MongoQUI
  • Pricing
  • Features
  • Download
Sign inDownload
Cookies

A small, honest list of cookies.

Draft: to be reviewed by counsel before publication.We use a small set of cookies to keep you signed in, keep the site secure, remember a few interface choices, and measure website traffic and ad conversions with Google tools.

Effective
2026-04-19
Updated
2026-09-24
Law
United Arab Emirates

Draft legal copy: to be reviewed by qualified counsel before publication. Do not treat as final.

Contents
  1. 01Introduction
  2. 02Strictly necessary cookies
  3. 03Performance & analytics cookies
  4. 04Functional cookies
  5. 05Marketing cookies
  6. 06Third-party cookies
  7. 07The full cookie table
  8. 08How to manage cookies
  9. 09DNT & Global Privacy Control
  10. 10Updates to this policy
  11. 11Contact

01 · IntroductionIntroduction

This Cookie Policy describes how MongoQUI ("MongoQUI", "we", "our", "us") uses cookies and similar technologies on our marketing website (mongoqui.com), our documentation portal (docs.mongoqui.com), our web application (app.mongoqui.com), our billing portal (license.mongoqui.com), and the shared report viewer. It supplements the Privacy Policy and should be read together with it.

A cookie is a small text file that a website places on your browser's storage area when you visit. Cookies can be first-party (set by the domain you are visiting) or third-party (set by a different domain referenced by the page). A cookie can be a session cookie (deleted when you close the browser) or a persistent cookie (retained for a stated duration). Cookies have no access to your hard drive or to files outside the browser.

Where this policy refers to "cookies", it also includes similar technologies that perform an equivalent function, such as browser local storage, session storage, and analytics tags. This policy covers those technologies in the same way as the equivalent cookie.

Counsel to confirm: whether the definition of "cookies and similar technologies" requires a more detailed enumeration of local storage, session storage, and device fingerprinting under the UAE PDPL, the EU ePrivacy Directive 2002/58/EC, and the UK PECR.

02 · Strictly necessary cookiesStrictly necessary cookies

These cookies are required for the Services to function. They do not require consent under the EU ePrivacy Directive or the UK Privacy and Electronic Communications Regulations (PECR), because they are strictly necessary to provide the service that you explicitly requested. You can block all cookies at the browser level, but doing so will break sign-in.

  • Refresh token.
    • Name: refresh_token
    • Purpose: keeps you signed in by letting the app request new access tokens from our authentication service. Set by our authentication service as HttpOnly and Secure, with SameSite=Strict (or SameSite=None when the app and the authentication service are on different sites).
    • Duration: 30 days.
  • Web app access token.
    • Name: token (uat_token on our test environment)
    • Purpose: holds the access token the MongoQUI web app sends with its API requests. Set with SameSite=Strict; it is readable by the web app's own scripts (not HttpOnly).
    • Duration: 7 days.
  • Shared report viewer settings.
    • Names: mongoqui_api_endpoint, mongoqui_auth_token, mongoqui_org_id, mongoqui_sales_channel
    • Purpose: let the shared report viewer call our API with your sign-in token and active organisation, and record whether you opened it from the desktop app or the web app. Set with SameSite=Lax.
    • Duration: 30 days.

These cookies are set by MongoQUI services on mongoqui.com subdomains; they are first-party.

Counsel to confirm: the exact cookie names, retention periods, SameSite posture, and whether the 12-month consent-record retention aligns with EU guidance (typical range 6–13 months).

03 · Performance & analytics cookiesPerformance and analytics cookies

We use Google Analytics 4 through Google Tag Manager to measure aggregate website traffic and download clicks on mongoqui.com. GA4 sets first-party cookies _ga and _ga_<id> (currently _ga_S75JTRQ8ES) that last up to 2 years.

  • Google Analytics 4. The Google Tag Manager and Google Analytics scripts load on every page of mongoqui.com. The _ga cookies hold a random identifier that lets Google Analytics count visits and sessions; they are set on mongoqui.com by Google's script, and Google receives the measurement data, including your IP address and browser details.
Counsel to confirm: whether web analytics meets the relevant "cookieless analytics" exemption under EDPB and UK ICO guidance, and whether to offer a more granular opt-out for EEA visitors even though no consent is legally required.

