Cookie and Tracking Policy

    Version 2.0

    Effective date: September 1, 2026

    1. Purpose and relationship with the Privacy Policy

    This Cookie and Tracking Policy explains how the System Owner uses cookies, pixels, tags, scripts, software development kits, local storage, device identifiers, server logs and similar technologies on CardsPro websites, dashboards, forms, support pages and related digital services.

    Some technologies process personal data, such as IP address, device or browser identifiers, session IDs, cookie IDs, referral information, pages visited, interaction events and consent preferences. That processing is also governed by the CardsPro Privacy Policy.

    This Policy applies to technologies controlled by the System Owner. A Partner, embedded service or linked third-party website may use technologies under its own privacy and cookie documentation.

    2. System Owner and platform status

    The controller responsible for CardsPro-controlled cookie and tracking activities is Kaizo FZE LLC, with its registered office at UAE, BC-892957, Amber Gem Tower, Ajman.

    CardsPro is a technology platform. Cookies used on CardsPro interfaces do not change the separate role of independent licensed or authorised Partners that provide regulated card, payment, safeguarding or settlement services under their own terms.

    3. What cookies and similar technologies are

    A cookie is a small text file stored on a device when a website is visited. A session cookie normally expires when the browser session ends. A persistent cookie remains until its stated expiry or earlier deletion.

    Similar technologies include:

    • Local and session storage, which allow information to be stored within the browser;
    • Pixels and tags, which record that a page, message or action was viewed;
    • Scripts and SDKs, which provide functionality, analytics, security or integration features;
    • Device and online identifiers, which help distinguish a browser, device, application session or API client; and
    • Server-side logs and event data, which record requests, errors, security events and interactions without necessarily placing a file on the device.

    Technologies may be set directly by CardsPro (“first-party”) or by an integrated provider (“third-party”).

    4. Categories of technologies

    We classify technologies according to their principal purpose. A technology may serve more than one compatible purpose, but it will be placed in the category that determines the applicable choice or legal basis.

    • Strictly necessary: platform operation, requested communications, authentication, session continuity, load balancing, fraud prevention, security and storage of consent choices;
    • Functional: language, region, display, dashboard, accessibility and other user preferences;
    • Analytics and performance: audience measurement, page and feature use, error analysis, service performance and user-flow improvement;
    • Marketing and attribution: campaign measurement, lead attribution, audience management and evaluation of business marketing; and
    • Security and anti-fraud: suspicious-device detection, bot protection, account-abuse detection, rate limiting, credential protection and investigation of technical threats.

    The current cookie preference centre or cookie banner identifies the technologies presently deployed, including available information about their provider, purpose, category and duration. Because website configuration and providers may change, the live preference centre is the current operational inventory.

    5. Purposes of use

    We may use cookies and similar technologies to:

    • deliver pages, forms, dashboards and requested functions;
    • authenticate users and maintain secure sessions;
    • remember privacy choices and settings;
    • detect attacks, bots, account takeover, fraud and misuse;
    • troubleshoot errors and measure technical performance;
    • understand aggregated use of websites and features;
    • improve navigation, support and service design;
    • attribute business leads and assess campaign effectiveness; and
    • comply with legal, security and recordkeeping requirements.

    We do not use a cookie category for a materially different purpose without updating the relevant notice and obtaining consent where required.

    6. Legal bases

    Strictly necessary technologies are used where required to provide a service expressly requested by the user, secure the Service, authenticate an account, route network traffic or remember privacy choices. Depending on the applicable law, this processing may rely on technical necessity, contract performance, legal obligation or legitimate interests.

    Non-essential analytics, functional, marketing and attribution technologies are activated on the basis of consent where the ePrivacy rules, GDPR, UK privacy rules or another applicable law requires consent.

    Where a technology does not require consent under the law applicable to a particular user, related personal-data processing must still have a valid legal basis and comply with transparency, purpose-limitation and data-minimisation requirements.

    7. Consent management

    Where consent is required, non-essential technologies will not be activated before a valid choice is recorded. The consent interface should allow the user to:

    • accept all optional categories;
    • reject non-essential technologies;
    • select categories individually;
    • review the principal purpose and provider information; and
    • change or withdraw consent at any time.

    Consent is intended to be freely given, specific, informed and unambiguous. Closing a banner, inactivity, continued browsing or pre-selected optional settings will not be treated as consent where an affirmative action is required.

    Rejecting optional technologies should not prevent access to ordinary website or Service functionality. A feature may be affected only where the relevant technology is genuinely required for that specific requested function.

    8. Strictly necessary and security technologies

    Necessary technologies may store or access session identifiers, authentication status, load-balancing data, consent records and security signals. Disabling them through browser or network settings may prevent login, session continuity, form submission or protection against abuse.

    Security technologies may analyse IP address, device attributes, request patterns, timestamps and account events to identify bots, credential attacks, fraud, unauthorised access or API misuse. They are not used for unrelated advertising merely because the same technical provider offers advertising products.

    9. Functional technologies

    Functional technologies may remember language, region, time zone, accessibility preferences, dashboard layout, form state and similar choices. Where required, they are activated only after consent.

