Skip to content
POSX
IndividualsBusinessNetworkDevelopersCompany
Contact
Legal Center

POSX Legal · United States

Cookie and Tracking Policy

Cookies, SDKs, device identifiers and similar technologies used in the POSX app and on POSX websites — what they do, and how to control them.

Effective
October 1, 2026
Published
August 25, 2026
Version
1.0
Issued by
POSX US Inc.

On this page

  1. 1. Why this policy exists
  2. 2. What we use, and what it does
  3. 2.1 Categories
  4. 2.2 In the app specifically
  5. 3. How we ask for consent, and how you change your mind
  6. 4. How long these technologies last
  7. 5. Third parties
  8. 6. Changes
  9. 7. Contact
  10. Appendix A — Inventory of cookies, SDKs and identifiers
  11. A.1 Website
  12. A.2 Mobile app SDKs and identifiers
On this page

On this page

  1. 1. Why this policy exists
  2. 2. What we use, and what it does
  3. 2.1 Categories
  4. 2.2 In the app specifically
  5. 3. How we ask for consent, and how you change your mind
  6. 4. How long these technologies last
  7. 5. Third parties
  8. 6. Changes
  9. 7. Contact
  10. Appendix A — Inventory of cookies, SDKs and identifiers
  11. A.1 Website
  12. A.2 Mobile app SDKs and identifiers
Applies to

Users in the United States and in every market where POSX US Inc. is named as the app publisher

Governing law

Laws of the State of Delaware

Legal note

About this document

This document is part of the POSX legal pack published at https://posx.io/legal. It is written to be read by the people it applies to, not only by lawyers: where a term has a particular meaning, it is defined the first time it appears, and the sections that matter most to you are flagged as such. If anything here is unclear, write to legal@posx.io and we will explain it. Every previous version stays published, so you can always see what changed and when.

1. Why this policy exists

1.1 This policy explains the technologies POSX uses to store information on, or read information from, your device — on our websites and inside the POSX mobile application — and how you control them. It sits alongside the Privacy Policy, which explains what we do with the personal information those technologies produce.

1.2 The law in this area is not limited to browser cookies. Consent rules under the ePrivacy Directive as interpreted by the European Data Protection Board in 2024 apply to any storing of information on, or gaining of access to information already stored on, your device. That includes mobile SDKs, local storage, device and advertising identifiers, pixels, tracking URLs and device fingerprinting. This policy therefore covers all of them, not only cookies.

2. What we use, and what it does

2.1 Categories

Reference table 1 in Cookie and Tracking Policy
CategoryWhat it doesDo we need your consent?
Strictly necessaryKeeps you signed in, remembers your session, routes traffic, balances load, protects against fraud and abuse, remembers your cookie choices, and makes the app function. The Service cannot work without these.No — they are exempt, because they are strictly necessary to provide the service you asked for. You cannot turn them off.
FunctionalRemembers preferences such as language, region, display settings and whether you have seen a particular prompt.Yes where required in your region. Turning them off means you re-set preferences each time.
Analytics and performanceCounts users, measures which screens and features are used, times how long things take, and reports crashes and errors so we can fix them.Yes where required in your region. We aggregate and do not use analytics to build advertising profiles.
Marketing, attribution and advertisingNot currently used. If POSX ever runs advertising or install attribution, this category would measure whether a campaign led to an install or a sign-up.Yes, always, where required — and on iOS also subject to Apple's App Tracking Transparency permission, which POSX does not currently request.

2.1.1 We do not use advertising or profiling technologies to build a picture of you across other companies' apps and websites.

2.2 In the app specifically

Mobile apps do not use browser cookies. Inside POSX the equivalent technologies are:

— Local storage on your device — the session token that keeps you signed in, cached content so the app opens quickly offline, and your preferences.

— Vendor identifier (iOS) / app-set ID (Android) — a per-installation identifier that lets us recognise the same installation between sessions. It resets when you delete the app.

— Advertising identifier (IDFA on iOS, Advertising ID on Android) — not used. POSX does not read the advertising identifier and does not show Apple's App Tracking Transparency prompt. If that ever changes we will ask for your permission first.

— Push notification token — issued by Apple or Google so we can deliver notifications you have allowed.

— Software development kits (SDKs) embedded in the app for crash reporting, analytics, identity verification and security. Each one is listed in Appendix A.

— Device and integrity signals used to detect emulators, rooted or jailbroken devices, automated access and account takeover.

3. How we ask for consent, and how you change your mind

3.1 Where the law requires prior consent — including in the European Economic Area and the United Kingdom — we ask before any non-essential technology runs, and nothing beyond the strictly necessary category is set until you choose. Refusing is as easy as accepting.

3.2 You can change your choices at any time:

— In the app — Settings → Privacy → Tracking and analytics.

— On the website — the "Cookie settings" link in the footer of every page.

— On iOS — Settings → Privacy & Security → Tracking, to control tracking permission for any app. POSX does not request it.

— On Android — Settings → Privacy → Ads, to delete or reset the advertising identifier.

— In your browser — block or delete cookies through the browser's own settings. Blocking strictly necessary cookies will break sign-in.

3.3 We honour the Global Privacy Control and other recognised opt-out preference signals sent by your browser or device as a valid opt-out of sale and of sharing for targeted advertising, wherever the law gives that signal effect. We do not currently respond to the older "Do Not Track" browser header, because no common standard for it was ever agreed.

