Skip to content

Cookie Policy

Last updated: 19 July 2026

This policy lists every cookie and similar storage technology used on Money Owl, what each one is for, how long it lasts, and how you control whether it’s set. We follow the Spanish Law on Information Society Services (LSSI-CE, Ley 34/2002) Art. 22.2 and the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) Art. 6(1)(a) and Art. 7. If anything in this Cookie Policy contradicts our Privacy Policy, the Privacy Policy wins.

What cookies are (definition)

A cookie is a small text file that a website asks your browser to store on your device. The browser sends it back with every subsequent request so the site can recognise you, remember a preference, or measure how you use it. We also use “similar technologies” (things like localStorage, session storage, and server-set tokens) and treat all of them as cookies for the purposes of this policy and LSSI-CE Art. 22.2. On Money Owl that currently means six localStorage keys, each written only when you actively use the feature it belongs to, and each staying until you clear your browser storage:

  • PREFERRED_MARKET and PREFERRED_LANGUAGE remember the market and language you pick in the preference banner.
  • PREFERRED_COLOR_SCHEME remembers your light-or-dark theme choice.
  • mastodon-instance remembers the Mastodon server you type into the share widget, so you don’t have to retype it.
  • moNetWorth:v1 and moSubscriptions:v1 save the figures you enter into the net-worth tracker and the subscription calculator, on your device only. Both tools have a visible reset that deletes the data; nothing you type into a calculator is ever transmitted to us or to anyone else.

Under LSSI-CE Art. 22.2, we can only store or retrieve information on your device after you have given informed consent, with one narrow exception: cookies that are strictly necessary for the service you’ve asked us for (for example, the session cookie that lets the contact form submit) can be set without explicit consent. Every other cookie (analytics, advertising, preferences) requires your consent under GDPR Art. 6(1)(a), obtained before the cookie is set.

We obtain that consent through our consent management platform (CMP). Until you interact with it, non-strictly-necessary cookies are not set.

  • Strictly necessary: cookies that are strictly necessary for the site to work. Set without consent, per LSSI-CE Art. 22.2.
  • Preferences: cookies that remember your choices (e.g. market, language). Set only after consent, or where they are technically strictly-necessary to the feature you’re using.
  • Statistics / Analytics: cookies that help us understand how the site is used (Google Analytics 4, Microsoft Clarity). Set only after consent.
  • Marketing / Advertising: cookies used to measure and target advertising (Google AdSense). Set only after consent, and only once AdSense is active on the site.

Cookies we use (enumerated table)

The table below lists every cookie we currently set or that our third-party providers set on our behalf. “First-party” means set on money-owl.com; “third-party” means set on a provider’s own domain. “HttpOnly” cookies cannot be read by JavaScript. They are visible only to the server that set them.

NameProviderPurposeCategoryDurationFirst/Third-party
__cf_bmCloudflareBot-management session token (HttpOnly)Strictly necessary30 minutesFirst-party
cf_clearanceCloudflare TurnstileContact-form anti-bot verification tokenStrictly necessary30 minutesFirst-party
_gaGoogle AnalyticsUnique visitor IDStatistics2 yearsThird-party
_ga_WH3SNQXJWHGoogle AnalyticsGA4 session state bound to our measurement IDStatistics2 yearsThird-party
_clckMicrosoft ClarityUnique visitor ID for session replayStatistics1 yearThird-party
_clskMicrosoft ClaritySession identifier for session replayStatistics1 dayThird-party
NIDGoogleAdvertising preferences (served via AdSense)Marketing6 monthsThird-party
IDEGoogle (DoubleClick)Conversion measurement (served via AdSense)Marketing13 monthsThird-party
FCCDCFGoogle Funding ChoicesConsent state for the Google Privacy & Messaging CMPStrictly necessary13 monthsThird-party
FCNECGoogle Funding ChoicesNetwork-level CMP consent signal, used by Funding Choices for cross-region consent propagation and TCF v2.3 downstream signalling. Strictly necessary for the CMP to operate.Strictly necessary12 monthsThird-party

Notes on the table:

  • __cf_bm is HttpOnly: you won’t see it in your browser’s JavaScript console, only in the Application / Cookies panel.
  • cf_clearance is a Cloudflare Challenge-platform cookie set after you pass a Cloudflare security challenge (JS challenge, CAPTCHA, or Turnstile). On Money Owl it’s set when you successfully submit the contact form via Turnstile.
  • _clck / _clsk are set by Microsoft Clarity once analytics consent is granted. Before consent, neither cookie is set.
  • NID and IDE are set by Google AdSense. Their appearance on the site depends on the AdSense approval state (approval timelines vary for new sites). When AdSense is approved and serving ads, these cookies are gated by your consent.
  • FCCDCF and FCNEC are both Google Funding Choices cookies storing the consent state produced by the CMP. Both are strictly-necessary for the CMP to operate.
  • One measurement tool is deliberately absent from this table: Cloudflare Web Analytics. It sets no cookie and uses no similar technology at all; it reports aggregate page views without storing anything on your device, which is why it can run without consent. The Privacy Policy describes it.

We update this table whenever a new cookie is added or an existing one changes. The last update date is at the top of this policy.

We use Google Privacy & Messaging as our CMP. It speaks the IAB Transparency and Consent Framework v2.3 (TCF v2.3), the version mandatory for all TCF participants since 28 February 2026, so that downstream providers (Google Analytics, Microsoft Clarity, Google AdSense) receive a standard consent signal rather than implementation-specific workarounds.

When you arrive on the site for the first time, the CMP shows you a banner asking whether you accept, reject, or manage individual categories. Your choice is stored in the FCCDCF cookie and honoured across the site. Analytics and advertising cookies are only set after you have said yes to the relevant category; rejecting the banner means only strictly-necessary cookies are set.

Under GDPR Art. 7(3), you can withdraw consent as easily as you gave it. There’s a “Cookie settings” link in the site footer that reopens the CMP banner. Use it at any time to change your choices. Withdrawing consent does not affect anything we did while you were consenting; it just stops future data collection under that category.

Browser controls (blocking cookies at the source)

Your browser is the other layer of control. You can block all cookies, block only third-party cookies, or delete cookies that have already been set, independently of what any CMP does. Instructions:

  • Chrome / Chromium: Settings → Privacy and security → Cookies and other site data.
  • Firefox: Settings → Privacy & Security → Enhanced Tracking Protection.
  • Safari (macOS): Settings → Privacy.
  • Safari (iOS / iPadOS): Settings → Safari → Privacy & Security.
  • Edge: Settings → Cookies and site permissions → Manage and delete cookies.

Blocking all cookies in the browser will break the contact form’s bot-protection flow, which relies on Cloudflare-set challenge cookies, and may break the CMP itself. If you block cookies entirely we won’t be able to remember your consent preference, so you’ll see the banner on every visit.

Cookies and the Privacy Policy

This Cookie Policy is a companion document to the Privacy Policy. The Privacy Policy explains the wider data-protection framework (processors, retention, data subject rights, international transfers, AEPD complaint path). This page documents only the cookie-specific detail.

Changes to this policy (effective date)

We update this Cookie Policy when we add a cookie, change a provider, or adjust a duration. The date at the top moves whenever we do. A bigger change, like a new provider or a new consent category, gets its own dated note on this page. So the table above is never quietly out of date.

19 July 2026 — Removed the CF_Authorization row (and its note) from the table above. That token was issued only by Cloudflare Access on the pre-launch UAT subdomain; it is not set on the public production site.