Legal
Cookie Policy
Last updated 5 Aug 2026
This Cookie Policy explains what cookies and similar technologies are, which ones we use on magandaexperience.com, why we use them, and how you can control them. It complements our Privacy Policy.
Data controller: Maganda Experience OÜ, VAT EE102740310, Tööstuse 75-71, 10416 Tallinn, Estonia. Contact: hello@magandaexperience.com.
1. What are cookies?
Cookies are small text files a website stores on your device when you visit it. They let the site remember your actions and preferences over time. We also use similar technologies such as local storage, pixels and tracking beacons; for simplicity we call all of them "cookies" in this policy.
First-party cookies are set by magandaexperience.com. Third-party cookies are set by other companies whose services we embed, such as our tag manager, our advertising platform or our booking provider.
2. How we ask for your consent
When you first visit the site, a cookie banner lets you accept all cookies, reject all non-essential cookies, or choose category by category. Strictly necessary cookies are always active because the site cannot work without them; analytics and marketing cookies are only activated after you opt in.
Your choice is stored in a first-party cookie named "maganda_consent" for 180 days, and is applied through Google Consent Mode v2, which instructs any measurement tag on the site whether it may use storage. Until you consent, marketing and analytics tags run in a restricted, storage-free mode or do not run at all.
You can change or withdraw your choice at any time from the "Cookie settings" link in the footer. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
3. Categories of cookies we use
3.1 Strictly necessary (always active)
Required for the site to function, to keep it secure and to remember your privacy choices. They do not require consent.
- maganda_consent: first party, 180 days. Stores your cookie preferences and the version of the banner you responded to.
- Cloudflare Turnstile (cf_chl_*, __cf_bm and similar): Cloudflare, session to 30 minutes. Anti-bot verification on our contact, waitlist and lead forms. Provider: Cloudflare, Inc.
- Cloudflare network and hosting cookies: Cloudflare, session to 1 year. Load balancing, security filtering and delivery of the site from the closest data centre.
3.2 Analytics (consent required)
Help us understand how the site is used so we can improve it.
- Cloudflare Web Analytics: cookieless. It collects aggregated page-view metrics without cookies and without cross-site tracking. Provider: Cloudflare, Inc.
- Google Tag Manager: no cookies of its own. It is the container that loads the measurement tags listed in this policy, and it respects your Consent Mode choices. Provider: Google Ireland Ltd.
- Google Analytics 4 (_ga, _ga_*), if enabled in our tag container: Google, up to 2 years. Aggregated audience and traffic-source statistics, with IP truncation and no advertising features unless you also accept marketing cookies.
3.3 Marketing (consent required)
Used to measure our advertising campaigns and to show you relevant ads on third-party platforms.
- Meta Pixel (_fbp, up to 90 days; _fbc, up to 90 days when you arrive from a Facebook or Instagram ad): Meta Platforms Ireland Ltd. Measures which ads led to enquiries and lets us build audiences for future campaigns.
- Meta Conversions API: server-side event forwarding. It sends the same conversion events from our server, is only triggered when you have accepted marketing cookies, and uses hashed identifiers.
3.4 Third-party services you may interact with
Some services only load when you actively use them, and they set their own cookies under their own policies:
- WeTravel: our booking and payment provider. When you continue to checkout you are taken to WeTravel’s own domain, where their cookie and privacy policies apply.
- Brevo: our email and CRM platform. It processes the data you submit in our forms. Our forms are served from our own domain, so no Brevo cookie is set on this site.
- Embedded content (for example Instagram, YouTube or Vimeo players): the provider may set cookies once the content is loaded. We block or defer these embeds until you accept the relevant category.
4. International transfers
Some providers listed above are established outside the European Economic Area or may access data from third countries. Transfers are covered by the European Commission’s Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. Details and copies of the safeguards are available on request at hello@magandaexperience.com.
5. Managing cookies in your browser
Beyond our banner, you can block or delete cookies in your browser settings. Blocking strictly necessary cookies may stop parts of the site from working, including our forms.
- Chrome: Settings → Privacy and security → Third-party cookies.
- Safari: Settings → Privacy → Manage website data.
- Firefox: Settings → Privacy & Security → Cookies and Site Data.
- Edge: Settings → Cookies and site permissions.
6. Changes to this policy
We update this policy whenever we add, remove or materially change a cookie or a provider. When the change affects consent, the banner is shown again so you can renew your choice. The date at the top of this page always reflects the latest version.
7. Contact
For any question about this policy or about how we use cookies, write to hello@magandaexperience.com or to Tööstuse 75-71, 10416 Tallinn, Estonia. You can also read our Privacy Policy for the full picture of how we handle personal data, and lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or with the authority of the EU country where you live if you believe your rights have not been respected.
