MONODAT

Version: 1.2.1 · Effective date: 2026-10-15

The binding version of this document is the Polish version. Other language versions are provided for information only.

MONODAT — Cookie Policy

1. Summary

MONODAT uses no analytics cookies, no advertising or remarketing cookies, and no tracking technologies of any kind. We do not use Google Analytics or any equivalent tool. We do not profile visitors. We do not share data with advertising networks. We do not sell data.

We store in your browser only the technical data strictly necessary for the Platform to work, plus the settings you choose yourself, plus one narrow, clearly-labelled security exception described in section 3.4. For this reason the Platform displays no cookie consent panel — consent is not required for the technologies we use, including the security exception (Art. 173(3)(2) of the Polish Telecommunications Law: data strictly necessary for the provision of a service you requested, which includes protecting that service against automated abuse). We display a one-off informational notice only.

The complete list is in section 3. If, after reading it, you believe any entry is not strictly necessary, write to help@monodat.com.

2. Cookies and Related Technologies

Cookies are small text files stored on your device by your browser. Beyond cookies, browsers provide other local storage mechanisms — localStorage and IndexedDB — which work similarly and which this Policy treats identically to cookies, describing them explicitly. We do so because what matters for your privacy is the fact that data is written to your device, not the technical name of the mechanism.

3. Complete List of Data Stored on Your Device

3.1. Cookies

NameSet byPurposeRetentionConsent
monodat_cookie_noticeMONODAT (first-party)Records that we have shown you the cookie notice, so it is not repeated on every visit12 monthsNot required — essential
NEXT_LOCALEMONODAT (first-party)Remembers your chosen language (Polish / English)12 monthsNot required — user setting

These are all the cookies the Platform sets. The Platform sets no other cookies.

3.2. Local Storage (localStorage)

KeyPurposeRetentionConsent
themeRemembers your chosen theme (light / dark)Until you delete itNot required — user setting
monodat_session_idWritten only when you sign in. Identifies your session so the Platform can enforce one active session per Account and protect it against session hijackingUntil sign-out or session expiryNot required — essential to the service you requested

3.3. IndexedDB — Only After Sign-In

DatabaseSet byPurposeRetentionConsent
firebaseLocalStorageDbGoogle (Firebase Authentication)Maintains your signed-in session. Sign-in is impossible without itUntil sign-out or session expiryNot required — essential to the service you requested
firebase-heartbeat-databaseGoogle (Firebase Authentication)Technical telemetry of the Firebase library (SDK usage dates)Up to 30 daysNot required — essential

These databases are created only when you sign in. If you visit the Platform without creating an account, we will not write them to your device.

Note: Firebase Authentication does not use cookies — it stores the session in IndexedDB. Earlier versions of this Policy described this imprecisely.

3.4. Security Verification (Cloudflare Turnstile) — Only When Suspicious Activity Is Detected

If, and only if, our systems flag your session as showing signs of automated or abusive behaviour (for example, an unusually high request rate), we load a challenge script from Cloudflare (challenges.cloudflare.com) that computes a bot-likelihood score from browser and device signals, so we can distinguish a legitimate User from an automated script before granting further access.

What loadsSet byPurposeRetentionConsent
Turnstile challenge script and associated verification cookie/storageCloudflare, Inc. / Cloudflare Ireland Ltd.Distinguish human Users from automated/abusive trafficVerification result: 30 days. See Cloudflare's own policy for anything it stores directlyNot required — strictly necessary for the security of the service you requested

This is the only circumstance in which the Platform loads a script from a security/verification provider, and the only case in which a third party receives browser or device signals beyond a plain IP address. It is not used for analytics, advertising, or to track you across visits or sites — solely to answer the question "is this request automated." We disclose it here precisely because we hold ourselves to the "complete list, no exceptions" standard set out in section 1.

