01 · IntroductionIntroduction
This Cookie Policy describes how MongoQUI ("MongoQUI", "we", "our", "us") uses cookies and similar technologies on our marketing website (mongoqui.com), our documentation portal (docs.mongoqui.com), our web application (app.mongoqui.com), our billing portal (license.mongoqui.com), and the shared report viewer. It supplements the Privacy Policy and should be read together with it.
A cookie is a small text file that a website places on your browser's storage area when you visit. Cookies can be first-party (set by the domain you are visiting) or third-party (set by a different domain referenced by the page). A cookie can be a session cookie (deleted when you close the browser) or a persistent cookie (retained for a stated duration). Cookies have no access to your hard drive or to files outside the browser.
Where this policy refers to "cookies", it also includes similar technologies that perform an equivalent function, such as browser local storage, session storage, and analytics tags. This policy covers those technologies in the same way as the equivalent cookie.
02 · Strictly necessary cookiesStrictly necessary cookies
These cookies are required for the Services to function. They do not require consent under the EU ePrivacy Directive or the UK Privacy and Electronic Communications Regulations (PECR), because they are strictly necessary to provide the service that you explicitly requested. You can block all cookies at the browser level, but doing so will break sign-in.
- Refresh token.
- Name:
refresh_token - Purpose: keeps you signed in by letting the app request new access tokens from our authentication service. Set by our authentication service as HttpOnly and Secure, with SameSite=Strict (or SameSite=None when the app and the authentication service are on different sites).
- Duration: 30 days.
- Name:
- Web app access token.
- Name:
token(uat_tokenon our test environment) - Purpose: holds the access token the MongoQUI web app sends with its API requests. Set with SameSite=Strict; it is readable by the web app's own scripts (not HttpOnly).
- Duration: 7 days.
- Name:
- Shared report viewer settings.
- Names:
mongoqui_api_endpoint,mongoqui_auth_token,mongoqui_org_id,mongoqui_sales_channel - Purpose: let the shared report viewer call our API with your sign-in token and active organisation, and record whether you opened it from the desktop app or the web app. Set with SameSite=Lax.
- Duration: 30 days.
- Names:
These cookies are set by MongoQUI services on mongoqui.com subdomains; they are first-party.
03 · Performance & analytics cookiesPerformance and analytics cookies
We use Google Analytics 4 through Google Tag Manager to measure aggregate website traffic and download clicks on mongoqui.com. GA4 sets first-party cookies _ga and _ga_<id> (currently _ga_S75JTRQ8ES) that last up to 2 years.
- Google Analytics 4. The Google Tag Manager and Google Analytics scripts load on every page of
mongoqui.com. The_gacookies hold a random identifier that lets Google Analytics count visits and sessions; they are set onmongoqui.comby Google's script, and Google receives the measurement data, including your IP address and browser details.
04 · Functional cookiesFunctional cookies
These cookies remember choices you make in our interfaces.
- License portal sidebar.
- Name:
sidebar:state - Purpose: remembers whether the sidebar in the license and billing portal (
license.mongoqui.com) is open or collapsed. It contains no Personal Data. - Duration: 7 days.
- Name:
05 · Marketing cookiesMarketing cookies
Our website loads a Google Ads tag through Google Tag Manager on every page of mongoqui.com. It sends page views and download clicks to Google Ads so that we can measure conversions from our ads. Google's Conversion Linker sets the first-party cookie _gcl_au (90 days), and _gcl_aw (90 days) if you arrive from a Google ad. Google may also set or read its own cookies on google.com and doubleclick.net.
We do not embed social-media tracking pixels on our sites. If we add another marketing or advertising tag, we will update this policy, list the relevant cookies with vendor, purpose, and retention, and ask for any consent the law requires before a marketing cookie is set.
06 · Third-party cookiesThird-party cookies
In a small number of places, a third party may set a cookie from its own domain. We list every such case below.
- Stripe (checkout). When you are in the billing portal and initiate a payment, Stripe's embedded checkout may set cookies required for fraud prevention and session continuity on
stripe.com. These are strictly necessary for the payment flow. Stripe's cookie and privacy notices are authoritative:https://stripe.com/privacyandhttps://stripe.com/cookies-policy/legal. - Bot protection. On the sign-in and registration forms we use Cloudflare Turnstile to protect against automated abuse. Turnstile may set cookies; Cloudflare sets and names them.
