COOKIE POLICY
MAG.ONLINE — Online Payment Solutions OÜ
1. Introduction
This Cookie Policy explains how the MAG.ONLINE platform, operated by Online Payment Solutions OÜ ("we", "us", or "our"), use cookies and similar tracking technologies on our websites and applications.
This Policy complies with:
- EU ePrivacy Directive (2002/58/EC as amended)
- General Data Protection Regulation (GDPR) — EU 2016/679
- Estonian Information Society Services Act
By using the Platform, you consent to the use of cookies as described in this Policy. You may manage your cookie settings at any time through our Cookie Consent Manager.
2. What Are Cookies?
Cookies are small text files stored on your device (computer, smartphone, or tablet) when you visit a website. They allow the website to remember your actions and preferences (login status, language, display settings) for a period of time.
Similar technologies we use:
- Local storage: browser storage for persistent preferences
- Session storage: temporary data within a browser session
- Pixel tags / web beacons: miniature images used to track page visits or email opens
- SDKs: tracking components in applications from third-party analytics tools
Important clarification: the term "token" in cookie names (e.g. "session token") refers to technical cryptographic identifiers for a browser session or payment data. This technical term is unrelated to MAG.ONLINE Credits — the Platform's internal unit of account.
3. Cookie Categories
3.1 Strictly Necessary Cookies (technically required)
Consent required: No — necessary for the Platform to function.
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
session_id | MAG.ONLINE | Maintains your login session | Session |
csrf_token | MAG.ONLINE | Protection against CSRF attacks | Session |
cookie_consent | MAG.ONLINE | Stores your cookie preferences | 12 months |
lang_pref | MAG.ONLINE | Stores language preferences | 12 months |
__stripe_mid | Stripe | Payment fraud prevention | 1 year |
__stripe_sid | Stripe | Secure payment session | 30 minutes |
ts | PayPal | Fraud prevention | Session |
These cookies cannot be disabled without impairing the core functions of the Platform.
3.2 Analytics Cookies
Consent required: Yes — set only with your consent.
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
_ga | Google Analytics 4 | Distinguishes unique users | 2 years |
_ga_[ID] | Google Analytics 4 | Maintains session state | 2 years |
_gid | Google Analytics 4 | Identifies a user session | 24 hours |
_gat | Google Analytics 4 | Throttles request rate | 1 minute |
_gcl_au | Google Ads (via GA4) | Conversion tracking | 90 days |
GA4 data we collect:
- Page views and navigation paths
- Session duration and bounce rate
- Device type, browser, and operating system
- Geographic region (country/city level, no precise geolocation)
- Referral sources and UTM campaign data
Data is anonymised: IP addresses are anonymised before storage. We do not enable User-ID tracking without explicit consent.
GA4 data retention: set to 26 months.
3.3 Preference / Functional Cookies
Consent required: Yes — enhance experience but are not strictly necessary.
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
display_mode | MAG.ONLINE | Light/dark theme preference | 12 months |
timezone | MAG.ONLINE | Selected time zone | 12 months |
currency_display | MAG.ONLINE | Display currency preference (EUR equivalent) | 12 months |
recently_viewed | MAG.ONLINE | Recently viewed Specialists | 30 days |
3.4 Marketing / Advertising Cookies
Consent required: Yes — explicit consent required.
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
_fbp | Meta (Facebook) | Retargeting and ad measurement | 90 days |
_fbc | Meta (Facebook) | Tracking clicks from Facebook ads | 90 days |
IDE | Google (DoubleClick) | Retargeting advertising | 13 months |
ads_session_id | Google Ads | Session-level ad conversion | Session |
Note: Marketing cookies are disabled by default and are only activated with your explicit consent.
4. Third-Party Cookies
Some cookies are set by third-party services we use. We do not control these cookies. Their privacy policies apply:
| Third Party | Purpose | Privacy Policy |
|---|---|---|
| Google LLC | Analytics (GA4), advertising | policies.google.com/privacy |
| Meta Platforms, Inc. | Advertising (Facebook Pixel) | facebook.com/policy |
| Stripe, Inc. | Payment processing | stripe.com/privacy |
| PayPal Holdings, Inc. | Payment processing | paypal.com/privacy |
| Hotjar (if applicable) | User behaviour analytics | hotjar.com/legal/policies/privacy |
5. User Consent
5.1 Cookie Consent Manager
When you first visit the Platform, a "Cookie Consent Banner" will be displayed. You may:
- Accept all — activates all cookie categories
- Reject optional — only strictly necessary cookies are set
- Customise — select specific categories to activate
Your preferences are stored in the cookie_consent cookie for 12 months.
5.2 Changing Your Preferences
You may change your consent at any time:
- Click "Cookie Settings" in the website footer
- Go to Account Settings → Privacy and Cookies
- Clear your browser cookies (this will reset all preferences)
5.3 Managing Cookies via Your Browser
You may also manage cookies through your browser settings:
- Chrome: Settings → Privacy and security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Settings → Privacy → Cookies and website data
- Edge: Settings → Privacy, search, and services → Cookies
Note: Disabling all cookies will impair the Platform's functionality, including login and payments.
6. Cookie Retention Periods
| Cookie Type | Retention Period |
|---|---|
| Session cookies | Deleted when the browser is closed |
| Consent preference cookies | 12 months |
| Analytics cookies (GA4) | Up to 2 years |
| Marketing cookies | 90 days – 13 months (depending on provider) |
| Payment security cookies (Stripe) | Session to 1 year |
7. Do Not Track (DNT) Signal
Some browsers send a "Do Not Track" (DNT) signal. The Platform does not currently respond to DNT signals; however, users may use the Consent Manager to control tracking.
8. Opting Out of Google Analytics
To opt out of Google Analytics tracking across all websites:
- Install the Google Analytics opt-out browser add-on: tools.google.com/dlpage/gaoptout
- Or withdraw consent for analytics cookies via the Consent Manager on the Platform
9. Changes to This Policy
We may update this Cookie Policy in response to changes in our practices or legal requirements. We will notify you of material changes via the Cookie Consent Banner or a notice on the Platform.
10. Contact Details
Email: contact@mag.online
Online Payment Solutions OÜ
Registration number: 17449916
Vesivärava tn 50-201, Tallinn 10152, Estonia