Back to Home
Legal

Cookie Policy

Last updated: 2025-01-05

Version: 2.0 (Enhanced Compliance and Transparency)

Cookie Policy

Last Updated: 2025-01-05 Effective Date: 2025-01-05 Version: 2.0 (Enhanced Compliance and Transparency)


1. Introduction

1.1 Purpose

This Cookie Policy ("Policy") explains how PayWolt Platform ("PayWolt", "we", "us", "our") and our service providers use cookies, web beacons, local storage, mobile identifiers, and similar tracking technologies (collectively, "Cookies") when you access or use:

  • PayWolt Website: https://paywolt.com and associated subdomains
  • PayWolt Mobile Applications: iOS and Android applications
  • PayWolt Platform APIs: When accessed via web browser

(Collectively, the "Platform" or "Services")

This Policy should be read in conjunction with our Privacy Policy and Terms of Service.

1.2 PayWolt's Service Model

Important Context:

PayWolt operates as a technology service provider (TSP) that orchestrates cross-border remittance transfers between licensed payment service providers (Wise, Flutterwave, Stripe). We do NOT operate as an electronic money institution (EMI) or payment institution (PI).

Cookie Usage Context:

  • Cookies Set by PayWolt: Used for Platform functionality, authentication, analytics, and security
  • Cookies Set by Payment Providers: When you interact with payment flows (Stripe, Wise, Flutterwave), these providers may set their own cookies on their respective domains according to their privacy policies
  • Cookies Set by Third-Party Services: Analytics, support, and security services we use may set cookies

Critical Principle: PayWolt is responsible for cookies set on the PayWolt Platform. Payment service providers and other third parties are independently responsible for cookies they set on their own domains or within their embedded services.


2. What Are Cookies and Similar Technologies?

2.1 Cookies Defined

Cookies are small text files (typically 4KB or less) placed on your device (computer, smartphone, tablet) by websites you visit. Cookies contain:

  • A unique identifier
  • The domain that set the cookie
  • Expiration date/time
  • Optional data values

Cookies enable websites to recognize your device, remember preferences, and provide personalized experiences.

2.2 Types of Storage Technologies We Use

TechnologyDescriptionWhere UsedPersistence
HTTP CookiesText files stored in browser cookie jarWebsiteSession or persistent (up to 2 years)
Local StorageBrowser storage API (HTML5) providing larger storage capacityWebsitePersistent until manually cleared
Session StorageBrowser storage API cleared when browser tab closesWebsiteSession only
IndexedDBBrowser database for structured dataWebsite (offline mode)Persistent until manually cleared
Web Beacons / PixelsTiny transparent images (1x1 pixel) embedded in pages or emailsWebsite, EmailN/A (server-side tracking)
Mobile SDKsSoftware development kits embedded in mobile apps that collect usage dataMobile AppsVaries by SDK
Device FingerprintingCollecting device characteristics to create unique identifierWebsite, Mobile AppsPer session

2.3 First-Party vs. Third-Party Cookies

TypeSet ByExamplePurpose
First-Party CookiesPayWolt (paywolt.com domain)Authentication, preferencesEssential Platform functionality
Third-Party CookiesExternal services (e.g., Google Analytics)Analytics, advertisingService enhancement, marketing

Important: Third-party cookies can track you across multiple websites, not just PayWolt. We limit third-party cookies and require your consent for non-essential third-party cookies.


3. Cookie Categories and Legal Basis

We categorize cookies based on their purpose and the legal basis for processing under GDPR and ePrivacy Directive.

3.1 Strictly Necessary Cookies

Purpose: Essential for the Platform to function. Without these cookies, core services cannot be provided.

Legal Basis: Legitimate interest (GDPR Article 6(1)(f)) - necessary for service delivery. No consent required.

Specific Uses:

Cookie NamePurposeDurationDomainSet By
pwt_sessionUser authentication; maintain logged-in stateSession (expires on browser close).paywolt.comPayWolt
pwt_csrfCross-Site Request Forgery (CSRF) protectionSession.paywolt.comPayWolt
pwt_device_idDevice identification for security and fraud detection1 year.paywolt.comPayWolt
pwt_consentRecord of cookie consent choices1 year.paywolt.comPayWolt
pwt_localeLanguage and regional settings (e.g., en-GB, fr-FR)1 year.paywolt.comPayWolt
pwt_2fa_verifiedTwo-factor authentication verification statusSession.paywolt.comPayWolt
__stripe_midStripe fraud prevention (merchant ID)1 year.paywolt.comStripe
__stripe_sidStripe fraud prevention (session ID)30 minutes.paywolt.comStripe

Data Processing:

  • Stored: Locally on your device
  • Transmitted: To PayWolt servers on each request (encrypted via HTTPS)
  • Shared with third parties: Only Stripe (for payment processing); no other third parties

Cannot Be Disabled: Disabling these cookies will prevent you from logging in, making transfers, or using core Platform features.

3.2 Functional Cookies

Purpose: Enhance Platform functionality and personalization. Not essential, but significantly improve user experience.

Legal Basis: Consent (GDPR Article 6(1)(a)) - you can opt out. Consent required.

Specific Uses:

Cookie NamePurposeDurationDomainSet By
pwt_prefsUser interface preferences (currency display format, notification settings)1 year.paywolt.comPayWolt
pwt_currencyLast selected source currency for quick access6 months.paywolt.comPayWolt
pwt_themeLight/dark mode preference1 year.paywolt.comPayWolt
pwt_recent_corridorsRecently used transfer corridors for quick access6 months.paywolt.comPayWolt
intercom-id-{app_id}Intercom support chat identifier9 months.paywolt.comIntercom
intercom-session-{app_id}Intercom active support session1 week.paywolt.comIntercom
intercom-device-id-{app_id}Intercom device identifier9 months.paywolt.comIntercom

Data Processing:

  • Stored: Locally on your device
  • Transmitted: To PayWolt servers and Intercom servers (for support chat)
  • Shared with third parties: Intercom (for customer support chat functionality)

Impact if Disabled:

  • Preferences will not be remembered between sessions
  • You will need to re-select currency, theme, and other settings each time
  • Support chat may not remember your conversation history

How to Disable: Use the Cookie Consent Manager (see Section 5) or browser settings (see Section 6).

