Legal
Cookie Policy
Last updated
Every cookie and similar technology we set, why it exists, how long it lives and how to withdraw your consent in one click.
1. What cookies are
A cookie is a small text file that a website asks your browser to store and to send back on later requests. Cookies let a site remember that a form was already submitted, that a shopping session belongs to you, or that you dismissed a banner. Similar technologies achieve the same result by other means: local storage and session storage keep values in the browser, pixels and tracking URLs report that a message was opened, and device fingerprinting infers identity from configuration. Wherever this policy says “cookie”, it means all of these technologies.
Cookies are described as first-party when mazecrafts.biz sets them and third-party when an embedded service does. They are session cookies if they disappear when the browser closes and persistent if they survive until an expiry date.
2. How we ask for consent
Strictly necessary cookies are set on the basis of section 25(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG), which allows storage that is absolutely necessary to provide a service you expressly requested. Everything else — marketing, embedded video, session replay — is set only after you click “Accept” in the consent banner, in line with section 25(1) TDDDG and Article 6(1)(a) GDPR. Declining is a single click, the two buttons carry equal visual weight, and we do not use cookie walls. Your choice is recorded in the mc_consent cookie together with a timestamp and the policy version, so that we can demonstrate the consent we relied on.
3. Cookies we set
| Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
mc_session |
mazecrafts.biz | Keeps a facilitator or player signed in during an event and protects requests against cross-site request forgery. | Session | Strictly necessary |
mc_consent |
mazecrafts.biz | Stores your cookie choices and the version of this policy you saw, so the banner is not shown again. | 12 months | Strictly necessary |
_stripe_mid |
Stripe | Fraud prevention on the checkout page; ties a payment attempt to a browser to detect card testing. | 12 months | Strictly necessary |
plausible_ignore |
mazecrafts.biz | Set only on our own team’s devices so internal visits are excluded from aggregate statistics. | Persistent (local storage) | Functional |
hubspotutk |
HubSpot | Recognises a returning visitor so a repeat demo request is not counted as a new contact. | 6 months | Marketing |
__hssc |
HubSpot | Tracks the current session for form analytics and page-view counting. | 30 minutes | Analytics |
__hstc |
HubSpot | Records first visit, previous visit and current visit timestamps plus the campaign source. | 6 months | Analytics |
VISITOR_INFO1_LIVE |
YouTube (Google) | Set when you play an embedded case-study video; estimates bandwidth and stores playback preferences. | 6 months | Marketing |
wordpress_test_cookie |
mazecrafts.biz | Checks whether your browser accepts cookies before showing the editor sign-in form. | Session | Strictly necessary |
Our website analytics run on Plausible, which is cookieless: it counts page views without storing an identifier in your browser and without building a cross-site profile. The plausible_ignore entry exists only to suppress our own traffic. YouTube embeds are loaded in two-click mode, so no Google cookie is set until you actively start a video.
3.1 What the categories mean
- Strictly necessary — without them sign-in, checkout security and consent storage break. These cannot be switched off.
- Functional — remember preferences such as reduced motion or an excluded internal device.
- Analytics — help us understand which pages help buyers decide, in aggregate.
- Marketing — attribute a demo request to a campaign and avoid showing the same message twice.
4. Withdrawing or changing consent
Select “Cookie settings” in the footer of any page to reopen the preference panel, change a category and save. Withdrawal takes effect immediately: we delete the affected cookies in the same response and stop loading the corresponding scripts. Withdrawal does not affect the lawfulness of processing that already took place. If you clear your browser storage, the banner reappears because the record of your choice was stored there.
5. Browser controls
You can also manage cookies in the browser itself. Blocking all cookies will prevent sign-in and checkout from working.
- Google Chrome: Settings → Privacy and security → Third-party cookies, then “See all site data and permissions” to remove entries for a single site.
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data → Manage Data; Enhanced Tracking Protection can be set to Strict.
- Safari (macOS): Safari → Settings → Privacy → Manage Website Data; “Prevent cross-site tracking” is enabled by default.
- Safari (iOS/iPadOS): Settings → Apps → Safari → Advanced → Website Data.
- Microsoft Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data.
- Brave: Settings → Shields, then adjust cross-site cookie blocking per site from the lion icon.
Most browsers also offer a private or incognito window, which discards all cookies when the last such window closes.
6. Do Not Track and Global Privacy Control
We honour the Global Privacy Control signal: when your browser or extension sends Sec-GPC: 1, we treat it as a refusal of all non-essential cookies and skip the banner. The older DNT header is also respected in the same way. Because these signals are transmitted per browser and per device, you may still see the banner on another device.
7. Cookies inside the player app
During a licensed event the player app stores a short-lived session token and a team identifier so that a reconnecting phone rejoins the right run. These entries are strictly necessary, live in session storage, and are discarded when the run ends. The app sets no advertising identifiers and contains no third-party SDK for advertising or attribution.
8. Third-party responsibility
Where a cookie is set by Stripe, HubSpot or YouTube, that provider processes the resulting data under its own privacy notice and in the role described in our Privacy Policy. Links to those notices appear in the preference panel. We audit the embedded list quarterly and remove anything that stops earning its place.
9. Changes to this policy
We update this policy whenever a cookie is added, renamed, re-purposed or removed, and we review it at least once a year. Material changes increment the policy version stored in mc_consent, which causes the banner to ask again so that your consent always matches what we actually set. Questions go to [email protected].
Questions about this document?
Our legal team answers within two business days. Procurement teams can request a signable PDF with company details pre-filled.
[email protected]
MazeCrafts Studio GmbH, Ritterstraße 12, 10969 Berlin, Germany
VAT DE352188104 · HRB 214 887 B