Cookie Policy
What we store in your browser, why we store it, and how to change your choice at any time.
Last updated 2026-08-12
How we handle them
Strictly necessary cookies are always set, because sign-in and security do not work without them. Every other category stays off until you turn it on. Refusing is as easy as accepting and does not limit your access to the public part of the site.
Alongside cookies we also use localStorage and sessionStorage — similar technologies, listed below for full transparency.
The categories
- Strictly necessary — session, security, two-factor verification and your cookie choice itself. These cannot be switched off.
- Preferences — language, saved deals and dashboard layout.
- Analytics — measuring how the site is used. We currently run no analytics tool; the category exists so your choice is respected from day one if we ever add one.
- Marketing — advertising and cross-site tracking. We currently use none.
Third parties
The site's fonts are served from our own servers, so your browser does not send your IP address to an external font provider when you open a page.
The “Continue with Google” button is loaded from Google on the sign-in and registration pages only, not across the rest of the site. We have not enabled “One Tap”, so Google neither signs you in automatically nor shows any prompt you did not ask for. As soon as either of those two pages opens, Google's script sets one cookie of its own, `g_state`, listed in the table above. If you press the button, Google returns your name and email address to us — nothing more, and never your password.
Changing your choice
Use “Cookie settings” at the bottom of any page to review or withdraw your consent. You can also delete all cookies from your browser settings.
What we store, in full
| Name | Type | Category | Purpose | Kept for |
|---|---|---|---|---|
| mcl_consent | Cookie | Strictly necessary | Stores your cookie choice so we do not ask again on every page. | 6 months |
| locale | Cookie | Preferences | Remembers the language you selected (Albanian or English). Written only when you change it yourself. | 1 year |
| sidebar_state | Cookie | Preferences | Remembers whether the dashboard sidebar is open or collapsed. | 7 days |
| ilyriacap_token | localStorage | Strictly necessary | The session token that keeps you signed in. | Until you sign out |
| ilyriacap_user / ilyriacap_role / ilyriacap_account_roles | localStorage | Strictly necessary | Your name, role and account permissions so the dashboard opens on the right view. | Until you sign out |
| g_state | Cookie | Strictly necessary | Set by Google on the sign-in and registration pages, as part of the “Continue with Google” button. It holds the state of Google's own component; we neither read it nor use it to track you. | Set by Google, not by us. You can delete it from your browser settings. |
| ilyriacap_2fa_challenge | sessionStorage | Strictly necessary | Temporary identifier for the two-factor check during sign-in. | Until the tab is closed |
| mcl_entry_role | localStorage | Preferences | Remembers whether you said you are a buyer, a seller or just browsing, so we do not ask again. | 1 year (or until the tab closes) |
| ilyriacap_watchlist | localStorage | Preferences | Deals you saved, so they are still there when you come back. | Until you clear your browser storage |