3.3 Analytics and Performance Cookies

Purpose: Understand how visitors use the Platform, which features are most popular, and where improvements can be made. Helps us optimize Platform performance and user experience.

Legal Basis: Consent (GDPR Article 6(1)(a)) - you can opt out. Consent required.

Specific Uses:

Cookie NamePurposeDurationDomainSet By
_gaGoogle Analytics: Distinguish unique users2 years.paywolt.comGoogle Analytics
_ga_{container_id}Google Analytics 4: Persist session state and user properties2 years.paywolt.comGoogle Analytics
_gidGoogle Analytics: Distinguish users (short-term)24 hours.paywolt.comGoogle Analytics
_gat_UA-{property_id}Google Analytics: Throttle request rate to prevent server overload1 minute.paywolt.comGoogle Analytics
mp_{token}_mixpanelMixpanel: Product analytics and user behavior tracking1 year.paywolt.comMixpanel
mp_optoutMixpanel: Record opt-out status5 years.paywolt.comMixpanel

Data Collected via Analytics Cookies:

Data CategoryExamplesPurpose
Page ViewsURLs visited, page titles, referrer URLUnderstand content popularity
User InteractionsButton clicks, form submissions (not field values), scroll depthOptimize user flows
Session InformationSession duration, pages per session, bounce rateMeasure engagement
Device InformationBrowser type/version, OS, screen resolution, languageOptimize for devices
Geographic LocationCountry, region, city (derived from IP address)Understand user base geography
Traffic SourcesReferral source (e.g., Google search, social media, direct)Measure marketing effectiveness

Privacy Protections:

  • IP Anonymization: Google Analytics is configured with IP anonymization enabled (anonymizeIp: true). The last octet of your IP address is removed before storage (e.g., 192.168.1.123 → 192.168.1.0).
  • No Personally Identifiable Information (PII): We do not send user IDs, email addresses, names, or other PII to analytics services.
  • Data Retention Limits: Analytics data is automatically deleted after 26 months (Google Analytics setting).
  • Data Processing Agreements: We have signed Data Processing Agreements (DPAs) with Google and Mixpanel per GDPR Article 28.

Third-Party Privacy Policies:

Impact if Disabled:

  • No impact on Platform functionality
  • You will not be tracked for analytics purposes
  • We will have less insight into how to improve the Platform based on usage patterns

How to Disable:

3.4 Marketing and Advertising Cookies

Purpose: Deliver personalized advertising, measure ad campaign effectiveness, and retarget visitors who did not complete transfers.

Legal Basis: Consent (GDPR Article 6(1)(a)) - opt-in only. Explicit consent required.

Specific Uses:

Cookie NamePurposeDurationDomainSet By
_fbpMeta (Facebook) Pixel: Browser identification for ad targeting and conversion tracking3 months.paywolt.comMeta Platforms
_fbcMeta (Facebook) Pixel: Store Facebook click ID for ad attribution3 months.paywolt.comMeta Platforms
_gcl_auGoogle Ads: Store and track conversions from Google Ads campaigns3 months.paywolt.comGoogle Ads
_gcl_awGoogle Ads: Store click information from Google Ads3 months.paywolt.comGoogle Ads
_gcl_dcGoogle Ads: Store click information from Display & Video 360 ads3 months.paywolt.comGoogle Ads

Data Collected via Marketing Cookies:

  • Ad Interactions: Which ads you clicked before visiting PayWolt
  • Conversion Events: Whether you completed a transfer after seeing an ad
  • Retargeting Data: Pages visited, actions taken (used to show relevant ads on other websites)

Privacy Protections:

  • Opt-In Only: Marketing cookies are disabled by default. They are only activated if you explicitly consent via the Cookie Consent Manager.
  • No Sensitive Data: We do not share sensitive personal data (health, financial details, identity documents) with advertising platforms.
  • Standard Contractual Clauses (SCCs): Data transfers to Meta and Google (US-based) are covered by SCCs per GDPR Article 46.

Third-Party Privacy Policies:

Impact if Disabled:

  • No impact on Platform functionality
  • You will not see personalized PayWolt ads on other websites
  • You may still see generic (non-targeted) PayWolt ads

How to Disable:


4. Third-Party Services and Cookies

4.1 Third-Party Services We Use

PayWolt integrates with third-party services that may set cookies on our Platform. We have contractual agreements and Data Processing Agreements (DPAs) with all third parties per GDPR Article 28.

4.1.1 Analytics Services

ProviderPurposeCookies SetData Transferred ToPrivacy Policy
Google AnalyticsWebsite and app usage analytics_ga, _gid, _gatUnited States (Google LLC)Google Privacy Policy
MixpanelProduct analytics and user behavior trackingmp_*United States (Mixpanel Inc.)Mixpanel Privacy Policy
Firebase Analytics (Mobile apps)Mobile app usage analytics and crash reportingN/A (mobile SDK, not cookies)United States (Google LLC)Firebase Privacy Policy

Data Shared: Page views, events, anonymized IP addresses, device information. NOT shared: User names, email addresses, transfer amounts, identity documents.

