Cookie
Policy
1. Introduction
This Cookie Policy explains how BayLeaf OÜ, a private limited company incorporated under the laws of the Republic of Estonia, operating as Tomorrow's Wallet ("we", "us", or "our"), uses cookies and similar tracking technologies on tomorrowswallet.com and in our mobile application (collectively, the "Service").
As an Estonian entity, we are subject to the General Data Protection Regulation (EU) 2016/679 (GDPR) and the ePrivacy Directive (2002/58/EC). Consistent with the CJEU's rulings in Planet49 (C-673/17) and Orange România (C-61/19), we require active, prior, informed consent before placing any non-essential cookies or activating any non-essential tracking technology. Pre-ticked boxes are never used. Non-essential cookies are not placed until consent has been obtained.
This Cookie Policy is part of our legal framework and must be read alongside our Privacy Policy and Terms of Service. Your personal data collected via cookies is processed in accordance with our Privacy Policy.
2. What Are Cookies?
Cookies are small text files that a website stores on your device (browser, hard drive, or similar storage) when you visit. They allow the website to remember information about your visit, such as your session state or preferences — to make your next visit easier and the Service more useful.
We use, or may use, the following technologies on the Service:
- Session cookies: Temporary cookies deleted when you close your browser. Used for session authentication and CSRF protection. Used on: Website.
- Persistent cookies: Remain on your device for a set duration. Used for preference storage and trusted device recognition. Used on: Website.
- Pixel tags / web beacons: Tiny invisible images embedded in pages or emails to confirm receipt or trigger tracking events. Used on: Website (analytics, if consented).
- Local storage: Browser-side key-value storage used to persist UI state (e.g., theme preference, onboarding progress) across sessions without a server round-trip. Not transmitted to servers automatically. See Section 10. Used on: Website.
- Session storage: Short-term in-browser storage cleared when the tab is closed. Used to hold temporary form state and navigation context. See Section 10. Used on: Website.
- SDK-based device storage: Mobile-equivalent of cookies, identifiers stored by app SDKs in device storage. Used for analytics and secure device recognition in our mobile application. See Section 9. Used on: Mobile app.
3. Cookies We Use
3.1 Strictly Necessary Cookies
These cookies are exempt from consent requirements under applicable ePrivacy rules because they are strictly necessary to provide the service requested by the user. They cannot be disabled without preventing the Service from functioning. No consent banner controls apply to this category.
| Cookie Name | Provider | Purpose | Retention | Renewal |
|---|---|---|---|---|
| session_id | BayLeaf OÜ | Authenticates your logged-in session and prevents unauthorized access | Session | Set on each new login |
| csrf_token | BayLeaf OÜ | Cross-Site Request Forgery (CSRF) protection token — prevents malicious third-party requests | Session | Regenerated per session |
| device_trust | BayLeaf OÜ | Recognises trusted devices after MFA verification to reduce re-authentication friction | 30 days | Reset on re-authentication or device change |
| consent_prefs | BayLeaf OÜ | Stores your cookie category consent choices to avoid re-prompting on every visit | 12 months | Reset on consent withdrawal or policy update requiring fresh consent |
3.2 Functional Cookies
These cookies remember your preferences to personalise your experience. They are not strictly necessary, the Service functions without them, but with reduced personalisation. Requires your consent.
| Cookie Name | Provider | Purpose | Retention | Renewal |
|---|---|---|---|---|
| ui_theme | BayLeaf OÜ | Stores your light/dark mode display preference | 12 months | Reset when preference is changed |
| lang_pref | BayLeaf OÜ | Stores your language selection | 12 months | Reset when language is changed |
| onboarding_step | BayLeaf OÜ | Tracks your progress through the onboarding flow to allow resumption after interruption | 7 days | Deleted on onboarding completion or expiry |
3.3 Analytics Cookies
Analytics cookies help us understand how users interact with the Service, which features are used, where users encounter difficulty, and how flows can be improved. All analytics are activated only after you provide active, informed consent. Data is aggregated and pseudonymised where technically possible.
| Cookie Name | Provider | Purpose | Retention | Renewal |
|---|---|---|---|---|
| ph_phc_* | PostHog | Product usage analytics — feature interaction, session recording (where enabled), funnel analysis, error event capture. IP anonymisation enabled. Data stored in EU PostHog Cloud (eu.posthog.com) where available. | 12 months | Renewed on each active session; reset on consent withdrawal |
PostHog analytics are activated only after you click "Accept Analytics" in our Cookie Preference Centre. If you decline, no ph_phc_* cookies are set and no event data is collected. You may change this choice at any time via Cookie Settings in our footer.
