Cookie Policy

Version 1.0 — Last updated 6 August 2026

This page explains what we store on your device, why, and how to change your mind.

There are two parts to MarginChief and they behave slightly differently:

  • marginchief.com — our public website, and our other subdomains.
  • app.marginchief.com — the application you sign in to.

Both use a small number of items that are strictly necessary, and both use analytics that we will not load unless you agree to it.

This page supplements our Privacy Policy.

Your choice

Under the Privacy and Electronic Communications Regulations 2003, and the equivalent rules across the European Economic Area, we need your consent before we store information on your device or read information already stored there — unless that storage is strictly necessary to provide the service you asked for.

So we split what we use into two groups:

  • Strictly necessary. Signing you in, keeping your session secure, remembering your display settings, and remembering your cookie choice. These do not require consent, and you cannot turn them off while using the service.
  • Analytics. PostHog, which tells us which pages and features people use. This is not strictly necessary, so we ask first. PostHog does not load and sets nothing on your device unless you accept.

We show a banner the first time you visit. Refusing is as easy as accepting — there is no pre-ticked box, no “legitimate interest” tab, and refusing does not limit anything you can do on our website or in the application. Signing in and paying for a subscription do not change this: we still ask, and we still do not load analytics unless you agree.

We record your choice against the whole of marginchief.com and its subdomains, so you only have to make it once, and it carries across from our website into the application.

To change your mind at any time, use the Cookie settings link in the footer of every page. Withdrawing consent stops PostHog loading immediately and clears the cookies it set. You can also email info@marginchief.com and we will action it.

We do not treat continuing to browse, scrolling, or closing the banner as consent.

Analytics: what PostHog does

We use PostHog for website and product analytics across marginchief.com, app.marginchief.com and our other subdomains. If you consent, it records:

  • the pages you view and the features you use, and in what order;
  • your device type, browser and screen size;
  • an approximate location derived from your IP address, which PostHog resolves to a country and region and then discards;
  • the site or search that referred you to us;
  • a pseudonymous identifier that distinguishes you from other visitors. Once you sign in, that identifier is associated with your account so that we can support you and understand how the product is used.

We use the European Union deployment of PostHog, so this data is stored in Frankfurt, Germany, and not in the United States. PostHog acts as our processor under a data processing agreement and does not use the data for its own purposes.

On our public website, the identifier is pseudonymous — it tells us one visitor from another, but not who you are. Inside the application, once you sign in, we associate that identifier with your account, so product analytics is linked to you as a named customer. That means your rights of access and erasure reach this data too: if you ask us to delete your personal data, we delete your PostHog record along with the rest.

We do not use PostHog session replay, feature-flag targeting on personal characteristics, or any advertising integration.

Our public website: marginchief.com

NameTypeWhat it doesHow long it lastsCategory
ph_phc_*_posthogCookiePostHog analytics. Holds a pseudonymous identifier that distinguishes one visitor from another, the current session identifier, and the page you arrived from. It is what lets us count a returning visitor as one person rather than two.12 monthsAnalytics — consent required
ph_phc_*_posthog (local storage keys)Local storagePostHog stores the same identifiers in local storage as well as in the cookie, so that they survive if cookies are cleared for the tab but not the site.Until you clear site data or withdraw consentAnalytics — consent required
ph_opt_in_out_phc_*CookieRecords that you have refused or withdrawn consent to analytics, so that we do not ask again on every page and do not load PostHog. Set only if you decline.12 monthsStrictly necessary
mc_consentLocal storageRecords your cookie choice — whether you accepted or refused analytics, and the date you chose. This is how we honour and evidence your decision.12 monthsStrictly necessary

Nothing in the analytics rows is set unless you accept analytics. Until you make a choice, only the consent record itself is written.

Our public website is served as static files from a content delivery network. The hosting itself sets no cookies at all, so the table above is the complete list of what marginchief.com can put on your device.

The application: app.marginchief.com

These items are stored once you sign in. All but the last are needed for the application to function.