4.1.2 Customer Support Services

ProviderPurposeCookies SetData Transferred ToPrivacy Policy
IntercomLive chat support, help center, customer messagingintercom-id-*, intercom-session-*United States (Intercom Inc.)Intercom Privacy Policy

Data Shared: Name, email address, support conversation history, page you're viewing when you contact support. NOT shared: Identity documents, full financial transaction details.

4.1.3 Security and Fraud Prevention Services

ProviderPurposeCookies SetData Transferred ToPrivacy Policy
StripePayment processing and fraud prevention__stripe_mid, __stripe_sidUnited States/Ireland (Stripe Inc./Stripe Payments Europe Ltd.)Stripe Privacy Policy
CloudflareDDoS protection, content delivery network (CDN), security__cflb, __cf_bmGlobal (Cloudflare Inc.)Cloudflare Privacy Policy

Data Shared: IP address, device fingerprint, request headers. NOT shared: Identity documents, sensitive personal data.

4.1.4 Identity Verification Services

ProviderPurposeCookies SetData Transferred ToPrivacy Policy
Sumsub (Integrated via iframe)KYC identity verificationSet on sumsub.com domain (not .paywolt.com)Cyprus (Sum & Substance Ltd.)Sumsub Privacy Policy

Important: When you complete identity verification, you are redirected to Sumsub's domain (sumsub.com). Sumsub is an independent data controller for identity verification data per our Privacy Policy. Sumsub sets cookies on their own domain according to their privacy policy, not this Cookie Policy.

4.2 Payment Service Provider Cookies

When you initiate a transfer, you interact with payment collection and payout providers. These providers may set cookies on their own domains (not .paywolt.com):

ProviderWhen You InteractCookies Set OnPrivacy Policy
StripeCard payment collectionstripe.com, js.stripe.comStripe Privacy Policy
FlutterwaveBank transfer / mobile money collection (Africa)flutterwave.comFlutterwave Privacy Policy
WisePayout execution (Europe/Global)wise.com, transferwise.comWise Privacy Policy

Important: PayWolt does NOT control cookies set by payment providers on their own domains. These providers are independent data controllers. Please review their respective privacy and cookie policies.

4.3 Embedded Third-Party Content

The Platform may embed third-party content that sets cookies:

Content TypeExamplesCookies May Be Set By
VideosYouTube embedded videos (help center, tutorials)YouTube (Google)
MapsGoogle Maps (office location)Google Maps
Social Media PluginsTwitter/X share buttons, LinkedIn share buttonsTwitter/X, LinkedIn

How to Control: You can block third-party cookies via browser settings (see Section 6) or disable marketing cookies via Cookie Consent Manager.


5. Cookie Consent Management

5.1 Consent Requirement (GDPR & ePrivacy Directive)

Under EU law (GDPR, ePrivacy Directive) and UK law (PECR), we must obtain your explicit consent before setting non-essential cookies (Functional, Analytics, Marketing).

Exceptions (No Consent Required):

  • Strictly Necessary cookies (essential for service delivery)
  • Cookies used solely for anonymous statistical purposes (we still request consent as best practice)

5.2 Cookie Consent Banner

First Visit:

When you first visit the PayWolt Platform, you will see a Cookie Consent Banner before any non-essential cookies are set.

Options Presented:

ButtonEffect
Accept AllConsent to all cookie categories (Necessary, Functional, Analytics, Marketing)
Reject AllOnly Strictly Necessary cookies enabled; all others disabled
CustomizeOpens detailed consent manager where you can select specific cookie categories

Granular Consent:

The "Customize" option allows you to:

  • Enable/disable each cookie category individually (Functional, Analytics, Marketing)
  • View detailed list of cookies in each category
  • Read about specific third-party services

Default State:

  • Strictly Necessary: Always enabled (cannot be disabled)
  • Functional, Analytics, Marketing: Disabled by default; require opt-in

5.3 Consent Records (GDPR Article 7)

We maintain detailed records of your consent to comply with GDPR Article 7 (Conditions for consent):

Recorded Information:

  • User Identifier: Anonymous device ID or user ID (if logged in)
  • Consent Timestamp: Date and time of consent (ISO 8601 format, UTC)
  • Consent Choices: Which categories you consented to (e.g., {functional: true, analytics: false, marketing: false})
  • Cookie Policy Version: Version of this Policy presented at time of consent
  • Consent Method: How consent was given (e.g., "banner_accept_all", "banner_customize", "settings_page")
  • User Agent: Browser and device information (for verification purposes)

Retention Period: Consent records are retained for 3 years from the date of consent or withdrawal, whichever is later, to demonstrate compliance with GDPR.

Access to Consent Records: You may request a copy of your consent records by contacting privacy@paywolt.com.

5.4 Withdrawing Consent

You may withdraw your consent at any time. Withdrawal is as easy as giving consent.

How to Withdraw Consent:

  1. Cookie Settings Page:

    • Website: Click "Cookie Settings" link in footer
    • Mobile App: Settings > Privacy > Cookie Preferences
  2. Change Preferences:

    • Toggle off cookie categories you no longer wish to allow
    • Click "Save Preferences"
  3. Effect of Withdrawal:

    • Non-essential cookies will stop being set
    • Existing cookies will be deleted (where technically feasible)
    • No retroactive effect (data already collected remains unless you request deletion per GDPR Article 17)

No Negative Consequences:

Withdrawing consent will NOT:

  • Affect your ability to use core Platform features
  • Result in account suspension or termination
  • Affect the lawfulness of processing based on consent before withdrawal (GDPR Recital 65)

Requesting Data Deletion:

If you wish to delete data collected via cookies before withdrawal, exercise your Right to Erasure per our Privacy Policy Section 9 (Your Rights Under GDPR).

5.5 Consent for Minors

Age Restriction:

The PayWolt Platform is not intended for children under 18 years of age. We do not knowingly collect personal data from minors.

