Cookie Policy
Effective: April 25, 2026 — Version 2.0
1. Introduction
This Cookie Policy explains what cookies are, what types Wappi Holding LLC ("Wappi") uses, for what purpose, how long they are stored on your device, and how you can manage them. Cookies are small text files stored on your device (computer, smartphone, tablet) when you visit a website or use an application. This policy forms part of our Privacy Policy and should be read together with it.
2. Types of Cookies We Use
We classify our cookies into the following categories based on their purpose:
2.1 Strictly necessary cookies
Essential for the basic functioning of the Platform. Without these cookies, essential features such as authentication, page navigation, and access to secure areas would be unavailable. They do not require consent as they are technically necessary. These include: authentication session cookie (Supabase Auth, duration: session), CSRF security token (duration: session), language preference (duration: 1 year), cookie acceptance status (duration: 1 year).
2.2 Performance and analytics cookies
Collect anonymized and aggregated information about how users interact with the Platform, allowing us to identify areas for improvement and optimize the experience. They do not directly identify the user. These include: page performance metrics (duration: session), feature usage counters (duration: 30 days).
2.3 Functionality and preference cookies
Allow us to remember user settings and preferences to personalize the experience on subsequent visits. These include: interface theme (light/dark, duration: 1 year), dashboard configuration (duration: 1 year), last selected store in multi-tenant environments (duration: 30 days).
2.4 Security cookies
Help protect user accounts and Platform integrity by detecting malicious activity. These include: Cloudflare Turnstile verification token (duration: session), device fingerprint for anomaly detection (duration: 30 days), CSRF attack protection (duration: session).
3. Third-Party Cookies
Some of our service providers may place their own cookies on your device when you interact with features that depend on their services:
- Stripe Inc. — Payment processing and fraud prevention — Cookies: __stripe_mid (1 year), __stripe_sid (session) — Purpose: payment authentication, fraud detection
- Supabase Inc. — Authentication and session management — Cookies: sb-access-token, sb-refresh-token — Purpose: user authentication, session renewal
- Cloudflare Inc. — Security and bot protection — Cookies: cf_clearance (30 min), __cf_bm (30 min) — Purpose: legitimate visitor verification
4. Cookie Management and Control
You have full control over the cookies stored on your device. You can manage your cookie preferences in the following ways:
- Browser settings: all modern browsers allow blocking, deleting, or limiting cookies. Consult your browser's documentation: Chrome (chrome://settings/cookies), Firefox (about:preferences#privacy), Safari (Preferences > Privacy), Edge (edge://settings/content/cookies)
- Third-party cookies: you can manage Stripe cookies at stripe.com/cookie-settings and Cloudflare cookies through your browser settings
- Important: disabling strictly necessary cookies may prevent the Platform from functioning correctly, including the inability to log in or use features requiring authentication
5. Statement on Advertising and Tracking Cookies
Wappi expressly declares that it does NOT use advertising, tracking, retargeting, or profiling cookies for marketing purposes. We do not share data collected through cookies with advertising networks, data brokers, or third parties for commercial or advertising purposes. We do not participate in real-time bidding (RTB) or cross-site tracking systems.
6. Updates and Contact
This Cookie Policy may be updated periodically to reflect changes in our practices or applicable legislation. We will notify material changes in accordance with our Privacy Policy. For cookie-related inquiries: [email protected]