All legal documents

Legal

Cookie Policy

Every cookie and storage key this site sets, what it is for, and how long it lasts.

Musket Goose (Pty) Ltd · Effective · Last updated

1. What this policy covers

Cookies are small files a website stores on your device. Related technologies do the same job by other means, and the one we use is local storage, which keeps a value in your browser until something clears it.

This policy covers https://musketgoose.com and the operator platform on the same domain. Software we build and operate for a client runs on its own domain, under its own policy.

It names each cookie and storage key individually. You can check it against your own browser, and if you find something here that is not on the list, we would like to know.

2. Cookies we set

One. The public marketing site sets no cookies at all, and you can read every page of it without one being written.

The cookie below is set only when a member of our team signs in to the operator platform. It is strictly necessary: without it there is no way to stay signed in, so it cannot be turned off while remaining signed in.

Every cookie set by this site.
NamePurposeLifetimeFlags
mg_sessionKeeps an authorised operator signed in to the platform, and identifies which operator is making each request.7 days, or 30 days if you choose to stay signed in. Cleared immediately on sign out.HttpOnly, Secure, SameSite=Lax, first party

2.1 What is inside it

The cookie carries the operator's account id, username, display name, role and session id, together with an expiry. It is signed so that it cannot be altered, and it is marked HttpOnly so that scripts in the page cannot read it.

It is signed rather than encrypted, so anyone who obtains the cookie itself can read those fields. That is why it is HttpOnly and Secure, why signing out revokes it on the server rather than only deleting it from your browser, and why we ask the team not to stay signed in on a shared machine.

3. What we keep in your browser's local storage

Local storage is not a cookie and is never sent to our servers. It stays on your device and holds preferences, so that the interface looks the way you left it.

Every local storage key written by this site.
KeyPurposeWhere
themeWhether you prefer the light or dark theme.Any page, including the public site
mg:nav-collapsedWhich sidebar sections you have collapsed.Operator platform only
mg-command-recentThe destinations you have used recently in the command palette.Operator platform only
umami.disabledRead, never written by us. If you set it, our analytics stops recording your visits.Any page

4. Analytics, and why there is no cookie banner

We use Umami for website analytics. It records the page viewed, the referring page, screen size, language and page title, and reports them without a cookie and without writing anything to your device.

That is the whole reason there is no banner on this site. A consent banner exists to ask permission to store something on your device, and our analytics stores nothing. There is no advertising identifier, no cross-site profile, and nothing that follows you to another website.

South African law supports the same conclusion by a different route. POPIA contains no equivalent of the European ePrivacy rule that makes a banner compulsory, and requires instead that we tell you what we process and have a lawful ground for it. Telling you is what this page is for, and the ground is our legitimate interest in knowing which pages are worth keeping.

If you would rather not be counted at all, any tracker blocker will stop it, or you can set the umami.disabled key above.

The tracker is loaded on every page of the domain, which includes the operator platform. That means the page addresses our own team visits are counted too, and those addresses can contain record identifiers. It is our own staff and our own tool, but it is worth stating plainly rather than describing the analytics as though it only watched the marketing site.

5. Other services your browser contacts

None of these sets a cookie on this site, but each one means a request leaves your browser and reaches somebody else, so it belongs on this page.

Requests made to third parties from the browser.
ServiceWhenWhat it receives
Umami (cloud.umami.is)Every page view.The analytics event described above. Umami's servers see the connecting IP address, as any server does.
Open Exchange Rates API (open.er-api.com)Operator platform only, when a screen shows a foreign currency amount in rand.Nothing about you. It is a request for the day's exchange rates.
Have I Been Pwned (api.pwnedpasswords.com)Operator platform only, when an operator runs a password health check in the vault.The first five characters of a hash of the password, padded with decoys. The password itself never leaves the browser and cannot be reconstructed from what is sent.

5.1 Fonts are served from us, not from Google

The site uses two Google typefaces, Plus Jakarta Sans and JetBrains Mono. The font files are downloaded once when we build the site and served from our own domain, so your browser never contacts Google to render this page and Google never sees your address.

6. What this site does not do

  • No advertising cookies, and no remarketing or conversion pixels.
  • No social media tracking pixels.
  • No cross-site tracking, and no sale or sharing of behavioural data.
  • No session recording, heatmaps, or scroll tracking.
  • No fingerprinting, and no attempt to identify you when you are signed out.

7. Managing cookies and storage

Every browser lets you see, block and delete cookies and local storage for a site, usually from the padlock icon in the address bar or from the privacy section of settings.

Blocking storage on this site has no effect on reading it. The only thing you lose is the theme preference, which resets to the default. Blocking the mg_session cookie will stop an operator signing in, because there is then no way to remember that they did.

  • Chrome: Settings, then Privacy and security, then Third-party cookies and Site data.
  • Safari: Settings, then Privacy, then Manage Website Data.
  • Firefox: Settings, then Privacy and Security, then Cookies and Site Data.
  • Edge: Settings, then Cookies and site permissions.

8. Changes and contact

We update this page whenever we add or remove a cookie, a storage key or a third-party service. The last updated date at the top of the page is the date of the most recent change.

Questions, or something on your device that is not listed here: jack.spence@musketgoose.com.

Questions about this document? Email jack.spence@musketgoose.com