Merlin Cookie Policy

What are Cookies?

Cookies are small text files that are stored in your internet browser or by your internet browser on your computer system. They help websites remember information about your visit, making your online experience easier and more personalized.

We rely on the following lawful bases for processing personal data through cookies: Consent: For all non-essential cookies (e.g. analytics, marketing, personalization). Legitimate Interest: For strictly necessary cookies essential to the functionality and security of our services.

Users are presented with a cookie banner at first visit, allowing them to:

  • Accept all cookies
  • Reject non-essential cookies, or
  • Customize preferences by cookie category.

You can withdraw or modify your cookie consent at any time by clicking the “Cookie Settings” link in the footer of our website or in your browser settings. The details are also noted below.

On your first visit, our cookie banner will appear and allow you to:

  • Accept all cookies,
  • Reject non-essential cookies, or
  • Customize preferences based on categories (e.g., Necessary, Functional, Analytics, Marketing).

If you choose Customize, select which categories (excluding Necessary cookies) you're comfortable enabling. These categories are clearly defined in the Cookie Types section.

Withdrawal & Preference Changes

You may withdraw or modify your consent at any time by:

  • Clicking the “Cookie Settings” link located in the footer of our website

Browser-Level Controls

  • You can also manage or block cookies via your web browser’s settings.
  • See detailed guidance at AboutCookies.org and YourOnlineChoices.eu.
  • This consent covers all browsers and devices using our Services unless you explicitly change it.
  • If we introduce new cookie categories or update our policy, you'll be prompted to renew your consent via the banner.
Cookie TypeService / ProviderPurposeExamples of Data CollectedRetention PeriodLegal Basis (EU/UK/CH)
Strictly Necessary CookiesWebsite Core (e.g., session ID, load balancer)Enables core website functionality (navigation, authentication, fraud prevention, cart, etc.)Session ID, authentication token, shopping cart contentsSession duration onlyArt. 6(1)(b) GDPR — Performance of a Contract or Art. 6(1)(f) GDPR — Legitimate Interests
Functional CookiesLanguage preference, geolocation cookieRemembers language, region, or other user preferencesLanguage, region, user preference settingsUp to 12 monthsArt. 6(1)(a) GDPR — Consent
Analytics/Performance CookiesGoogle Analytics, HotjarCollects usage data to improve site performance and usabilityIP address (truncated), device ID, browser type, pages visited, session time6 to 24 monthsArt. 6(1)(a) GDPR — Consent
Advertising/Marketing CookiesGoogle Ads, Meta Pixel, LinkedIn AdsTracks browsing to deliver personalised ads and measure campaign effectivenessDevice ID, IP address, browser ID, pages visited, ad interactionsUp to 24 monthsArt. 6(1)(a) GDPR — Consent
Social Media CookiesFacebook Like Button, Twitter Share ButtonAllows sharing via social networks and enables social platform trackingSocial media account ID, pages visited, browser/device infoControlled by providerArt. 6(1)(a) GDPR — Consent
Preference Management CookiesConsent Management Tools (e.g., OneTrust)Stores cookie consent preferences and ensures legal complianceConsent status, timestamp, consent IDUp to 12 monthsArt. 6(1)(f) GDPR — Legitimate Interest

Types of Cookies We Use

Necessary Cookies

These cookies are required to operate our Services. For example, they allow us to authenticate users or enable specific features within the Services, including for security purposes. These cookies cannot be disabled as they are essential for our website to function properly.

Cookie NameSource (Provider)Expiry Date / Data retention time periodPurpose/Description
__Host-authjs.csrf-tokenMerlinSessionSecurity token to prevent CSRF attacks during user sessions.
NEXT_LOCALEMerlin~1 yearStores the user's preferred language for localization.
__Secure-authjs.callback-urlMerlinSessionEnsures a secure callback URL after successful login.
__Secure-authjs.session-tokenMerlin~1 monthSecure session management token to keep the user logged in.
AECGoogle~6 monthsEnsures requests are user-initiated; used by reCAPTCHA.
SEARCH_SAMESITEGoogle~6 monthsSecurity cookie to prevent CSRF across same-site requests.

