Cookie Policy
Last updated: 19 July 2026
This policy lists every cookie and similar storage technology used on Money Owl, what each one is for, how long it lasts, and how you control whether it’s set. We follow the Spanish Law on Information Society Services (LSSI-CE, Ley 34/2002) Art. 22.2 and the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) Art. 6(1)(a) and Art. 7. If anything in this Cookie Policy contradicts our Privacy Policy, the Privacy Policy wins.
What cookies are (definition)
A cookie is a small text file that a website asks your browser to store on your device. The browser sends it back with every subsequent request so the site can recognise you, remember a preference, or measure how you use it. We also use “similar technologies” (things like localStorage, session storage, and server-set tokens) and treat all of them as cookies for the purposes of this policy and LSSI-CE Art. 22.2. On Money Owl that currently means six localStorage keys, each written only when you actively use the feature it belongs to, and each staying until you clear your browser storage:
PREFERRED_MARKETandPREFERRED_LANGUAGEremember the market and language you pick in the preference banner.PREFERRED_COLOR_SCHEMEremembers your light-or-dark theme choice.mastodon-instanceremembers the Mastodon server you type into the share widget, so you don’t have to retype it.moNetWorth:v1andmoSubscriptions:v1save the figures you enter into the net-worth tracker and the subscription calculator, on your device only. Both tools have a visible reset that deletes the data; nothing you type into a calculator is ever transmitted to us or to anyone else.
Why we can use cookies (legal basis: LSSI-CE Art. 22.2)
Under LSSI-CE Art. 22.2, we can only store or retrieve information on your device after you have given informed consent, with one narrow exception: cookies that are strictly necessary for the service you’ve asked us for (for example, the session cookie that lets the contact form submit) can be set without explicit consent. Every other cookie (analytics, advertising, preferences) requires your consent under GDPR Art. 6(1)(a), obtained before the cookie is set.
We obtain that consent through our consent management platform (CMP). Until you interact with it, non-strictly-necessary cookies are not set.
Cookie categories (classification)
- Strictly necessary: cookies that are strictly necessary for the site to work. Set without consent, per LSSI-CE Art. 22.2.
- Preferences: cookies that remember your choices (e.g. market, language). Set only after consent, or where they are technically strictly-necessary to the feature you’re using.
- Statistics / Analytics: cookies that help us understand how the site is used (Google Analytics 4, Microsoft Clarity). Set only after consent.
- Marketing / Advertising: cookies used to measure and target advertising (Google AdSense). Set only after consent, and only once AdSense is active on the site.
Cookies we use (enumerated table)
The table below lists every cookie we currently set or that our third-party providers set on our behalf. “First-party” means set on money-owl.com; “third-party” means set on a provider’s own domain. “HttpOnly” cookies cannot be read by JavaScript. They are visible only to the server that set them.