- Google (analytics and ads). The Google Tag Manager, Google Analytics, and Google Ads scripts load from Google's servers on every page of
mongoqui.com. See Sections 3 and 5 for the cookies they use. - Desktop auto-update. The desktop app periodically checks our release manifest at downloads.mongoqui.com. That request sets no cookies and is outside the browser context of our websites.
We do not embed social-media share buttons, YouTube iframes, or similar widgets on our pages.
07 · The full cookie tableThe full cookie table
A single table of the cookies described above, by cookie.
| Cookie | Set by / where | Purpose | Duration |
|---|---|---|---|
refresh_token | MongoQUI authentication service (first-party) | Keeps you signed in by issuing new access tokens; HttpOnly, Secure, SameSite=Strict (SameSite=None when cross-site) | 30 days |
token (uat_token on our test environment) | MongoQUI web app (first-party) | Access token sent with web app API requests; SameSite=Strict | 7 days |
mongoqui_api_endpoint, mongoqui_auth_token, mongoqui_org_id, mongoqui_sales_channel | MongoQUI shared report viewer (first-party) | Lets the report viewer call our API with your sign-in and organisation, and records whether you came from the desktop or web app; SameSite=Lax | 30 days |
sidebar:state | MongoQUI license portal, license.mongoqui.com (first-party) | Remembers whether the sidebar is open or collapsed | 7 days |
_ga | Google Analytics 4 on mongoqui.com (first-party, set by Google's script) | Random identifier used to count visits and sessions | Up to 2 years |
_ga_S75JTRQ8ES | Google Analytics 4 on mongoqui.com (first-party, set by Google's script) | Keeps session state for Google Analytics measurement | Up to 2 years |
_gcl_au, _gcl_aw | Google Ads Conversion Linker on mongoqui.com (first-party, set by Google's script) | Measures download conversions from our Google Ads; _gcl_aw is set only if you arrive from a Google ad | 90 days |
| Cloudflare Turnstile cookies | Cloudflare, on the sign-in and registration forms | Bot check that protects sign-in and registration | Set by Cloudflare; see Cloudflare's notice |
| Stripe checkout cookies | Stripe, Inc., inside checkout | Fraud prevention and session continuity inside checkout | As described in Stripe's notice |
08 · How to manage cookiesHow to manage cookies
Our sites do not currently show a cookie banner or offer a cookie preference centre. You can control cookies with your browser settings and, for Google Analytics, with Google's opt-out add-on.
8.1 Browser controls
You can manage or delete cookies directly in your browser. The steps below are correct at the time of writing; please consult your browser's current help for the definitive path.
- Google Chrome: Settings → Privacy and security → Third-party cookies (and Site data).
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data.
- Apple Safari: Preferences → Privacy → Manage Website Data.
- Microsoft Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data.
- Brave, Vivaldi, Arc, and other Chromium-based browsers: similar paths; consult each browser's help.
Blocking all cookies will prevent you from signing in. Blocking only non-essential cookies has no effect on core functionality.
8.2 Google Analytics opt-out
To stop Google Analytics from measuring your visits, install Google's Google Analytics Opt-out Browser Add-on from https://tools.google.com/dlpage/gaoptout, or block cookies and scripts from Google in your browser.
8.3 Mobile devices
On iOS and Android, in-app web views honour the browser-level cookie settings for the system browser on each platform.
09 · DNT & Global Privacy ControlDo Not Track and Global Privacy Control
Our website does not currently detect or act on the browser-level Do Not Track (DNT) or Global Privacy Control (GPC) signals. The Google Analytics and Google Ads tags load whether or not your browser sends them. To stop Google Analytics measurement, use the controls in Section 8.
10 · Updates to this policyUpdates to this policy
We will update this Cookie Policy when our cookie usage changes, when we add a new Sub-processor that sets cookies, or when we change durations. When we make a material change:
- we will update the "Last updated" date at the top of this document; and
- for changes that materially affect your rights, we will notify registered users by email.
Minor wording or typographic corrections may be made without separate notice.
11 · ContactContact
- Privacy enquiries and cookie questions:
privacy@mongoqui.com - General support:
support@mongoqui.com - Postal address: Fahid Digital Ventures LLC, Sharjah Media City Free Zone, Sharjah, United Arab Emirates.
If you believe we are using cookies in a way that breaches applicable law, you may contact the supervisory authority in your country (see Privacy Policy, Section 13.4).