If You Are Under 18:

  • Do not use the PayWolt Platform
  • Do not provide any personal information
  • If we discover we have collected data from a minor, we will delete it promptly

Parental Notice:

If you believe your child has provided personal information to PayWolt, contact us immediately at privacy@paywolt.com.


6. Managing and Controlling Cookies

6.1 Browser Cookie Settings

All modern browsers allow you to control cookies. You can:

  • Block all cookies (may break website functionality)
  • Block third-party cookies only (recommended for privacy)
  • Delete cookies (clears existing cookies)
  • View cookies (inspect cookies stored by websites)

Browser-Specific Instructions:

Google Chrome

  1. Settings > Privacy and security > Cookies and other site data
  2. Choose:
    • Block all cookies (not recommended)
    • Block third-party cookies (recommended)
    • Allow all cookies
  3. To delete cookies: Delete browsing data > Select "Cookies and other site data" > Clear data

Mozilla Firefox

  1. Settings > Privacy & Security > Cookies and Site Data
  2. Choose:
    • Standard (blocks known trackers)
    • Strict (blocks all third-party cookies)
    • Custom (configure manually)
  3. To delete cookies: Clear Data > Select "Cookies and Site Data" > Clear

Apple Safari (macOS)

  1. Preferences > Privacy
  2. Enable Prevent cross-site tracking (blocks third-party cookies)
  3. Enable Block all cookies (may break websites)
  4. To delete cookies: Safari > Clear History > Select time range > Clear History

Apple Safari (iOS)

  1. Settings > Safari > Privacy & Security
  2. Enable Prevent Cross-Site Tracking
  3. Enable Block All Cookies (may break apps)
  4. To delete cookies: Settings > Safari > Clear History and Website Data

Microsoft Edge

  1. Settings > Cookies and site permissions > Manage and delete cookies
  2. Choose:
    • Block all cookies
    • Block third-party cookies
    • Allow all cookies
  3. To delete cookies: Settings > Privacy > Clear browsing data > Select "Cookies and other site data"

Important: Blocking or deleting cookies may prevent you from using certain Platform features.

6.2 Third-Party Opt-Out Tools

You can opt out of specific third-party tracking services:

ServiceOpt-Out ToolEffect
Google AnalyticsBrowser Add-onPrevents Google Analytics from tracking you on all websites
Google AdsAd SettingsOpt out of personalized ads from Google
Facebook AdsAd PreferencesOpt out of personalized ads from Facebook/Meta
Network Advertising Initiative (NAI)NAI Opt-OutOpt out of multiple ad networks at once
Digital Advertising Alliance (DAA)DAA Opt-OutOpt out of interest-based advertising (US)
European Interactive Digital Advertising Alliance (EDAA)YourOnlineChoicesOpt out of interest-based advertising (EU)

Note: Opting out does NOT mean you will not see ads. You will still see generic (non-personalized) ads.

6.3 Do Not Track (DNT) Signals

What is DNT?

Do Not Track (DNT) is a browser setting that sends a signal to websites requesting not to be tracked.

PayWolt's DNT Policy:

We respect the DNT signal. When DNT is enabled in your browser:

  • Analytics cookies will not be set
  • Marketing cookies will not be set
  • Functional cookies will not be set (unless you explicitly consent via Cookie Consent Manager)
  • Strictly Necessary cookies will still be set (required for service functionality)

How to Enable DNT:

BrowserInstructions
ChromeNot supported (removed in Chrome 78); use Settings > Privacy and security > Cookies instead
FirefoxSettings > Privacy & Security > Enable Tell websites not to sell or share my data
SafariPreferences > Privacy > Enable Prevent cross-site tracking
EdgeSettings > Privacy > Enable Send "Do Not Track" requests

Industry Support:

DNT is not universally respected by all websites. PayWolt voluntarily respects DNT as part of our commitment to user privacy.

6.4 Mobile Device Settings

iOS (iPhone/iPad):

  1. Limit Ad Tracking:
    • Settings > Privacy > Tracking > Disable Allow Apps to Request to Track
  2. Disable Analytics:
    • Settings > Privacy > Analytics & Improvements > Disable Share iPhone Analytics
  3. Reset Advertising Identifier:
    • Settings > Privacy > Apple Advertising > Reset Advertising Identifier

Android:

  1. Opt Out of Ad Personalization:
    • Settings > Privacy > Ads > Enable Opt out of Ads Personalization
  2. Disable Usage & Diagnostics:
    • Settings > Privacy > Usage & diagnostics > Disable
  3. Reset Advertising ID:
    • Settings > Privacy > Ads > Reset advertising ID

Effect on PayWolt Mobile App:

  • Marketing tracking (IDFA/GAID) will be disabled
  • Analytics may be limited (basic crash reporting remains for app stability)
  • Core app functionality unchanged

6.5 Impact of Blocking Cookies

By Cookie Category:

CategoryIf BlockedImpact on PayWolt Platform
Strictly Necessary❌ Cannot be blocked (required)Platform will not function; you cannot log in or make transfers
Functional✅ Can be blockedPreferences not saved; settings reset each session; support chat may not work
Analytics✅ Can be blockedNo impact on functionality; we cannot improve Platform based on usage data
Marketing✅ Can be blockedNo impact on functionality; you will not see personalized ads

Recommendation:

  • Allow Strictly Necessary: Required for Platform to work
  • Allow Functional: Significantly improves user experience
  • Allow Analytics: Helps us improve Platform; data is anonymized
  • Block Marketing: If you prefer not to see personalized ads (optional)

7. Mobile Application Tracking

7.1 Mobile Device Identifiers

Our mobile applications (iOS, Android) use device identifiers for analytics, fraud prevention, and push notifications.

