This Cookie Policy explains how Sigmix (“Sigmix,” “we,” “us”) uses cookies and similar technologies on the Sigmix websites (sigmix.ai, sigmix.sa) and platform. It supplements our Privacy Policy and is written to meet the consent and transparency requirements of the Saudi Personal Data Protection Law (PDPL).
What cookies are
Cookies are small text files placed on your device when you visit a website. We also use similar technologies such as pixels, local storage, and SDKs. Some are set by us (first-party); some by our providers (third-party). Cookies can be session (deleted when you close your browser) or persistent (kept for a set period or until deleted).
The categories we use
| Category | What it does | Consent |
|---|---|---|
| Strictly necessary | Core functionality: login and session management, security, fraud prevention, load balancing, and the billing/checkout flow. The Services won't work properly without these. | No consent required — always on |
| Functional / preference | Remembers your choices — language, theme, RTL/LTR, workspace, and similar — for a better experience. | On by default — opt out anytime |
| Analytics / performance | Helps us understand usage — pages and features visited, errors, performance — so we can improve the Services. | On by default — opt out anytime |
| Marketing | Measures and supports our marketing, including Google Ads conversion measurement (linking ad clicks to sign-ups). | On by default — opt out anytime |
We use an opt-out model for non-essential cookies: analytics and marketing-measurement cookies are enabled by default to help us operate and improve the Services, with clear notice on your first visit. You can decline them at any time — from the cookie banner or the “Cookie settings” link in the footer — and your choice is remembered; rejecting is as easy as accepting. Strictly necessary cookies are always on.
Cookies and providers
Sigmix (first-party) · Strictly necessary · In-Kingdom. Purpose: login, session, security, checkout. Cookies: sigmix_session — your sign-in session (HttpOnly and Secure; never readable by page scripts) · locale — your language choice (English or Arabic). Type / duration: session + persistent (up to 12 months). Transfer: in-Kingdom.
Sigmix (first-party) · Analytics · In-Kingdom. Purpose: site and product usage analytics, on our own in-Kingdom infrastructure — random identifiers, not your name or email. Cookies: _smx_vid — visitor identifier (12 months) · _smx_sid — session identifier (30 minutes, sliding) · _smx_utm — campaign attribution (UTM) (90 days). Type / duration: persistent (30 minutes to 12 months). Transfer: in-Kingdom.
Google Analytics 4 (Google) · Analytics · Cross-border. Purpose: marketing-site usage analytics. Cookies: _ga and _ga_* (measurement ID G-RWBSE2QGF7), loaded via Google Tag Manager. Type / duration: persistent (up to ~14 months). Transfer: cross-border (Google).
Google Ads (Google) · Marketing / conversion measurement · Cross-border. Purpose: measuring the effectiveness of our advertising and linking ad clicks to sign-ups (conversions). Cookies: Google conversion-linker cookies (e.g. _gcl_*), loaded via Google Tag Manager. Type / duration: persistent (up to ~90 days). Transfer: cross-border (Google).
Mixpanel · Analytics / product usage · Cross-border (EU endpoint). Purpose: marketing-site usage analytics and session replay. Cookies: mp_*. Type / duration: persistent (up to ~12 months). Transfer: cross-border (EU ingestion endpoint).
LinkedIn (Microsoft) · Advertising / audience measurement · Cross-border. Purpose: measuring campaign reach and building remarketing audiences. Cookies: li_adsId, li_*. Type / duration: persistent (up to ~6 months). Transfer: cross-border.
TikTok · Advertising / audience measurement · Cross-border. Purpose: campaign measurement and remarketing. Cookies: _ttp, ttcsid*. Type / duration: persistent (up to ~13 months). Transfer: cross-border.
X (Twitter) · Advertising / audience measurement · Cross-border. Purpose: campaign measurement and remarketing. Cookies: _twpid. Type / duration: persistent. Transfer: cross-border.
Scope of our zero-egress guarantee. The “0 bytes egress” commitment describes the Sigmix products you deploy — the sealed on-premises servers and the on-device workspace, where your content stays on your own hardware. It does not describe this public marketing site, which uses ordinary web analytics and advertising measurement, listed in full above, and which you can decline.
Third-party cookies are also governed by those providers' own privacy policies. Cross-border transfers are handled as described in the Privacy Policy.
Your choices and how to withdraw consent
- Cookie notice. On your first visit (and again periodically, or when our cookies change) a notice explains that analytics and marketing-measurement cookies are on by default. You can acknowledge it, Decline analytics (opt out), or Manage preferences (granular, per category).
- Change anytime. Reopen your choices via the “Cookie settings” link in the website footer.
- Browser controls. You can block or delete cookies in your browser settings; blocking strictly-necessary cookies may break login, checkout, or other features.
- Consent records. We log your consent choices (timestamp and categories) as evidence of consent, and keep these records as stated in the Privacy Policy.
Changes
We may update this Cookie Policy. Material changes are notified per the Privacy Policy. In case of conflict between language versions, the Arabic version prevails.
Contact
Questions: dpo@sigmix.sa. See also the Privacy Policy.