POSX Legal · United States
Cookie and Tracking Policy
Cookies, SDKs, device identifiers and similar technologies used in the POSX app and on POSX websites — what they do, and how to control them.
On this page
Users in the United States and in every market where POSX US Inc. is named as the app publisher
Laws of the State of Delaware
1. Why this policy exists
1.1 This policy explains the technologies POSX uses to store information on, or read information from, your device — on our websites and inside the POSX mobile application — and how you control them. It sits alongside the Privacy Policy, which explains what we do with the personal information those technologies produce.
1.2 The law in this area is not limited to browser cookies. Consent rules under the ePrivacy Directive as interpreted by the European Data Protection Board in 2024 apply to any storing of information on, or gaining of access to information already stored on, your device. That includes mobile SDKs, local storage, device and advertising identifiers, pixels, tracking URLs and device fingerprinting. This policy therefore covers all of them, not only cookies.
2. What we use, and what it does
2.1 Categories
| Category | What it does | Do we need your consent? |
|---|---|---|
| Strictly necessary | Keeps you signed in, remembers your session, routes traffic, balances load, protects against fraud and abuse, remembers your cookie choices, and makes the app function. The Service cannot work without these. | No — they are exempt, because they are strictly necessary to provide the service you asked for. You cannot turn them off. |
| Functional | Remembers preferences such as language, region, display settings and whether you have seen a particular prompt. | Yes where required in your region. Turning them off means you re-set preferences each time. |
| Analytics and performance | Counts users, measures which screens and features are used, times how long things take, and reports crashes and errors so we can fix them. | Yes where required in your region. We aggregate and do not use analytics to build advertising profiles. |
| Marketing, attribution and advertising | Not currently used. If POSX ever runs advertising or install attribution, this category would measure whether a campaign led to an install or a sign-up. | Yes, always, where required — and on iOS also subject to Apple's App Tracking Transparency permission, which POSX does not currently request. |
2.1.1 We do not use advertising or profiling technologies to build a picture of you across other companies' apps and websites.
2.2 In the app specifically
Mobile apps do not use browser cookies. Inside POSX the equivalent technologies are:
— Local storage on your device — the session token that keeps you signed in, cached content so the app opens quickly offline, and your preferences.
— Vendor identifier (iOS) / app-set ID (Android) — a per-installation identifier that lets us recognise the same installation between sessions. It resets when you delete the app.
— Advertising identifier (IDFA on iOS, Advertising ID on Android) — not used. POSX does not read the advertising identifier and does not show Apple's App Tracking Transparency prompt. If that ever changes we will ask for your permission first.
— Push notification token — issued by Apple or Google so we can deliver notifications you have allowed.
— Software development kits (SDKs) embedded in the app for crash reporting, analytics, identity verification and security. Each one is listed in Appendix A.
— Device and integrity signals used to detect emulators, rooted or jailbroken devices, automated access and account takeover.
3. How we ask for consent, and how you change your mind
3.1 Where the law requires prior consent — including in the European Economic Area and the United Kingdom — we ask before any non-essential technology runs, and nothing beyond the strictly necessary category is set until you choose. Refusing is as easy as accepting.
3.2 You can change your choices at any time:
— In the app — Settings → Privacy → Tracking and analytics.
— On the website — the "Cookie settings" link in the footer of every page.
— On iOS — Settings → Privacy & Security → Tracking, to control tracking permission for any app. POSX does not request it.
— On Android — Settings → Privacy → Ads, to delete or reset the advertising identifier.
— In your browser — block or delete cookies through the browser's own settings. Blocking strictly necessary cookies will break sign-in.
3.3 We honour the Global Privacy Control and other recognised opt-out preference signals sent by your browser or device as a valid opt-out of sale and of sharing for targeted advertising, wherever the law gives that signal effect. We do not currently respond to the older "Do Not Track" browser header, because no common standard for it was ever agreed.
3.4 Withdrawing consent stops future processing; it does not undo what happened while consent was in place. Where a technology has already written data to your device, clearing your browser storage or reinstalling the app removes it.
4. How long these technologies last
4.1 Session cookies and session storage are deleted when you close the browser or the app. Persistent cookies and stored identifiers last for the period stated in Appendix A, which is never longer than 13 months for consent-based technologies in the European Economic Area and the United Kingdom, after which we ask again.
5. Third parties
5.1 Some technologies in Appendix A are set by our providers rather than by us. They act on our instructions under a written contract. Where a provider is also a controller in its own right for some purpose, we say so in the appendix and link to its notice.
5.2 Content embedded from another site — a video, a map, a font, a payment frame — may set its own technologies. We keep embedded third-party content to a minimum and load it only after consent where consent is required.
6. Changes
6.1 We update this policy whenever the inventory in Appendix A changes. The version number and effective date at the front of the document tell you which version you are reading. Material changes are announced in the app or on the site.
7. Contact
7.1 Questions about this policy: privacy@posx.io. Postal address: POSX US Inc., 16192 Coastal Highway, Lewes, Delaware 19958, United States (registered office); correspondence to 340 Madison Avenue, Suite 6D, New York, NY 10173, United States. You may also complain to the attorney general of your state and, if you are a California resident, the California Privacy Protection Agency.
Appendix A — Inventory of cookies, SDKs and identifiers
A.1 Website
| Name | Set by | Category | Purpose | Duration |
|---|---|---|---|---|
| posx_session | POSX | Strictly necessary | Keeps you signed in | Session |
| posx_csrf | POSX | Strictly necessary | Protects forms against cross-site request forgery | Session |
| posx_consent | POSX | Strictly necessary | Records your cookie choices | 6 months |
| posx_locale | POSX | Functional | Remembers your language and region | 12 months |
| Analytics cookies | Our analytics provider, named in the subprocessor list | Analytics | Counts visits and measures which pages are used | 13 months |
A.2 Mobile app SDKs and identifiers
The current name of each provider is published at posx.io/legal/subprocessors.
| SDK or identifier | Provider | Category | What it collects | Consent gate |
|---|---|---|---|---|
| Crash and performance reporting | Named in the subprocessor list at posx.io/legal/subprocessors | Analytics | Crash traces, device model, OS and app version | Consent in EEA / UK |
| Product analytics | Named in the subprocessor list at posx.io/legal/subprocessors | Analytics | Screen views, feature events, session data | Consent in EEA / UK |
| Identity verification | Named in the subprocessor list at posx.io/legal/subprocessors | Strictly necessary | Document and selfie capture during onboarding | Not a consent gate under this policy — but the biometric template it creates requires separate explicit consent and a manual alternative under Privacy Policy §3 |
| Fraud and device integrity | Named in the subprocessor list at posx.io/legal/subprocessors | Strictly necessary | Device integrity, emulator and tamper signals | None — necessary for security |
| Wallet infrastructure | Privy | Strictly necessary | Account identifier, authentication signals, wallet public address | None — necessary to provide the wallet you asked for |
| Push notifications | Named in the subprocessor list at posx.io/legal/subprocessors | Strictly necessary | Push token | OS notification permission |
| Attribution | None at present | Marketing | Install source, campaign identifier — not collected | If ever added: consent, plus App Tracking Transparency on iOS |
| Advertising identifier | Not used | Marketing | IDFA / Advertising ID — not read | If ever added: App Tracking Transparency on iOS; opt-out on Android |
Questions about this document
Contact POSX Legal
We can explain how this document applies to the POSX service.