Cookie policy
Version 2026-10-08 · last updated 2026-10-08
MWaste uses strictly necessary cookies only. There are no analytics, advertising or third-party tracking cookies, and no cookie banner, because nothing optional is set.
| Cookie | Purpose | Lifetime |
|---|---|---|
__Secure-next-auth.session-token | Keeps you signed in (encrypted session token) | 30 days, renewed while you use the app |
__Host-next-auth.csrf-token | Protects sign-in forms against cross-site request forgery | Session |
__Secure-next-auth.callback-url | Returns you to the page you wanted after sign-in | Session |
wb-td | Remembers a device you trusted for two-factor sign-in (random token, no personal data) | 30 days |
mw-dc | Remembers whether this device is phone-sized so the right layout loads before the page paints | Session |
mw-desktop | Set when you press the 'desktop' button on a phone to keep the desktop layout | Session |
Local storage
The driver and office apps keep working data in your browser's local storage and IndexedDB — queued records waiting to send, cached lists, the last filters you used, and the service worker's offline cache. This is not sent to anyone else and is cleared when you sign out of a shared device or clear site data.
Third parties
Stripe (billing), Google and Microsoft (sign-in, only if you choose them) set their own cookies on their own domains when you are redirected there; see their policies. Map tiles are loaded as images without cookies.