Cookie Policy
The cookies MazeCrafts sets, what each one does, how long it lasts, and how to change or withdraw your consent.
This Cookie Policy explains how MazeCrafts Labs, Inc. uses cookies and similar technologies on mazecrafts.com and in the MazeCrafts learning portal. It names every cookie we set, says what each one is for, and shows how to change your mind at any time. It supplements our Privacy Policy, which describes our wider handling of personal information.
The short version: we set the few cookies needed to keep you signed in, remember your cart and honour your consent choice, plus one first-party analytics cookie and the fraud-prevention cookies our payment processor requires. We run no advertising trackers and no cross-site profiling.
1. What cookies are
A cookie is a small text file that a website asks your browser to store and send back on later requests. Cookies let a site recognise a returning browser, so a shopping cart survives a page reload and a signed-in session does not ask for your password on every click. A first-party cookie is set by the site you are visiting. A third-party cookie is set by another domain whose code is embedded in the page. A session cookie is deleted when you close the browser. A persistent cookie survives until its stated expiry or until you delete it.
We also use two related technologies. Local storage keeps small values in your browser, such as your reduced-motion preference and your position in a build video, and is never transmitted to us automatically. Pixels are tiny images in emails that tell us whether a message was opened; you can stop them by disabling remote images in your email client.
2. Cookies we set
| Name | Set by | Purpose | Category | Type | Duration |
|---|---|---|---|---|---|
| mc_consent | mazecrafts.com | Stores your cookie consent choice per category so we do not ask again on every visit | Strictly necessary | First-party persistent | 12 months |
| mc_session | mazecrafts.com | Keeps you signed in to the learning portal and links requests to your account securely | Strictly necessary | First-party session | Session |
| mc_cart | mazecrafts.com | Remembers the kits and printable packs in your basket between pages and visits | Strictly necessary | First-party persistent | 14 days |
| mc_csrf | mazecrafts.com | Protects forms and checkout against cross-site request forgery | Strictly necessary | First-party session | Session |
| mc_prefs | mazecrafts.com | Stores display choices such as high-contrast mode, reduced motion and measurement units | Functional | First-party persistent | 6 months |
| mc_locale | mazecrafts.com | Remembers your country and currency selection for pricing and shipping estimates | Functional | First-party persistent | 6 months |
| _plausible | mazecrafts.com | First-party analytics identifier used to count unique visits without cross-site tracking | Analytics | First-party persistent | 24 hours |
| __cf_bm | Cloudflare | Distinguishes humans from automated traffic to protect the site from bots and abuse | Strictly necessary | Third-party | 30 minutes |
| cf_clearance | Cloudflare | Records that a challenge was passed, so you are not challenged repeatedly | Strictly necessary | Third-party | 30 minutes |
| __stripe_mid | Stripe | Fraud prevention: identifies the browser across a payment session to detect card testing | Strictly necessary | Third-party persistent | 12 months |
| __stripe_sid | Stripe | Fraud prevention within a single checkout session | Strictly necessary | Third-party | 30 minutes |
| mc_klv | mazecrafts.com | Links a newsletter click to your session so an unsubscribe or preference change applies to the right record | Functional | First-party persistent | 90 days |
We audit this table quarterly against the cookies actually observed in a clean browser session, and we publish the change date at the top of this page. If you find a cookie on mazecrafts.com that is not listed here, please tell us at [email protected] and we will investigate and correct the list.
3. The categories we use
3.1 Strictly necessary
These cookies make the site work: signing in, keeping a basket, submitting a form safely, taking a payment without fraud, and remembering your consent choice. They cannot be switched off in our banner because the service would not function without them, and we rely on the legitimate interest of providing a service you asked for rather than on consent. They set no advertising identifier and are never used to profile you.
3.2 Functional
These remember choices you made, such as high-contrast display, reduced motion, currency and newsletter preferences. Declining them does not break the site; it simply means you re-select those options on each visit.
