Cookie Policy
Last updated: 2025-01-05
Version: 2.0 (Enhanced Compliance and Transparency)
Cookie Policy
Last Updated: 2025-01-05 Effective Date: 2025-01-05 Version: 2.0 (Enhanced Compliance and Transparency)
1. Introduction
1.1 Purpose
This Cookie Policy ("Policy") explains how PayWolt Platform ("PayWolt", "we", "us", "our") and our service providers use cookies, web beacons, local storage, mobile identifiers, and similar tracking technologies (collectively, "Cookies") when you access or use:
- PayWolt Website: https://paywolt.com and associated subdomains
- PayWolt Mobile Applications: iOS and Android applications
- PayWolt Platform APIs: When accessed via web browser
(Collectively, the "Platform" or "Services")
This Policy should be read in conjunction with our Privacy Policy and Terms of Service.
1.2 PayWolt's Service Model
Important Context:
PayWolt operates as a technology service provider (TSP) that orchestrates cross-border remittance transfers between licensed payment service providers (Wise, Flutterwave, Stripe). We do NOT operate as an electronic money institution (EMI) or payment institution (PI).
Cookie Usage Context:
- Cookies Set by PayWolt: Used for Platform functionality, authentication, analytics, and security
- Cookies Set by Payment Providers: When you interact with payment flows (Stripe, Wise, Flutterwave), these providers may set their own cookies on their respective domains according to their privacy policies
- Cookies Set by Third-Party Services: Analytics, support, and security services we use may set cookies
Critical Principle: PayWolt is responsible for cookies set on the PayWolt Platform. Payment service providers and other third parties are independently responsible for cookies they set on their own domains or within their embedded services.
2. What Are Cookies and Similar Technologies?
2.1 Cookies Defined
Cookies are small text files (typically 4KB or less) placed on your device (computer, smartphone, tablet) by websites you visit. Cookies contain:
- A unique identifier
- The domain that set the cookie
- Expiration date/time
- Optional data values
Cookies enable websites to recognize your device, remember preferences, and provide personalized experiences.
2.2 Types of Storage Technologies We Use
| Technology | Description | Where Used | Persistence |
|---|---|---|---|
| HTTP Cookies | Text files stored in browser cookie jar | Website | Session or persistent (up to 2 years) |
| Local Storage | Browser storage API (HTML5) providing larger storage capacity | Website | Persistent until manually cleared |
| Session Storage | Browser storage API cleared when browser tab closes | Website | Session only |
| IndexedDB | Browser database for structured data | Website (offline mode) | Persistent until manually cleared |
| Web Beacons / Pixels | Tiny transparent images (1x1 pixel) embedded in pages or emails | Website, Email | N/A (server-side tracking) |
| Mobile SDKs | Software development kits embedded in mobile apps that collect usage data | Mobile Apps | Varies by SDK |
| Device Fingerprinting | Collecting device characteristics to create unique identifier | Website, Mobile Apps | Per session |
2.3 First-Party vs. Third-Party Cookies
| Type | Set By | Example | Purpose |
|---|---|---|---|
| First-Party Cookies | PayWolt (paywolt.com domain) | Authentication, preferences | Essential Platform functionality |
| Third-Party Cookies | External services (e.g., Google Analytics) | Analytics, advertising | Service enhancement, marketing |
Important: Third-party cookies can track you across multiple websites, not just PayWolt. We limit third-party cookies and require your consent for non-essential third-party cookies.
3. Cookie Categories and Legal Basis
We categorize cookies based on their purpose and the legal basis for processing under GDPR and ePrivacy Directive.
3.1 Strictly Necessary Cookies
Purpose: Essential for the Platform to function. Without these cookies, core services cannot be provided.
Legal Basis: Legitimate interest (GDPR Article 6(1)(f)) - necessary for service delivery. No consent required.
Specific Uses:
| Cookie Name | Purpose | Duration | Domain | Set By |
|---|---|---|---|---|
pwt_session | User authentication; maintain logged-in state | Session (expires on browser close) | .paywolt.com | PayWolt |
pwt_csrf | Cross-Site Request Forgery (CSRF) protection | Session | .paywolt.com | PayWolt |
pwt_device_id | Device identification for security and fraud detection | 1 year | .paywolt.com | PayWolt |
pwt_consent | Record of cookie consent choices | 1 year | .paywolt.com | PayWolt |
pwt_locale | Language and regional settings (e.g., en-GB, fr-FR) | 1 year | .paywolt.com | PayWolt |
pwt_2fa_verified | Two-factor authentication verification status | Session | .paywolt.com | PayWolt |
__stripe_mid | Stripe fraud prevention (merchant ID) | 1 year | .paywolt.com | Stripe |
__stripe_sid | Stripe fraud prevention (session ID) | 30 minutes | .paywolt.com | Stripe |
Data Processing:
- Stored: Locally on your device
- Transmitted: To PayWolt servers on each request (encrypted via HTTPS)
- Shared with third parties: Only Stripe (for payment processing); no other third parties
Cannot Be Disabled: Disabling these cookies will prevent you from logging in, making transfers, or using core Platform features.
3.2 Functional Cookies
Purpose: Enhance Platform functionality and personalization. Not essential, but significantly improve user experience.
Legal Basis: Consent (GDPR Article 6(1)(a)) - you can opt out. Consent required.
Specific Uses:
| Cookie Name | Purpose | Duration | Domain | Set By |
|---|---|---|---|---|
pwt_prefs | User interface preferences (currency display format, notification settings) | 1 year | .paywolt.com | PayWolt |
pwt_currency | Last selected source currency for quick access | 6 months | .paywolt.com | PayWolt |
pwt_theme | Light/dark mode preference | 1 year | .paywolt.com | PayWolt |
pwt_recent_corridors | Recently used transfer corridors for quick access | 6 months | .paywolt.com | PayWolt |
intercom-id-{app_id} | Intercom support chat identifier | 9 months | .paywolt.com | Intercom |
intercom-session-{app_id} | Intercom active support session | 1 week | .paywolt.com | Intercom |
intercom-device-id-{app_id} | Intercom device identifier | 9 months | .paywolt.com | Intercom |
Data Processing:
- Stored: Locally on your device
- Transmitted: To PayWolt servers and Intercom servers (for support chat)
- Shared with third parties: Intercom (for customer support chat functionality)
Impact if Disabled:
- Preferences will not be remembered between sessions
- You will need to re-select currency, theme, and other settings each time
- Support chat may not remember your conversation history
How to Disable: Use the Cookie Consent Manager (see Section 5) or browser settings (see Section 6).