4. Third-Party Content and IP Address Transmission

Independently of any data written to your device, merely loading content from a third party's server transmits your IP address to that third party. Below is the complete list of such cases on the Platform:

PartyWhen the connection occursWhat the third party receives
OpenStreetMap Foundation (United Kingdom)Automatically when you open a profile containing a location map: a public company or CEIDG entrepreneur profile (without logging in), and a company or CEIDG entrepreneur profile in the dashboard. Your browser then fetches the base-map tiles of the area viewedYour IP address and standard browser request headers (including user-agent). The address of the entity viewed is not transmitted — MONODAT computes the map point's coordinates on its own servers (Privacy Policy, section 6)
Google LLC (Firebase Authentication)Only on the sign-in and sign-up pages, and in the dashboard once signed inYour IP address, your sign-in data
Stripe Payments Europe, Ltd.Only when you proceed to payment. Payment takes place on the checkout.stripe.com domainYour IP address, payment data. Stripe sets its own cookies on its own domain, not on the MONODAT domain
Cloudflare, Inc. / Cloudflare Ireland Ltd.Only when your session is flagged as potentially automated (section 3.4)Your IP address, browser/device signals used to compute a bot-likelihood score
flagcdn.comOnly in the dashboard once signed in, in the foreign investment module (country flag icons)Your IP address

The Platform's public pages — including the home page and the search engines — make no automatic connections to any third party, with two exceptions: (1) public company and CEIDG entrepreneur profiles automatically fetch map tiles from the OpenStreetMap Foundation's servers, as described in the table above; (2) the narrow security exception in section 3.4, when it is triggered. Displaying the map does not cause MONODAT to store any data on your device. If you do not want to connect to the OpenStreetMap Foundation, you can block content from the openstreetmap.org domains in your browser — the profile will display without the map. Fonts are served from our own server (fetched at build time), not from Google Fonts.

Privacy policies: Google · Stripe · Cloudflare · OpenStreetMap

5. What We Do NOT Do

We state expressly that the Platform:

  • does not use analytics, statistics or measurement cookies,
  • does not use advertising, remarketing or profiling cookies,
  • does not use Google Analytics, Google Tag Manager, Meta Pixel, Hotjar, Matomo or any equivalent tool,
  • does not embed tracking pixels or web beacons,
  • does not share data from your device with advertising networks or data brokers,
  • does not track you across websites or build an advertising profile,
  • does not set any third-party cookies on its own domain, other than the narrow security exception in section 3.4.

The one narrow exception to the above is the Cloudflare Turnstile security check (section 3.4), which computes a bot-likelihood score from device signals only for sessions already flagged as suspicious — this is a security control, not analytics, advertising or behavioural tracking, and it does not run on ordinary visits.

We also maintain error-monitoring software (Sentry) in our codebase that is not currently active — no data is sent to it in the deployed Platform. If we activate it, or introduce any other analytics, advertising or tracking technology, we commit to implementing a prior consent panel first, and to updating this Policy and notifying you under section 8 before doing so — not after.

6. How to Delete Stored Data

Since we collect no consent for the technologies above, there is nothing to withdraw — but you retain full control over data stored on your device:

  • Browser settings — every browser lets you delete cookies, localStorage and IndexedDB, and block them from being written (see your browser's documentation: Chrome, Firefox, Safari, Edge).
  • Private browsing — data is deleted automatically when you close the window.

Deleting the data in section 3.2 (monodat_session_id) or 3.3 will sign you out. Blocking the Cloudflare script in section 3.4 may prevent you from completing sign-in if your session has been flagged. Deleting the remaining entries is safe — you will only lose your saved language and theme settings.

7. Legal Basis

The data described in section 3 is strictly necessary to provide the service you requested (including protecting it against automated abuse, section 3.4), or constitutes settings you chose yourself. Under Art. 173(3)(2) of the Act of 16 July 2004 — Telecommunications Law, storing such information requires no consent.

To the extent this data constitutes personal data, the basis is Art. 6(1)(b) GDPR (contract performance — session and sign-in) and Art. 6(1)(f) GDPR (legitimate interest — Platform security, bot detection, and remembering your settings).

8. Changes to this Policy

We give at least 14 days' notice of material changes by e-mail (to Users holding an Account) and via a notice on the Platform. The current version is always available at https://monodat.com/en/cookies. Earlier versions are available on request.

In particular, we undertake to give prior notice of any introduction of any analytics, advertising or tracking technology whatsoever — together with a prior consent panel.

9. Contact

Questions about cookies and local storage: help@monodat.com

Details of personal data processing are set out in the Privacy Policy.

10. Language

This is a translation. In the event of any discrepancy, the binding version is the Polish-language version available at https://monodat.com/cookies.

Last updated: 2026-10-02