3.3 Analytics
We use Plausible Analytics, a privacy-focused, European-hosted tool. It counts page views, referrers, approximate country, and device class in aggregate. It does not use cross-site identifiers, does not build advertising profiles, and does not share data with an advertising network. We use it to see which build guides get abandoned halfway and which activity pages help teachers, then fix the ones that do not.
3.4 Advertising
We do not use advertising or retargeting cookies. There is no Meta pixel, no advertising conversion tag, and no data broker script on mazecrafts.com. If that ever changes, we will update this policy, ask for consent before setting anything, and say so plainly in the banner.
4. Consent management and changing your choices
On your first visit you see a consent banner with three equally prominent options: accept all, reject all non-essential, and manage preferences. Nothing beyond the strictly necessary cookies is set before you choose, and rejecting is exactly one click, the same as accepting. Your choice is stored in the mc_consent cookie for twelve months, after which we ask again.
You can revisit your choice at any time using the “Cookie preferences” link in the footer of every page. The preference panel lets you toggle functional and analytics categories independently, shows which cookies each category sets, and applies the change immediately. Withdrawing consent removes the cookies in that category on the next page load and is as easy as giving it. Because your preference is itself stored in a cookie, clearing your browser cookies also clears the record of your choice, and the banner will appear again.
We honour consent signals from the Global Privacy Control specification. If your browser or extension sends the GPC header, we treat it as a rejection of non-essential cookies and of any sale or sharing of personal information, without waiting for a banner interaction.
5. Browser and device controls
Your browser gives you independent control over cookies, and those settings override anything we do. In most browsers you will find the options under privacy or content settings, where you can block third-party cookies, delete cookies for a single site, clear all cookies on close, or browse in a private window that discards cookies at the end of the session.
- Chrome and Edge: Settings, then Privacy and security, then Cookies and other site data.
- Safari on macOS: Settings, then Privacy, where Prevent cross-site tracking is on by default.
- Safari on iOS: Settings app, then Safari, then Privacy and Security.
- Firefox: Settings, then Privacy and Security, then Cookies and Site Data, with Enhanced Tracking Protection set to Standard or Strict.
Blocking all cookies will stop you signing in to the learning portal and will prevent checkout from completing, because the sign-in session and the fraud checks both need a cookie. If you prefer not to accept cookies at all, you can order by telephone on +1 (503) 555-0142, and schools can order by purchase order under our Subscription and Billing Terms.
6. Do Not Track
Some browsers send a Do Not Track header. There is still no agreed industry standard for interpreting it, and many sites ignore it. We take a simple position: because we set no advertising or cross-site tracking cookies at all, a Do Not Track signal makes no practical difference to what we collect. Where the header is present we additionally treat it as a rejection of the analytics category, so no _plausible cookie is set. As noted above, we act on Global Privacy Control signals in the same way.
7. Third-party cookies and why they exist
The only third-party cookies on our site come from Cloudflare, which protects the site from bots and denial-of-service traffic, and from Stripe, which screens payments for fraud. Both are necessary for a working, safe storefront and both are named in the subprocessor table in our Privacy Policy. We embed no social media widgets, no comment platforms and no font services that phone home, and our fonts are self-hosted for exactly that reason. Build videos are served from our own storage with a privacy-preserving player, so watching one sets no third-party cookie.
8. Children and cookies
MazeCrafts accounts belong to adults, and we do not knowingly collect personal information from children under 13. Our analytics tool is configured so that it cannot build a behavioural profile of any visitor, child or adult. Our children’s-data posture is set out in full in our Privacy Policy.
9. Changes to this policy
We update this page whenever we add, remove or change a cookie, and always before a new cookie appears in a released build. The effective date at the top reflects the current version. Where a change would set a new non-essential cookie, we reset the consent record and ask again rather than relying on an older permission.
10. Contact
Questions about cookies, consent or tracking: [email protected]. General enquiries: [email protected]. Telephone +1 (503) 555-0142. Post: MazeCrafts Labs, Inc., 214 Birchwood Ave, Suite 3, Portland, OR 97214, USA. Related policies: Privacy Policy, Terms of Service, Accessibility Statement.