3.3 Analytics and Performance Cookies
Purpose: Understand how visitors use the Platform, which features are most popular, and where improvements can be made. Helps us optimize Platform performance and user experience.
Legal Basis: Consent (GDPR Article 6(1)(a)) - you can opt out. Consent required.
Specific Uses:
| Cookie Name | Purpose | Duration | Domain | Set By |
|---|---|---|---|---|
_ga | Google Analytics: Distinguish unique users | 2 years | .paywolt.com | Google Analytics |
_ga_{container_id} | Google Analytics 4: Persist session state and user properties | 2 years | .paywolt.com | Google Analytics |
_gid | Google Analytics: Distinguish users (short-term) | 24 hours | .paywolt.com | Google Analytics |
_gat_UA-{property_id} | Google Analytics: Throttle request rate to prevent server overload | 1 minute | .paywolt.com | Google Analytics |
mp_{token}_mixpanel | Mixpanel: Product analytics and user behavior tracking | 1 year | .paywolt.com | Mixpanel |
mp_optout | Mixpanel: Record opt-out status | 5 years | .paywolt.com | Mixpanel |
Data Collected via Analytics Cookies:
| Data Category | Examples | Purpose |
|---|---|---|
| Page Views | URLs visited, page titles, referrer URL | Understand content popularity |
| User Interactions | Button clicks, form submissions (not field values), scroll depth | Optimize user flows |
| Session Information | Session duration, pages per session, bounce rate | Measure engagement |
| Device Information | Browser type/version, OS, screen resolution, language | Optimize for devices |
| Geographic Location | Country, region, city (derived from IP address) | Understand user base geography |
| Traffic Sources | Referral source (e.g., Google search, social media, direct) | Measure marketing effectiveness |
Privacy Protections:
- IP Anonymization: Google Analytics is configured with IP anonymization enabled (
anonymizeIp: true). The last octet of your IP address is removed before storage (e.g., 192.168.1.123 → 192.168.1.0). - No Personally Identifiable Information (PII): We do not send user IDs, email addresses, names, or other PII to analytics services.
- Data Retention Limits: Analytics data is automatically deleted after 26 months (Google Analytics setting).
- Data Processing Agreements: We have signed Data Processing Agreements (DPAs) with Google and Mixpanel per GDPR Article 28.
Third-Party Privacy Policies:
- Google Analytics: https://policies.google.com/privacy
- Mixpanel: https://mixpanel.com/legal/privacy-policy/
Impact if Disabled:
- No impact on Platform functionality
- You will not be tracked for analytics purposes
- We will have less insight into how to improve the Platform based on usage patterns
How to Disable:
- Use the Cookie Consent Manager (see Section 5)
- Install Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout
- Enable browser Do Not Track (DNT) setting (see Section 6.3)
3.4 Marketing and Advertising Cookies
Purpose: Deliver personalized advertising, measure ad campaign effectiveness, and retarget visitors who did not complete transfers.
Legal Basis: Consent (GDPR Article 6(1)(a)) - opt-in only. Explicit consent required.
Specific Uses:
| Cookie Name | Purpose | Duration | Domain | Set By |
|---|---|---|---|---|
_fbp | Meta (Facebook) Pixel: Browser identification for ad targeting and conversion tracking | 3 months | .paywolt.com | Meta Platforms |
_fbc | Meta (Facebook) Pixel: Store Facebook click ID for ad attribution | 3 months | .paywolt.com | Meta Platforms |
_gcl_au | Google Ads: Store and track conversions from Google Ads campaigns | 3 months | .paywolt.com | Google Ads |
_gcl_aw | Google Ads: Store click information from Google Ads | 3 months | .paywolt.com | Google Ads |
_gcl_dc | Google Ads: Store click information from Display & Video 360 ads | 3 months | .paywolt.com | Google Ads |
Data Collected via Marketing Cookies:
- Ad Interactions: Which ads you clicked before visiting PayWolt
- Conversion Events: Whether you completed a transfer after seeing an ad
- Retargeting Data: Pages visited, actions taken (used to show relevant ads on other websites)
Privacy Protections:
- Opt-In Only: Marketing cookies are disabled by default. They are only activated if you explicitly consent via the Cookie Consent Manager.
- No Sensitive Data: We do not share sensitive personal data (health, financial details, identity documents) with advertising platforms.
- Standard Contractual Clauses (SCCs): Data transfers to Meta and Google (US-based) are covered by SCCs per GDPR Article 46.
Third-Party Privacy Policies:
- Meta (Facebook): https://www.facebook.com/privacy/policy/
- Google Ads: https://policies.google.com/privacy
Impact if Disabled:
- No impact on Platform functionality
- You will not see personalized PayWolt ads on other websites
- You may still see generic (non-targeted) PayWolt ads
How to Disable:
- Do not consent to marketing cookies in Cookie Consent Manager
- Opt out of personalized advertising:
- Facebook: https://www.facebook.com/ads/preferences/
- Google: https://adssettings.google.com/
- Use browser privacy features (e.g., Safari Intelligent Tracking Prevention, Firefox Enhanced Tracking Protection)
4. Third-Party Services and Cookies
4.1 Third-Party Services We Use
PayWolt integrates with third-party services that may set cookies on our Platform. We have contractual agreements and Data Processing Agreements (DPAs) with all third parties per GDPR Article 28.
4.1.1 Analytics Services
| Provider | Purpose | Cookies Set | Data Transferred To | Privacy Policy |
|---|---|---|---|---|
| Google Analytics | Website and app usage analytics | _ga, _gid, _gat | United States (Google LLC) | Google Privacy Policy |
| Mixpanel | Product analytics and user behavior tracking | mp_* | United States (Mixpanel Inc.) | Mixpanel Privacy Policy |
| Firebase Analytics (Mobile apps) | Mobile app usage analytics and crash reporting | N/A (mobile SDK, not cookies) | United States (Google LLC) | Firebase Privacy Policy |
Data Shared: Page views, events, anonymized IP addresses, device information. NOT shared: User names, email addresses, transfer amounts, identity documents.