IdentifierPlatformPurposeCan Be Reset?
IDFA (Identifier for Advertisers)iOSAdvertising attribution and analytics (with user consent per iOS 14.5+)✅ Yes (Settings > Privacy > Apple Advertising > Reset Advertising Identifier)
IDFV (Identifier for Vendor)iOSAnalytics and fraud prevention (does not require consent)❌ No (resets when app is uninstalled)
GAID (Google Advertising ID)AndroidAdvertising attribution and analytics (with user consent)✅ Yes (Settings > Privacy > Ads > Reset advertising ID)
Android IDAndroidDevice identification for analytics and fraud prevention❌ No (resets on factory reset)
Device UUIDBothUnique device identifier generated by PayWolt app for security❌ No (resets when app is uninstalled)
Push TokenBothPush notification delivery❌ No (resets when permissions changed)

Consent for Advertising Identifiers (IDFA/GAID):

Per iOS App Tracking Transparency (ATT) and Google Play policies:

  • We request explicit permission before accessing IDFA (iOS) or GAID (Android) for advertising purposes
  • You can deny permission; this does not affect core app functionality
  • Advertising identifiers are used solely for ad attribution (measuring ad campaign effectiveness)

7.2 Mobile Analytics SDKs

Our mobile apps integrate analytics and crash reporting SDKs:

SDKProviderPurposeData CollectedPrivacy Policy
Firebase AnalyticsGoogle LLCUsage analytics, user engagement, conversion trackingApp opens, screen views, events, device info, anonymized IPFirebase Privacy
Firebase CrashlyticsGoogle LLCCrash reporting to improve app stabilityCrash logs, stack traces, device state at time of crashFirebase Privacy
MixpanelMixpanel Inc.Product analytics, user journey trackingUser interactions, events, session durationMixpanel Privacy

Data Collected by SDKs:

Data TypeExamplesPurpose
App UsageScreens viewed, buttons tapped, features usedUnderstand how users interact with app
Session DataSession start/end time, session durationMeasure engagement
Device InformationDevice model, OS version, screen size, languageOptimize app for devices
CrashesStack traces, error messages, device stateFix bugs and improve stability
PerformanceApp launch time, network latency, battery usageOptimize performance

Data NOT Collected:

  • Identity documents or selfies
  • Full transfer amounts or transaction details
  • User passwords or authentication tokens
  • Contacts or photos from device

Data Retention:

  • Firebase Analytics: 2 months (configurable; set to 2 months for privacy)
  • Crashlytics: 90 days (crash reports deleted after 90 days)
  • Mixpanel: 5 years (configurable; you can request deletion via GDPR rights)

7.3 Managing Mobile App Tracking

iOS:

  1. App Tracking Transparency (ATT) Prompt:

    • When you first open the PayWolt app, you will see a system prompt: "Allow PayWolt to track your activity across other companies' apps and websites?"
    • Allow: Enables IDFA for advertising attribution
    • Ask App Not to Track: Blocks IDFA; no advertising tracking
  2. Change Tracking Permission Later:

    • Settings > Privacy & Security > Tracking > PayWolt > Toggle on/off
  3. Reset Advertising Identifier:

    • Settings > Privacy > Apple Advertising > Reset Advertising Identifier
    • This assigns a new IDFA, breaking the link to previous tracking

Android:

  1. Opt Out of Ad Personalization:

    • Settings > Privacy > Ads > Enable "Opt out of Ads Personalization"
    • This prevents apps from using GAID for personalized advertising
  2. Reset Advertising ID:

    • Settings > Privacy > Ads > Reset advertising ID
    • This assigns a new GAID

Effect of Disabling Mobile Tracking:

  • Advertising attribution will not work (we cannot measure which ads led to app installs)
  • Analytics may be limited (basic usage analytics still collected for app improvement)
  • No impact on core app functionality (transfers, account management work normally)

8. Data Retention and Deletion

8.1 Cookie Data Retention Periods

Cookie CategoryTypical Cookie ExpiryData Retention by PayWolt/Third Parties
Session CookiesDeleted when browser closesNot retained (ephemeral)
Strictly Necessary (persistent)Up to 1 yearRetained for duration of cookie expiry or account closure
FunctionalUp to 1 yearRetained for duration of cookie expiry or until you change preferences
AnalyticsUp to 2 years (cookie expiry)Google Analytics: 26 months (auto-deletion)<br>Mixpanel: 5 years (or until deletion request)
MarketingUp to 3 months (cookie expiry)Meta: 90 days<br>Google Ads: 90 days

Legal Basis for Retention:

  • Strictly Necessary: Legitimate interest in service delivery (GDPR Article 6(1)(f))
  • Functional, Analytics, Marketing: Consent (retained until consent withdrawn) (GDPR Article 6(1)(a))

8.2 Automatic Deletion of Cookie Data

Browser-Level Deletion:

Cookies are automatically deleted when:

  • Cookie expiry date/time is reached (browser deletes expired cookies)
  • You clear browser data (cookies manually deleted)
  • You uninstall the PayWolt mobile app (app data deleted)

Server-Level Deletion:

Data collected via cookies is automatically deleted per retention policies above. For example:

  • Google Analytics data is auto-deleted after 26 months
  • Meta advertising data is deleted after 90 days

8.3 Manual Deletion of Cookie Data

Delete Cookies from Browser:

See Section 6.1 (Browser Cookie Settings) for instructions on deleting cookies.