Support Chatbot Cookies

The following cookies are optional, but if you want to chat with live-support then these need to be enabled.

Cookie NameSource (Provider)ExpiryPurpose/Description
tawk_uuid_*Tawk.to~ 6 monthsUnique visitor tracking via UUID.
twk_idm_keyTawk.toSessionManages visitor's connection requests.
twk_token_*Tawk.toSessionAuthentication and secure connection management.
twk_uuid_propertyIdTawk.to~ 6 monthsTracks visits across pages for a property.
TawkConnectionTimeTawk.toSessionSynchronizes connection across browser tabs.

Analytics Cookies

These cookies help us understand how visitors interact with our website, allowing us to analyze usage patterns and improve our services and user experience.

Cookie NameSource (Provider)ExpiryPurpose/Description
_clckMicrosoft Clarity (via GTM)~1 yearPersists Clarity user ID across sessions for analytics.
_clskMicrosoft Clarity (via GTM)1 dayConnects multiple page views by a user into a single session recording.
_ga, _ga_*Google Analytics2 yearsUsed to distinguish users. Multiple variations per property.
CLIDMicrosoft Clarity~1 yearIdentifies the first time Clarity saw this user on any site using Clarity.

Marketing Cookies

These cookies help us support and measure the performance of our marketing campaigns, deliver targeted advertising, and enhance the Services' visibility across various platforms.

Cookie NameSource (Provider)ExpiryPurpose/Description
_fbpMeta/Facebook (via GTM)3 monthsStores a unique ID for retargeting ads via Facebook.
_gcl_auGoogle Ads (via GTM)3 monthsTracks ad conversion data across websites.
_rdt_uuidReddit Ads (via GTM)~90 daysTracks conversion and campaign effectiveness on Reddit.
__Secure-1PAPISIDGoogle~2 yearsUsed for ad targeting and Google sign-in flows.
__Secure-1PSIDGoogle~2 yearsFor user verification, Google Sign-In, and reCAPTCHA.
__Secure-1PSIDCCGoogle~2 yearsEnhances session integrity and fraud prevention.
__Secure-1PSIDTSGoogle~2 yearsStores session-related data for authentication.
__Secure-3PAPISIDGoogle~2 yearsEnables personalized advertising across Google services.
__Secure-3PSIDGoogle~2 yearsBuilds ad interest profiles based on user interactions.
__Secure-3PSIDCCGoogle~2 yearsProtects session data and enables secure tracking.
__Secure-3PSIDTSGoogle~2 yearsSupports personalized ads and session protection.
APISIDGoogle~2 yearsStores preferences for YouTube, Maps, and Google services.
DVGoogle24 hoursAnalytics + security for Google services and reCAPTCHA.
HSIDGoogle~2 yearsEnsures security of authenticated Google users.
NIDGoogle~6 monthsStores ad preferences and Google UI customizations.
SAPISIDGoogle~2 yearsUsed for Google Sign-In and personalization across Google services.
SIDGoogle~2 yearsAuthenticates Google users via encrypted ID.
SIDCCGoogle~1 yearProtects user session integrity and data.
SNIDGoogle~6 monthsUsed for securely identifying repeat Google users.
SSIDGoogle~2 yearsStores Google service preferences.
SGoogleSessionHandles session state for secure Google logins.
IDEGoogle DoubleClick1 yearDelivers targeted ads across the web based on browsing behavior.
DSIDGoogle DoubleClick~1 yearLinks user activity across devices for targeted advertising.
ANONCHKMicrosoft Clarity~1 yearDetermines if a MUID is passed to ANID, used for advertising.
SMMicrosoft ClaritySessionSynchronizes the MUID across Microsoft domains.
test_cookieGoogle DoubleClick~15 minsTests if the browser supports cookies.

Google Cookies

We use various Google services that may set cookies on your device:

  • Google Analytics: We use Google Analytics to understand how visitors interact with our website. This helps us improve our services and user experience. Google Analytics cookies collect information in an anonymous form, including the number of visitors to the site, where visitors have come to the site from, and the pages they visited.