4.1.2 Customer Support Services
| Provider | Purpose | Cookies Set | Data Transferred To | Privacy Policy |
|---|---|---|---|---|
| Intercom | Live chat support, help center, customer messaging | intercom-id-*, intercom-session-* | United States (Intercom Inc.) | Intercom Privacy Policy |
Data Shared: Name, email address, support conversation history, page you're viewing when you contact support. NOT shared: Identity documents, full financial transaction details.
4.1.3 Security and Fraud Prevention Services
| Provider | Purpose | Cookies Set | Data Transferred To | Privacy Policy |
|---|---|---|---|---|
| Stripe | Payment processing and fraud prevention | __stripe_mid, __stripe_sid | United States/Ireland (Stripe Inc./Stripe Payments Europe Ltd.) | Stripe Privacy Policy |
| Cloudflare | DDoS protection, content delivery network (CDN), security | __cflb, __cf_bm | Global (Cloudflare Inc.) | Cloudflare Privacy Policy |
Data Shared: IP address, device fingerprint, request headers. NOT shared: Identity documents, sensitive personal data.
4.1.4 Identity Verification Services
| Provider | Purpose | Cookies Set | Data Transferred To | Privacy Policy |
|---|---|---|---|---|
| Sumsub (Integrated via iframe) | KYC identity verification | Set on sumsub.com domain (not .paywolt.com) | Cyprus (Sum & Substance Ltd.) | Sumsub Privacy Policy |
Important: When you complete identity verification, you are redirected to Sumsub's domain (sumsub.com). Sumsub is an independent data controller for identity verification data per our Privacy Policy. Sumsub sets cookies on their own domain according to their privacy policy, not this Cookie Policy.
4.2 Payment Service Provider Cookies
When you initiate a transfer, you interact with payment collection and payout providers. These providers may set cookies on their own domains (not .paywolt.com):
| Provider | When You Interact | Cookies Set On | Privacy Policy |
|---|---|---|---|
| Stripe | Card payment collection | stripe.com, js.stripe.com | Stripe Privacy Policy |
| Flutterwave | Bank transfer / mobile money collection (Africa) | flutterwave.com | Flutterwave Privacy Policy |
| Wise | Payout execution (Europe/Global) | wise.com, transferwise.com | Wise Privacy Policy |
Important: PayWolt does NOT control cookies set by payment providers on their own domains. These providers are independent data controllers. Please review their respective privacy and cookie policies.
4.3 Embedded Third-Party Content
The Platform may embed third-party content that sets cookies:
| Content Type | Examples | Cookies May Be Set By |
|---|---|---|
| Videos | YouTube embedded videos (help center, tutorials) | YouTube (Google) |
| Maps | Google Maps (office location) | Google Maps |
| Social Media Plugins | Twitter/X share buttons, LinkedIn share buttons | Twitter/X, LinkedIn |
How to Control: You can block third-party cookies via browser settings (see Section 6) or disable marketing cookies via Cookie Consent Manager.
5. Cookie Consent Management
5.1 Consent Requirement (GDPR & ePrivacy Directive)
Under EU law (GDPR, ePrivacy Directive) and UK law (PECR), we must obtain your explicit consent before setting non-essential cookies (Functional, Analytics, Marketing).
Exceptions (No Consent Required):
- Strictly Necessary cookies (essential for service delivery)
- Cookies used solely for anonymous statistical purposes (we still request consent as best practice)
5.2 Cookie Consent Banner
First Visit:
When you first visit the PayWolt Platform, you will see a Cookie Consent Banner before any non-essential cookies are set.
Options Presented:
| Button | Effect |
|---|---|
| Accept All | Consent to all cookie categories (Necessary, Functional, Analytics, Marketing) |
| Reject All | Only Strictly Necessary cookies enabled; all others disabled |
| Customize | Opens detailed consent manager where you can select specific cookie categories |
Granular Consent:
The "Customize" option allows you to:
- Enable/disable each cookie category individually (Functional, Analytics, Marketing)
- View detailed list of cookies in each category
- Read about specific third-party services
Default State:
- Strictly Necessary: Always enabled (cannot be disabled)
- Functional, Analytics, Marketing: Disabled by default; require opt-in
5.3 Consent Records (GDPR Article 7)
We maintain detailed records of your consent to comply with GDPR Article 7 (Conditions for consent):
Recorded Information:
- User Identifier: Anonymous device ID or user ID (if logged in)
- Consent Timestamp: Date and time of consent (ISO 8601 format, UTC)
- Consent Choices: Which categories you consented to (e.g.,
{functional: true, analytics: false, marketing: false}) - Cookie Policy Version: Version of this Policy presented at time of consent
- Consent Method: How consent was given (e.g., "banner_accept_all", "banner_customize", "settings_page")
- User Agent: Browser and device information (for verification purposes)
Retention Period: Consent records are retained for 3 years from the date of consent or withdrawal, whichever is later, to demonstrate compliance with GDPR.
Access to Consent Records: You may request a copy of your consent records by contacting privacy@paywolt.com.
5.4 Withdrawing Consent
You may withdraw your consent at any time. Withdrawal is as easy as giving consent.
How to Withdraw Consent:
-
Cookie Settings Page:
- Website: Click "Cookie Settings" link in footer
- Mobile App: Settings > Privacy > Cookie Preferences
-
Change Preferences:
- Toggle off cookie categories you no longer wish to allow
- Click "Save Preferences"
-
Effect of Withdrawal:
- Non-essential cookies will stop being set
- Existing cookies will be deleted (where technically feasible)
- No retroactive effect (data already collected remains unless you request deletion per GDPR Article 17)
No Negative Consequences:
Withdrawing consent will NOT:
- Affect your ability to use core Platform features
- Result in account suspension or termination
- Affect the lawfulness of processing based on consent before withdrawal (GDPR Recital 65)
Requesting Data Deletion:
If you wish to delete data collected via cookies before withdrawal, exercise your Right to Erasure per our Privacy Policy Section 9 (Your Rights Under GDPR).
