1. Introduction
1.1 This Cookie Policy explains what cookies and similar tracking technologies are, how Monesize Limited ("Monesize", "we", "us", or "our") uses them in connection with Monesize Engage ("the Service"), and what choices are available to you.
1.2 This policy should be read alongside our Privacy Policy and Terms of Service, which provide broader information about how we collect and process personal data and the terms on which the Service is provided.
1.3 If you have any questions about this Cookie Policy, please contact us at hello@monesize.com.
2. What Cookies Are
2.1 A cookie is a small text file that a website or web application places on your device when you visit or use it. Cookies are widely used to make services work correctly, to remember your preferences, and to provide information to the operators of a service about how it is being used.
2.2 Cookies may be classified in several ways:
2.2.1 Session cookies exist only for the duration of your browser session and are deleted when you close your browser.
2.2.2 Persistent cookies remain on your device for a defined period, or until you delete them manually.
2.2.3 First-party cookies are set directly by the website or application you are using.
2.2.4 Third-party cookies are set by a domain other than the one you are visiting, typically by advertising networks, analytics providers, or social media platforms embedded in a page.
2.2.5 Strictly necessary cookies are essential for a service to function. Without them, core functionality such as authentication cannot operate.
2.2.6 Analytics and performance cookies are used to collect information about how visitors use a service, typically in aggregate and anonymised form.
2.2.7 Advertising and tracking cookies are used to build profiles of your interests and to serve targeted advertisements across different websites and platforms.
3. Cookies We Use
3.1 Monesize Engage uses a minimal cookie footprint. We use exactly one cookie to operate the Service.
3.2 The Authentication Cookie
Name — “engage_token”Type — First-party, persistentDuration — 7 days from issuancePurpose — Maintains your authenticated session within the ServiceClassification — Strictly necessary
3.2.1 The “engage_token” cookie contains a signed JSON Web Token ("JWT") that identifies your authenticated session and the organizational workspace you are logged into. Without this cookie, the Service cannot verify your identity and you will not be able to access any authenticated functionality.
3.2.2 This cookie is set when you successfully sign in to the Service, including via email and password authentication, Google OAuth, or Microsoft OAuth. It is refreshed upon certain session events and is cleared when you log out.
3.2.3 This cookie is configured with the following security attributes:
3.2.3.1 HttpOnly: the cookie cannot be read or modified by JavaScript running in your browser. This protects it from cross-site scripting attacks.
3.2.3.2 Signed: the cookie value is cryptographically signed using a server-side secret. Any attempt to tamper with the cookie value will be detected and the session will be rejected.
3.2.3.3 Secure: in production environments, the cookie is only transmitted over HTTPS connections. It will not be sent over unencrypted HTTP.
3.2.3.4 SameSite=Strict: the cookie is only sent with requests that originate from the same site. This provides protection against cross-site request forgery attacks.
3.3 We do not use analytics cookies. We do not use advertising or tracking cookies. We do not use social media cookies. We do not embed any third-party scripts that set cookies on our behalf.
4. What We Do Not Use
4.1 To be explicit about our approach, the following technologies are not used on the Service:
4.1.1 Google Analytics or any equivalent analytics platform;
4.1.2 Meta Pixel or any equivalent advertising pixel from social media platforms;
4.1.3 Hotjar, Heap, Mixpanel, Amplitude, or any equivalent product analytics or session recording tools;
4.1.4 Any retargeting or behavioural advertising technology;
4.1.5 Any third-party cookies of any kind.
4.2 This means that your use of the Service is not tracked across other websites and your data is not shared with advertising networks or data brokers in connection with your use of the Service.
5. Email Tracking Technologies
5.1 Although email tracking technologies are not cookies in the traditional sense, they are related tracking technologies that we consider it important to disclose clearly in this policy.
5.2 Campaign emails sent through the Service by Organizations may contain two types of tracking technology embedded by the sending Organization at the time of send:
5.2.1 Open tracking pixels: a one-by-one pixel transparent image is embedded in the body of Campaign emails. The image URL contains an identifier unique to the individual recipient. When your email client loads the image, a request is made to the Service's tracking infrastructure, which records that the email was opened and increments the open count associated with your recipient record within the sending Organization's workspace.
