Cookie Notice
Last updated: EFFECTIVE_DATE
This Cookie Notice explains how Mareel Waters, operated by LEGAL_ENTITY ("we", "us", "our"), uses cookies and similar storage technologies on our website at https://mareelearth.com and admin.mareelearth.com, including the marketing pages and the developer portal. It is written to meet our transparency obligations under the EU ePrivacy rules as implemented in Sweden by the Electronic Communications Act (lagen om elektronisk kommunikation, "LEK") and, where personal data is involved, the General Data Protection Regulation (GDPR).
In short: we set only the strictly necessary cookies that keep you securely logged in, and we use no tracking cookies at all. Because of how our analytics is designed, we do not need a cookie consent banner. The sections below set this out in full.
For how we handle personal data more generally, please read our Privacy Policy. This Cookie Notice forms part of, and should be read together with, that policy.
1. What a cookie is, and the scope of this Notice
A cookie is a small text file that a website asks your browser to store on your device. On later visits the browser can send that file back, which lets the site recognise your browser or session. "Similar technologies" include other ways of storing or reading information on your device, such as `localStorage`, `sessionStorage`, pixels and software development kits. We refer to all of these together as "cookies and similar technologies" in this Notice.
Under LEK, storing information on, or gaining access to information already stored in, a user's terminal equipment is generally only allowed if the user has consented, having been given clear and comprehensive information about the purpose. There is an exception: consent is not required for storage or access that is strictly necessary to provide a service that the user has expressly requested.
This Notice covers the cookies and similar technologies used on our own websites and the developer portal. It does not cover:
- The behaviour of any third-party website you reach by following a link from us. Those sites have their own notices.
- The data you send to our tides API as part of a request (such as coordinates and times), or the modelled tide values we return. Those are addressed in our Privacy Policy and in our Terms of Service, not here, because the API is consumed programmatically and does not set cookies in your browser.
2. Essential cookie (no consent required)
We set a small set of strictly necessary authentication cookies. No consent is required for it because it is strictly necessary to provide a service you have expressly requested, namely staying logged in.
- Name and purpose. The Authentication Cookie keeps you signed in to your Account in the developer portal (and the admin area, for authorised staff). Without it, you would have to re-authenticate on every page request.
- What it contains. The cookie holds an encrypted authentication token (a JSON Web Token managed by our authentication library), which cannot be read or tampered with by your browser or a third party. Authentication is stateless: we do not run a separate server-side session store keyed to this cookie. Our authentication library also sets a small number of related strictly necessary cookies (for example a CSRF-protection token and a sign-in callback token); these are all essential to logging in securely and none are used for tracking.
- First-party and not for tracking. It is a first-party cookie set by our own domain. It is used only to authenticate your session. It is not used to profile you, to track you across other websites, or for advertising.
- Lifetime. It persists for the duration of your sign-in and expires when the token's validity ends or when you log out, after which it no longer authenticates you. You can also delete it at any time through your browser settings (see section 6).
- Why no consent is needed. Keeping you logged in is a service you actively request by signing in. Storage that is strictly necessary to deliver that requested service falls within the LEK exception, so we do not ask for consent to set it. If you block this cookie, you will not be able to remain logged in to the portal.
3. Non-essential and tracking cookies: none
We do not use any non-essential, advertising, marketing or tracking cookies. Specifically:
- No Google Analytics and no other third-party analytics cookies.
- No advertising or marketing cookies, and no remarketing, conversion or social-media tracking pixels.
- No third-party trackers and no cross-site or cross-device tracking cookies.
- No "cookie walls". Because we set no non-essential storage, there is nothing to gate access behind.
We have deliberately built the site this way. Where we use a third party at the network edge to deliver and protect the site (Cloudflare, for content delivery, our tunnel, the web application firewall and bot management), that service may process technical request data to keep the service available and secure, as described in our Privacy Policy; we do not use it to set advertising or analytics cookies on your device.
4. Cookieless analytics
We run our own first-party web and marketing analytics so we can understand, in aggregate, how the site is used and improve it. This analytics is cookieless and is designed so that it does not store or access information on your device for non-essential purposes.
- No cookie is set. To distinguish page views within a single browsing session, we generate a visitor identifier and keep it in `sessionStorage`. `sessionStorage` is cleared by your browser when you close the tab or window, is not sent to other sites, and is not a cookie. We do not write this identifier to a cookie or to persistent storage.