5.5 Consent for Minors
Age Restriction:
The PayWolt Platform is not intended for children under 18 years of age. We do not knowingly collect personal data from minors.
If You Are Under 18:
- Do not use the PayWolt Platform
- Do not provide any personal information
- If we discover we have collected data from a minor, we will delete it promptly
Parental Notice:
If you believe your child has provided personal information to PayWolt, contact us immediately at privacy@paywolt.com.
6. Managing and Controlling Cookies
6.1 Browser Cookie Settings
All modern browsers allow you to control cookies. You can:
- Block all cookies (may break website functionality)
- Block third-party cookies only (recommended for privacy)
- Delete cookies (clears existing cookies)
- View cookies (inspect cookies stored by websites)
Browser-Specific Instructions:
Google Chrome
- Settings > Privacy and security > Cookies and other site data
- Choose:
- Block all cookies (not recommended)
- Block third-party cookies (recommended)
- Allow all cookies
- To delete cookies: Delete browsing data > Select "Cookies and other site data" > Clear data
Mozilla Firefox
- Settings > Privacy & Security > Cookies and Site Data
- Choose:
- Standard (blocks known trackers)
- Strict (blocks all third-party cookies)
- Custom (configure manually)
- To delete cookies: Clear Data > Select "Cookies and Site Data" > Clear
Apple Safari (macOS)
- Preferences > Privacy
- Enable Prevent cross-site tracking (blocks third-party cookies)
- Enable Block all cookies (may break websites)
- To delete cookies: Safari > Clear History > Select time range > Clear History
Apple Safari (iOS)
- Settings > Safari > Privacy & Security
- Enable Prevent Cross-Site Tracking
- Enable Block All Cookies (may break apps)
- To delete cookies: Settings > Safari > Clear History and Website Data
Microsoft Edge
- Settings > Cookies and site permissions > Manage and delete cookies
- Choose:
- Block all cookies
- Block third-party cookies
- Allow all cookies
- To delete cookies: Settings > Privacy > Clear browsing data > Select "Cookies and other site data"
Important: Blocking or deleting cookies may prevent you from using certain Platform features.
6.2 Third-Party Opt-Out Tools
You can opt out of specific third-party tracking services:
| Service | Opt-Out Tool | Effect |
|---|---|---|
| Google Analytics | Browser Add-on | Prevents Google Analytics from tracking you on all websites |
| Google Ads | Ad Settings | Opt out of personalized ads from Google |
| Facebook Ads | Ad Preferences | Opt out of personalized ads from Facebook/Meta |
| Network Advertising Initiative (NAI) | NAI Opt-Out | Opt out of multiple ad networks at once |
| Digital Advertising Alliance (DAA) | DAA Opt-Out | Opt out of interest-based advertising (US) |
| European Interactive Digital Advertising Alliance (EDAA) | YourOnlineChoices | Opt out of interest-based advertising (EU) |
Note: Opting out does NOT mean you will not see ads. You will still see generic (non-personalized) ads.
6.3 Do Not Track (DNT) Signals
What is DNT?
Do Not Track (DNT) is a browser setting that sends a signal to websites requesting not to be tracked.
PayWolt's DNT Policy:
We respect the DNT signal. When DNT is enabled in your browser:
- Analytics cookies will not be set
- Marketing cookies will not be set
- Functional cookies will not be set (unless you explicitly consent via Cookie Consent Manager)
- Strictly Necessary cookies will still be set (required for service functionality)
How to Enable DNT:
| Browser | Instructions |
|---|---|
| Chrome | Not supported (removed in Chrome 78); use Settings > Privacy and security > Cookies instead |
| Firefox | Settings > Privacy & Security > Enable Tell websites not to sell or share my data |
| Safari | Preferences > Privacy > Enable Prevent cross-site tracking |
| Edge | Settings > Privacy > Enable Send "Do Not Track" requests |
Industry Support:
DNT is not universally respected by all websites. PayWolt voluntarily respects DNT as part of our commitment to user privacy.
6.4 Mobile Device Settings
iOS (iPhone/iPad):
- Limit Ad Tracking:
- Settings > Privacy > Tracking > Disable Allow Apps to Request to Track
- Disable Analytics:
- Settings > Privacy > Analytics & Improvements > Disable Share iPhone Analytics
- Reset Advertising Identifier:
- Settings > Privacy > Apple Advertising > Reset Advertising Identifier
Android:
- Opt Out of Ad Personalization:
- Settings > Privacy > Ads > Enable Opt out of Ads Personalization
- Disable Usage & Diagnostics:
- Settings > Privacy > Usage & diagnostics > Disable
- Reset Advertising ID:
- Settings > Privacy > Ads > Reset advertising ID
Effect on PayWolt Mobile App:
- Marketing tracking (IDFA/GAID) will be disabled
- Analytics may be limited (basic crash reporting remains for app stability)
- Core app functionality unchanged
6.5 Impact of Blocking Cookies
By Cookie Category:
| Category | If Blocked | Impact on PayWolt Platform |
|---|---|---|
| Strictly Necessary | ❌ Cannot be blocked (required) | Platform will not function; you cannot log in or make transfers |
| Functional | ✅ Can be blocked | Preferences not saved; settings reset each session; support chat may not work |
| Analytics | ✅ Can be blocked | No impact on functionality; we cannot improve Platform based on usage data |
| Marketing | ✅ Can be blocked | No impact on functionality; you will not see personalized ads |
Recommendation:
- Allow Strictly Necessary: Required for Platform to work
- Allow Functional: Significantly improves user experience
- Allow Analytics: Helps us improve Platform; data is anonymized
- Block Marketing: If you prefer not to see personalized ads (optional)
7. Mobile Application Tracking
7.1 Mobile Device Identifiers
Our mobile applications (iOS, Android) use device identifiers for analytics, fraud prevention, and push notifications.
