Cookie Policy

Last updated: 30 June 2026 · Effective date: 27 April 2026

At a glance

This policy explains what cookies are, which cookies we use on motleyexim.com, what they do, how long they last, who has access to them, and how you can manage or withdraw consent. It supplements our Privacy Policy and applies in addition to your rights under India's Digital Personal Data Protection Act 2023 (DPDP Act), the EU General Data Protection Regulation (GDPR), the ePrivacy Directive 2002/58/EC, the UK Privacy and Electronic Communications Regulations (PECR), and the California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA).

1. What are cookies?

Cookies are small text files that a website places on your device. They store information so the site can remember your preferences and give you a faster, safer experience on subsequent visits. Similar technologies include local-storage entries, session-storage entries, pixels, and SDKs in mobile apps. Where we refer to "cookies" in this policy, we mean cookies and similar technologies, except where the difference matters.

Cookies are classified by who sets them, how long they last, and what they are used for:

2. Cookies we use

We set the strictly-necessary cookies below on every visit. We also use analytics — Google Analytics 4 and Microsoft Clarity — on a region-aware basis (see section 6): in the EU/EEA, UK and India, GA4 is set only after you Accept; Microsoft Clarity is consent-gated in the EU/EEA and UK and runs on an opt-out basis elsewhere. The "do NOT use" list in section 2.1 reflects what we do not and will not deploy.

Cookie Type Purpose Duration Set by
cf_clearance, __cf_bm Strictly necessary Cloudflare DDoS / bot protection / WAF challenge state Session / up to 30 days Cloudflare
me_cookie_consent Strictly necessary Remembers your cookie consent choice (accept / reject / preferences) 6 months (tighter than CNIL's 13-month cap) motleyexim.com
me_form_token Strictly necessary Anti-CSRF token for inquiry forms; bot-detection timing Session motleyexim.com
_ga Analytics — consent required in EU/EEA, UK & India; opt-out elsewhere Google Analytics 4 — distinguish unique users for aggregated traffic stats Up to 6 months (we cap well below the GA4 default 2 years) Google
_ga_<container> Analytics — consent required in EU/EEA, UK & India; opt-out elsewhere GA4 session state; per-property identifier Up to 6 months Google
_gid Analytics — consent required in EU/EEA, UK & India; opt-out elsewhere Distinguish users within a 24-hour window 24 hours Google
_clck Analytics (session) — consent in EU/EEA & UK; opt-out elsewhere Microsoft Clarity — persistent identifier for product-improvement analytics (heatmaps / masked session replay) Up to 1 year Microsoft (Clarity)
_clsk Analytics (session) — consent in EU/EEA & UK; opt-out elsewhere Microsoft Clarity — session identifier linking page views within one session 1 day Microsoft (Clarity)
CLID Analytics (session) — consent in EU/EEA & UK; opt-out elsewhere Microsoft Clarity — first-party identifier set on the Clarity/Bing domain Up to 1 year Microsoft (clarity.ms / c.bing.com)

In the EU/EEA, UK and India, Google Analytics 4 is not set unless and until you click "Accept" on our cookie banner; Microsoft Clarity is treated the same way in the EU/EEA and UK. Outside those regions, GA4 and Clarity operate on an opt-out basis — you can decline at any time via the banner, your browser, or (for GA4) the GPC signal. Strictly-necessary cookies are set on every visit because the site cannot function without them.

2.1 Cookies we do NOT use

We do not set:

3. Strictly necessary cookies (no consent required)

Under Article 5(3) of the ePrivacy Directive, the proviso to ePrivacy implementing legislation in EU Member States, the UK PECR, and equivalent rules elsewhere, "strictly necessary" cookies are exempt from the consent requirement. We rely on this exemption only for cookies that are essential for delivering a service explicitly requested by you, such as security, load balancing, session-state, and remembering your consent choice itself. They cannot be disabled without breaking the site.

Bot protection (Google reCAPTCHA v3). When enabled, our contact forms use Google reCAPTCHA v3 to block automated abuse. reCAPTCHA sets a _GRECAPTCHA cookie (and similar tokens) and analyses interaction signals to score each submission. Because this is strictly necessary to protect the forms from spam and abuse — a security service you implicitly request by using the form — it is treated as a strictly-necessary measure and is not gated behind the analytics-consent banner. reCAPTCHA data is processed by Google LLC under Google's privacy policy; see also the reCAPTCHA terms. This is forward-looking: it applies only once reCAPTCHA is configured on the site.

