Cookie notice
Last updated: 31 July 2026
Maditon uses the minimum number of cookies needed to keep you signed in and to process payments. No cross-site tracking. One page — the free CRA Readiness Scan — can set an advertising cookie, and only if you say yes on the banner shown there.
Cookies set by Maditon
The Maditon website (maditon.com) sets no cookies — first-party or third-party — on any page except /cra-scan. It is a fully static site.
The exception: maditon.com/cra-scan. That page is the landing page for a Google Ads campaign, so it needs Google's advertising tag to tell us whether an ad brought you there. That tag sets cookies, which means we ask first. The page shows a banner with equal-weight Accept and Decline buttons and defaults to declined: until you press Accept, no request is made to any Google server and no cookie is set. Press Decline and none ever is. The scan itself — the questions, the scoring, the result, the emailed report — works identically either way; nothing about it is gated on your answer. Your choice is remembered in your browser's localStorage, not in a cookie, so declining leaves the page genuinely cookie-free.
| Cookie | Purpose | Duration | Category |
|---|---|---|---|
_gcl_* and related Google Ads cookies | Attribute a completed CRA Readiness Scan back to the ad that brought you — set only on /cra-scan, and only after you press Accept | Up to 90 days | Marketing — consent required |
The Maditon application (maditon.app) sets a small number of strictly-necessary first-party cookies to keep you signed in and to protect the sign-in flow. These are essential — the app cannot function without them — so no consent is required, and they carry no advertising or tracking data. They are set by Auth.js, the open-source session library the app runs on.
| Cookie | Purpose | Duration | Category |
|---|---|---|---|
authjs.session-token | Keeps you signed in — holds your encrypted session token | Session, until you sign out | Strictly necessary |
authjs.csrf-token | Protects the sign-in flow against cross-site request forgery | Session | Strictly necessary |
authjs.callback-url | Remembers where to return you after sign-in | Session | Strictly necessary |
Over HTTPS these are sent with the hardened __Secure- / __Host- name prefixes. All are HttpOnly where the session library allows it and are never readable by advertising or analytics scripts.
Third-party cookies set during specific user actions
When you sign in or make a payment, you are redirected to a trusted third-party service. Those services set their own cookies on their own domains, subject to their own policies. Nothing on that list is for marketing or tracking.
| Source | Domain | Purpose | Duration | Category |
|---|---|---|---|---|
| Zitadel | our Zitadel auth domain | Keep you signed in during the OIDC login flow | Session + refresh window | Strictly necessary |
| Stripe | checkout.stripe.com | Process the payment checkout and fraud-detect your session on Stripe | Session, plus fraud-prevention windows | Strictly necessary |
Analytics
Maditon uses Plausible Insights for aggregate analytics. Plausible is cookieless by design: no cookies, no cross-site identifier, no personal data sent. It runs on every page and needs no consent, which is why the only page that shows a banner is the one carrying the Google Ads tag.
Managing cookies in your browser
You can clear or block cookies from your browser settings at any time. Note that blocking the strictly-necessary cookies above will prevent you from signing in or completing payment.
What would change this
If the set of cookies we use changes — for example, if we add analytics that use cookies, video embeds from YouTube, or social-media sharing widgets — we will update this page and show a consent banner where the law requires one, as we already do on /cra-scan. The "Last updated" date reflects the most recent revision.
Contact
Please feel free to contact us at privacy@maditon.com if you have any questions.