04 · Functional cookiesFunctional cookies

These cookies remember choices you make in our interfaces.

  • License portal sidebar.
    • Name: sidebar:state
    • Purpose: remembers whether the sidebar in the license and billing portal (license.mongoqui.com) is open or collapsed. It contains no Personal Data.
    • Duration: 7 days.
Counsel to confirm: whether theme and org-selector cookies qualify as "strictly necessary" under EDPB guidance on user-interface-preference cookies, and whether they should be relocated to Section 2.

05 · Marketing cookiesMarketing cookies

Our website loads a Google Ads tag through Google Tag Manager on every page of mongoqui.com. It sends page views and download clicks to Google Ads so that we can measure conversions from our ads. Google's Conversion Linker sets the first-party cookie _gcl_au (90 days), and _gcl_aw (90 days) if you arrive from a Google ad. Google may also set or read its own cookies on google.com and doubleclick.net.

We do not embed social-media tracking pixels on our sites. If we add another marketing or advertising tag, we will update this policy, list the relevant cookies with vendor, purpose, and retention, and ask for any consent the law requires before a marketing cookie is set.

Counsel to confirm: the policy for opt-in consent under GDPR / UK PECR / UAE PDPL before any future marketing cookie is activated.

06 · Third-party cookiesThird-party cookies

In a small number of places, a third party may set a cookie from its own domain. We list every such case below.

  • Stripe (checkout). When you are in the billing portal and initiate a payment, Stripe's embedded checkout may set cookies required for fraud prevention and session continuity on stripe.com. These are strictly necessary for the payment flow. Stripe's cookie and privacy notices are authoritative: https://stripe.com/privacy and https://stripe.com/cookies-policy/legal.
  • Bot protection. On the sign-in and registration forms we use Cloudflare Turnstile to protect against automated abuse. Turnstile may set cookies; Cloudflare sets and names them.
  • Google (analytics and ads). The Google Tag Manager, Google Analytics, and Google Ads scripts load from Google's servers on every page of mongoqui.com. See Sections 3 and 5 for the cookies they use.
  • Desktop auto-update. The desktop app periodically checks our release manifest at downloads.mongoqui.com. That request sets no cookies and is outside the browser context of our websites.

We do not embed social-media share buttons, YouTube iframes, or similar widgets on our pages.

Counsel to confirm: whether Turnstile's interaction with page-level consent banners requires an explicit notice prior to the form rendering, and whether Stripe's cookies should be listed individually in the table below or covered by the link to Stripe's own notice.

07 · The full cookie tableThe full cookie table

A single table of the cookies described above, by cookie.

CookieSet by / wherePurposeDuration
refresh_tokenMongoQUI authentication service (first-party)Keeps you signed in by issuing new access tokens; HttpOnly, Secure, SameSite=Strict (SameSite=None when cross-site)30 days
token (uat_token on our test environment)MongoQUI web app (first-party)Access token sent with web app API requests; SameSite=Strict7 days
mongoqui_api_endpoint, mongoqui_auth_token, mongoqui_org_id, mongoqui_sales_channelMongoQUI shared report viewer (first-party)Lets the report viewer call our API with your sign-in and organisation, and records whether you came from the desktop or web app; SameSite=Lax30 days
sidebar:stateMongoQUI license portal, license.mongoqui.com (first-party)Remembers whether the sidebar is open or collapsed7 days
_gaGoogle Analytics 4 on mongoqui.com (first-party, set by Google's script)Random identifier used to count visits and sessionsUp to 2 years
_ga_S75JTRQ8ESGoogle Analytics 4 on mongoqui.com (first-party, set by Google's script)Keeps session state for Google Analytics measurementUp to 2 years
_gcl_au, _gcl_awGoogle Ads Conversion Linker on mongoqui.com (first-party, set by Google's script)Measures download conversions from our Google Ads; _gcl_aw is set only if you arrive from a Google ad90 days
Cloudflare Turnstile cookiesCloudflare, on the sign-in and registration formsBot check that protects sign-in and registrationSet by Cloudflare; see Cloudflare's notice
Stripe checkout cookiesStripe, Inc., inside checkoutFraud prevention and session continuity inside checkoutAs described in Stripe's notice
Counsel to confirm: final cookie names, durations, and the inclusion of any additional operational cookies not yet listed. Any change made between counsel review and publication must be reflected in the banner's cookie-scanner configuration.