| Identifier | Platform | Purpose | Can Be Reset? |
|---|---|---|---|
| IDFA (Identifier for Advertisers) | iOS | Advertising attribution and analytics (with user consent per iOS 14.5+) | ✅ Yes (Settings > Privacy > Apple Advertising > Reset Advertising Identifier) |
| IDFV (Identifier for Vendor) | iOS | Analytics and fraud prevention (does not require consent) | ❌ No (resets when app is uninstalled) |
| GAID (Google Advertising ID) | Android | Advertising attribution and analytics (with user consent) | ✅ Yes (Settings > Privacy > Ads > Reset advertising ID) |
| Android ID | Android | Device identification for analytics and fraud prevention | ❌ No (resets on factory reset) |
| Device UUID | Both | Unique device identifier generated by PayWolt app for security | ❌ No (resets when app is uninstalled) |
| Push Token | Both | Push notification delivery | ❌ No (resets when permissions changed) |
Consent for Advertising Identifiers (IDFA/GAID):
Per iOS App Tracking Transparency (ATT) and Google Play policies:
- We request explicit permission before accessing IDFA (iOS) or GAID (Android) for advertising purposes
- You can deny permission; this does not affect core app functionality
- Advertising identifiers are used solely for ad attribution (measuring ad campaign effectiveness)
7.2 Mobile Analytics SDKs
Our mobile apps integrate analytics and crash reporting SDKs:
| SDK | Provider | Purpose | Data Collected | Privacy Policy |
|---|---|---|---|---|
| Firebase Analytics | Google LLC | Usage analytics, user engagement, conversion tracking | App opens, screen views, events, device info, anonymized IP | Firebase Privacy |
| Firebase Crashlytics | Google LLC | Crash reporting to improve app stability | Crash logs, stack traces, device state at time of crash | Firebase Privacy |
| Mixpanel | Mixpanel Inc. | Product analytics, user journey tracking | User interactions, events, session duration | Mixpanel Privacy |
Data Collected by SDKs:
| Data Type | Examples | Purpose |
|---|---|---|
| App Usage | Screens viewed, buttons tapped, features used | Understand how users interact with app |
| Session Data | Session start/end time, session duration | Measure engagement |
| Device Information | Device model, OS version, screen size, language | Optimize app for devices |
| Crashes | Stack traces, error messages, device state | Fix bugs and improve stability |
| Performance | App launch time, network latency, battery usage | Optimize performance |
Data NOT Collected:
- Identity documents or selfies
- Full transfer amounts or transaction details
- User passwords or authentication tokens
- Contacts or photos from device
Data Retention:
- Firebase Analytics: 2 months (configurable; set to 2 months for privacy)
- Crashlytics: 90 days (crash reports deleted after 90 days)
- Mixpanel: 5 years (configurable; you can request deletion via GDPR rights)
7.3 Managing Mobile App Tracking
iOS:
-
App Tracking Transparency (ATT) Prompt:
- When you first open the PayWolt app, you will see a system prompt: "Allow PayWolt to track your activity across other companies' apps and websites?"
- Allow: Enables IDFA for advertising attribution
- Ask App Not to Track: Blocks IDFA; no advertising tracking
-
Change Tracking Permission Later:
- Settings > Privacy & Security > Tracking > PayWolt > Toggle on/off
-
Reset Advertising Identifier:
- Settings > Privacy > Apple Advertising > Reset Advertising Identifier
- This assigns a new IDFA, breaking the link to previous tracking
Android:
-
Opt Out of Ad Personalization:
- Settings > Privacy > Ads > Enable "Opt out of Ads Personalization"
- This prevents apps from using GAID for personalized advertising
-
Reset Advertising ID:
- Settings > Privacy > Ads > Reset advertising ID
- This assigns a new GAID
Effect of Disabling Mobile Tracking:
- Advertising attribution will not work (we cannot measure which ads led to app installs)
- Analytics may be limited (basic usage analytics still collected for app improvement)
- No impact on core app functionality (transfers, account management work normally)
8. Data Retention and Deletion
8.1 Cookie Data Retention Periods
| Cookie Category | Typical Cookie Expiry | Data Retention by PayWolt/Third Parties |
|---|---|---|
| Session Cookies | Deleted when browser closes | Not retained (ephemeral) |
| Strictly Necessary (persistent) | Up to 1 year | Retained for duration of cookie expiry or account closure |
| Functional | Up to 1 year | Retained for duration of cookie expiry or until you change preferences |
| Analytics | Up to 2 years (cookie expiry) | Google Analytics: 26 months (auto-deletion)<br>Mixpanel: 5 years (or until deletion request) |
| Marketing | Up to 3 months (cookie expiry) | Meta: 90 days<br>Google Ads: 90 days |
Legal Basis for Retention:
- Strictly Necessary: Legitimate interest in service delivery (GDPR Article 6(1)(f))
- Functional, Analytics, Marketing: Consent (retained until consent withdrawn) (GDPR Article 6(1)(a))
8.2 Automatic Deletion of Cookie Data
Browser-Level Deletion:
Cookies are automatically deleted when:
- Cookie expiry date/time is reached (browser deletes expired cookies)
- You clear browser data (cookies manually deleted)
- You uninstall the PayWolt mobile app (app data deleted)
Server-Level Deletion:
Data collected via cookies is automatically deleted per retention policies above. For example:
- Google Analytics data is auto-deleted after 26 months
- Meta advertising data is deleted after 90 days
8.3 Manual Deletion of Cookie Data
Delete Cookies from Browser:
See Section 6.1 (Browser Cookie Settings) for instructions on deleting cookies.
Delete Data from Third-Party Services:
You can request deletion of your data from third-party services directly:
| Service | Deletion Request Method |
|---|---|
| Google Account - Delete Data | |
| Mixpanel | Mixpanel GDPR Request or email privacy@paywolt.com (we will forward request) |
| Meta (Facebook) | Facebook Privacy Settings - Contact Meta directly |
Delete All PayWolt Data (Right to Erasure):
To delete all your personal data held by PayWolt (including data collected via cookies), exercise your Right to Erasure per GDPR Article 17:
- Email privacy@paywolt.com with subject "GDPR Right to Erasure Request"
- Provide your account email and user ID
- We will process your request within 30 days (GDPR requirement)
Exceptions to Erasure:
We may retain certain data if required by law (e.g., AML/CTF compliance requires 5-year retention of transaction records). See Privacy Policy Section 9.3 for full details on Right to Erasure limitations.