3.4 Withdrawing consent stops future processing; it does not undo what happened while consent was in place. Where a technology has already written data to your device, clearing your browser storage or reinstalling the app removes it.

4. How long these technologies last

4.1 Session cookies and session storage are deleted when you close the browser or the app. Persistent cookies and stored identifiers last for the period stated in Appendix A, which is never longer than 13 months for consent-based technologies in the European Economic Area and the United Kingdom, after which we ask again.

5. Third parties

5.1 Some technologies in Appendix A are set by our providers rather than by us. They act on our instructions under a written contract. Where a provider is also a controller in its own right for some purpose, we say so in the appendix and link to its notice.

5.2 Content embedded from another site — a video, a map, a font, a payment frame — may set its own technologies. We keep embedded third-party content to a minimum and load it only after consent where consent is required.

6. Changes

6.1 We update this policy whenever the inventory in Appendix A changes. The version number and effective date at the front of the document tell you which version you are reading. Material changes are announced in the app or on the site.

7. Contact

7.1 Questions about this policy: privacy@posx.io. Postal address: POSX US Inc., 16192 Coastal Highway, Lewes, Delaware 19958, United States (registered office); correspondence to 340 Madison Avenue, Suite 6D, New York, NY 10173, United States. You may also complain to the attorney general of your state and, if you are a California resident, the California Privacy Protection Agency.

Appendix A — Inventory of cookies, SDKs and identifiers

A.1 Website

Reference table 2 in Cookie and Tracking Policy
NameSet byCategoryPurposeDuration
posx_sessionPOSXStrictly necessaryKeeps you signed inSession
posx_csrfPOSXStrictly necessaryProtects forms against cross-site request forgerySession
posx_consentPOSXStrictly necessaryRecords your cookie choices6 months
posx_localePOSXFunctionalRemembers your language and region12 months
Analytics cookiesOur analytics provider, named in the subprocessor listAnalyticsCounts visits and measures which pages are used13 months

A.2 Mobile app SDKs and identifiers

The current name of each provider is published at posx.io/legal/subprocessors.

Reference table 3 in Cookie and Tracking Policy
SDK or identifierProviderCategoryWhat it collectsConsent gate
Crash and performance reportingNamed in the subprocessor list at posx.io/legal/subprocessorsAnalyticsCrash traces, device model, OS and app versionConsent in EEA / UK
Product analyticsNamed in the subprocessor list at posx.io/legal/subprocessorsAnalyticsScreen views, feature events, session dataConsent in EEA / UK
Identity verificationNamed in the subprocessor list at posx.io/legal/subprocessorsStrictly necessaryDocument and selfie capture during onboardingNot a consent gate under this policy — but the biometric template it creates requires separate explicit consent and a manual alternative under Privacy Policy §3
Fraud and device integrityNamed in the subprocessor list at posx.io/legal/subprocessorsStrictly necessaryDevice integrity, emulator and tamper signalsNone — necessary for security
Wallet infrastructurePrivyStrictly necessaryAccount identifier, authentication signals, wallet public addressNone — necessary to provide the wallet you asked for
Push notificationsNamed in the subprocessor list at posx.io/legal/subprocessorsStrictly necessaryPush tokenOS notification permission
AttributionNone at presentMarketingInstall source, campaign identifier — not collectedIf ever added: consent, plus App Tracking Transparency on iOS
Advertising identifierNot usedMarketingIDFA / Advertising ID — not readIf ever added: App Tracking Transparency on iOS; opt-out on Android

Questions about this document

Contact POSX Legal

We can explain how this document applies to the POSX service.

legal@posx.io

POSX Legal

Related policies

ConsumerTerms of ServiceConsumerPrivacy PolicySecuritySecurity PolicySoftware LicenceEnd User License AgreementAccessibilityAccessibility Statement
POSX

Rewards for real-world spending.

Official channels

Stay in the loop

Get the latest updates on product news, rewards and announcements.

Product

IndividualsBusinessNetworkDevelopers
Product
IndividualsBusinessNetworkDevelopers

Company

About POSXNewsroomContactTrust
Company
About POSXNewsroomContactTrust

Resources

Developer docsBrand center
Resources
Developer docsBrand center

Legal

Privacy PolicyTerms of ServiceCookie PolicySecurityAccessibilityDelete your account
Legal
Privacy PolicyTerms of ServiceCookie PolicySecurityAccessibilityDelete your account

Legal notice

POSX is a rewards network, not a bank. POSX Rewards are a promotional benefit funded by participating merchants. They have no cash value, cannot be exchanged for cash, transferred or traded, and are not a deposit, e-money, a security or an investment. Reward balances are records on POSX's own systems and are not held on any blockchain. They are not insured by the Federal Deposit Insurance Corporation or protected by any deposit protection scheme.

Where the POSX app provides a wallet, it is self-custodial and provisioned through Privy: the assets in it belong to you and POSX cannot move, freeze or recover them. POSX does not take custody of user funds or assets.

Nothing on this site is financial, investment, legal or tax advice, or an offer to buy or sell any security. Any statement about future performance, adoption or value is a forward-looking statement and should not be relied on.

Services in the United States are provided by POSX US Inc., 340 Madison Ave, Suite 6D, New York. Services elsewhere are provided by POSX Commerce Technology Limited, Unit J&K, 34/F, Office Tower, Convention Plaza, No. 1 Harbour Road, Wan Chai, Hong Kong (Certificate of Incorporation No. (UBI) 80761816). Availability varies by country and not all features are available in all markets.

© 2026 POSX. All rights reserved.