Cookie policy
What we store on your device, and what we don't. Every cookie and local-storage key the site and platform set, by purpose and lifetime, and how to change your choice.
What this covers
Last updated: 11 September 2026.
This page lists what mercleo.com and the Mercleo platform store on your device, why, for how long, and which of it depends on your choice. It supplements our Privacy policy.
What we may store before you decide depends on where you are. Where the law requires consent first — Quebec, the EEA and the UK, Brazil, and anywhere we cannot tell — you are shown a banner and our analytics store nothing at all and send nothing until you allow it. Everywhere else our analytics start in a cookie-free mode described under "Analytics" below, and you can turn them off at any time. Either way you can change your choice with the "Cookie preferences" link in the footer.
Strictly necessary
These make the site or service work and are set without consent because the service cannot run without them.
- _p_consent_* (cookie and local storage, 365 days): your consent choice itself, so we do not ask again.
- sb-*-auth-token (session): keeps you signed in to your Mercleo account across our subdomains.
- mercleo_portal_token (30 days): keeps a participant signed in to an organization's portal. Set only on that portal's address.
- mercleo_learning_cart, events_kiosk_token (24 hours), events_cockpit_token (12 hours), sign-in state cookies: short-lived state for a purchase, a check-in kiosk or a sign-in flow.
- _p_optout_* (local storage): a per-device "do not track my visits" flag an organization's own staff can set.
Preferences
Remember how you like the product to look. Set without consent; they identify nothing about you.
- mercleo-theme, mercleo_last_product_*, mercleo_settings_closed (1 year), sidebar_state (7 days), active_product (30 days), mercleo_account_id (1 year): theme, last-opened area, sidebar state, active workspace.
- Feature list view (local storage): grid or list layout on the features page.
Analytics
Measures how the site and product are used. What runs before you decide depends on the rule that applies to you.
Where consent is required first (Quebec, the EEA and the UK, Brazil, and any visit whose location we cannot determine): our analytics script writes none of the keys below and sends no measurement until you allow the analytics category. If you decline, it stays silent for the rest of the visit. The only thing recorded is the decision itself, in _p_consent_* above.
Everywhere else (the rest of Canada, the United States): our analytics start in a cookie-free mode. That mode sets no cookie and keeps no identifier that outlives the browser tab, but it is not nothing, and the tab-scoped keys it uses are listed below so you can see them.
- _p_sid_* and _p_sts_* (session storage, cleared when you close the tab): a session identifier and its last-activity timestamp, so a series of page views reads as one visit. Set in cookie-free mode without consent; in consent-first regions, only after you allow analytics.
- _p_vid_* (cookie, 365 days): a visitor identifier that lets us recognize a returning device. Set only after you allow analytics, in every region.
- In cookie-free mode, with no _p_vid_* to go on, page views are grouped by a value derived from your browser and screen settings that changes every week. It is not stored on your device and it is not unique to you, but for up to seven days it can group visits from the same device. Allowing or declining analytics both end this: allowing replaces it with _p_vid_*, declining stops the measurement.
- ph_*_posthog (cookie, about 1 year): PostHog product analytics. On mercleo.com and on our public surfaces — an organization's portal, our help centre and our sign-in screens — PostHog runs entirely in memory, with session recording off, and writes this cookie only after you allow analytics. Signed-in product analytics are covered separately below.
Signed-in product analytics
Inside the Mercleo product, where someone is signed in to their organization's account, we measure product usage as part of providing and improving the Services. That processing is governed by the agreement with the customer organization and our Data processing addendum, not by this site's consent banner, so no banner is shown there and ph_*_posthog is set on sign-in. It is shared across our own subdomains so a session survives moving between areas of the product. Input values are masked in session recordings, and recording can be switched off centrally. If you use Mercleo through your employer or an organization you belong to, ask them — they decide what the account is used for.
Attribution from a link you clicked
These record that you arrived from a specific message, so the organization that sent it can see which message led to a registration or purchase. They are written by our servers as the page loads, before any script runs, and they are not analytics: without them a link you deliberately clicked cannot be credited to the message it came from.
- mercleo_touch (30 days) and mercleo_utm (until the browser closes): set on an organization's portal when you follow a tracked link from one of their emails. They hold identifiers for the message and the campaign, not a profile of you.
- _p_attr_* (session storage, cleared when you close the tab): the same signal held in the browser so it can be attached to a form you submit in the same visit. In consent-first regions this one is not written until you allow analytics.
What we do not use
No Google Analytics or Tag Manager, no Meta or LinkedIn pixels, no advertising or cross-site tracking cookies, no session-replay or heatmap vendors beyond PostHog, no Google Fonts, no embedded YouTube. We do not sell personal information. If any of that changes, this page changes first.
Organizations that use Mercleo on their own websites
When an organization installs Mercleo's analytics on its own site, that organization decides what is collected and is responsible for its own cookie notice. The same regional rule applies: where consent is required first, our script stores nothing and sends nothing until a visitor allows it through that organization's banner; elsewhere it starts in the cookie-free mode described under "Analytics". An organization can also switch its own banner into consent-first mode everywhere.
Changing your mind
Use the "Cookie preferences" link in the footer of this site, or the equivalent link on an organization's portal, to reopen the panel and change any category. Clearing your browser's cookies and site data for a site removes everything listed here for that site, including the record of your choice, and you will be asked again.
Contact
Privacy officer, Mercleo Technologies Inc. Email privacy@mercleo.com.