This translation is provided for information only. In the event of any discrepancy, only the French version is binding.
Cookies
Last updated: 25 September 2026
Use of cookies
MaCompta uses a deliberately limited number of cookies, strictly necessary for the application to work. No advertising or third-party tracking cookies are used.
Technical cookies
All the cookies set by MaCompta are strictly necessary for the service to work. They cannot be disabled without preventing login, and none is used for audience measurement or advertising — the audience measurement described below works entirely without cookies. The list is exhaustive:
macompta_session: keeps the session open while browsing. Duration: 30 days without use, renewed with each activity.pending_pro: remembers that a business subscription has been paid for, between payment and account creation. Duration: 24 hours.macompta_lang: remembers the display language chosen (two letters, for example “nl”), so that emails sent before any login — forgotten password, address confirmation — go out in that language. It contains no personal data. Duration: one year.- Cookies set by our authentication system when logging in by email or with Google (session token and security parameters of the login flow). They are deleted on logout.
mclic_admin_session: reserved for the publisher's operations panel, at the address/licence-admin. It is only set in the browser of a member of the publisher's staff who logs in there, never in that of a visitor or a customer. Duration: 12 hours. It is listed here because the list above is announced as exhaustive, and an adjective like that has to be earned.
Login cookies
The session cookie lets you stay logged in to the application, within the limit of its validity (30 days without use, renewed with each activity), without having to re-enter your username and password for every action.
Technologies used
In addition to the session cookie, the application uses the browser's local storage (localStorage) to remember certain display preferences or avoid needlessly repeating notifications (for example, a subscription expiry alert, or the welcome message). This information is stored only on the user's device.
Payment by Stripe
Paying for a subscription redirects the user to the secure payment page hosted by Stripe (stripe.com), outside the macompta.app domain. Any cookies set on that page are the sole responsibility of Stripe and subject to its own cookie policy.
Audience measurement
MaCompta measures the audience of its website: the pages viewed, where visits come from, and a few steps in the sales journey — opening the demo, creating an account, starting a payment, taking out a subscription. This is what tells us how many people come, what they read, and at which step they stop.
This measurement neither writes nor reads anything on your device: no measurement cookie, no local storage, no session storage. Everything happens on our server. That is also why no consent banner is shown to you: there is nothing to place on your device, so nothing to ask you to accept.
So as not to count the same person ten times, the server calculates a technical fingerprint from your IP address, the browser your device declares, and a randomly drawn secret that changes every 24 hours. Only this fingerprint is recorded: the IP address is not kept. The next day, the secret has changed: your fingerprint is no longer the same, and you are counted as a new visitor. This fingerprint therefore distinguishes you from other visitors for one day, and no longer. It makes it impossible to follow you from one day to the next, to reconstruct a browsing history beyond the day, or to link you to a person — this last statement has a limit on the day you log in, and we set it out below rather than keep quiet about it.
The previous day's secret, for its part, is not destroyed at midnight: it is destroyed by the clean-up task the following night. Yesterday's secret therefore still exists today, and disappears tonight. We say so rather than round it off, because this is what limits the only conceivable re-identification: as long as a secret exists, someone holding both our database and the key that is not in it — it lives in the server's configuration, never in the database — could check that a given IP address matches a fingerprint from that day. Once that period is over, no one can, and that is final.
From your browsing, the following is recorded — and nothing else:
- the page viewed;
- the origin of the visit: the site that sent you, as it chooses to declare itself, and the campaign parameters present in the address (utm_source, utm_medium, utm_campaign, utm_content, utm_term);
- the device family (computer, phone, tablet), that of the browser and that of the operating system: “Firefox on Android”, never “Firefox 142.0.1 on Android 14”. The version number is not recorded, because a precise version number serves first and foremost to recognise a device;
- the steps in the sales journey mentioned above;
- the day's technical fingerprint and the timestamp;
- a technical visit identifier, randomly drawn by our server and returned to your browser, which links together the pages of a single visit. It lives in the tab's memory and is never written to your device: it is not a cookie, it does not follow you from one site to another, it designates no one, and it disappears as soon as the tab is closed or reloaded — a new visit then receives a new identifier, unrelated to the previous one;
- three technical markers, so that this list stays closed: the side of the website concerned (personal or business), whether or not the action comes from a demo, and where applicable the reason why the record was excluded from the count (recognised bot, visit by the publisher itself).