- The IP address is hashed. We do not store your raw IP address for analytics. Instead we store a daily-salted hash of it, so that we can roughly de-duplicate and filter traffic without retaining the address itself. We also derive a coarse user-agent family (for example, the broad browser category) and tag traffic we identify as automated. The IP hash and user-agent family apply only to this cookieless web and marketing analytics.
- No third-party analytics processor. This analytics is operated by us on our own infrastructure. We do not send your browsing of our site to Google Analytics or any comparable third-party analytics provider.
- Why no consent banner is required. The LEK consent requirement is triggered by storing or accessing information on your device for non-essential purposes. Reading and writing a short-lived `sessionStorage` value that you yourself caused to be created by loading the page, solely to measure our own site and without any cookie, persistent identifier, third-party tracker or cross-site profiling, does not, in our assessment, amount to non-essential storage of, or access to, information on your device of the kind that requires consent. For that reason, and because our only cookie is the strictly necessary Authentication Cookie in section 2, we do not display a cookie consent banner.
For completeness: this is separate from how our API records Usage. Each Usage Event stored against your Account records the Endpoint called, the HTTP status, a timestamp, the request coordinates and the computed cost. Usage Events do not store an IP address or a user-agent. Usage is covered in our Privacy Policy, not by this Notice, because it does not involve storing or reading anything on your device.
5. Future changes and your consent
We may change the way we use cookies and similar technologies as the product develops, including as we bring the planned forecast and water-state API and the planned iOS and Android apps to market.
If we ever introduce any non-essential storage on your device, for example analytics or measurement cookies, persistent identifiers, or any third-party tracking, we will first obtain your prior, informed, freely given and specific opt-in consent before that storage is set or accessed. Where we ask for consent:
- Rejecting will be as easy as accepting, presented with equal prominence, with no pre-ticked boxes.
- You will be able to withdraw your consent at any time, as easily as you gave it, and we will respect that choice going forward.
- We will update this Notice to describe any new technology, its purpose, who sets it, and how long it lasts, before it goes live.
Until and unless that happens, the position remains as described above: one essential Authentication Cookie, cookieless analytics, and no consent banner.
6. Managing cookies in your browser
You can control and delete cookies through your browser settings, including blocking all cookies or deleting those already stored. If you block or delete the Authentication Cookie described in section 2, you will not be able to stay logged in to the developer portal and parts of the service that require sign-in will not work. Blocking storage will not give you a different experience of our marketing pages, because we set no non-essential storage there.
Most browsers also offer a "Do Not Track" or "Global Privacy Control" signal. Because we do not track you across sites and set no advertising or analytics cookies, there is no cross-site tracking for such a signal to switch off.
7. Supervisory authority
Supervision of the cookie and electronic-communications rules under LEK in Sweden is the responsibility of the Swedish Post and Telecom Authority (Post- och telestyrelsen, "PTS"). Where the use of cookies also involves the processing of personal data under the GDPR, the competent data protection authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, "IMY").
We would always prefer the chance to resolve any concern first, so please contact us using the details below. You also have the right to lodge a complaint directly with PTS or, for data protection matters, with IMY or the supervisory authority in your country of residence or workplace within the EU or EEA.
8. Contact
If you have questions about this Cookie Notice or about our use of cookies and similar technologies, please contact us:
- Privacy and data protection enquiries: [email protected]
- Legal enquiries: [email protected]
- General support: [email protected]
- Data protection point of contact: [email protected]
Operator: LEGAL_ENTITY, REGISTERED_ADDRESS, organisation number ORG_NUMBER, VAT number VAT_NUMBER. Governing law and forum for any dispute relating to this Notice are as stated in our Terms of Service (Sweden; the courts of Sweden, with Stockholm District Court (Stockholms tingsratt) as court of first instance).
Related pages
- Privacy Policy - how we process personal data, including account email, hashed credentials, Usage Events and cookieless analytics.
- Terms of Service - the terms governing use of the API and the website.
- Attribution and Disclaimers - data-source attributions and the not-for-navigation disclaimer.
---
Last updated: [[EFFECTIVE_DATE]]
This Cookie Notice is provided for general information and to support transparency about our use of cookies. It is not legal advice. If you need advice on your own obligations, please consult a qualified professional.