Last updated: 2 October 2026
In short
EU law allows these cookies without consent, because the site can’t provide what you asked for without them. That’s why there is no consent banner: a short notice on your first visit tells you about them, with a link to this page. If we ever add cookies that need consent, we will ask you first, and saying no will be as easy as saying yes.
What cookies and browser storage are
Cookies are small text files that a website stores in your browser. Local storage and session storage work in a similar way. The same rules apply to all of them, so this page lists everything we store on your device, whatever the technique.
On askmerra.com and in the dashboard
| Name | Purpose | Duration | Type |
|---|---|---|---|
am_locale | Remembers the language you chose in the language menu. Set only when you choose a language. | 1 year | Preference you asked for |
am_cookie_notice (local storage) | Remembers that you closed the cookie notice, so it isn’t shown again. | Until you clear your browser data | Preference you asked for |
__Host-am_session | Keeps you signed in to the dashboard. Holds a random token; we store only its hash. | 30 days after you sign in, or until you sign out | Strictly necessary |
__Host-am_csrf | Security token that protects your account against forged requests (CSRF). Set when you open the sign-in or sign-up page, send a form or use the dashboard. | Until you close the browser | Strictly necessary |
__Host-am_2fa | Remembers a sign-in in progress while you enter your two-factor code. | 5 minutes | Strictly necessary |
am_oauth_state | Protects “Continue with Google” against forged sign-ins. | 10 minutes | Strictly necessary |
All of these are first-party cookies set by askmerra.com. The session, two-factor and Google cookies are HttpOnly, so scripts on the page can’t read them. Browsing the public pages without choosing a language, closing the cookie notice or sending a form stores nothing on your device. Pages with a form also load Cloudflare’s bot check, described below.
Third-party services
- Bot protection (Cloudflare Turnstile). The sign-in, sign-up, password reset and contact forms load a security check from Cloudflare that tells people apart from bots. It runs in a frame from challenges.cloudflare.com, which may keep a technical item in your browser for this check only. It is strictly necessary to protect the forms and is never used for advertising. Cloudflare handles the data under its Turnstile privacy addendum.
- Google sign-in. If you click “Continue with Google”, you go to Google’s website, where Google uses its own cookies under Google’s privacy policy.
- Payments. When you pay, you are sent to Stripe’s checkout page, where Stripe uses its own cookies to process the payment and prevent fraud, under Stripe’s privacy policy.
Google and Stripe load nothing on our pages until you click. In the dashboard, product images load from your own shop’s website, as listed in your catalog.
In the chat widget on shops’ websites
Shops that use AskMerra add our chat widget to their website. The widget sets no cookies. It stores the following in the shopper’s browser, and only after the shopper opens the chat or starts typing. Until then, loading a page stores nothing and sends no identifier.
| Name | Purpose | Duration | Type |
|---|---|---|---|
askmerra:visitor (local storage) | Random visitor id, so that a conversation and any follow-up request belong to the same person. Holds no name or contact details. | 30 days after the last chat | Strictly necessary |
askmerra:session:<site key> (local storage) | Short-lived security token showing that the browser passed our anti-abuse check. | 30 minutes | Strictly necessary |
askmerra:<site key>:conversation (local storage) | The current conversation, so it continues when the shopper moves to another page. | 24 hours | Strictly necessary |
askmerra:<site key>:open (session storage) | Keeps the chat open while the shopper browses the shop. | Until the tab is closed | Strictly necessary |
askmerra:<site key>:proactive (session storage) | Remembers that the shopper closed the greeting bubble. | Until the tab is closed | Preference the shopper asked for |
Browser storage has no built-in expiry, so the widget deletes these items itself once their time is up. Usage events, such as “chat opened” or “product clicked”, are sent only after the shopper has used the chat. The widget does not fingerprint browsers and does not follow shoppers across websites.
Sales measurement, only with consent. If the shopper accepts analytics in the shop’s cookie banner, the widget reads the visitor id above on the shop’s order confirmation page and links the order (number, amount, products) to the chat, so the shop can see sales after a chat. Without that consent, or for shoppers who never chatted, it doesn’t.
AskMerra.setConsent()), so list it under analytics or statistics.How to control or delete them
You can delete cookies and site data at any time in your browser settings, and block them for our site. If you block the strictly necessary cookies, you won’t be able to sign in. Shoppers can also ask a shop to delete their chat data, and shops can offer a delete button on their privacy page with AskMerra.forget().
Changes
We update this page whenever we add, change or remove a cookie or storage item. The date at the top shows the current version.
Questions
Write to [email protected]. Our privacy policy explains how we handle personal data in general.