Cookie Policy
This page lists the cookies Mintward uses and how to control them. It sits alongside our Privacy Policy, which covers everything else we collect.
What are cookies?
Cookies are small text files a site stores in your browser. Some are essential — they're how a site remembers you're logged in from one page to the next. Others are optional and used for things like analytics. We keep ours to a minimum.
Cookies we use
| Name | Purpose | Duration | Category |
|---|---|---|---|
| next-auth.session-token | Keeps you signed in after you log in. | Up to 30 days | Strictly Necessary |
| next-auth.csrf-token | Protects sign-in against cross-site request forgery. | Session | Strictly Necessary |
| next-auth.callback-url | Remembers where to send you after a successful sign-in. | Session | Strictly Necessary |
| mtw_td | Remembers a device you marked "trusted" so you can skip the MFA code on it. Only set if you tick "remember this device". | 30 days | Functional |
Over HTTPS, the next-auth.* cookies carry a __Secure- or __Host- prefix — a browser hardening detail; their purpose is unchanged. “Session” means the cookie is cleared when you close your browser.
Third-party cookies
None. We don't run third-party advertising or analytics cookies. If we add site analytics, we plan to use a cookieless, privacy-first tool. Note that if you reach Square's hosted checkout to manage billing, Square may set its own cookies on its pages, governed by Square's privacy terms.
Managing cookies
You can block or delete cookies from your browser's settings — see the help pages for Chrome, Safari, or Firefox. Because our essential cookies are how sign-in works, disabling them means you won't be able to log in or stay logged in.
Changes and contact
We'll update this page if the cookies we use change; material changes get the same 14-day notice described in our Privacy Policy. Questions go to support@mintward.app.