    If a preference is stored only at the user’s specific request and is necessary to deliver that preference, the applicable law may permit it without separate consent.

    10. Analytics and performance

    Analytics may record page views, navigation, referral source, approximate location derived from IP address, device type, browser, session duration, feature use, conversion events and technical errors.

    Where reasonably possible, analytics settings should reduce unnecessary data collection, shorten retention, limit precise location, avoid collecting form contents and apply IP truncation or comparable safeguards.

    Analytics results are used to understand service performance and improve CardsPro. They are not authoritative transaction, account or settlement records.

    11. Marketing and attribution

    Marketing technologies may measure whether a business campaign produced a visit, inquiry, registration or other conversion. They may also support frequency controls or business-audience management where enabled.

    Marketing technologies are optional and are used only after consent where required. Withdrawing consent stops future optional collection through CardsPro-controlled integrations, although a third party may retain data already lawfully collected under its own retention policy.

    CardsPro marketing must not suggest that Kaizo FZE LLC is a bank or financial institution or that regulated card or payment services are provided directly by CardsPro where they are in fact provided by independent Partners.

    12. Third-party providers

    We may engage providers of hosting, content delivery, consent management, analytics, communications, customer support, bot protection, fraud prevention and campaign measurement.

    A third-party provider may receive an online identifier, IP address, device information and interaction data when its technology is enabled. Depending on the arrangement, the provider may act as processor, independent controller or joint controller.

    The current provider list and links to available provider notices should be displayed in the live cookie preference centre. Third-party technologies are subject to the provider’s own retention, security and transfer practices in addition to our contractual safeguards.

    13. Server-side measurement and API logs

    Some measurement and security activities occur on CardsPro servers and do not place a cookie on the user’s device. Server-side operation does not remove data-protection obligations or permit circumvention of a valid consent choice.

    Operational and API logs may be processed separately from cookie consent where necessary for authentication, cybersecurity, fraud prevention, debugging, compliance or delivery of the requested Service.

    14. International transfers

    Providers may process data in countries outside the British Virgin Islands, European Economic Area or United Kingdom. Where required, we apply an appropriate transfer mechanism and safeguards as described in the CardsPro Privacy Policy.

    Provider location and transfer information may be obtained from the live preference centre, the provider’s privacy documentation or by contacting us through contacts.

    15. Duration and retention

    Cookie duration varies according to purpose. Session cookies ordinarily expire when the browser is closed. Persistent cookies remain until their stated expiry, withdrawal of consent, configuration change or manual deletion.

    The live cookie inventory should state the duration of each cookie or, where exact duration is controlled by a provider, identify the applicable provider documentation.

    Related server-side event and consent records may be retained longer than the browser cookie where necessary to demonstrate consent, maintain security, investigate fraud, analyse performance or comply with law. Retention is periodically reviewed and data no longer required is deleted or anonymised.

    16. Changing or withdrawing consent

    Users may reopen the cookie preference centre through the cookie settings link displayed on the CardsPro website and change or withdraw optional consent at any time. Withdrawal applies to future processing and does not affect the lawfulness of processing before withdrawal.

    It should be as easy to reject or withdraw optional technologies as it is to accept them. A consent choice may need to be requested again after a material change, expiry of the consent record, deletion of the relevant preference cookie or use of another browser or device.

    17. Browser and device controls

    Most browsers allow users to view, block or delete cookies and restrict site storage. Mobile devices and applications may provide additional advertising, tracking or permission controls.

    Browser deletion may remove the cookie that stores a consent choice, causing the banner to reappear. Blocking all cookies may impair authentication, forms, dashboard access, security and preferences.

    18. Do Not Track and global privacy signals

    Some browsers transmit Do Not Track, Global Privacy Control or similar signals. Because legal requirements and technical standards differ, we respond to a recognised signal where required by applicable law and technically applicable to the relevant processing.

    Where a signal is not legally binding or does not map reliably to cookie categories, users should use the CardsPro preference centre to record their choice.

    19. Children

    CardsPro is a business technology platform intended for users aged 18 and over. It is not directed to children, and optional tracking is not knowingly used to profile or market CardsPro services to persons under 18.

    If we learn that tracking data relates to a minor who accessed the Service contrary to the eligibility rules, we will take reasonable steps consistent with the CardsPro Privacy Policy.

    20. Privacy rights

    Where online identifiers or cookie data constitute personal data, applicable rights may include access, deletion, restriction, objection and withdrawal of consent. Rights and request procedures are described in the CardsPro Privacy Policy.

    Requests and complaints may be submitted through contacts. We may request information reasonably necessary to verify the requester and locate the relevant browser, account or consent record.

    21. Changes to this Policy

    We may update this Policy when technologies, providers, purposes, laws or website configuration change. The updated version will state its effective date and be published on the CardsPro website.

    Where a change materially affects an existing consent, we will request a new choice where required. Continuing to browse will not by itself constitute consent to newly introduced non-essential technologies where affirmative consent is required.

    22. Contact

    System Owner: Kaizo FZE LLC

    Registered office: UAE, BC-892957, Amber Gem Tower, Ajman.

    Cookie, privacy and general questions: contacts.