessions. Without your consent GA4 receives only a cookieless ping (IP address, browser and page, no cookie and no account identifier) used for aggregate modelling.
Vercel Web Analytics / Speed InsightsSessionPage views and performance metrics. Load only with Analytics consent.

Advertising (requires consent)

CookieDurationPurpose
_fbp90 daysMeta Pixel — identifies your browser to measure our Meta campaigns. Set only with Advertising consent and only once our Pixel is active.
_fbc90 daysMeta Pixel — stores the click identifier from a Meta ad you clicked.
_gcl_au, _gcl_aw90 daysGoogle Ads — measures conversions from our Google campaigns. Set only with Advertising consent and only once our Google Ads tag is active.

Events sent to Meta from our server

Separately from cookies, when you have an account Markuva sends Meta the events "account created", "viewed the brand kit offer", "started checkout" and "purchased" from our server (Conversions API). Each event carries your email and account id as SHA-256 hashes, the Meta click identifier when there is one, your IP address and browser, and the purchase amount and currency. The purpose is to measure and optimise Markuva's advertising. The legal basis is legitimate interest, so the cookie banner does not switch it off — you can object at any time in Settings, and from that moment no event of your account is sent. Events already sent cannot be recalled. Nothing is sent until our Meta integration is activated; this section describes what the code does once it is.

Change your choice

You can review your cookie categories and the Meta objection in Settings.

Open Settings