Cookie Policy
This Cookie Policy explains how Maxinodes (“we”, “us”, “our”) uses cookies and similar technologies on our website and in the Client Area at my.maxinodes.com. It sits alongside our Privacy Policy, which describes more fully how we handle personal data. Where this policy refers to “you” or “your”, it means any visitor to our site, whether or not you are a Customer.
We want to be straightforward about this: beyond the strictly-necessary cookies that make the site work, nothing loads until you agree to it, and we never sell your browsing data. With your consent we load privacy-friendly, self-hosted analytics, a live-chat widget, and advertising measurement that tells Meta (Facebook and Instagram) when one of our ads led to a visit or a sign-up. We will not pretend that last one is harmless: it is genuine advertising technology operated by a third party, which is exactly why it stays switched off unless you switch it on. When you first visit, a consent banner lets you accept, reject, or choose per purpose; nothing non-essential runs until you opt in, and you can change your mind at any time using the Cookie settings button below. This policy explains exactly what we set and the choices you have.
1. What cookies are
A cookie is a small text file that a website asks your browser to store on your device. When you return to the site, your browser sends the cookie back, which lets the site recognise your session, remember choices you have made, or keep you securely signed in. Cookies cannot run programs or carry viruses, and they cannot read other files on your device.
Cookies are usually classified in two ways:
- By who sets them. A first-party cookie is set by the website you are visiting (in our case, maxinodes.com). A third-party cookie is set by a different domain — for example an analytics or advertising provider embedded in a page. The Meta advertising cookies described below sit awkwardly across that line: they are written on our own domain, so your browser treats them as first-party, but the data they carry is read by Meta. We set no other third-party cookies.
- By how long they last. A session cookie is temporary and is deleted when you close your browser. A persistent cookie remains for a set period, or until you delete it.
Where this policy refers to “cookies”, it also covers similar technologies that store or read information on your device for comparable purposes. These include browser localStorage and sessionStorage, IndexedDB, pixels, tags, software development kits, and device or browser fingerprinting. The same rules and consent principles in this policy apply to all of them, regardless of the specific technology used.
2. Categories of cookies
To make choices clearer, cookies and similar technologies fall into four categories, which match the toggles in our consent banner. We describe each in plain English below. Strictly necessary is always on; analytics and live chat run only if you opt in; and we currently use nothing in the marketing category at all.
Strictly necessary
These cookies are essential for the website and Client Area to work. They do things like keep you signed in, protect forms and sign-in requests against cross-site request forgery, balance load across servers, and remember the steps you have completed in a checkout or order — and they remember the cookie choices you make here. Without them, core features simply will not function. Because they are essential to deliver a service you have asked for, these cookies do not require consent under EU and Irish law — but we still tell you about them here.
Functional / preferences
These are not essential but make the site more useful — for example remembering a choice you have made, or running our live-chat widget so you can message us. We load them only after you opt in to the relevant category, and you can withdraw at any time.
Analytics
These help us understand how visitors use the site — which pages are useful and where things break — in aggregate, to improve it. Ours is self-hosted Matomo: it is cookieless, anonymises IP addresses, never tracks you across other sites, and is never shared with advertisers. Its measurement script runs only if you opt in to analytics.
Marketing
These cookies are used to measure the effectiveness of advertising campaigns and, on the advertising network’s side, to build a profile of your interests and show you advertising across different websites. We use one such tool: the Meta pixel, which lets us see which visits and sign-ups came from our Facebook and Instagram ads so we stop paying to advertise to people who have already found us. It is loaded only if you opt in to the Marketing category, and if you do not, it is never downloaded at all.
We also send the same events to Meta from our own server (Meta calls this the Conversions API), because browser-based measurement is frequently blocked and, for a payment that confirms minutes after you close the tab, there is no browser left to report it. This is the same information about the same events — it is not a way of tracking you when you have said no. Server-side events are sent only where we have recorded your consent, and never otherwise.
3. What we use today
As at the date at the top of this page:
- Strictly-necessary cookies (always on). First-party cookies required to run the website and Client Area — a session cookie and a security / CSRF cookie — plus a small cookie that remembers your consent choice so we do not have to ask on every page. Our security provider (Cloudflare) also sets a strictly-necessary bot-protection cookie. These need no consent under EU and Irish law.
- Analytics (only with your consent). Self-hosted Matomo, used to measure aggregate traffic. It is cookieless and anonymises IP addresses, never tracks you across other sites, and is never shared with advertisers — and its measurement script loads only after you opt in to the analytics category. If you reject or ignore the banner, it never runs.
- Live chat (only with your consent). Our self-hosted live-chat widget (Chatwoot, on support.maxinodes.com). It loads — and sets its cookies and similar storage — only after you opt in to the live-chat category, so you can message us. If you do not opt in, the widget is not loaded at all.
- Advertising measurement (only with your consent). The Meta pixel, plus equivalent events sent from our server, used to measure whether our Facebook and Instagram advertising works. If you opt in, this shares your IP address, browser details, the pages you view and, where you have given it to us, a scrambled (hashed) form of your email address with Meta Platforms Ireland Ltd, which acts as a joint controller with us for this and may transfer data outside the EU. It sets the
_fbpand_fbccookies listed below. If you reject or ignore the banner, none of it runs. - No third-party fonts. We self-host our fonts, so loading a page does not send your IP address to any third-party font service.
You can review or change these choices at any time using the Cookie settings button near the top of this page. The Client Area at my.maxinodes.com applies the same consent choice and sets its own strictly-necessary session and security cookies to keep you signed in and protect your account.