4. Analytics cookies — Google Analytics 4 & Microsoft Clarity

We use Google Analytics 4 to understand which pages are popular, how visitors find us, and where they drop off; and Microsoft Clarity for product-improvement analytics (aggregated heatmaps and session replays of on-site behaviour, with text and form inputs masked). Our consent rules are region-aware (see section 6): in the EU/EEA, UK and India, GA4 loads only after you Accept; Microsoft Clarity is consent-gated in the EU/EEA and UK and runs on an opt-out basis elsewhere.

5. Marketing & advertising cookies

We do not use marketing or advertising cookies. We do not run retargeting campaigns, conversion pixels, or third-party advertising trackers. Because of this, the "Accept" path on our cookie banner does not trigger any advertising-related processing.

6. Cross-jurisdiction summary

RegionStatutory basisOur default behaviour
EU / EEA ePrivacy Directive 2002/58/EC; GDPR Arts 6 & 7 Opt-in for both Google Analytics 4 and Microsoft Clarity. Nothing optional fires before you click Accept; GPC is honoured as an opt-out for both.
United Kingdom PECR; UK GDPR Opt-in for both GA4 and Microsoft Clarity. Same banner and GPC behaviour as the EU/EEA.
India DPDP Act 2023 (in particular §6 consent requirements once in force) and IT Act 2000 Google Analytics 4: opt-in (we honour the DPDP §6(1)–(2) consent standard). Microsoft Clarity: operated on an opt-out basis, with notice via this policy and the cookie banner.
California (CCPA / CPRA) and other US states Cal. Civ. Code §1798; VCDPA, CPA, CTDPA, UCPA, TDPSA, etc. Opt-out. GPC is honoured for Google Analytics; we do not "sell" or "share" personal information for cross-context behavioural advertising.
Other jurisdictions Various (PIPL, APPI, PIPA, LGPD, PDPA, etc.) We apply the more protective of the local rule and the EU/India default.

7. Manage your preferences

You can also manage cookies via your browser settings:

8. Withdraw consent (DPDP §6 / GDPR Art 7)

You may withdraw consent at any time. The simplest way is to click "Reject Non-Essential Cookies" above; this clears Google Analytics and Microsoft Clarity cookies, sets me_cookie_consent to rejected, and updates Google Consent Mode v2 to a fully denied state for Google Analytics. In the EU/EEA and UK this also stops Microsoft Clarity. Withdrawal of consent applies prospectively; processing already performed under valid consent remains lawful.

9. Global Privacy Control (GPC)

If your browser sends the Global Privacy Control signal (Sec-GPC: 1), we treat it as a valid opt-out under CCPA / CPRA and as a withdrawal of any prior cookie consent. For Google Analytics we honour GPC in every region — GA cookies are not set on GPC visits, and the banner is suppressed. For Microsoft Clarity we honour GPC in the EU/EEA and UK.

10. Google Consent Mode v2 mapping

We send the following Google Consent Mode v2 signals to gtag for Google Analytics. Defaults are region-scoped: in the EU/EEA, UK and India the default is fully denied until you Accept; in the rest of the world analytics_storage defaults to granted (opt-out). Signals are updated when you make a choice or when we detect a GPC signal. Microsoft Clarity is not part of Google Consent Mode and is controlled separately (see sections 4 and 6).

Stateanalytics_storagead_storagead_user_dataad_personalization
Default — EU/EEA, UK, India (pre-consent)denieddenieddenieddenied
Default — rest of world (opt-out)granteddenieddenieddenied
Accept allgranteddenied (we don't run ads)denieddenied
Accept analytics onlygranteddenieddenieddenied
Reject / GPC signaldenieddenieddenieddenied

11. Children

motleyexim.com is a B2B defence-procurement website and is not directed to anyone under 18. We do not knowingly set non-essential cookies on devices used by children. The protections of DPDP Act §9 and GDPR Art 8 apply.

12. Changes to this policy

We may update this Cookie Policy as our practices, sub-processors, or applicable law evolve. Material changes will be flagged at the top with an updated date. Material additions to the cookie inventory will trigger a re-prompt of the consent banner so you can review your preferences.

13. Grievance Officer and complaints

If you believe a cookie was set without proper consent, or if the consent banner is not behaving as described, please raise a grievance with our designated Grievance Officer Tejasvi Shedha (Business Development Executive) at [email protected]. We acknowledge within 24 hours and resolve within 15 days. Full process at /grievance-officer/. You may also lodge a complaint directly with the Data Protection Board of India (DPDP §18), your EU / UK supervisory authority, your state Attorney General (US), or the relevant authority in your jurisdiction.

14. Contact

Questions about cookies? Email [email protected] or read our Privacy Policy and Terms of Service.

Cookie-specific grievances: Tejasvi Shedha, Business Development Executive — [email protected] — full process at /grievance-officer/.