NameTypeWhat it doesHow long it lastsCategory
access_tokenCookie (HttpOnly)Keeps you signed in. This is your authentication session. Marked HttpOnly, so it cannot be read by scripts running in your browser.Until you sign out or the session expiresStrictly necessary
logout_idCookie (HttpOnly)Used to sign you out cleanly across the application and our authentication provider. Also HttpOnly.Until you sign out or the session expiresStrictly necessary
__SIMPLE_NEXT_CONFIG__Local storageRemembers how you have set up the interface: theme, colour scheme, sidebar layout and similar display choices.Until you clear it or change the settingsStrictly necessary
shopify_oauth_errorSession storageHolds an error message if connecting your Shopify account fails, so we can show you what went wrong. Only written when a connection attempt fails.Deleted when you close the tabStrictly necessary
xero_oauth_errorSession storageThe same, for connecting your Xero account.Deleted when you close the tabStrictly necessary
ph_phc_*_posthogCookie and local storagePostHog product analytics: which features are used and in what order, so we can see where the product is confusing or slow. Loaded only if you consented to analytics.12 monthsAnalytics — consent required

A note on the different types. Cookies are sent to our servers with each request. Local storage stays in your browser and is not sent anywhere automatically. Session storage works the same way but is wiped when you close the tab. The law treats all three the same, which is why they are listed together.

The two authentication cookies are marked HttpOnly. That means scripts running in your browser cannot read them, which protects your session if a malicious script ever reached the page.

Email we send you

Our marketing email is sent through Brevo. Marketing messages contain a tracking pixel and wrapped links, which tell us whether the message was opened and which links were clicked. We use this to stop sending to people who never open our email. If you would rather not be measured this way, most email clients let you block remote images, and every marketing email carries a one-click unsubscribe.

Service messages about your account, billing and security are also sent through Brevo but are not used for marketing measurement.

Services you connect yourself

MarginChief can connect to your Shopify and Xero accounts if you choose to link them. Those connections are made through OAuth, which means you sign in to Shopify or Xero directly and they tell us you have authorised access — we never see your password for those services.

Shopify and Xero may set their own cookies on their own sign-in pages during that process. Those are governed by their privacy policies, not this page, and only appear if you start a connection.

When you buy a subscription

Payments are handled by Paddle, which acts as merchant of record. When you start a checkout, Paddle loads its own scripts and may set its own cookies to process the payment and prevent fraud. Those are governed by Paddle’s privacy policy, not this page, and they only load if you begin a purchase.

What we do not use

CategoryPosition
Advertising and retargetingWe do not advertise using cookies and we run no retargeting or ad-network pixels.
Selling or sharing dataWe do not sell, rent or share what our analytics collects with anyone, and we do not use it to build profiles for anyone else.
Social media buttons and trackersWe do not embed share buttons, Meta pixels or LinkedIn insight tags.
Session replay and heatmapsPostHog offers a session replay feature. We have not enabled it. We do not record your screen, your mouse movements or your keystrokes.
Cross-site trackingNothing we set can be used to follow you to another company’s website.
Automated decisionsAnalytics data is never used to make a decision about you individually.
Cross-site request forgery cookieOur application does not use one. Protection against that class of attack is handled another way.

Controlling storage in your browser

The simplest way to control analytics is the Cookie settings link in our footer.

You can also block or delete cookies, local storage and session storage through your browser settings, usually under Privacy or Site Settings. Most browsers offer a “Do Not Track” or “Global Privacy Control” signal; where your browser sends Global Privacy Control, we treat it as a refusal of analytics.

Blocking the strictly necessary items will stop the application working — you will not be able to stay signed in.

Changes to this policy

If we start using any technology that requires consent, we will update this page and ask for your consent before that technology is used. The version and date above will change, and previous versions remain available.

Questions

CloudRev Intelligence Ltd, 71–75 Shelton Street, London WC2H 9JQ, United Kingdom.

Email: info@marginchief.com

You can also complain to the Information Commissioner’s Office at ico.org.uk.


Registered in England and Wales, company number 17234811.