This policy explains which cookies and similar technologies MaShop uses, what each one does, and how you can control them. It complements the Privacy Policy and the Terms. MaShop is operated by Edeverse.
What cookies and similar technologies are
Cookies are small text files that your browser stores when you visit a site. The site can read them back on later visits, for example to keep you signed in or remember your language. We also use similar browser storage, mainly localStorage and sessionStorage. These hold small pieces of data inside your browser and are not sent to our servers with each request. In this policy, "cookies" covers all of these unless we say otherwise.
Two contexts, two behaviors
We treat our public marketing sites and the signed-in platform differently.
On the marketing sites (the mashop.app website, the documentation site, and the support site), analytics is off by default. Google Analytics loads with all measurement and advertising consent signals set to denied, so it sends only cookieless pings until you decide. A consent banner asks you to accept or decline analytics cookies on your first visit.
On the signed-in platform (the MaShop workspace, plus the admin console our staff uses), there is no cookie banner. Analytics loads with consent granted by default. The basis is the acceptance you gave at signup, when you agreed to the Terms. We chose not to re-prompt you on every workspace load. If you disagree with this, section "Your choices" explains what you can do.
Cookies that are strictly necessary, such as the sign-in cookie, are set in both contexts. You cannot use a signed-in product without them.
Cookies we set
The table lists every cookie our code sets on the sites you use, plus the Google Analytics cookies loaded through our pages. The status column follows the CNIL's distinction between cookies exempt from consent and cookies that need consent.
| Cookie | Purpose | Set by | Duration | Status |
|---|---|---|---|---|
preferred-language |
Remembers your display language, detected from your browser on first visit or chosen in the language switcher | MaShop (first party) | 1 year | Exempt (interface preference) |
mashop_geo_country |
Stores the country code detected from network-level headers, used to preset language and currency defaults | MaShop (first party) | 30 days | Exempt (interface preference) |
mashop-onboarded |
Records that you finished or skipped onboarding, so we can skip a database check on later requests | MaShop (first party) | 1 year | Exempt (technical) |
sb-*-auth-token* |
Keeps you signed in | MaShop (first party, via our authentication library) | Managed by the authentication library; refreshed while you stay signed in | Exempt (authentication) |
maintenance_access |
Lets you keep using the platform during a maintenance window, set only after you enter a valid access code | MaShop (first party) | 30 days | Exempt (technical) |
mashop-cookie-consent |
Records your accept or decline choice for analytics cookies on the marketing sites | MaShop (first party) | 1 year | Exempt (consent record) |
_ga, _ga_* |
Google Analytics visitor and session measurement | Google (third party) | Controlled by Google's tag, not set in our code | Consent required on marketing sites; granted by default when signed in (see above) |
A few notes on this table. The sign-in cookie is scoped to .mashop.app, so you stay signed in when moving between our subdomains. The language cookie set by the marketing-site language switcher uses the same scope, so your choice carries over to the workspace. Our internal admin console, which only Edeverse staff browse, sets one more functional cookie, admin-workspace (1 year), to remember the selected workspace.
Local and session storage
We use browser localStorage for first-party, functional preferences only. These keys stay in your browser and are not sent to our servers. The keys our code writes are:
mashop_app_settings: a cached copy of your language, currency, and formatting settings in the workspace.mashop_exchange_rates: a cached table of currency exchange rates, so prices convert without a refetch.mashop_storefront_config: a local copy of your project settings, saved when you edit them in the workspace.mashop.selectedModel: the model option you picked in the workspace chat.mashop:lastProjectId: the last project you opened, so login can return you to it.mashop:notif-archived: which workspace notifications you archived.mashop_sidebar_open: whether the workspace sidebar is open or collapsed.mashop-onboarding-stepandmashop-onboarding-project: your progress in the onboarding wizard, removed when you finish it.mashop_languageandmashop_currency: cached language and currency preferences on the marketing sites and the admin console.support.csat-dismissed.followed by a ticket reference: records that you dismissed the satisfaction prompt on that support ticket (support site).
The internal admin console also stores staff-only preferences under the same pattern, such as dismissed deploy notices.
One disclosure for completeness: the platform code contains an older first-party page-view tracker. It runs only if a legacy key named mashop_cookies_accepted is set to true. Nothing in the product sets that key, so the tracker is inactive, and its session identifier (mashop_session_id) is not written in practice.
You can clear all of these through your browser's site-data controls at any time. The workspace keeps working; you only lose the saved preferences.
Analytics and error monitoring
We use Google Analytics 4 on all our sites. Our configuration enables IP anonymization (anonymize_ip). We load it with Google Consent Mode v2 in its advanced form. On the marketing sites, all measurement and advertising consent signals default to denied, and Google's ads data redaction is on in the denied state. If you accept, your saved choice in mashop-cookie-consent restores full consent on later visits. On the signed-in platform and admin console, the consent default is granted, as described above.
The workspace also uses Sentry for error and performance monitoring. Sentry activates only when its monitoring key is configured in our deployment. When active, it traces a sample of page loads (10 percent in production) and uses Session Replay: it records 10 percent of sessions and any session where an error occurs, so we can reconstruct what went wrong. How our providers handle this data is covered in the Privacy Policy.
We do not run advertising cookies, retargeting pixels, or social-media tracking widgets on any of our sites today.
Your choices
On the marketing sites, the banner lets you accept or decline analytics cookies. Your choice is stored for 1 year. We do not currently offer a control to reopen the banner after you choose. If you want to change your decision, delete the mashop-cookie-consent cookie in your browser; the banner appears again on your next visit.
On the signed-in platform, we do not currently offer an in-product analytics toggle. You can block or delete cookies through your browser, or email us and we will help. Note that blocking or deleting the sb-*-auth-token* cookie signs you out.
All modern browsers let you block or delete cookies, per site or globally, through their settings. Blocking the strictly necessary cookies listed above will break sign-in and language persistence.
Our sites do not currently read Global Privacy Control or Do Not Track signals. Sending them changes nothing today. Your effective controls are the banner and your browser settings.
Changes to this policy
If we add a cookie, remove one, or change what an existing one does, we will update this page and the date shown at the top. Check back if you want to track changes.
Contact
For any question about cookies or this policy, email contact@edeverse.com. For how we handle personal data more broadly, see the Privacy Policy.