Back to the portal

Cookie Policy

Version 1.0.0Effective July 18, 2026

Cookie Policy Mikasa Labs LLC Version 1.0.0. Effective date: 2026-07-18. 1. Who we are and what this policy covers Mikasa Labs LLC ("we", "us") operates the investordataroom.com platform, including tenant sites served on subdomains of investordataroom.com (the "Platform"). This policy explains the cookies and similar technologies the Platform itself uses, lists every one of them, and describes your choices. This policy covers Platform technology only. The investment funds and regional centers that use the Platform (each a "Tenant") publish their own terms and privacy policies on their own websites, and content a Tenant publishes can involve third parties as described in Section 6. For how we process personal data generally, and for your privacy rights, see the Platform Privacy Policy, which the Platform presents for acceptance at your first sign-in and after any material change. 2. What cookies and similar technologies are A cookie is a small text file a website stores in your browser. Browsers offer other kinds of on-device storage that work in similar ways, including localStorage and IndexedDB, which are storage areas scoped to a website. Web pages can also load scripts and frames from third parties, which may store or read information on your device in their own context. In this policy, "cookies and similar technologies" means all of these. 3. What the Platform stores on your device This is the complete list. The Platform sets exactly one cookie and four on-device storage entries. - Session cookie. Name: __Host-session (non-production development builds use the name "session"). A first party cookie whose only purpose is keeping you securely signed in. It is marked HttpOnly (scripts running in the page cannot read it), Secure (sent only over encrypted connections), and SameSite=Lax, and it is scoped to the exact web address you signed in on. It lasts up to 8 hours and is removed when you sign out. It holds a signed sign-in credential, not your password. This cookie is strictly necessary: without it, you cannot sign in or stay signed in. - Theme preference. A localStorage entry named "idr-theme" that stores your light or dark display choice on your device. It is created only when you use the theme toggle, it is never transmitted to us or anyone else, and it stays on your device until you clear your browser's site data. Its only purpose is remembering the appearance you chose. - Sign-in state. Our authentication provider (Firebase Authentication, a Google service) keeps your sign-in state in your browser's IndexedDB storage so that you stay signed in while you use the Platform and do not have to re-enter your password on every page. Its only purpose is authentication. It is removed when you sign out, or when your browser clears site data. - Security attestation state. Our anti-abuse service (Firebase App Check with reCAPTCHA Enterprise; see Section 5) keeps its current attestation token in your browser's IndexedDB storage, so the security check does not have to re-run on every request. Its only purpose is security. The token is short-lived and refreshed automatically, and the entry is removed when your browser clears site data. - Library service records. The Google client libraries the Platform is built with (Firebase) keep small records in your browser's IndexedDB storage listing the library versions in use and the dates they were used. These records accompany the Platform's requests to Google's services as diagnostic information. They contain no name, no email address, and no account identifier, and they are removed when your browser clears site data. The Platform determines which Tenant site you are visiting from the web address of your request, not from a cookie. 4. What we do not use The Platform uses no analytics cookies, no advertising cookies, no tag managers, no session-replay tools, no social media trackers, and no tracking pixels of any kind. We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use cookies or similar technologies to track you across other websites or to build advertising profiles. 5. Security service: reCAPTCHA Enterprise (Google) Every Platform page, including the sign-in screens, loads Google's reCAPTCHA Enterprise service. It runs scripts served from www.google.com and www.gstatic.com and an invisible frame from www.google.com, and it sends attestation signals to Google so that our systems can verify that requests come from a real browser rather than from automated abuse. This protects your account and the documents in your data room, and it cannot be switched off, because it is part of how the Platform defends itself and its users. In this context Google acts as our security provider and may set cookies or use similar technologies within its own frame. Google's terms for reCAPTCHA Enterprise state that Google processes information submitted through the service only as necessary to provide and maintain the service and to keep its threat detection effective, and not for other purposes such as personalized advertising by Google. This site is protected by reCAPTCHA Enterprise. The Google Privacy Policy and Terms of Service apply: https://policies.google.com/privacy https://policies.google.com/terms 6. Videos your fund manager embeds (YouTube and Vimeo) A Tenant can include a video in an update by embedding it from YouTube or Vimeo. If you view an update that contains an embedded video, your browser loads that video in a frame directly from the provider (www.youtube.com or player.vimeo.com). The provider then receives your IP address and information about your browser, and may set its own cookies and similar technologies inside its frame, under its own policies: https://policies.google.com/privacy (YouTube is a Google service) https://vimeo.com/privacy This happens only when a Tenant has embedded a video and you view the update containing it. The Platform does not embed videos of its own, does not integrate with the providers' analytics, and does not receive viewing data from these players. If no update you view contains a video, no video provider is contacted. 7. Your choices and browser controls Your browser lets you block, restrict, or delete cookies and site data. You can also clear this site's data at any time in your browser settings. The honest consequences on this Platform: - Blocking or deleting the session cookie prevents sign-in, or signs you out. - Clearing site data resets your theme choice and signs you out. - Blocking third party content in your browser may prevent embedded videos from playing and may interfere with the reCAPTCHA security check. Because the Platform sets no optional cookies, there is no cookie consent banner: there is nothing optional to accept or decline. The items listed in Section 3 exist for sign-in, for security, and for the operation of the Platform's own software libraries, except the theme preference, which is created only if you use the theme toggle. 8. Global Privacy Control and Do Not Track Some browsers can send opt-out preference signals such as Global Privacy Control (GPC) or Do Not Track (DNT). We do not sell personal information, do not share it for cross-context behavioral advertising, and use no advertising or analytics cookies, so these signals have nothing to switch off on the Platform: there is no optional tracking to disable, and pages behave the same whether or not a signal is present. If our practices ever change, we will update this policy first and honor applicable opt-out preference signals as the law requires. 9. Changes to this policy We publish each version of this policy to the Platform Legal Ledger, our append-only record of published platform legal documents, where each version carries its version number and effective date and prior versions are retained. If a change materially affects how cookies or similar technologies are used, we will take reasonable steps to bring it to your attention in the Platform before or when it takes effect. 10. Contact Questions about this policy: privacy@investordataroom.com Mikasa Labs LLC 37010 Dusterberry Way 546, Fremont, CA 94536