Delete Data from Third-Party Services:

You can request deletion of your data from third-party services directly:

ServiceDeletion Request Method
GoogleGoogle Account - Delete Data
MixpanelMixpanel GDPR Request or email privacy@paywolt.com (we will forward request)
Meta (Facebook)Facebook Privacy Settings - Contact Meta directly

Delete All PayWolt Data (Right to Erasure):

To delete all your personal data held by PayWolt (including data collected via cookies), exercise your Right to Erasure per GDPR Article 17:

  1. Email privacy@paywolt.com with subject "GDPR Right to Erasure Request"
  2. Provide your account email and user ID
  3. We will process your request within 30 days (GDPR requirement)

Exceptions to Erasure:

We may retain certain data if required by law (e.g., AML/CTF compliance requires 5-year retention of transaction records). See Privacy Policy Section 9.3 for full details on Right to Erasure limitations.


9. International Data Transfers

9.1 Transfers Outside the EEA

Cookie data may be transferred to and processed in countries outside the European Economic Area (EEA), including:

Third PartyCountryData TransferredLegal Safeguard
Google (Analytics, Ads, Firebase)United StatesAnalytics data, advertising dataStandard Contractual Clauses (SCCs) per GDPR Article 46(2)(c)<br>Google SCCs
MixpanelUnited StatesProduct analytics dataStandard Contractual Clauses (SCCs) per GDPR Article 46(2)(c)<br>Mixpanel DPA
Meta (Facebook Pixel)United StatesAdvertising dataStandard Contractual Clauses (SCCs) per GDPR Article 46(2)(c)<br>Meta DPA
IntercomUnited StatesSupport chat dataStandard Contractual Clauses (SCCs) per GDPR Article 46(2)(c)<br>Intercom DPA
CloudflareUnited States (global CDN)Security data (IP addresses, request headers)Standard Contractual Clauses (SCCs)<br>Cloudflare DPA

9.2 Adequacy Decisions

Some countries have been deemed to provide adequate data protection by the European Commission (GDPR Article 45):

CountryAdequacy DecisionApplies To
United Kingdom✅ Yes (June 2021)N/A (PayWolt uses UK providers only when necessary)
Switzerland✅ Yes (Sep 2000)N/A

United States:No adequacy decision (Privacy Shield invalidated by CJEU in Schrems II case, July 2020). Transfers to US rely on Standard Contractual Clauses (SCCs) and supplementary measures.

9.3 Standard Contractual Clauses (SCCs)

What are SCCs?

Standard Contractual Clauses are pre-approved contract terms by the European Commission that ensure adequate data protection when transferring personal data outside the EEA.

PayWolt's Use of SCCs:

We have signed Data Processing Agreements (DPAs) incorporating EU SCCs with all third-party service providers that process personal data outside the EEA:

Supplementary Measures:

In addition to SCCs, we implement supplementary measures per EDPB Recommendations 01/2020:

  • Data minimization: Only necessary data is transferred
  • Pseudonymization: Where possible (e.g., Google Analytics anonymizes IP addresses)
  • Encryption in transit: All data transfers use TLS 1.2+ encryption
  • Encryption at rest: Third-party providers encrypt data at rest

9.4 Your Rights Regarding International Transfers

Right to Object (GDPR Article 21):

You have the right to object to international data transfers. If you object:

  • We will stop transferring your data to third parties outside the EEA
  • This may limit Platform functionality (e.g., analytics, support chat may not work)

How to Object:

Email privacy@paywolt.com with subject "Objection to International Data Transfers".


10. Legal Framework and Compliance

10.1 Applicable Laws and Regulations

This Cookie Policy complies with:

Law/RegulationJurisdictionKey Requirements
GDPR (General Data Protection Regulation) - Regulation (EU) 2016/679European Union (EU) + European Economic Area (EEA)Consent for non-essential cookies (Article 6(1)(a))<br>Transparency (Articles 12-14)<br>Data subject rights (Articles 15-22)
ePrivacy Directive (Directive 2002/58/EC)European Union (EU)Prior consent for storing/accessing information on user devices (Article 5(3))
UK PECR (Privacy and Electronic Communications Regulations 2003)United KingdomCookie consent requirements (Regulation 6)
CCPA (California Consumer Privacy Act)California, USARight to opt-out of "sale" of personal information<br>Right to know what data is collected
LGPD (Lei Geral de Proteção de Dados)BrazilConsent requirements similar to GDPR
POPIA (Protection of Personal Information Act)South AfricaConsent for processing personal information

PayWolt's Commitment:

We design our Cookie Policy to comply with the strictest applicable standard (GDPR + ePrivacy Directive) globally, ensuring all users benefit from strong privacy protections regardless of jurisdiction.

10.2 GDPR Compliance

Legal Bases for Cookie Processing (GDPR Article 6):

Cookie CategoryLegal BasisGDPR Article
Strictly NecessaryLegitimate interests (necessary for service delivery)Article 6(1)(f)
FunctionalConsentArticle 6(1)(a)
AnalyticsConsentArticle 6(1)(a)
MarketingConsentArticle 6(1)(a)

Consent Requirements (GDPR Article 7 & GDPR Recital 32):

Our consent mechanism meets GDPR standards:

  • Freely given: You can refuse consent without negative consequences
  • Specific: Consent is granular (separate for Functional, Analytics, Marketing)
  • Informed: Cookie Consent Banner clearly explains what you're consenting to
  • Unambiguous: Requires affirmative action (clicking "Accept" or toggling categories)
  • Withdrawable: You can withdraw consent as easily as you gave it (Cookie Settings page)

Transparency Requirements (GDPR Articles 12-14):

This Cookie Policy provides:

  • ✅ Identity of data controller (PayWolt Platform)
  • ✅ Purposes of processing (functionality, analytics, marketing)
  • ✅ Legal bases (consent, legitimate interests)
  • ✅ Categories of data collected (device info, usage data, etc.)
  • ✅ Recipients of data (third-party services listed)
  • ✅ International transfers (countries and safeguards listed)
  • ✅ Retention periods (cookie expiry and data retention listed)
  • ✅ Data subject rights (GDPR Articles 15-22 - see Section 10.3)

