Legal
Cookie Policy
Last updated 26 August 2026
This policy explains the cookies and similar technologies E Labs Ventures Ltd uses on meta-ads-mcp.com, why we use them, and how you can control them.
1. What this policy covers
Cookies are small text files stored on your device. We also use pixels, local storage, and similar tools. This policy should be read with the Privacy Policy.
It applies to https://meta-ads-mcp.com and the logged-in app. It does not cover cookies set by Meta Ads Manager, ChatGPT, Claude, Cursor, or other sites you open in another tab.
2. Who is responsible
E Labs Ventures Ltd (company number 17050248), 128 City Road, London EC1V 2NX, United Kingdom, trading as Meta Ads MCP. Contact hello@meta-ads-mcp.com.
Some cookies are set by us (first-party). Crisp sets cookies for live chat. Google or Meta set cookies only if you accept analytics or advertising (third-party).
3. Types of cookies
Strictly necessary
Required to operate the site: keep you logged in, protect Facebook OAuth, remember this cookie choice, complete Stripe checkout, and run the Crisp live-chat widget so you can message support. These do not need consent under PECR. The site will break without the account cookies. You can still email us if you block the chat widget.
Analytics
Help us see which pages are used and whether checkout works. We only set these if you accept analytics. That is Google Analytics 4, property G-3EXZ9M9TBN.
Advertising
Measure ads and send conversion events (including Meta Conversions API on the server when you start or finish checkout). We only set browser pixels if you accept advertising cookies. Google Ads conversion tags, if configured, sit in this group too.
We do not use cookies to sell a data list. We do not run third-party ad networks on article pages.
4. Cookie table
Names can change when vendors update their tags. Duration is typical, not guaranteed.
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
| sb-*-auth-token and related sb-* cookies | Meta Ads MCP / Supabase | Session and login | Strictly necessary | Session up to ~1 week (refresh) |
| meta_oauth_state | Meta Ads MCP | Stop CSRF on Facebook Login | Strictly necessary | 10 minutes |
| mam_cookie_consent | Meta Ads MCP | Store your analytics and ads choice | Strictly necessary | 12 months |
| Stripe cookies on checkout.stripe.com | Stripe | Take payment, fraud checks | Strictly necessary (on Stripe's domain) | As set by Stripe |
| crisp-client / crisp-client/* | Crisp | Live chat session and message history in this browser | Strictly necessary (support chat) | Up to 6 months |
| _ga, _ga_*, _gid | Google Analytics | Distinguish visitors and sessions | Analytics (consent) | Up to 13 months / 24 hours |
| _fbp, _fbc | Meta | Pixel matching and ads measurement | Advertising (consent) | Up to 90 days |
| Google Ads conversion cookies (e.g. _gcl_au) | Measure ad clicks and conversions | Advertising (consent) | Up to 90 days |
Local storage may hold the same consent object (mam_cookie_consent) so the banner does not reappear
every page load.
5. Pixels and similar tech
If you accept analytics cookies, gtag.js loads Google Analytics 4 (measurement ID G-3EXZ9M9TBN) and records page views. Scripts do not load until you accept.
If you accept advertising cookies and we have configured the ids:
- the Meta Pixel loads on the site and can fire PageView, InitiateCheckout, and Purchase (Purchase is also sent from our server via Conversions API using a hashed email and a shared event id)
- Google tag (gtag.js) loads Google Analytics 4 (G-3EXZ9M9TBN) and, if set, Google Ads
If you reject optional cookies, we do not load those scripts. Server-side conversion events that do not depend on a browser cookie may still run for a logged-in checkout (hashed email, no advertising cookie). That is a transactional measurement, not a marketing cookie on your device.
ChatGPT, Claude, and Cursor are not our cookies. When you paste the MCP URL into those products, their privacy notices apply.
6. Legal basis
Strictly necessary cookies: PECR exemption for cookies that are essential to provide a service you asked for; UK GDPR Art. 6(1)(b) contract or Art. 6(1)(f) legitimate interests (security of login).
Analytics and advertising cookies: PECR consent, and UK GDPR Art. 6(1)(a) consent. Refusing does not block an account. You can withdraw by using the buttons below or clearing the consent cookie and choosing again.
7. How to choose
Use these buttons at any time. They overwrite your last choice on this browser.
The first-visit banner offers the same choice. Necessary cookies are always on.
8. Browser controls
You can delete cookies in your browser settings. Blocking all cookies will log you out and can break Facebook OAuth. Industry tools such as Your Online Choices and Google's ad settings can limit some advertising cookies.
Most browsers let you send a Global Privacy Control or Do Not Track signal. We treat an explicit choice on this site as the source of truth for our tags. We do not currently interpret DNT as consent or refusal on its own.
9. Third-party policies
10. Changes
We will update this page if we add tags or change vendors. The date at the top is the latest version. Related: Privacy Policy and Terms of Service.