Effective date: September 1, 2026
Version: 2.0
Part of: the website appmuza.com and its subdomains (the "Website"), and, for the purposes of Section 7, the Muza mobile application (the "App")
Company details. In this document, "Company", "we", "us" and "our" refer to:
Legal name: ONCREATE LTD, a limited liability company organized under the laws of Ukraine
Registered address: 31V Serhiia Podolynskoho Street, Dnipro, 49069, Ukraine
Privacy requests: [email protected]
1. What this Policy covers
This Policy explains how we use cookies and similar technologies on the Website, which of them are necessary for the Website to work, which ones you can refuse, and how to manage your choices. It also explains, in Section 7, how the App uses device identifiers and software development kits (SDKs) that serve a similar purpose. This Policy forms part of our Privacy Notice (appmuza.com/info/privacy), which explains how we use personal data in general and what rights you have. Capitalized terms not defined here have the meaning given in the Privacy Notice and the Terms of Service.
2. What cookies and similar technologies are
Cookies are small text files that a website places on your device. "Similar technologies" include pixels (tiny images or scripts that record that a page or email was opened), tags, scripts, local storage, session storage, device fingerprinting techniques used for security, and SDKs in mobile apps that store or read identifiers on the device. In this Policy we call all of these "cookies" unless the distinction matters.
Cookies can be first-party (set by us) or third-party (set by another company whose technology is embedded in the Website, for example an analytics or advertising provider). They can be session cookies (deleted when you close your browser) or persistent cookies (kept for a set period or until you delete them).
3. Cookies that are necessary (no consent required)
Some cookies are strictly necessary for the Website to function, to keep it secure and to honor your choices. They are used on the basis of our legitimate interest in operating a secure and functioning Website (and, where applicable, to deliver a service you have requested), and they cannot be switched off through our cookie settings. They include:
- Security and traffic management cookies set by our content delivery and security provider (Cloudflare), which distinguish genuine visitors from automated traffic, protect against attacks and balance load (for example cookies named __cf_bm and cf_clearance, kept for up to 30 minutes and up to one year respectively);
- Consent preference cookies that record the choices you made in the cookie banner so that we do not ask again and can prove your choices (kept for up to 12 months);
- Session and functionality cookies that keep you signed in to your account on the Website, remember the contents of forms you are filling in, or store the state of a checkout while you complete a purchase (kept for the session or up to 24 hours);
- Fraud and abuse prevention cookies used by our payment processors during checkout on the Website, which are set by those processors under their own policies.
If you block necessary cookies in your browser, parts of the Website (including sign-in and purchases) may not work.
4. Cookies you can accept or refuse
All other cookies are optional. Where the law requires it (including in the EU, EEA, UK and Switzerland), we set them only after you have given consent in the cookie banner, and you can withdraw consent at any time through the "Cookie settings" link in the Website footer. Refusing optional cookies does not prevent you from using the Website. Optional cookies fall into the following categories:
| Category | Purpose | Examples of cookies that may be set | Typical lifetime |
| Preferences | Remember choices you make, such as language, region or display settings | First-party preference cookies (for example a language cookie) | Up to 12 months |
| Analytics | Understand how visitors use the Website (pages visited, time on page, referrer, approximate location, device and browser) so that we can improve it; measure the performance of pages and campaigns | Google Analytics (_ga, _ga_*, _gid), Google Tag Manager, Microsoft Clarity or Hotjar (session recordings and heatmaps, _clck, _clsk, _hj*), first-party analytics cookies | From the session up to 2 years |
| Marketing and attribution | Measure the effectiveness of our advertising, build audiences for Muza advertising on other platforms and apps, attribute App installations to Website visits or advertisements, and personalize the ads you see for Muza elsewhere | Meta Pixel (_fbp, _fbc), Google Ads and DoubleClick (_gcl_*, IDE), TikTok Pixel (_ttp), LinkedIn Insight, X Pixel, Snap Pixel, AppsFlyer OneLink and web attribution scripts (AF_*), Apple Ads attribution | From the session up to 2 years |
| Embedded content | Display content from other services on the Website, such as videos, app store badges, social media posts or maps; those services may set their own cookies when the content loads | YouTube or Vimeo players, social media embeds, App Store and Google Play badges | Set by the third party under its own policy |
The exact cookies in use, their providers and lifetimes change as we add or remove tools. The list above gives examples of cookies that may be set; the current list is shown in the cookie settings panel on the Website, which we keep up to date. Third-party cookies are set by the providers named above under their own privacy policies (for example policies.google.com/privacy, facebook.com/privacy/policy, tiktok.com/legal/privacy-policy, appsflyer.com/legal/privacy-policy, clarity.microsoft.com/terms, hotjar.com/legal/policies/privacy). Those providers may combine the information collected on the Website with information they hold about you from other sources; we do not control that processing.
