Skip to content

Legal

Cookie policy

Every cookie and storage item we use, what it does and how long it lasts. No analytics, no advertising, no consent banner.

Last updated: 2 October 2026

In short

We use only cookies that are strictly necessary for things you ask for, such as signing in, plus one cookie that remembers the language you choose. We don’t use analytics, advertising or social media cookies. The only third-party element is Cloudflare’s bot check on our sign-in, sign-up, password reset and contact forms, which is strictly necessary too.

EU law allows these cookies without consent, because the site can’t provide what you asked for without them. That’s why there is no consent banner: a short notice on your first visit tells you about them, with a link to this page. If we ever add cookies that need consent, we will ask you first, and saying no will be as easy as saying yes.

What cookies and browser storage are

Cookies are small text files that a website stores in your browser. Local storage and session storage work in a similar way. The same rules apply to all of them, so this page lists everything we store on your device, whatever the technique.

On askmerra.com and in the dashboard

NamePurposeDurationType
am_localeRemembers the language you chose in the language menu. Set only when you choose a language.1 yearPreference you asked for
am_cookie_notice (local storage)Remembers that you closed the cookie notice, so it isn’t shown again.Until you clear your browser dataPreference you asked for
__Host-am_sessionKeeps you signed in to the dashboard. Holds a random token; we store only its hash.30 days after you sign in, or until you sign outStrictly necessary
__Host-am_csrfSecurity token that protects your account against forged requests (CSRF). Set when you open the sign-in or sign-up page, send a form or use the dashboard.Until you close the browserStrictly necessary
__Host-am_2faRemembers a sign-in in progress while you enter your two-factor code.5 minutesStrictly necessary
am_oauth_stateProtects “Continue with Google” against forged sign-ins.10 minutesStrictly necessary

All of these are first-party cookies set by askmerra.com. The session, two-factor and Google cookies are HttpOnly, so scripts on the page can’t read them. Browsing the public pages without choosing a language, closing the cookie notice or sending a form stores nothing on your device. Pages with a form also load Cloudflare’s bot check, described below.

Third-party services

  • Bot protection (Cloudflare Turnstile). The sign-in, sign-up, password reset and contact forms load a security check from Cloudflare that tells people apart from bots. It runs in a frame from challenges.cloudflare.com, which may keep a technical item in your browser for this check only. It is strictly necessary to protect the forms and is never used for advertising. Cloudflare handles the data under its Turnstile privacy addendum.
  • Google sign-in. If you click “Continue with Google”, you go to Google’s website, where Google uses its own cookies under Google’s privacy policy.
  • Payments. When you pay, you are sent to Stripe’s checkout page, where Stripe uses its own cookies to process the payment and prevent fraud, under Stripe’s privacy policy.

Google and Stripe load nothing on our pages until you click. In the dashboard, product images load from your own shop’s website, as listed in your catalog.

In the chat widget on shops’ websites

Shops that use AskMerra add our chat widget to their website. The widget sets no cookies. It stores the following in the shopper’s browser, and only after the shopper opens the chat or starts typing. Until then, loading a page stores nothing and sends no identifier.

NamePurposeDurationType
askmerra:visitor (local storage)Random visitor id, so that a conversation and any follow-up request belong to the same person. Holds no name or contact details.30 days after the last chatStrictly necessary
askmerra:session:<site key> (local storage)Short-lived security token showing that the browser passed our anti-abuse check.30 minutesStrictly necessary
askmerra:<site key>:conversation (local storage)The current conversation, so it continues when the shopper moves to another page.24 hoursStrictly necessary
askmerra:<site key>:open (session storage)Keeps the chat open while the shopper browses the shop.Until the tab is closedStrictly necessary
askmerra:<site key>:proactive (session storage)Remembers that the shopper closed the greeting bubble.Until the tab is closedPreference the shopper asked for

Browser storage has no built-in expiry, so the widget deletes these items itself once their time is up. Usage events, such as “chat opened” or “product clicked”, are sent only after the shopper has used the chat. The widget does not fingerprint browsers and does not follow shoppers across websites.

Sales measurement, only with consent. If the shopper accepts analytics in the shop’s cookie banner, the widget reads the visitor id above on the shop’s order confirmation page and links the order (number, amount, products) to the chat, so the shop can see sales after a chat. Without that consent, or for shoppers who never chatted, it doesn’t.

For shops: you are the controller for this data and can copy this table into your own cookie policy. In our assessment these items are strictly necessary for the chat the shopper asks for, so they don’t need consent; if you use a consent tool, list them as strictly necessary. National rules can differ, so check with your adviser. Sales measurement is the exception: it runs only with analytics consent (Google Consent Mode or AskMerra.setConsent()), so list it under analytics or statistics.

How to control or delete them

You can delete cookies and site data at any time in your browser settings, and block them for our site. If you block the strictly necessary cookies, you won’t be able to sign in. Shoppers can also ask a shop to delete their chat data, and shops can offer a delete button on their privacy page with AskMerra.forget().

Changes

We update this page whenever we add, change or remove a cookie or storage item. The date at the top shows the current version.

Questions

Write to [email protected]. Our privacy policy explains how we handle personal data in general.