Small files, clear purpose.
This Cookie Policy explains what cookies and similar technologies MeetWho uses, why we use them, how long they last, and how you can accept, reject or change your preferences at any time.
What is a cookie?
A cookie is a small text file that a website places on your device to remember information about you, your device or your session. Similar technologies include localStorage, sessionStorage, IndexedDB, service workers, and pixels — this Policy covers all of them.
Categories we use
- Strictly necessary. Required to authenticate you, keep you signed in, remember your language and theme, protect against CSRF and abuse, and route requests. Legal basis: contract / legitimate interests. Consent is not required under GDPR Art. 5(3) ePrivacy exemption.
- Functional. Remember preferences you actively set (notification opt-in, sidebar collapsed state, filters). Legal basis: consent where the preference is not required to deliver the service you asked for.
- Analytics. Google Analytics 4 with IP anonymisation and no advertising signals — aggregated page views, feature usage, retention. Legal basis: consent.
- Product research. Hotjar heatmaps and anonymised session recordings with keystroke suppression and PII masking. Legal basis: consent.
- Advertising. None. We do not run ad-tech cookies.
Cookie table
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
sb-*-auth-token | meetwho.app | Authentication session | Strictly necessary | 1 year |
sb-*-refresh-token | meetwho.app | Refresh access tokens | Strictly necessary | 1 year |
mw_locale | meetwho.app | Selected language (en / tr) | Strictly necessary | 1 year |
mw_theme | meetwho.app | Light/dark preference | Functional | 1 year |
mw_cookie_consent | meetwho.app | Your cookie choices | Strictly necessary | 12 months |
_ga, _ga_* | Google Analytics | Distinguish users, sessions | Analytics | 2 years |
_hjSessionUser_* | Hotjar | Persistent Hotjar ID | Product research | 1 year |
_hjSession_* | Hotjar | Current session data | Product research | 30 minutes |
__cf_bm, cf_clearance | Cloudflare | Bot management, DDoS protection | Strictly necessary | 30 minutes – 1 year |
Names beginning with an asterisk are set by the provider with a random suffix per project or session.
How to manage cookies
- Use the cookie banner shown the first time you visit — Accept, Reject non-essential, or open Preferences.
- Change your mind at any time via the “Cookie preferences” link in the footer.
- Browser settings let you block or delete cookies for meetwho.app entirely. Note: blocking strictly necessary cookies will sign you out and disable the service.
- Google Analytics opt-out: install the Google Analytics Opt-out Browser Add-on.
- Hotjar opt-out: visit hotjar.com/legal/compliance/opt-out.
Do Not Track & Global Privacy Control
We honour the Global Privacy Control (GPC) signal for California users under the CPRA — receiving a GPC signal is treated as a request to opt out of the sale/sharing of personal information. We do not currently respond to DNT headers because there is no consistent industry standard.
Changes
We update this Policy when we add, remove or change cookies. Material changes are announced in-product. See also our Privacy Policy.
Contact
Cookie questions: privacy@meetwho.app.