5.2.2 Click tracking redirects: links within Campaign emails are rewritten to pass through the Service's click tracking infrastructure before redirecting you to the intended destination. When you click a tracked link, the click is recorded against your recipient record within the sending Organization's workspace, and you are then forwarded to the original destination URL. The encoding of destination URLs uses base64url format and the redirect is performed via an HTTP 302 response.
5.3 These tracking technologies are used exclusively by Organizations to measure the engagement of their own outbound campaigns. The data collected is stored within the sending Organization's workspace and is not used by Monesize for its own purposes.
5.4 You have the following options in relation to email tracking:
5.4.1 Open tracking: you can prevent open tracking pixels from loading by disabling automatic image loading in your email client. Most email clients provide this option in their settings. If images are not automatically loaded, the tracking pixel will not fire.
5.4.2 Click tracking: to avoid click tracking, you can choose not to click links in Campaign emails. If you wish to visit a destination linked in a Campaign email without being tracked, you can manually copy and identify the destination from the link without clicking.
5.4.3 Unsubscribe: every Campaign email sent through the Service contains an unsubscribe link. Clicking the unsubscribe link will update your communication status within the sending Organization's workspace to Unsubscribed and you will not receive further Campaign emails from that Organization through the Service. The unsubscribe process does not require you to create an Account and is processed automatically.
5.5 Monesize notes that open tracking via pixel images is subject to significant reliability limitations. Certain email clients, including Apple Mail operating under Apple Mail Privacy Protection introduced in iOS 15 and macOS Monterey, pre-fetch tracking pixels regardless of whether the email has been opened by the recipient. This means that open tracking data may overcount actual opens for recipients using affected email clients. Click tracking does not have this limitation.
6. Your Choices and Controls
6.1 The authentication cookie is strictly necessary. Because the “engage_token” cookie is essential for the Service to function, it cannot be disabled without preventing you from signing in. If you disable or delete this cookie, you will be signed out and will need to authenticate again.
6.2 Browser cookie controls: most web browsers allow you to view, manage, and delete cookies stored on your device through the browser's settings interface. You can typically find these controls under settings menus labelled Privacy, Security, or similar. Note that deleting the “engage_token” cookie will sign you out of the Service.
6.3 Logging out: logging out of the Service via the logout function clears the `engage_token` cookie from your browser and simultaneously invalidates the session on the server side, meaning the token cannot be reused even if it were retained by a third party.
6.4 Do Not Track: some browsers send a Do Not Track ("DNT") signal. Because the Service does not engage in cross-site tracking, advertising targeting, or behavioural profiling, the presence or absence of a DNT signal does not change our cookie practices.
6.5 Global Privacy Control: if your browser sends a Global Privacy Control ("GPC") signal, Monesize will treat this as an opt-out of any sale or sharing of personal data. As noted in this policy and our Privacy Policy, Monesize does not sell or share personal data, so this signal does not change our practices but we acknowledge and respect it.
7. Cookie Consent
7.1 When you first visit the Service, we show you a cookie notice that explains our use of cookies and asks for your consent. You can accept cookies or open the preferences window to review each category in detail. Your choice is remembered on your device so we do not ask you again on every visit.
7.2 The Service currently uses only a single strictly necessary cookie, which is required for the Service to function and cannot be switched off. We do not use analytics, advertising, or any other non-essential cookies. If we ever introduce non-essential cookies, we will update this Cookie Policy, ask for your consent before setting them, and notify existing users in accordance with our Privacy Policy.
7.3 You can change your cookie preferences at any time by clicking "Cookie Preferences" in the footer of any page. This opens the preferences window, where you can review your current settings and update them.
8. Changes to This Cookie Policy
8.1 We may update this Cookie Policy from time to time to reflect changes in the technologies we use, changes to the Service, or changes in applicable law. When we make material changes, we will update the "Last updated" date at the top of this policy and notify users via the email address associated with their Account at least 14 days before the changes take effect.
8.2 Your continued use of the Service after the revised Cookie Policy takes effect constitutes your acknowledgement of the changes. If you do not agree with the changes, you should stop using the Service.
9. Contact Us
If you have any questions about this Cookie Policy or about our use of cookies and tracking technologies, please contact us at:
Monesize Limited128 City RoadLondon, EnglandEC1V 2NXUnited Kingdom
Email: hello@monesize.com
We aim to respond to all enquiries within five business days.
