← All policies

Cookie & Tracking Policy

Version 2026-09-08
Not legal advice. These policies are written as a community-friendly summary. They are not a substitute for advice from a licensed attorney in your jurisdiction. We are actively improving this language with counsel; bookmark this page and check the version stamp.

What are cookies?

Cookies are small text files that a website stores in your browser to remember information about you between page loads or visits. Some are essential to make the site work. Others help us understand how the site is used so we can improve it. This policy explains exactly what we set, why, and how you can control it.

Cookies we set

Essential cookies (always on — required for the site to function)

| Name | Purpose | Duration |

|---|---|---|

| `mgc_sid` | Session identifier — keeps you logged in | 2 hours (rolling) |

| `mgc_pv` | Anonymous visitor ID for analytics deduplication | 180 days |

| `_csrf` | Cross-site request forgery protection | Session |

| `g_csrf_token` | Google Sign-In CSRF protection | 5 min (only when signing in with Google) |

| `mgc_consent` | Remembers your cookie consent choices | 12 months |

These are strictly necessary. Turning them off will break login, form submission, or the site entirely.

Analytics cookies (optional — you can opt out)

We use first-party analytics to track anonymous pageviews for improving the site. If you opt out, or if your browser sends a Do Not Track signal, we skip this entirely. There is no third-party analytics beacon on the free tier.

| Name | Purpose | Duration |

|---|---|---|

| Anonymous pageview event | Which pages get traffic, referrers, first-touch attribution | Aggregated, 180-day raw retention |

Third-party cookies from features you use

Some third-party services set cookies only when you interact with a specific feature:

  • Stripe (only when you go to checkout) — payment security and fraud prevention. See https://stripe.com/privacy.
  • Cloudflare Turnstile (only on `/signup`) — CAPTCHA verification. See https://www.cloudflare.com/privacypolicy/.
  • Google Sign-In (only if you click Sign in with Google) — auth session. See https://policies.google.com/privacy.
  • Microsoft Clarity (admin-side only by default) — session recording for QA. Not enabled for regular users.

None of these run until you actively engage the relevant feature.

What we DON'T use

  • No advertising cookies
  • No third-party ad networks
  • No cross-site tracking pixels
  • No Facebook Pixel, Google Ads pixel, TikTok pixel, LinkedIn Insight, or similar
  • No behavioral profiling for retargeting

Your controls

  • First visit — you'll see a banner asking to accept, reject, or customize cookies. Your choice is remembered.
  • Change later — [Privacy Settings](/profile/privacy) lets you toggle analytics on/off at any time.
  • Browser controls — you can also block cookies in your browser settings. If you block essential cookies, the site will not function.
  • Do Not Track — we honor DNT. If your browser sends DNT, we do not set analytics cookies.

Retention

  • Session cookies delete when you close your browser
  • Persistent cookies expire on the schedule above
  • Server-side analytics data is purged after 180 days automatically

Contact

Questions about cookies or tracking? [privacy@mygrowcommunity.com](mailto:privacy@mygrowcommunity.com)

_Policy last reviewed: September 8, 2026_

Questions or feedback: legal@mygrowcommunity.com