9. International Data Transfers
9.1 Transfers Outside the EEA
Cookie data may be transferred to and processed in countries outside the European Economic Area (EEA), including:
| Third Party | Country | Data Transferred | Legal Safeguard |
|---|---|---|---|
| Google (Analytics, Ads, Firebase) | United States | Analytics data, advertising data | Standard Contractual Clauses (SCCs) per GDPR Article 46(2)(c)<br>Google SCCs |
| Mixpanel | United States | Product analytics data | Standard Contractual Clauses (SCCs) per GDPR Article 46(2)(c)<br>Mixpanel DPA |
| Meta (Facebook Pixel) | United States | Advertising data | Standard Contractual Clauses (SCCs) per GDPR Article 46(2)(c)<br>Meta DPA |
| Intercom | United States | Support chat data | Standard Contractual Clauses (SCCs) per GDPR Article 46(2)(c)<br>Intercom DPA |
| Cloudflare | United States (global CDN) | Security data (IP addresses, request headers) | Standard Contractual Clauses (SCCs)<br>Cloudflare DPA |
9.2 Adequacy Decisions
Some countries have been deemed to provide adequate data protection by the European Commission (GDPR Article 45):
| Country | Adequacy Decision | Applies To |
|---|---|---|
| United Kingdom | ✅ Yes (June 2021) | N/A (PayWolt uses UK providers only when necessary) |
| Switzerland | ✅ Yes (Sep 2000) | N/A |
United States: ❌ No adequacy decision (Privacy Shield invalidated by CJEU in Schrems II case, July 2020). Transfers to US rely on Standard Contractual Clauses (SCCs) and supplementary measures.
9.3 Standard Contractual Clauses (SCCs)
What are SCCs?
Standard Contractual Clauses are pre-approved contract terms by the European Commission that ensure adequate data protection when transferring personal data outside the EEA.
PayWolt's Use of SCCs:
We have signed Data Processing Agreements (DPAs) incorporating EU SCCs with all third-party service providers that process personal data outside the EEA:
- Google: Google Ads Data Processing Terms
- Mixpanel: Mixpanel DPA
- Meta: Meta Data Processing Terms
- Intercom: Intercom DPA
Supplementary Measures:
In addition to SCCs, we implement supplementary measures per EDPB Recommendations 01/2020:
- Data minimization: Only necessary data is transferred
- Pseudonymization: Where possible (e.g., Google Analytics anonymizes IP addresses)
- Encryption in transit: All data transfers use TLS 1.2+ encryption
- Encryption at rest: Third-party providers encrypt data at rest
9.4 Your Rights Regarding International Transfers
Right to Object (GDPR Article 21):
You have the right to object to international data transfers. If you object:
- We will stop transferring your data to third parties outside the EEA
- This may limit Platform functionality (e.g., analytics, support chat may not work)
How to Object:
Email privacy@paywolt.com with subject "Objection to International Data Transfers".
10. Legal Framework and Compliance
10.1 Applicable Laws and Regulations
This Cookie Policy complies with:
| Law/Regulation | Jurisdiction | Key Requirements |
|---|---|---|
| GDPR (General Data Protection Regulation) - Regulation (EU) 2016/679 | European Union (EU) + European Economic Area (EEA) | Consent for non-essential cookies (Article 6(1)(a))<br>Transparency (Articles 12-14)<br>Data subject rights (Articles 15-22) |
| ePrivacy Directive (Directive 2002/58/EC) | European Union (EU) | Prior consent for storing/accessing information on user devices (Article 5(3)) |
| UK PECR (Privacy and Electronic Communications Regulations 2003) | United Kingdom | Cookie consent requirements (Regulation 6) |
| CCPA (California Consumer Privacy Act) | California, USA | Right to opt-out of "sale" of personal information<br>Right to know what data is collected |
| LGPD (Lei Geral de Proteção de Dados) | Brazil | Consent requirements similar to GDPR |
| POPIA (Protection of Personal Information Act) | South Africa | Consent for processing personal information |
PayWolt's Commitment:
We design our Cookie Policy to comply with the strictest applicable standard (GDPR + ePrivacy Directive) globally, ensuring all users benefit from strong privacy protections regardless of jurisdiction.
10.2 GDPR Compliance
Legal Bases for Cookie Processing (GDPR Article 6):
| Cookie Category | Legal Basis | GDPR Article |
|---|---|---|
| Strictly Necessary | Legitimate interests (necessary for service delivery) | Article 6(1)(f) |
| Functional | Consent | Article 6(1)(a) |
| Analytics | Consent | Article 6(1)(a) |
| Marketing | Consent | Article 6(1)(a) |
Consent Requirements (GDPR Article 7 & GDPR Recital 32):
Our consent mechanism meets GDPR standards:
- ✅ Freely given: You can refuse consent without negative consequences
- ✅ Specific: Consent is granular (separate for Functional, Analytics, Marketing)
- ✅ Informed: Cookie Consent Banner clearly explains what you're consenting to
- ✅ Unambiguous: Requires affirmative action (clicking "Accept" or toggling categories)
- ✅ Withdrawable: You can withdraw consent as easily as you gave it (Cookie Settings page)
Transparency Requirements (GDPR Articles 12-14):
This Cookie Policy provides:
- ✅ Identity of data controller (PayWolt Platform)
- ✅ Purposes of processing (functionality, analytics, marketing)
- ✅ Legal bases (consent, legitimate interests)
- ✅ Categories of data collected (device info, usage data, etc.)