4. The cookies we set
The table below lists the cookies and similar storage we may set. The strictly-necessary ones are always present; the live-chat cookies appear only after you opt in to live chat, and the Meta advertising cookies only after you opt in to marketing. Our analytics is cookieless, so it has no entry here. Exact technical names can change between releases of the software that powers our site, so where a name may vary we describe the cookie by its function.
| Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
| Session cookie | Maxinodes (first party, maxinodes.com) | Maintains your browsing session and keeps you securely signed in to the website and Client Area. Essential for navigation, ordering and account access. | Session (deleted when you close your browser, or sooner on sign-out) | Strictly necessary |
| CSRF-protection cookie | Maxinodes (first party, maxinodes.com) | Holds a security token that protects forms and sign-in and ordering requests against cross-site request forgery (CSRF). Essential for security. | Session | Strictly necessary |
Consent-preferences cookie (mx_consent) |
Maxinodes (first party, .maxinodes.com) | Remembers the cookie choices you made in our consent banner, so we apply them and don’t ask again on every page. Shared across our subdomains so one choice covers the whole site. | Up to 6 months | Strictly necessary (records your consent) |
Security / bot-protection cookie (e.g. __cf_bm) |
Cloudflare (our content-delivery & security provider) | Set by the security network in front of our site to tell humans apart from automated bots and protect the site against abuse. Essential to deliver the site securely. | About 30 minutes | Strictly necessary |
Live-chat cookies (e.g. cw_conversation) |
Chatwoot (our self-hosted live-chat tool, support.maxinodes.com) | Set only after you opt in to the Live chat category, to run your conversation and let you continue it if you move between pages or return later. Not set unless you allow live chat. | Up to 180 days (or until you clear it) | Functional (live chat) — consent required |
| Client Area session & security cookies | Maxinodes (first party, my.maxinodes.com) | Set by the billing and account portal to keep you signed in to your account and to protect account and billing actions. Essential to operate the Client Area. | Session | Strictly necessary |
| Essential local storage | Maxinodes (first party) | Where used, browser localStorage / sessionStorage that supports core site functionality (for example holding a value needed for a single visit). No analytics or marketing data is stored. | Cleared on sign-out or when you clear site data | Strictly necessary |
Meta advertising cookie (_fbp) |
Meta Platforms Ireland Ltd (written on .maxinodes.com by Meta’s script) | Set only after you opt in to Marketing. Gives your browser a random identifier so Meta can tell that a visit, an enquiry or a sign-up came from one of our Facebook or Instagram ads. Not set unless you allow marketing. | Up to 90 days (often much shorter in Safari) | Marketing — consent required |
Meta click cookie (_fbc) |
Meta Platforms Ireland Ltd (written on .maxinodes.com by Meta’s script) | Set only after you opt in to Marketing, and only if you reached us by clicking one of our ads. Stores the click identifier from that ad so the visit can be matched to it. Not set unless you allow marketing. | Up to 90 days (often much shorter in Safari) | Marketing — consent required |
Our analytics deliberately sets no cookies, so it has no row here (see section 3). Should we introduce any further non-essential cookie in future, we will list it here — with its name, provider, purpose, duration and type — before relying on your consent to set it.
5. Consent and your choices
We use a consent banner to manage your choices, in line with the EU ePrivacy rules and the General Data Protection Regulation (GDPR) as applied in Ireland. The commitments below describe how it works:
- Prior opt-in consent. We do not load any analytics or live-chat cookie or script (or, in future, any marketing one) until you have given prior, freely given, specific, informed and unambiguous consent by a clear affirmative action. Strictly-necessary cookies are set without consent, as the law permits.
- Reject-all is as easy as accept-all. Our banner presents Reject all with the same prominence and the same number of clicks as Accept all, on the first screen. Every non-essential category is switched off by default until you turn it on.
- No cookie wall. We never block access to our website or condition the use of our Services on your acceptance of non-essential cookies. Declining is always a real, cost-free choice.
- Granular control. Using Manage preferences, you can consent to analytics and live chat separately rather than all-or-nothing.
- Withdrawing consent. You can withdraw at any time, as easily as you gave it, using the Cookie settings button near the top of this page, which reopens the preferences panel. Withdrawal does not affect the lawfulness of processing carried out before you withdrew. You can also clear or block cookies in your browser at any time (see section 6).
- We re-ask periodically. Consent does not last forever: we ask again at least every 6 months, and whenever the purposes change materially, so the consent we hold stays current. We keep a record of your consent for our own accountability.
If we ever use third-party cookies for analytics or marketing, the third party may also process your personal data under its own terms; we would name those providers in section 4 and in our Subprocessors list before relying on them.
6. Managing cookies in your browser
Separately from any consent choices on our site, your browser and device give you direct control over cookies and similar storage. You can usually view, block, limit or delete cookies through your browser settings, and most browsers let you refuse third-party cookies, clear stored data, or browse in a private / incognito window. The relevant controls are found in the privacy or security settings of Google Chrome, Mozilla Firefox, Apple Safari, Microsoft Edge and other browsers; mobile devices offer similar controls in their system settings.
Please note: some of the cookies we use are strictly necessary. If you block or delete those, parts of the website and the Client Area may not work correctly — for example you may be unable to sign in, stay signed in, place an Order, or complete account and billing actions. Blocking strictly-necessary cookies does not stop us providing the Services, but it may prevent your own browser from using them as intended.
7. Changes to this policy
We may update this Cookie Policy from time to time — for example if we change the cookies we use, introduce new technologies, or need to reflect changes in the law. The version in force is always the one published at this URL, with the version label and “last updated” date shown at the top and bottom of the page. If we introduce any non-essential cookie, we will update this policy and obtain your consent first, as described in section 5. We encourage you to review this page from time to time. Nothing in this policy limits your mandatory statutory rights.
Contact
Questions about cookies: [email protected].
By post: Maxinodes Ltd, 1 Ballycoolin Road, Dublin 15, Ireland.