Cookie Statement

Effective September 24, 2026

MessageFuel uses very few cookies: the ones that keep you signed in, and nothing that follows you around the internet. This page lists what is set, what stays on your device, and how the tracking inside marketing email works.

1. What this covers

This statement explains the cookies and similar technologies used on messagefuel.com, in the MessageFuel dashboard, and on the pages we host on behalf of our customers — signup forms, hosted copies of campaigns, preference centres and unsubscribe pages. It supplements our Privacy Policy.

A cookie is a small file a site stores in your browser. Related technologies — local storage, and the invisible tracking pixel used to measure an email open — do the same job by different means, and are covered here too.

2. What we use

Strictly necessary cookies

  • Authentication session. Set by our authentication provider when you sign in, and read on every request to keep you signed in and to scope what you can see to your organisation. Names begin with sb-. They are set as HTTP-only where possible, restricted to our domain, and expire when the session does or when you sign out.
  • Security tokens. Short-lived values used to complete a sign-in, password reset or invitation flow safely, and to protect form submissions from cross-site abuse.

These cannot be switched off in the product. Blocking them in your browser will prevent you from signing in at all, which is why no consent banner asks about them — a site is permitted to set what is strictly necessary to deliver the service you asked for.

Local storage

The campaign composer keeps an unsent draft in your browser’s local storage so that a closed tab or a refresh does not lose your work, and offers it back when you return. It stays on your device, is not sent to us as a cookie, and is cleared when the draft is submitted or discarded. Audience selections are deliberately excluded from it — restoring a stale audience onto a campaign about to send is the one recovery mistake with real consequences.

Product analytics, without a browser cookie

We record a small number of product events — a campaign created, a campaign sent, contacts imported — to understand which features are used. Those events are recorded by our servers and attributed to an account user id. There is no analytics script in your browser, no analytics cookie, and no device or cross-site identifier involved. Contacts are never the subject of a product event.

3. What we do not use

No advertising, no cross-site tracking

We do not set advertising cookies, retargeting pixels, social media tracking tags or cross-site identifiers on our own site or dashboard, and we do not allow third parties to set them there. We do not sell or share personal information for cross-context behavioural advertising. That is also why you are not asked to dismiss a consent banner to read this page.

4. Tracking in marketing email

Marketing email sent through the platform can carry two tracking technologies, both configured by the business that sends it rather than by us:

  • An open pixel. A transparent one-by-one image. Loading it records that the message was opened. Modern mail apps with privacy protection load it for messages nobody read, and image blocking hides reads that did happen, so an open figure is an estimate and we describe it that way everywhere it appears.
  • Click tracking. Links rewritten so that a click is recorded before the browser is redirected to the real destination.

Blocking remote images in your mail app stops the open pixel. The sender’s own privacy policy governs why they measure this — see our Privacy Policy for the split between what we decide and what our customers decide. SMS carries no pixel. When a sender turns on link tracking for a text, its links are rewritten to MessageFuel short links, and opening one records the click, as with email click tracking; no cookie is set.

5. Signup forms embedded on other websites

Our customers embed our signup forms on their own sites, as a frame, as plain HTML, or through a small loader script. The form itself sets no cookies and stores no identifier on your device; the script embed only measures the frame’s height and reports a completed signup back to the host page. Everything else on that page — including any analytics or advertising technology the site runs, and any conversion event it chooses to fire when a signup completes — belongs to the website you are visiting and is governed by its cookie and privacy notices, not by ours.

6. Managing cookies

Every major browser lets you see stored cookies, delete them, and block them per-site or entirely, usually under privacy or site settings. Clearing ours signs you out; blocking them stops you signing in.

Do Not Track and Global Privacy Control

Because we do not track you across sites and do not sell or share personal information, a Do Not Track header or a Global Privacy Control signal has nothing to opt out of on our site. We will honour a GPC signal as an opt-out request if that ever changes.

7. Changes and contact

If we introduce a cookie that is not strictly necessary, we will update this statement and ask for consent where the law requires it, before setting it.

Questions about anything here: Info@messagefuel.com.

Vadelis Labs Inc.Attn: MessageFuel1784 NW Madrid WayBoca Raton, FL 33432United StatesInfo@messagefuel.com