08 · How to manage cookiesHow to manage cookies

Our sites do not currently show a cookie banner or offer a cookie preference centre. You can control cookies with your browser settings and, for Google Analytics, with Google's opt-out add-on.

8.1 Browser controls

You can manage or delete cookies directly in your browser. The steps below are correct at the time of writing; please consult your browser's current help for the definitive path.

  • Google Chrome: Settings → Privacy and security → Third-party cookies (and Site data).
  • Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data.
  • Apple Safari: Preferences → Privacy → Manage Website Data.
  • Microsoft Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data.
  • Brave, Vivaldi, Arc, and other Chromium-based browsers: similar paths; consult each browser's help.

Blocking all cookies will prevent you from signing in. Blocking only non-essential cookies has no effect on core functionality.

8.2 Google Analytics opt-out

To stop Google Analytics from measuring your visits, install Google's Google Analytics Opt-out Browser Add-on from https://tools.google.com/dlpage/gaoptout, or block cookies and scripts from Google in your browser.

8.3 Mobile devices

On iOS and Android, in-app web views honour the browser-level cookie settings for the system browser on each platform.

Counsel to confirm: whether the "Cookie settings" footer link and in-account settings entry are in place on all subdomains before publication, and whether the banner needs a region-specific first-load behaviour (EEA/UK opt-in vs rest-of-world implied consent).

09 · DNT & Global Privacy ControlDo Not Track and Global Privacy Control

Our website does not currently detect or act on the browser-level Do Not Track (DNT) or Global Privacy Control (GPC) signals. The Google Analytics and Google Ads tags load whether or not your browser sends them. To stop Google Analytics measurement, use the controls in Section 8.

Counsel to confirm: whether DNT treatment should be more conservative (opt-out of Functional + Performance), whether GPC handling should be documented in the Privacy Policy in addition to here, and whether a "Do Not Sell or Share My Personal Information" link is required on the site footer despite the fact that we do not sell or share.

10 · Updates to this policyUpdates to this policy

We will update this Cookie Policy when our cookie usage changes, when we add a new Sub-processor that sets cookies, or when we change durations. When we make a material change:

  • we will update the "Last updated" date at the top of this document; and
  • for changes that materially affect your rights, we will notify registered users by email.

Minor wording or typographic corrections may be made without separate notice.

Counsel to confirm: notice mechanism for material change (30-day banner re-prompt is common), and whether email notice is required in addition to the in-app banner.

11 · ContactContact

  • Privacy enquiries and cookie questions: privacy@mongoqui.com
  • General support: support@mongoqui.com
  • Postal address: Fahid Digital Ventures LLC, Sharjah Media City Free Zone, Sharjah, United Arab Emirates.

If you believe we are using cookies in a way that breaches applicable law, you may contact the supervisory authority in your country (see Privacy Policy, Section 13.4).

Contact
Data protection
privacy@mongoqui.com
Legal notices
legal@mongoqui.com
Postal
Fahid Digital Ventures LLC, Sharjah Media City Free Zone, Sharjah, United Arab Emirates
Fahid Digital Ventures LLC · Sharjah Media City Free Zone, Sharjah, United Arab Emirates · Review cycle 2026-04-19
    MongoQUI

    The modern MongoDB workspace. Query, analyse and share MongoDB data from one keyboard-first desktop app. Start free, then pick the paid plan that fits your work.

    Product
    • Features
    • Pricing
    • Download
    • Changelog
    • Security
    Resources
    • Documentation
    • Web app
    • Blog
    • Support
    Company
    • About
    • Customers
    • Startups
    • Careers
    • Contact
    Legal
    • Privacy Policy
    • Terms of Service
    • Cookie Policy
    MongoQUI
    © 2026 MongoQUI · all rights reserved
    Made in the UAE
    Launch web app