| Name | Provider | Purpose | Category | Duration | First/Third-party |
|---|---|---|---|---|---|
__cf_bm | Cloudflare | Bot-management session token (HttpOnly) | Strictly necessary | 30 minutes | First-party |
cf_clearance | Cloudflare Turnstile | Contact-form anti-bot verification token | Strictly necessary | 30 minutes | First-party |
_ga | Google Analytics | Unique visitor ID | Statistics | 2 years | Third-party |
_ga_WH3SNQXJWH | Google Analytics | GA4 session state bound to our measurement ID | Statistics | 2 years | Third-party |
_clck | Microsoft Clarity | Unique visitor ID for session replay | Statistics | 1 year | Third-party |
_clsk | Microsoft Clarity | Session identifier for session replay | Statistics | 1 day | Third-party |
NID | Advertising preferences (served via AdSense) | Marketing | 6 months | Third-party | |
IDE | Google (DoubleClick) | Conversion measurement (served via AdSense) | Marketing | 13 months | Third-party |
FCCDCF | Google Funding Choices | Consent state for the Google Privacy & Messaging CMP | Strictly necessary | 13 months | Third-party |
FCNEC | Google Funding Choices | Network-level CMP consent signal, used by Funding Choices for cross-region consent propagation and TCF v2.3 downstream signalling. Strictly necessary for the CMP to operate. | Strictly necessary | 12 months | Third-party |
Notes on the table:
__cf_bmis HttpOnly: you won’t see it in your browser’s JavaScript console, only in the Application / Cookies panel.cf_clearanceis a Cloudflare Challenge-platform cookie set after you pass a Cloudflare security challenge (JS challenge, CAPTCHA, or Turnstile). On Money Owl it’s set when you successfully submit the contact form via Turnstile._clck/_clskare set by Microsoft Clarity once analytics consent is granted. Before consent, neither cookie is set.NIDandIDEare set by Google AdSense. Their appearance on the site depends on the AdSense approval state (approval timelines vary for new sites). When AdSense is approved and serving ads, these cookies are gated by your consent.FCCDCFandFCNECare both Google Funding Choices cookies storing the consent state produced by the CMP. Both are strictly-necessary for the CMP to operate.- One measurement tool is deliberately absent from this table: Cloudflare Web Analytics. It sets no cookie and uses no similar technology at all; it reports aggregate page views without storing anything on your device, which is why it can run without consent. The Privacy Policy describes it.
We update this table whenever a new cookie is added or an existing one changes. The last update date is at the top of this policy.
Consent management (how we ask, how we remember)
We use Google Privacy & Messaging as our CMP. It speaks the IAB Transparency and Consent Framework v2.3 (TCF v2.3), the version mandatory for all TCF participants since 28 February 2026, so that downstream providers (Google Analytics, Microsoft Clarity, Google AdSense) receive a standard consent signal rather than implementation-specific workarounds.
When you arrive on the site for the first time, the CMP shows you a banner asking whether you accept, reject, or manage individual categories. Your choice is stored in the FCCDCF cookie and honoured across the site. Analytics and advertising cookies are only set after you have said yes to the relevant category; rejecting the banner means only strictly-necessary cookies are set.
Withdrawing consent (changing your mind)
Under GDPR Art. 7(3), you can withdraw consent as easily as you gave it. There’s a “Cookie settings” link in the site footer that reopens the CMP banner. Use it at any time to change your choices. Withdrawing consent does not affect anything we did while you were consenting; it just stops future data collection under that category.
Browser controls (blocking cookies at the source)
Your browser is the other layer of control. You can block all cookies, block only third-party cookies, or delete cookies that have already been set, independently of what any CMP does. Instructions:
- Chrome / Chromium: Settings → Privacy and security → Cookies and other site data.
- Firefox: Settings → Privacy & Security → Enhanced Tracking Protection.
- Safari (macOS): Settings → Privacy.
- Safari (iOS / iPadOS): Settings → Safari → Privacy & Security.
- Edge: Settings → Cookies and site permissions → Manage and delete cookies.
Blocking all cookies in the browser will break the contact form’s bot-protection flow, which relies on Cloudflare-set challenge cookies, and may break the CMP itself. If you block cookies entirely we won’t be able to remember your consent preference, so you’ll see the banner on every visit.
Cookies and the Privacy Policy
This Cookie Policy is a companion document to the Privacy Policy. The Privacy Policy explains the wider data-protection framework (processors, retention, data subject rights, international transfers, AEPD complaint path). This page documents only the cookie-specific detail.
Changes to this policy (effective date)
We update this Cookie Policy when we add a cookie, change a provider, or adjust a duration. The date at the top moves whenever we do. A bigger change, like a new provider or a new consent category, gets its own dated note on this page. So the table above is never quietly out of date.
19 July 2026 — Removed the CF_Authorization row (and its note) from the table above. That token was issued only by Cloudflare Access on the pre-launch UAT subdomain; it is not set on the public production site.