Mast Finance Sàrl — Effective date: 13 July 2026 — Version 1.2
This Cookie Policy explains what cookies and similar technologies are, which ones Mast Finance uses on the Service, why we use them, and how you can manage your preferences. It should be read alongside our Privacy Policy.
1. What Are Cookies?
Cookies are small text files placed on your device when you visit a website or use an online service. They allow the service to recognise your device across sessions and store certain preferences. Cookies may be session cookies (deleted when you close your browser) or persistent cookies (retained for a defined period).
This policy also covers local storage, a similar browser technology used to store small amounts of data on your device.
2. Cookies and Local Storage We Use
2.1 Essential (Strictly Necessary)
These are strictly necessary for the Service to function. They cannot be disabled without impairing core functionality. They are placed without requiring your consent.
Essential storage is used for:
- Authentication and session management — keeping you logged in securely.
- Security — protecting against cross-site request forgery and other threats.
- Consent preference — remembering your cookie choice.
2.2 Analytics (Consent Required)
These are placed only with your consent. They allow us to understand how users navigate and use the Service to improve performance and usability. Analytics data does not identify you personally.
Analytics storage is used for:
- measuring page views, session durations, and feature usage;
- identifying errors or areas of poor performance;
- informing product development decisions.
Privacy safeguards:
- EU-based processing — Our analytics are processed in the EU (Frankfurt) by PostHog, Inc. via PostHog Cloud EU, a subprocessor listed in our Subprocessors page. Covered by the Swiss-EU adequacy decision.
- IP anonymisation — IP addresses are not stored or processed.
- Session recording masking — Form inputs are automatically masked; rendered elements holding Customer Data are further masked via the
data-ph-maskmechanism so financial figures and personal identifiers do not appear in recordings. - No Customer Data transmitted — only Service Data (behavioural telemetry, bucketed amounts, enum metadata). Financial records, customer names, IBANs, and other Customer Data stay in AWS Switzerland.
- No analytics before consent — The analytics library loads in a disabled state and makes no network request until you consent. No analytics events are captured, and no
ph_*or other tracking cookies or storage entries are set, before you provide consent. Fonts, icons, and other static assets are served from our own infrastructure, so loading the page does not transmit your IP address to any third party. If you decline, the analytics library stays disabled and no behavioural data is collected.
3. Storage Details
| Name / Prefix | Type | Category | Purpose | Retention |
|---|---|---|---|---|
CognitoIdentityServiceProvider.* |
Local storage | Essential | Authentication tokens (AWS Cognito) | Until logout or token expiry |
mast_analytics_consent |
Local storage | Essential | Stores your consent preference | Persistent (until cleared) |
ph_* |
Local storage / cookie | Analytics | Usage measurement and product improvement | Up to 12 months |
Note: Analytics entries (ph_*) are only created after you provide consent. Before consent, no analytics events are captured and no tracking identifiers are set; the analytics library remains loaded in a disabled state.
4. Managing Your Cookie Preferences
You can manage your preferences in the following ways:
- Cookie banner — On your first visit, you can accept or decline analytics cookies.
- Cookie settings link — Update your preference at any time via the "Cookie Settings" link in the footer.
- Browser settings — Most browsers allow you to block or delete cookies and local storage. Blocking essential storage will impair your ability to use the Service.
Withdrawing consent does not affect the lawfulness of processing based on consent before withdrawal.
5. Third-Party Cookies
We do not use third-party advertising or tracking cookies. Analytics is provided by PostHog Cloud EU (Frankfurt) as a subprocessor under our DPA — see Subprocessors page for the complete list of third parties and their roles.
6. Data Retention for Analytics
- Event data (page views, feature usage): 90 days.
- Session recordings: 30 days.
After these periods, data is automatically and permanently deleted.
7. Changes to This Policy
We may update this Cookie Policy at any time. The current version is always available at /cookies.
8. Contact
For questions about cookies or this policy, please contact us at contact@mastfinance.io.
Mast Finance Sàrl — Rue Centrale 15, 1003 Lausanne, Switzerland — contact@mastfinance.io
Revision history
- v1.2 (2026-07-13): Web fonts and the icon library are now self-hosted (served from Mast's own infrastructure) and analytics is fully deferred until consent, so no third-party network request is made before consent. Removed the earlier caveat about a minimal configuration request and web-font asset requests possibly involving your IP, which no longer applies.
- v1.1 (2026-07-13): Reworded the "no data before consent" claim to be accurate at the network layer. Now states that no analytics events are captured and no
ph_*or tracking cookies are set before consent, and that a minimal anonymous configuration request and static assets (such as web fonts) may involve your IP as a normal part of loading the page. Added draft banner. - v1.0 (2026-02-24): initial.