  • Google Ads and Remarketing: We use Google Ads cookies to measure the effectiveness of our advertising campaigns and to show you relevant ads based on your previous visits to our website. These cookies enable us to present you with more relevant advertising on Google services and across the web.

  • Google Tag Manager: We use Google Tag Manager to manage website tags without editing code. While Google Tag Manager itself doesn't set cookies, it may deploy other tags that do set cookies.

Facebook (Meta) Cookies

The Facebook pixel cookie (_fbp) helps us measure, optimize, and build audiences for our advertising campaigns. It allows us to:

  • Track conversions from Facebook ads
  • Optimize ads based on collected data
  • Build targeted audiences for future ads
  • Remarket to qualified leads who have already taken action on our website

Microsoft Clarity

Microsoft Clarity cookies help us understand how users interact with our website by collecting information about mouse movements, clicks, and scrolling behavior. This data is used to:

  • Create heatmaps showing where users click most frequently
  • Generate session recordings to identify usability issues
  • Improve website design and user experience
  • All data collected is anonymized and used in aggregate form

Reddit Ads

The Reddit advertising cookie (_rdt_uuid) enables us to:

  • Track the effectiveness of our Reddit advertising campaigns
  • Measure conversions from Reddit ads
  • Build audiences for retargeting campaigns on Reddit

Your web browser may also allow you to manage your cookie preferences, including to delete and disable cookies. You can take a look at the help section of your web browser or follow the links below to understand your options:

Important Notes

  • Functionality Impact: Please note that changes you make to your cookie settings may affect the availability or functionality of the Services. Cookies listed as "Necessary" are required for the Services to function and cannot be disabled.

  • Device and Browser Specific: Cookie settings are device- and browser-specific, so you will need to set cookie preferences for each device's browser.

  • Opt-Out Options: For many of the advertising cookies, you can also opt out through industry opt-out platforms such as:

Data Retention

Cookies have varying lifespans:

  • Session cookies: Deleted when you close your browser
  • Persistent cookies: Remain on your device for the period specified in the cookie or until manually deleted

Updates to This Policy

We may update this Cookie Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Cookie Policy on this page with an updated revision date.

Contact Us

If you have any questions about this Cookie Policy or our use of cookies, please contact us at support@getmerlin.in

For questions about our cookie practices: Data Protection Officer: dpo@foyer.work Customer Support: support@foyer.work DPO Phone: Sirsendu Sarkar (+91-8953348922) Our DPO: Sirsendu Sarkar (+91-8953348922)

EU GDPR Representative: Rickert Rechtsanwaltsgesellschaft m.b.H. Colmantstraße 15, 53115 Bonn, Germany Email: info@rickert.law Phone: +49 (0)228 74 898 0

UK GDPR Representative: Rickert Services Ltd UK PO Box 1487, Peterborough, PE1 9XX United Kingdom Email: art-27-rep-foyertech@rickert-services.uk

Mailing Address for DPO: House 721, 6th B Cross Road, Block-3, Koramangala, Bangalore, India 560034

Registered Address and Mailing Address: Foyer Tech Inc 16192 Coastal Highway, Lewes, DE 19958 United States Email: support@foyer.work


Procedure for Data Withdrawal via Erasure and Objection

You have the right to request the withdrawal of your data through erasure of your personal data held by us. This means we will delete all personal data pertaining to you from our systems, subject to any legal obligations for data retention.

To initiate a request for data erasure:

  1. Send an email to support@foyer.work
  2. CC dpo@foyer.work
  3. Include "Data Erasure Request" in the subject line
  4. Provide your account email and any relevant details

We will respond to your request within 30 days and complete the erasure within the timeframes required by applicable law.

You also have the right to object to the processing of your personal data where we rely on legitimate interests or use your data for direct marketing purposes. To exercise this right, contact us at dpo@foyer.work and support@foyer.work

Last Updated: 27-June-2025