That same visit identifier opens, when you arrive, a record summarising the visit: the day, the page through which you entered, the site that sent you, any campaign parameters, then the date of the steps taken afterwards, up to a possible subscription. It is opened for every visit, even one that reads a single page and leaves, and it is kept for thirteen months — this is what makes it possible to know, months later, which campaign led to which subscription. It carries no fingerprint, no IP address and no declared browser; it carries a household identifier and the Stripe references only if a subscription actually followed.
Inside the application, a few usage facts are counted in the same way: an account was created, a first transaction was entered, the setup assistant was completed. These records carry the identifier of the household concerned, not a fingerprint: this is what makes it possible to see that a given household went through the steps one after another. Only the fact is recorded, never its content. No amount, no transaction, no expense description, no account name, no category, no budget, no goal: nothing you write in your accounts enters this measurement. It concerns use of the product, never what you enter in it.
The limit announced above, spelled out. Three actions carry both the day's fingerprint and your household's identifier: opening a demo, creating an account, logging in. These are the three moments when the two need to be linked, precisely to know that a visit led to a sign-up. On that day, then, the public pages read from the same address and the same browser can be linked to your account, and they remain so for as long as those records exist — at the latest until their deletion, described just below. The next day, the fingerprint has changed: the link extends neither to the following day nor to previous ones. Outside these three actions, a page of the public website never carries your household, even if you are logged in while reading it.
Retention period. Three rules, and not one more:
- raw events, fingerprint included, are deleted after 30 days by a daily automated task, and no later than the 37th day. These seven extra days are a grace period, and we would rather announce the worst case than the average: the task refuses to erase a day whose total has not yet been calculated, because erasing it would mean losing that day for good. That refusal has an end: once the grace period is over, the day is erased even without its total. Keeping a fingerprint indefinitely would be worse than losing a figure;
- the record summarising a visit — the entry page, the referring site, the arrival campaign, the date of each step taken and, if a subscription followed, the household and the corresponding Stripe references — is kept for thirteen months, and for as long as the subscription it led to exists. It is opened for every visit, including one that leads nowhere, and it carries no fingerprint;
- after that, only daily totals remain (number of visitors, page views, sign-ups), which no longer carry any fingerprint or identifier, and which are kept with no time limit.
Objecting to audience measurement
This measurement is based on the publisher's legitimate interest (Article 6(1)(f) GDPR): knowing the audience of its own website. You can object to it without an account and without writing to us: if your browser sends a do-not-track signal — Do Not Track or Global Privacy Control — our server reads it before writing anything and then records nothing of your browsing: no fingerprint, no page, no origin, no visit identifier. Not even a record noting that you objected, since writing it would already be writing something about you. This setting can be found in the privacy preferences of most browsers, or in an extension that sends it for you. You can also write to us at support@macompta.app.
This also applies when paying. If you start taking out a subscription with this signal active, no visit record is opened and your origin is not recorded. Payment goes ahead normally: refusing to be counted is not refusing to buy, and all we lose is knowing which campaign brought you.
What this signal cannot do, and it is better to say so: it only concerns what leaves your browser. If you become a customer, our server records the fact that a subscription was created, renewed or cancelled — we need this to keep our own accounts. Those records carry no fingerprint, no page viewed and no origin.
No consent banner is needed for this measurement, since it neither reads nor writes anything on your device. If a non-essential cookie were ever added, a preference management mechanism would be made available here.