10.3 Your Rights Under GDPR

You have the following rights regarding data collected via cookies:

RightGDPR ArticleDescriptionHow to Exercise
Right of AccessArticle 15Request a copy of your personal dataEmail privacy@paywolt.com with subject "GDPR Access Request"
Right to RectificationArticle 16Correct inaccurate dataEmail privacy@paywolt.com or update via Account Settings
Right to ErasureArticle 17Delete your data (subject to legal retention obligations)Email privacy@paywolt.com with subject "GDPR Erasure Request"
Right to Restrict ProcessingArticle 18Limit how we use your dataEmail privacy@paywolt.com with subject "GDPR Restriction Request"
Right to Data PortabilityArticle 20Receive your data in machine-readable formatEmail privacy@paywolt.com with subject "GDPR Data Portability Request"
Right to ObjectArticle 21Object to processing based on legitimate interestsEmail privacy@paywolt.com with subject "GDPR Objection"
Right to Withdraw ConsentArticle 7(3)Withdraw consent for cookiesUse Cookie Settings page (see Section 5.4)
Right to Lodge a ComplaintArticle 77Complain to supervisory authorityContact your national Data Protection Authority (DPA)

Response Time: We will respond to all GDPR requests within 30 days (GDPR Article 12(3)). Complex requests may be extended by an additional 60 days with notification.

No Fee: Exercising your GDPR rights is free of charge unless requests are manifestly unfounded or excessive (GDPR Article 12(5)).

Identity Verification: To protect your privacy, we may request additional information to verify your identity before processing GDPR requests.

10.4 CCPA Compliance (California Users)

California Residents' Rights:

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

RightDescriptionHow to Exercise
Right to KnowKnow what personal information is collected, used, shared, or soldEmail privacy@paywolt.com with subject "CCPA Right to Know"
Right to DeleteRequest deletion of personal information (subject to exceptions)Email privacy@paywolt.com with subject "CCPA Deletion Request"
Right to Opt-Out of SaleOpt-out of "sale" of personal informationWe do NOT sell personal information<br>Marketing cookies can be disabled via Cookie Settings
Right to Non-DiscriminationNot be discriminated against for exercising CCPA rightsWe do not discriminate; core Platform functionality remains available

"Sale" of Personal Information:

Under CCPA, sharing data with third parties for advertising may be considered a "sale." PayWolt's Position:

  • We do NOT sell personal information for monetary consideration
  • Marketing cookies (Meta, Google Ads) may be considered "sharing" for advertising under CCPA
  • You can opt-out via Cookie Settings (disable Marketing cookies)

Do Not Sell My Personal Information:

California residents can opt-out by:

  1. Disabling Marketing cookies via Cookie Settings
  2. Enabling browser Do Not Track (DNT) signal
  3. Emailing privacy@paywolt.com with subject "CCPA Do Not Sell Request"

11. Updates to This Cookie Policy

11.1 Policy Changes

We may update this Cookie Policy periodically to reflect:

  • Changes to cookies we use
  • Changes to third-party services
  • Changes to applicable laws or regulations
  • Improvements to our cookie consent mechanisms
  • User feedback and best practices

11.2 Notification of Changes

Material Changes:

If we make material changes that significantly affect your rights or how cookies are used, we will:

  • Update the "Last Updated" date at the top of this Policy
  • Display a prominent notice on the Platform (banner or notification)
  • Re-request consent via Cookie Consent Banner (if changes affect non-essential cookies)
  • Send email notification to registered users (for significant changes)

Material Changes Definition:

Changes considered "material" include:

  • Adding new cookie categories (e.g., introducing Advertising cookies)
  • Adding new third-party services that process significant personal data
  • Changes to data retention periods (significant increases)
  • Changes to international transfer destinations or safeguards

Minor Changes:

Non-material changes (e.g., clarifications, formatting, minor updates) will be posted immediately without re-consent.

11.3 Review Frequency

We review this Cookie Policy every 6 months or when:

  • New cookies or third-party services are added
  • Applicable laws change
  • Regulatory guidance is updated

Recommended Action:

We recommend reviewing this Policy periodically, especially when you see the "Last Updated" date has changed.

11.4 Version History

VersionDateSummary of Changes
2.02025-01-05Enhanced compliance and transparency; added comprehensive cookie declarations; clarified PayWolt's role as TSP; enhanced GDPR/CCPA compliance sections; improved third-party service documentation
1.02025-12-28Initial version

Accessing Previous Versions:

Previous versions of this Cookie Policy are available upon request. Email legal@paywolt.com.


12. Contact Information

12.1 Privacy and Cookie Questions

For questions about our use of cookies or this Cookie Policy:

Contact TypeEmailResponse Time
General Cookie Questionsprivacy@paywolt.com48 hours (business days)
Data Protection Officer (DPO)dpo@paywolt.com48 hours (business days)
GDPR/CCPA Requestsprivacy@paywolt.com30 days (legally required)

12.2 Cookie Settings

Manage Your Cookie Preferences:

PlatformHow to Access Cookie Settings
WebsiteFooter link: "Cookie Settings" or "Manage Cookies"
Mobile AppSettings > Privacy > Cookie Preferences

12.3 Supervisory Authority (GDPR)

If you are located in the EEA/UK and have concerns about our cookie practices, you have the right to lodge a complaint with your national Data Protection Authority (DPA):

Greece (PayWolt's Lead Supervisory Authority):

Find Your National DPA:

Important: We encourage you to contact us first (privacy@paywolt.com) so we can address your concerns before escalating to a supervisory authority.