5. Your choices
5.1 Cookie banner and settings. When you first visit the Website from a jurisdiction where consent is required, a banner lets you accept all optional cookies, reject them all, or choose categories, with equal ease. Optional cookies are not set until you consent. You can change or withdraw your choices at any time through the "Cookie settings" link in the Website footer; withdrawing consent does not affect the lawfulness of processing before withdrawal. We keep a record of your consent choices to demonstrate compliance. In jurisdictions where consent is not required, optional cookies may be set on the basis of our legitimate interest in understanding and promoting the Service, and you can still opt out through the cookie settings or your browser.
5.2 Browser settings. Most browsers let you block or delete cookies and clear local storage through their settings, and let you block third-party cookies specifically. Instructions are available in your browser's help pages. If you block necessary cookies, parts of the Website may not work.
5.3 Global Privacy Control and Do Not Track. Where required by law (for example in certain US states), we treat a Global Privacy Control (GPC) signal from your browser as a request to opt out of the sale or sharing of personal data and of targeted advertising for the Website, and we disable marketing cookies accordingly. We do not respond to "Do Not Track" signals, for which no common standard exists.
5.4 Opting out with third parties. You can also manage advertising preferences with providers directly, for example through Google's Ads Settings (adssettings.google.com), Meta's Ad Preferences, TikTok's ad settings, the Digital Advertising Alliance (optout.aboutads.info), the European Interactive Digital Advertising Alliance (youronlinechoices.eu) and the Network Advertising Initiative (optout.networkadvertising.org), and you can install the Google Analytics opt-out browser add-on (tools.google.com/dlpage/gaoptout). These opt-outs depend on the third parties' tools and may need to be repeated if you clear your cookies or change devices.
6. Retention
Session cookies are deleted when you close your browser. Persistent cookies remain for the period stated in the cookie settings panel (generally no longer than 2 years) or until you delete them. Information collected through cookies is retained as described in Section 10 of the Privacy Notice, and consent records are kept for the life of the relationship and 3 years thereafter.
7. The App: device identifiers and SDKs
The App does not use browser cookies. It uses device identifiers and SDKs that serve similar purposes, as described in Sections 2 and 8 of the Privacy Notice:
- Necessary identifiers and SDKs, used to operate and secure the App and to deliver the Service you requested: a randomly generated installation identifier stored in the device keychain, the Apple identifier for vendors (IDFV) or the equivalent Android identifiers, push notification tokens, App integrity tokens (Apple App Attest and DeviceCheck, Firebase App Check, Google Play Integrity), authentication identifiers, purchase and subscription tokens, crash and performance reporting, and remote configuration. These are used on the basis of the contract with you and our legitimate interest in security and stability, and cannot be switched off individually.
- The advertising identifier (IDFA on iOS, advertising ID on Android). On iOS, the App asks for your permission in the App Tracking Transparency prompt before accessing the IDFA to track your activity across other companies' apps and websites for advertising attribution and measurement. If you do not allow tracking, the IDFA is not used, and attribution is limited to Apple's privacy-preserving frameworks (SKAdNetwork and AdAttributionKit) and to identifiers within the App. You can change your choice at any time in Settings > Privacy & Security > Tracking on your device. On Android, you can reset or delete the advertising ID and opt out of ads personalization in your device settings, and we honor those settings.
- Analytics, attribution and marketing SDKs that are used or may be used, such as Google Analytics for Firebase, Amplitude, AppsFlyer, Meta's Business Tools, and advertising network measurement tools, which collect usage events and identifiers as described in the Privacy Notice and on the Third-Party Services page (appmuza.com/info/third-party-services). In the EU, EEA, UK and Switzerland, we ask for your consent before using these SDKs for analytics and marketing purposes where the law requires it, and we set their consent signals to "denied" until you consent. You can change your choices in the App (Settings > Personal Data).
- US "sharing" opt-out. Residents of certain US states can opt out of the sharing of identifiers and usage data for cross-context behavioral advertising through the "Do Not Sell or Share My Personal Information" control in the App (Settings > Personal Data), as described in Section 8.5 of the Privacy Notice.
8. Changes
We may update this Policy from time to time, for example when we add or remove tools. The effective date above shows the latest revision. Significant changes will be notified through the Website or the App, and where required we will ask for your consent again. Minor changes, such as adding a provider within an existing category or updating a cookie name, may be made without separate notice by updating this Policy and the cookie settings panel.
9. Contact
Questions about cookies and similar technologies: [email protected].