- ✅ Recipients of data (third-party services listed)
- ✅ International transfers (countries and safeguards listed)
- ✅ Retention periods (cookie expiry and data retention listed)
- ✅ Data subject rights (GDPR Articles 15-22 - see Section 10.3)
10.3 Your Rights Under GDPR
You have the following rights regarding data collected via cookies:
| Right | GDPR Article | Description | How to Exercise |
|---|---|---|---|
| Right of Access | Article 15 | Request a copy of your personal data | Email privacy@paywolt.com with subject "GDPR Access Request" |
| Right to Rectification | Article 16 | Correct inaccurate data | Email privacy@paywolt.com or update via Account Settings |
| Right to Erasure | Article 17 | Delete your data (subject to legal retention obligations) | Email privacy@paywolt.com with subject "GDPR Erasure Request" |
| Right to Restrict Processing | Article 18 | Limit how we use your data | Email privacy@paywolt.com with subject "GDPR Restriction Request" |
| Right to Data Portability | Article 20 | Receive your data in machine-readable format | Email privacy@paywolt.com with subject "GDPR Data Portability Request" |
| Right to Object | Article 21 | Object to processing based on legitimate interests | Email privacy@paywolt.com with subject "GDPR Objection" |
| Right to Withdraw Consent | Article 7(3) | Withdraw consent for cookies | Use Cookie Settings page (see Section 5.4) |
| Right to Lodge a Complaint | Article 77 | Complain to supervisory authority | Contact your national Data Protection Authority (DPA) |
Response Time: We will respond to all GDPR requests within 30 days (GDPR Article 12(3)). Complex requests may be extended by an additional 60 days with notification.
No Fee: Exercising your GDPR rights is free of charge unless requests are manifestly unfounded or excessive (GDPR Article 12(5)).
Identity Verification: To protect your privacy, we may request additional information to verify your identity before processing GDPR requests.
10.4 CCPA Compliance (California Users)
California Residents' Rights:
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
| Right | Description | How to Exercise |
|---|---|---|
| Right to Know | Know what personal information is collected, used, shared, or sold | Email privacy@paywolt.com with subject "CCPA Right to Know" |
| Right to Delete | Request deletion of personal information (subject to exceptions) | Email privacy@paywolt.com with subject "CCPA Deletion Request" |
| Right to Opt-Out of Sale | Opt-out of "sale" of personal information | We do NOT sell personal information<br>Marketing cookies can be disabled via Cookie Settings |
| Right to Non-Discrimination | Not be discriminated against for exercising CCPA rights | We do not discriminate; core Platform functionality remains available |
"Sale" of Personal Information:
Under CCPA, sharing data with third parties for advertising may be considered a "sale." PayWolt's Position:
- We do NOT sell personal information for monetary consideration
- Marketing cookies (Meta, Google Ads) may be considered "sharing" for advertising under CCPA
- You can opt-out via Cookie Settings (disable Marketing cookies)
Do Not Sell My Personal Information:
California residents can opt-out by:
- Disabling Marketing cookies via Cookie Settings
- Enabling browser Do Not Track (DNT) signal
- Emailing privacy@paywolt.com with subject "CCPA Do Not Sell Request"
11. Updates to This Cookie Policy
11.1 Policy Changes
We may update this Cookie Policy periodically to reflect:
- Changes to cookies we use
- Changes to third-party services
- Changes to applicable laws or regulations
- Improvements to our cookie consent mechanisms
- User feedback and best practices
11.2 Notification of Changes
Material Changes:
If we make material changes that significantly affect your rights or how cookies are used, we will:
- Update the "Last Updated" date at the top of this Policy
- Display a prominent notice on the Platform (banner or notification)
- Re-request consent via Cookie Consent Banner (if changes affect non-essential cookies)
- Send email notification to registered users (for significant changes)
Material Changes Definition:
Changes considered "material" include:
- Adding new cookie categories (e.g., introducing Advertising cookies)
- Adding new third-party services that process significant personal data
- Changes to data retention periods (significant increases)
- Changes to international transfer destinations or safeguards
Minor Changes:
Non-material changes (e.g., clarifications, formatting, minor updates) will be posted immediately without re-consent.
11.3 Review Frequency
We review this Cookie Policy every 6 months or when:
- New cookies or third-party services are added
- Applicable laws change
- Regulatory guidance is updated
Recommended Action:
We recommend reviewing this Policy periodically, especially when you see the "Last Updated" date has changed.
11.4 Version History
| Version | Date | Summary of Changes |
|---|---|---|
| 2.0 | 2025-01-05 | Enhanced compliance and transparency; added comprehensive cookie declarations; clarified PayWolt's role as TSP; enhanced GDPR/CCPA compliance sections; improved third-party service documentation |
| 1.0 | 2025-12-28 | Initial version |
Accessing Previous Versions:
Previous versions of this Cookie Policy are available upon request. Email legal@paywolt.com.
12. Contact Information
12.1 Privacy and Cookie Questions
For questions about our use of cookies or this Cookie Policy:
| Contact Type | Response Time | |
|---|---|---|
| General Cookie Questions | privacy@paywolt.com | 48 hours (business days) |
| Data Protection Officer (DPO) | dpo@paywolt.com | 48 hours (business days) |
| GDPR/CCPA Requests | privacy@paywolt.com | 30 days (legally required) |
12.2 Cookie Settings
Manage Your Cookie Preferences:
| Platform | How to Access Cookie Settings |
|---|---|
| Website | Footer link: "Cookie Settings" or "Manage Cookies" |
| Mobile App | Settings > Privacy > Cookie Preferences |
12.3 Supervisory Authority (GDPR)
If you are located in the EEA/UK and have concerns about our cookie practices, you have the right to lodge a complaint with your national Data Protection Authority (DPA):
Greece (PayWolt's Lead Supervisory Authority):
- Hellenic Data Protection Authority (HDPA)
- Website: https://www.dpa.gr
- Email: contact@dpa.gr
Find Your National DPA:
- EU: https://edpb.europa.eu/about-edpb/board/members_en
- UK: Information Commissioner's Office (ICO) - https://ico.org.uk
Important: We encourage you to contact us first (privacy@paywolt.com) so we can address your concerns before escalating to a supervisory authority.