13. Definitions

TermDefinition
CookieA small text file placed on your device by a website, containing an identifier and optional data values
First-Party CookieCookie set by the website you are visiting (paywolt.com)
Third-Party CookieCookie set by a domain other than the website you are visiting (e.g., google-analytics.com)
Session CookieTemporary cookie deleted when you close your browser
Persistent CookieCookie with an expiry date that remains after you close your browser
HTTP CookieStandard cookie stored in browser cookie jar, sent with every HTTP request
Local StorageBrowser storage API (HTML5) for storing larger amounts of data locally
Web Beacon / PixelTiny transparent image (1x1 pixel) used to track page views or email opens
SDKSoftware Development Kit - code embedded in mobile apps to provide functionality (e.g., analytics)
IDFAIdentifier for Advertisers (iOS) - unique identifier for advertising purposes
GAIDGoogle Advertising ID (Android) - unique identifier for advertising purposes
DNTDo Not Track - browser setting requesting websites not to track user activity
DPAData Processing Agreement - contract between data controller and processor per GDPR Article 28
SCCStandard Contractual Clauses - EU-approved contract terms for international data transfers
ConsentFreely given, specific, informed, and unambiguous indication of wishes per GDPR Article 4(11)

14. Cookie Declaration

14.1 Complete List of Cookies

Below is a comprehensive list of all cookies currently used by the PayWolt Platform, updated as of 2025-01-05.

Strictly Necessary Cookies (Always Active)

Cookie NameProviderPurposeExpiryCategory
pwt_sessionPayWoltUser authentication and session managementSessionAuthentication
pwt_csrfPayWoltCSRF attack preventionSessionSecurity
pwt_device_idPayWoltDevice identification for security and fraud prevention1 yearSecurity
pwt_consentPayWoltCookie consent preferences record1 yearConsent Management
pwt_localePayWoltLanguage and region settings1 yearLocalization
pwt_2fa_verifiedPayWoltTwo-factor authentication verification statusSessionSecurity
__stripe_midStripe (Integrated)Stripe fraud prevention - merchant ID1 yearFraud Prevention
__stripe_sidStripe (Integrated)Stripe fraud prevention - session ID30 minutesFraud Prevention
__cflbCloudflareLoad balancing across Cloudflare's networkSessionInfrastructure
__cf_bmCloudflareBot management and DDoS protection30 minutesSecurity

Functional Cookies (Consent Required)

Cookie NameProviderPurposeExpiryCategory
pwt_prefsPayWoltUser interface preferences (currency format, notifications)1 yearPersonalization
pwt_currencyPayWoltLast selected source currency6 monthsConvenience
pwt_themePayWoltLight/dark mode preference1 yearPersonalization
pwt_recent_corridorsPayWoltRecently used transfer corridors for quick access6 monthsConvenience
intercom-id-{app_id}IntercomSupport chat user identifier9 monthsCustomer Support
intercom-session-{app_id}IntercomActive support chat session1 weekCustomer Support
intercom-device-id-{app_id}IntercomDevice identifier for support chat9 monthsCustomer Support

Analytics Cookies (Consent Required)

Cookie NameProviderPurposeExpiryCategory
_gaGoogle AnalyticsDistinguish unique users via randomly generated ID2 yearsAnalytics
_ga_{container_id}Google Analytics 4Persist session state and user properties2 yearsAnalytics
_gidGoogle AnalyticsDistinguish users (short-term tracking)24 hoursAnalytics
_gat_UA-{property_id}Google AnalyticsThrottle request rate to Google Analytics servers1 minuteAnalytics (Rate Limiting)
mp_{token}_mixpanelMixpanelProduct analytics and user behavior tracking1 yearAnalytics
mp_optoutMixpanelRecord user opt-out status from Mixpanel tracking5 yearsAnalytics (Opt-Out)

Marketing Cookies (Opt-In Required)

Cookie NameProviderPurposeExpiryCategory
_fbpMeta (Facebook)Facebook Pixel - browser identification for ad targeting3 monthsAdvertising
_fbcMeta (Facebook)Facebook Pixel - click ID for ad attribution3 monthsAdvertising
_gcl_auGoogle AdsGoogle Ads conversion tracking3 monthsAdvertising
_gcl_awGoogle AdsGoogle Ads click information (AdWords)3 monthsAdvertising
_gcl_dcGoogle AdsGoogle Display & Video 360 click information3 monthsAdvertising

Total Cookie Count: 28 cookies (10 Strictly Necessary, 7 Functional, 6 Analytics, 5 Marketing)

Note: This list is updated regularly. If you notice a cookie not listed here, please contact privacy@paywolt.com.

14.2 Local Storage and Session Storage

In addition to cookies, the PayWolt Platform uses HTML5 Web Storage APIs:

Storage TypeKey PrefixPurposePersistence
Local Storagepwt_*Offline transfer drafts, cached exchange ratesUntil manually cleared
Session Storagepwt_session_*Temporary wizard state (multi-step forms)Until browser tab closed
IndexedDBpwt_dbOffline mode support (cached data for app functionality)Until manually cleared

Legal Basis: Same as cookies (Strictly Necessary: legitimate interest; Functional: consent)

How to Clear: Browser settings > Clear browsing data > Select "Local storage" or "Cached images and files"


15. Document Information

FieldValue
Policy NameCookie Policy
Version2.0
Effective Date2025-01-05
Last Updated2025-01-05
Last Reviewed2025-01-05
Next Review Date2025-07-05 (6 months)
Document OwnerLegal & Privacy Team
Approved ByData Protection Officer (DPO)
ClassificationPublic
Related DocumentsPrivacy Policy<br>Terms of Service
Languages AvailableEnglish (primary)<br>Other languages available upon request

This Cookie Policy is provided in English. The English version prevails in case of any discrepancy with translations.

Last Updated: 2025-01-05 Version: 2.0 © 2025 PayWolt Platform - All Rights Reserved