This page explains the cookies and similar technologies that Mirox, LDA ("Mirox") uses on mirox.pt and the dashboard, and how you control them. It supplements the Privacy Policy.
1. What is a cookie
A cookie is a small text file a website stores on your device. We also use comparable technologies such as localStorage for the same purposes. The same rules apply to all of them under Article 5(3) of the ePrivacy Directive.
2. Three categories
Essential cookies — required for the site to work (sign-in, security, remembering your consent choice). These are set without consent under Art. 5(3) ePrivacy Directive.
Analytics cookies — help us understand aggregated, anonymised use of the site. We only set these after your explicit, affirmative consent via the cookie banner.
Ad-measurement cookies — a first-party cookie that remembers which advertisement you arrived from, plus the Google Ads tag, so we can tell which campaigns are worth running and reach you with our own ads elsewhere. No cookie in this category is set or read until you give explicit, affirmative consent. Since 29 August 2026 the Google tag itself loads before you have answered, in the restricted, cookieless mode described below; it may only touch storage once you say yes, and if you say no it is not loaded at all.
3. The cookies we set
Name
Purpose
Duration
Type
mirox_session
Authenticated session token after sign-in.
Session
Essential
mirox_csrf
CSRF protection for state-changing requests.
Session
Essential
mirox_consent
Records your cookie-banner choice per category so we do not ask again.
12 months
Essential
ph_<key>_posthog
PostHog product-analytics cookie holding a pseudonymous device identifier and session id.
First-party cookie holding the click identifier of the ad you arrived from (e.g. Google’s gclid) plus any campaign tags in the URL, so we can tell which campaigns bring people here. Set by us, readable only by us, and never used to personalise anything you see.
90 days
Ad measurement
_gcl_au, _gcl_aw, _gcl_dc
Set by the Google Ads tag (gtag.js) to link an ad click to a later conversion and to build advertising audiences. Written only if you switch on ad measurement. Before you have answered the banner the tag loads but is forbidden from reading or writing any of these; if you decline, it is not loaded at all.
90 days
Ad measurement
4. Third-party processors
When you accept analytics, the following processor receives event data on our behalf, bound by a written data-processing agreement under Art. 28 GDPR:
PostHog Inc. — product analytics (pageviews, navigation paths, conversion events). We use the PostHog EU Cloud tenant, hosted in Frankfurt, Germany. IP addresses are not stored verbatim — PostHog uses them only for coarse geo-resolution (country / region) and then discards them. We do not enable session recording. DPA: posthog.com/dpa.
Google Ireland Ltd. receives data directly from your browser through the Google Ads tag, and how much depends entirely on your answer. Before you answer the banner: the tag runs in Google's restricted “consent mode” — it may not read or write any cookie, the advertising click identifier is stripped out of what it sends, and no email address or other identifier of yours is attached. Google still receives your IP address, the address of the page, and basic browser information, which it uses only to estimate campaign results in aggregate. It cannot single you out from that, and it may not use it to build an advertising audience containing you. If you decline ad measurement: the tag is never fetched, no advertising code runs, and Google receives nothing whatsoever — not even the restricted signal above. If you switch ad measurement on: the tag may additionally set and read the _gcl_* cookies above, keep the click identifier, and — when you submit a form — send a one-way cryptographic hash of your email address so Google can match your conversion to the advertisement you clicked. Google may then attribute conversions and show you Mirox advertising on other sites. Google acts as an independent controller for this data under its own advertising terms, not as our processor, and it may be processed outside the EU under the EU–US Data Privacy Framework and Standard Contractual Clauses. Withdraw consent and the tag returns to the restricted mode above and its cookies are deleted. See Google's advertising data terms.
The first-party mirox_attr cookie is separate and is never read by anyone else while you browse. If you go on to submit a form (a free audit request, or signing up), we send the advertising network that brought you — Google Ireland Ltd. or Microsoft Ireland Operations Ltd. — a record that one conversion happened: the click identifier from that cookie (or a SHA-256 hash of your email address if the identifier is missing), the time, and a monetary value. Your name, your message, your uploaded file and your plaintext email are never included.
Calendly LLC hosts the booking calendar on /book, and nowhere else on this site. The calendar is an embedded frame from calendly.com that is not loaded until you press “Open the calendar”: before that click nothing at all is requested from Calendly, so it can neither read nor write a cookie. Press it and Calendly sets its own cookies inside that frame and receives what you type in to book — your name, your email address and any note. We send Calendly nothing about you; the only thing we attach is which page of ours you came from, so we know whether the booking came from the pricing page or the agency page. Calendly is in the United States and processes as our processor under Standard Contractual Clauses and the EU–US Data Privacy Framework. DPA · privacy notice. If you would rather not load it, the same page carries a plain link that opens Calendly in its own tab, and every other way of reaching us — the audit form, the agency form, email — involves Calendly not at all.
We do not use Google Analytics, Meta Pixel, LinkedIn Insight, X (Twitter) Pixel, TikTok Pixel or any Microsoft UET tag.
5. Managing your choice
On your first visit, the cookie banner asks which categories you accept. You can accept all, reject non-essential, or open Customize to decide on analytics and ad measurement separately. Closing the banner is treated as a rejection. You can revisit your choice at any time using the Cookie settings link in the footer; withdrawing ad-measurement consent deletes the mirox_attr and _gcl_* cookies immediately and revokes Google's ad-storage permission.
You can also block or delete cookies from your browser settings. Blocking essential cookies will break sign-in.
No advertising cookie is set until you say yes
Mirox advertises, and since 13 August 2026 we run the Google Ads tag to measure it. Since 29 August 2026 it also loads before you have answered the banner, rather than only after a yes — but it starts with every storage permission denied. Denied means denied: no cookie is read or written, the click identifier is stripped, and nothing that identifies you is sent. What Google receives in that state is an anonymous signal it uses to estimate, statistically, how many people a campaign reached. We made that change because measuring only the minority who accept cookies was teaching our advertising to chase the wrong people. Saying no still means no. Decline ad measurement and the script is never downloaded from Google at all — we did not quietly reclassify a refusal into a “restricted yes”. You can verify every word of this in your browser's network inspector, before and after choosing. There is still no Meta Pixel, no LinkedIn Insight Tag and no Microsoft UET tag. Withdraw consent and we revoke Google's storage permission and delete its cookies. We never sell data.
6. Changes to this policy
If we add or change cookies, we update this page and re-prompt for consent where required. The "last updated" date above always reflects the current version.