Mahhala
Sign in

Cookie Policy

Last updated 31 August 2026

Effective date: 31 August 2026

This Cookie Policy explains the cookies and similar technologies used on mahha.la, and what each one does. It supplements our Privacy Policy.

We keep this list short on purpose. Mahhala runs no advertising trackers and no cross-site analytics tags. Our analytics are first-party: they are recorded by our own servers, not by a third-party script watching you around the web.

What cookies are

A cookie is a small text file a website stores in your browser. Some are essential: without them you could not stay signed in or submit a form safely. Others remember a preference. Related technologies, such as your browser's local storage, work similarly; we list those below too.

Cookies we set

Strictly necessary

These cannot be switched off. The Services do not work without them.

Cookie Purpose Lifetime
mahhala-session Keeps you signed in and links your requests to your session. A one-way hash of it also groups the pages you view into one visit for our own site statistics. 2 hours idle
XSRF-TOKEN Protects forms against cross-site request forgery. Session
remember_web_* Set only if you choose "remember me" at sign-in, so you stay signed in on that device. Each remembered device gets its own, so signing out on one does not sign out the others. Up to 400 days
trusted_device Set only if you mark a device as trusted, so two-factor authentication does not re-challenge you on it every time. 30 days

Functional

Cookie Purpose Lifetime
appearance Stores whether the interface should render light or dark, so the correct theme is drawn on the very first paint instead of flashing white. Contains only the word light or dark. 1 year

Local storage

Key Purpose
theme Your light / dark / follow-my-system preference, so the choice survives sign-out.
theme:{account} The same preference recorded per signed-in account on a shared device.
mahhala.guest_favorites Lets you save products before you have an account. Kept in your browser only, never sent anywhere, until the first time you sign in, when the list is merged into your account and cleared.

Analytics

We measure engagement with first-party requests to our own servers: impressions, views, click-throughs, shares, and saves. These are recorded against a rotating session identifier, not a persistent advertising identifier, and are what make "trending" on Mahhala reflect real interest. There is no third-party analytics cookie.

Cookie Purpose Lifetime
mhl_session A random session identifier that groups one visit's activity together, so a product view and the click that follows it are not counted as two separate people. If you are signed out, it is also what holds any products you save before creating an account. It contains no name, email or advertising identifier. Set for mahha.la and its subdomains, because shared links and the rest of the site are served from different hostnames and would otherwise split a single visit in two. 30 days

Promoted placements

Promoted products and paid placements are served by our own ad-delivery service at ads.api.mahha.la, not by an advertising network. Your browser requests them directly, which means that service receives your IP address and browser user agent the same way any web request carries them. It uses them to work out which country to serve and to avoid showing you the same promotion over and over.

It sets no cookies, and your Mahhala cookies are never sent to it. The requests are made without credentials, so it has no way to know who you are. There is no advertising identifier, no profile, and nothing that follows you to another website. See the Privacy Policy for what it keeps and for how long.

Third-party cookies

We do not embed advertising or social tracking scripts. Two third-party contexts can set cookies:

  • Google reCAPTCHA Enterprise runs on the forms it protects, and only those: sign-up, sign-in, password recovery, password reset, and the waitlist. Google's script is not loaded on any other page. Google may set cookies for this purpose, governed by the Google Privacy Policy.
  • YouTube, where a page embeds a video guide. We use YouTube's privacy-enhanced mode (youtube-nocookie.com), which does not set tracking cookies unless you actually play the video. If you play one, YouTube's own policies apply.

Managing cookies

Every major browser lets you view, block and delete cookies through its settings. Blocking strictly necessary cookies will prevent you from signing in or submitting forms, and Mahhala will not work correctly. Clearing local storage will reset your theme preference and discard any favorites saved before you created an account.

Because we set no advertising or profiling cookies, there is no advertising consent banner to manage.

Changes

We will update this page when the cookies we use change, and revise the effective date above.

Contact

Questions about this policy: privacy@mahha.la

See also: Privacy Terms Cookies Help Center