Legal

Cookie Policy

This policy explains what cookies and similar technologies we use, why, and how you can control them.

Last updated: July 8, 2026

1. Introduction

MagicDots is operated by PREDA BOGDAN-MARIAN PERSOANĂ FIZICĂ AUTORIZATĂ, a self-employed person (persoană fizică autorizată) registered in Romania, holding tax ID (CUI) 51692615, with its registered office at Jud. Prahova, Municipiul Ploiești, Str. Cameliei nr. 9B, bl. 59, sc. 1, et. 3, ap. 14. In this policy, "MagicDots", "we", "us" or "our" refers to this provider.

This Cookie Policy describes how we use cookies and similar technologies (a) on the public website magicdots.io, (b) in our application app.magicdots.io, and (c) through the MagicDots pixel that merchants install on their own online stores. It complements our Privacy Policy, which explains in detail how we process personal data.

The Romanian-language version is the canonical version. In the event of any inconsistency between the Romanian and the English version of this policy, the Romanian version prevails.

2. What cookies and similar technologies are

Cookies are small text files that a website stores on your device (computer, phone, tablet) when you visit it. They are sent back to the site on later visits and allow, for example, recognizing your login session or remembering your language preference.

"Similar technologies" include, among others, browser local storage (localStorage / sessionStorage), tracking pixels/tags, and similar identifiers that perform functions comparable to cookies.

Cookies may be "session" cookies (deleted when you close your browser) or "persistent" cookies (they remain on the device for a defined period or until you delete them). They may be set by the site you visit ("first-party" cookies) or by a third party ("third-party" cookies).

3. How we use cookies

On the public website magicdots.io we use a minimal set of cookies, primarily for the correct functioning of the pages and for remembering the visitor's language preference.

In the application app.magicdots.io we use strictly necessary cookies to authenticate merchants and to keep the user session secure. Without these cookies, authentication and the protected areas of the application cannot function.

Separately, we provide merchants with a MagicDots pixel that they can install on their own stores (WooCommerce or Shopify). The cookies set by this pixel appear on the merchant's store domain, not on magicdots.io, and are addressed separately in section 5.

4. Categories of cookies on magicdots.io and app.magicdots.io

Strictly necessary cookies. These are essential for delivering the website and the application and cannot be disabled in our systems. They include authentication and session cookies used by our authentication infrastructure (provided via Supabase) in app.magicdots.io, as well as the NEXT_LOCALE language-preference cookie, which remembers whether you use the interface in Romanian or English.

Functional cookies. These help us remember choices and preferences you make, to give you a more consistent experience. Their absence does not prevent use of the service, but may reduce convenience.

Analytics cookies. If and when we use analytics cookies that are not strictly necessary, we will enable them only on the basis of your consent where the law so requires.

5. MagicDots pixel cookies on merchants' stores

When a merchant installs the MagicDots pixel on their store, the pixel may set first-party cookies on the merchant's store domain, to support the abandoned-cart recovery and traffic-source attribution features.

magicdots_cart_token — an opaque, stable identifier (pseudonym), which may constitute personal data, for the shopping cart/session, used to associate cart activity with any recovery emails. It is a first-party cookie, with path=/, with a duration of approximately 365 days, set with the SameSite=Lax attribute and with the Secure attribute when the store runs over HTTPS. This cookie does not itself contain the shopper's name or email address; it is an opaque identifier.

magicdots_utm — stores the "first-touch" traffic source, i.e. the utm_source, utm_medium and utm_campaign values from the first landing page carrying UTM parameters, for accurate conversion attribution. It is a persistent first-party cookie with a duration of approximately 365 days; the first captured value takes precedence and is not overwritten by later visits.

The role of consent and the merchant's responsibility. For shopper data captured through the pixel on a merchant's store, the merchant is the data CONTROLLER, and MagicDots acts as a PROCESSOR that processes this data on behalf of and according to the instructions of the merchant. The merchant is responsible for displaying their own cookie-consent banner/solution on their store, for obtaining shoppers' valid consent where the law so requires, and for having a legal basis for capturing and using contact data (email/phone) for cart-recovery purposes.

6. Third-party cookies and services (sub-processors)

Certain features rely on third-party providers that act, as applicable, as our sub-processors and that may set their own cookies or technical identifiers when you interact with the service. In particular, payments and subscriptions are processed through Stripe, which may set cookies necessary for payment processing and fraud prevention within its payment pages or components.

In addition, the application's hosting, delivery and communication infrastructure may involve cookies or technical identifiers that are strictly necessary for security and for the functioning of the service. The providers we use include: Supabase (database and authentication, EU-hosted), Vercel (application hosting), Stripe (payments and subscriptions), Resend (email delivery), as well as artificial-intelligence providers used to generate content within the application (OpenAI and Anthropic). These AI providers are called at the merchant's configuration time, not through cookies in the visitor's browser. The up-to-date list of sub-processors is available at magicdots.io/subprocessors.

Third-party cookies and processing are governed by the privacy and cookie policies of those respective providers.

7. Managing and disabling cookies

You can control and delete cookies from your browser settings. Most browsers let you see which cookies are stored, delete them individually or in bulk, and block cookies — either all of them or only those of third parties. Consult the help section of your browser (Chrome, Firefox, Safari, Edge) for specific instructions.

Where we display a cookie-consent banner/tool, you can give or withdraw your consent for the non-essential categories directly from that tool. Strictly necessary cookies cannot be disabled through the consent tool, because without them the service does not function.

For cookies set by the MagicDots pixel on a merchant's store, the consent and control mechanism belongs to that store (the merchant, as data controller). As a visitor to such a store, you can manage these cookies through the store's consent banner and through your browser settings.

8. Consequences of refusing cookies

If you block or delete strictly necessary cookies in app.magicdots.io, you may be unable to log in, may be logged out repeatedly, or may be unable to access the protected areas of the application.

If you reject functional or preference cookies (for example NEXT_LOCALE), some preferences, such as the interface language, may not be remembered between visits.

If, on a merchant's store, the shopper rejects the MagicDots pixel cookies, features such as abandoned-cart recovery or accurate traffic-source attribution may not work for that shopper. Refusing non-essential cookies does not affect your right to browse and make purchases.

9. Cookies and personal data (dual GDPR role)

Some cookies and identifiers may constitute personal data within the meaning of Regulation (EU) 2016/679 (GDPR). Our role differs depending on the context.

For the cookies on magicdots.io and in app.magicdots.io related to the merchant's account, MagicDots acts as CONTROLLER.

For the cookies and data captured through the MagicDots pixel on a merchant's store (for example magicdots_cart_token, magicdots_utm and shoppers' contact data), MagicDots acts as PROCESSOR, and the merchant remains the CONTROLLER. Full details about legal bases, rights and sub-processors are set out in the Privacy Policy and in the Data Processing Agreement.

10. Changes to this policy

We may update this Cookie Policy from time to time to reflect changes in the technologies we use, in legal requirements, or in our practices. The applicable version is the one published at this address.

When we make significant changes, we will update the "Last updated" date at the top of the policy and, where appropriate, inform you by suitable means. We encourage you to review this page periodically.

11. Contact

For any questions about this Cookie Policy or how we use cookies, you can contact us at contact@magicdots.io.

For requests concerning personal data (access, deletion, objection, etc.), please refer to the Privacy Policy. Merchants can export and delete their account data directly from the application (self-service) or by email at contact@magicdots.io.

The Romanian-language version of this document is the official version and prevails in case of any discrepancy with translations.