13. Definitions
| Term | Definition |
|---|---|
| Cookie | A small text file placed on your device by a website, containing an identifier and optional data values |
| First-Party Cookie | Cookie set by the website you are visiting (paywolt.com) |
| Third-Party Cookie | Cookie set by a domain other than the website you are visiting (e.g., google-analytics.com) |
| Session Cookie | Temporary cookie deleted when you close your browser |
| Persistent Cookie | Cookie with an expiry date that remains after you close your browser |
| HTTP Cookie | Standard cookie stored in browser cookie jar, sent with every HTTP request |
| Local Storage | Browser storage API (HTML5) for storing larger amounts of data locally |
| Web Beacon / Pixel | Tiny transparent image (1x1 pixel) used to track page views or email opens |
| SDK | Software Development Kit - code embedded in mobile apps to provide functionality (e.g., analytics) |
| IDFA | Identifier for Advertisers (iOS) - unique identifier for advertising purposes |
| GAID | Google Advertising ID (Android) - unique identifier for advertising purposes |
| DNT | Do Not Track - browser setting requesting websites not to track user activity |
| DPA | Data Processing Agreement - contract between data controller and processor per GDPR Article 28 |
| SCC | Standard Contractual Clauses - EU-approved contract terms for international data transfers |
| Consent | Freely given, specific, informed, and unambiguous indication of wishes per GDPR Article 4(11) |
14. Cookie Declaration
14.1 Complete List of Cookies
Below is a comprehensive list of all cookies currently used by the PayWolt Platform, updated as of 2025-01-05.
Strictly Necessary Cookies (Always Active)
| Cookie Name | Provider | Purpose | Expiry | Category |
|---|---|---|---|---|
pwt_session | PayWolt | User authentication and session management | Session | Authentication |
pwt_csrf | PayWolt | CSRF attack prevention | Session | Security |
pwt_device_id | PayWolt | Device identification for security and fraud prevention | 1 year | Security |
pwt_consent | PayWolt | Cookie consent preferences record | 1 year | Consent Management |
pwt_locale | PayWolt | Language and region settings | 1 year | Localization |
pwt_2fa_verified | PayWolt | Two-factor authentication verification status | Session | Security |
__stripe_mid | Stripe (Integrated) | Stripe fraud prevention - merchant ID | 1 year | Fraud Prevention |
__stripe_sid | Stripe (Integrated) | Stripe fraud prevention - session ID | 30 minutes | Fraud Prevention |
__cflb | Cloudflare | Load balancing across Cloudflare's network | Session | Infrastructure |
__cf_bm | Cloudflare | Bot management and DDoS protection | 30 minutes | Security |
Functional Cookies (Consent Required)
| Cookie Name | Provider | Purpose | Expiry | Category |
|---|---|---|---|---|
pwt_prefs | PayWolt | User interface preferences (currency format, notifications) | 1 year | Personalization |
pwt_currency | PayWolt | Last selected source currency | 6 months | Convenience |
pwt_theme | PayWolt | Light/dark mode preference | 1 year | Personalization |
pwt_recent_corridors | PayWolt | Recently used transfer corridors for quick access | 6 months | Convenience |
intercom-id-{app_id} | Intercom | Support chat user identifier | 9 months | Customer Support |
intercom-session-{app_id} | Intercom | Active support chat session | 1 week | Customer Support |
intercom-device-id-{app_id} | Intercom | Device identifier for support chat | 9 months | Customer Support |
Analytics Cookies (Consent Required)
| Cookie Name | Provider | Purpose | Expiry | Category |
|---|---|---|---|---|
_ga | Google Analytics | Distinguish unique users via randomly generated ID | 2 years | Analytics |
_ga_{container_id} | Google Analytics 4 | Persist session state and user properties | 2 years | Analytics |
_gid | Google Analytics | Distinguish users (short-term tracking) | 24 hours | Analytics |
_gat_UA-{property_id} | Google Analytics | Throttle request rate to Google Analytics servers | 1 minute | Analytics (Rate Limiting) |
mp_{token}_mixpanel | Mixpanel | Product analytics and user behavior tracking | 1 year | Analytics |
mp_optout | Mixpanel | Record user opt-out status from Mixpanel tracking | 5 years | Analytics (Opt-Out) |
Marketing Cookies (Opt-In Required)
| Cookie Name | Provider | Purpose | Expiry | Category |
|---|---|---|---|---|
_fbp | Meta (Facebook) | Facebook Pixel - browser identification for ad targeting | 3 months | Advertising |
_fbc | Meta (Facebook) | Facebook Pixel - click ID for ad attribution | 3 months | Advertising |
_gcl_au | Google Ads | Google Ads conversion tracking | 3 months | Advertising |
_gcl_aw | Google Ads | Google Ads click information (AdWords) | 3 months | Advertising |
_gcl_dc | Google Ads | Google Display & Video 360 click information | 3 months | Advertising |
Total Cookie Count: 28 cookies (10 Strictly Necessary, 7 Functional, 6 Analytics, 5 Marketing)
Note: This list is updated regularly. If you notice a cookie not listed here, please contact privacy@paywolt.com.
14.2 Local Storage and Session Storage
In addition to cookies, the PayWolt Platform uses HTML5 Web Storage APIs:
| Storage Type | Key Prefix | Purpose | Persistence |
|---|---|---|---|
| Local Storage | pwt_* | Offline transfer drafts, cached exchange rates | Until manually cleared |
| Session Storage | pwt_session_* | Temporary wizard state (multi-step forms) | Until browser tab closed |
| IndexedDB | pwt_db | Offline mode support (cached data for app functionality) | Until manually cleared |
Legal Basis: Same as cookies (Strictly Necessary: legitimate interest; Functional: consent)
How to Clear: Browser settings > Clear browsing data > Select "Local storage" or "Cached images and files"
15. Document Information
| Field | Value |
|---|---|
| Policy Name | Cookie Policy |
| Version | 2.0 |
| Effective Date | 2025-01-05 |
| Last Updated | 2025-01-05 |
| Last Reviewed | 2025-01-05 |
| Next Review Date | 2025-07-05 (6 months) |
| Document Owner | Legal & Privacy Team |
| Approved By | Data Protection Officer (DPO) |
| Classification | Public |
| Related Documents | Privacy Policy<br>Terms of Service |
| Languages Available | English (primary)<br>Other languages available upon request |
This Cookie Policy is provided in English. The English version prevails in case of any discrepancy with translations.
Last Updated: 2025-01-05 Version: 2.0 © 2025 PayWolt Platform - All Rights Reserved