Cookie policy
Last updated 18 September 2026
MonaLisaa is operated by Craig Malloy trading as MonaLisaa, a sole trader, at [BUSINESS-ADDRESS]. Questions: [email protected].
This policy covers monalisaa.co. Customer websites and Stripe’s hosted checkout have their own information and settings. Our Privacy policy explains personal information more broadly.
What these technologies do
Cookies are small values stored by your browser. Local storage and session storage can also remember information on your device. UK rules cover storage and access technologies beyond cookies, so a service being described as “cookieless” does not by itself settle whether permission is needed.
Storage used by the app
| Name and type | Purpose and provider | Lifetime in the application |
|---|---|---|
monalisaa_session — first-party cookie |
Keeps you signed in to MonaLisaa and allows account access | 30 days from session creation; sign-out clears the browser cookie |
monalisaa_guest — first-party cookie |
Recognises the browser authorised to edit a site before purchase | Up to 180 days from issue |
ml:plan — first-party local storage |
Remembers the plan selected in the quiz for the pricing page | No application-set expiry; remains until cleared by the browser or user, or replaced |
ml:lastSite — first-party local storage |
Remembers a site token so the pricing flow can return to that site | No application-set expiry; remains until cleared by the browser or user, or replaced |
ml:promoHidden — first-party session storage |
Remembers that you dismissed the pricing promotion during the browser session | For that tab’s session, subject to browser session-restore behaviour |
The sign-in and guest cookies support access and security for the service you request. They are marked Secure and HttpOnly, so ordinary page scripts cannot read them. These protections do not make a shared device private.
The application writes or reads these preferences in the quiz, pricing and editing flows without a separate in-page permission or reset control. The local-storage preferences have no application-set expiry. Their presence does not establish that every preference is strictly necessary; the storage assessment and any required controls remain incomplete.
External services and optional measurement
The app can load Cloudflare Web Analytics when configured. The application default is off: the beacon is inserted only if CF_ANALYTICS_TOKEN is non-empty. Generated customer sites separately insert it only if site.analytics.beaconToken is set. These settings are operator/site configuration, not visitor consent controls. The code does not wait for an in-page analytics choice. The deployed token state, retention and any applicable consent or exception conditions have not yet been verified for publication. There is no claim here that all analytics are automatically exempt from consent.
Cloudflare Turnstile checks appear on customer enquiry forms where configured, including when those forms are viewed in previews. Cloudflare processes browser and challenge information to help distinguish genuine requests from automated traffic. Whether a clearance cookie is used depends on the Cloudflare configuration. The form’s verification preference defaults to on, but verification also requires configured keys; an owner can turn the preference off. The source includes the Turnstile widget and server verification call. It does not establish whether the live Cloudflare configuration adds a clearance cookie, its lifetime, or other edge storage; those remain deployment checks, not asserted cookies.
The app loads Google Fonts through Google’s font service. This creates external requests which disclose connection information such as the visitor’s IP address and browser/request details. It is not described here as an advertising cookie. Ordinary browser caching may retain downloaded fonts and other website files.
Payments take place on Stripe’s hosted checkout, which has its own cookies and privacy information. Moving to Stripe is not consent to unrelated tracking on monalisaa.co. Our server creates a Stripe-hosted checkout session and the browser follows the returned URL. The inspected checkout does not embed Stripe.js or Stripe Elements on monalisaa.co. Stripe explains its own storage and choices in its Cookie policy and Privacy policy. A live checkout cookie inventory has not yet been verified.
Your choices
You can block or clear cookies and site storage in your browser. Blocking the access cookies can stop sign-in or draft editing. Clearing local storage can lose the remembered plan and last-site link. Keep important links safely, especially before clearing draft access information.
There is currently no in-page consent, withdrawal or analytics-objection control in the inspected application. Browser settings are available as described above, but do not replace any site control required by law. Before optional technology is enabled, its lawful basis and any required visitor control must be established.
Where consent is required, that technology must wait for your choice. Necessary service cookies do not depend on consent. Merely continuing to browse is not agreement to optional tracking.
We update this policy when the technologies or their purposes change. Contact [email protected] if you need help with a choice or an accessible way to use the service.