3.4 Marketing Cookies
We do not currently use marketing, advertising, or behavioural retargeting cookies. If this changes, we will update this policy, deploy a new consent category in our Cookie Preference Centre, and obtain your explicit, fresh consent before any such cookie is placed.
4. Device Identification and Fraud Prevention Technologies
In addition to standard cookies, we use fraud prevention technologies that collect device characteristics to protect user accounts and the integrity of the Service. These technologies are classified as strictly necessary for platform security.
4.1 Device Attributes Collected
Our fraud prevention and security layer may collect the following device attributes to generate a device fingerprint or risk score:
- IP address (hashed or truncated for storage after analysis)
- Browser type, version, and rendering engine
- Operating system and version
- Device type, screen resolution, and colour depth
- Installed fonts and plugins (enumerated, not individually stored)
- Timezone and language settings
- Network characteristics (connection type, ISP ASN)
- WebGL renderer and GPU information (for canvas fingerprinting detection)
- Cookie and JavaScript support flags
4.2 Purpose and Use
Device characteristic data is processed exclusively for the following security purposes:
- Account takeover prevention: Detecting anomalous login attempts from unrecognised devices
- Fraud and AML risk scoring: Assigning a session risk indicator to support transaction monitoring obligations under Estonia's MLTFPA and India's PMLA
- Bot and automation detection: Distinguishing legitimate user sessions from automated scripts or credential-stuffing attacks
- Trusted device management: Recognising previously verified devices to reduce MFA friction for legitimate users
Device characteristics are never used for advertising, profiling, or behavioural targeting.
4.3 Retention and Legal Basis
| Cookie / Signal | Retention | Legal Basis |
|---|---|---|
| fp_token — Device fingerprint token | 90 days | Legitimate Interests (GDPR Art. 6(1)(f)) + Legal Obligation (AML) |
| risk_score — Session risk indicator | Session only | Legitimate Interests (GDPR Art. 6(1)(f)) + Legal Obligation (AML) |
| Raw device attribute signals | 90 days (security logs) | Legitimate Interests (fraud detection) + Legal Obligation |
A three-part Legitimate Interests Assessment (LIA) has been conducted for device fingerprinting and risk scoring.
5. Legal Basis for Each Cookie Category
| Category | Legal Basis | Consent Required? | Can Be Disabled? | Impact If Disabled |
|---|---|---|---|---|
| Strictly Necessary | Contract necessity and service delivery (Art. 6(1)(b)) | No — exempt | No | Service non-functional |
| Security / Fraud Prevention | Legitimate Interests (Art. 6(1)(f)) + Legal Obligation (Art. 6(1)(c)) for AML | No — exempt | No | Increased fraud/account risk |
| Functional | Consent (Art. 6(1)(a)) | Yes | Yes | Reduced personalisation |
| Analytics | Consent (Art. 6(1)(a)) | Yes | Yes | No product impact to user |
| Marketing | Consent (Art. 6(1)(a)) | Yes | Yes | Not currently used |
6. Third-Party Cookie Providers
The following third-party providers may set cookies or collect data through the Service. All are bound by GDPR Article 28 Data Processing Agreements (DPAs). We provide a direct link to each provider's privacy notice for your independent review.
| Provider | Category | Purpose | Data Location | Privacy Notice |
|---|---|---|---|---|
| PostHog | Analytics | Product usage analytics, session analysis, funnel tracking, error events | EU (eu.posthog.com) — SCC fallback for non-EU sub-processors | posthog.com/privacy |
| Amazon Web Services (AWS) | Infrastructure | Cloud hosting, content delivery, and application infrastructure | EU-West primary; SCC + TIA for non-EU processing | aws.amazon.com/privacy |
| Turnkey | Security | Non-custodial wallet infrastructure; device trust tokens for wallet operations | US — SCC + TIA on file | turnkey.com/privacy-policy |
Note: Where payment processing services are activated (subscription billing), a payment processor will set security tokens. This section will be updated with the processor's name, cookie details, and privacy notice when payment infrastructure is finalised.
7. International Transfers Related to Cookie Data
Some cookie data, including analytics event data collected by PostHog and device identifiers processed by Turnkey, may be transferred to servers located outside the European Economic Area (EEA), principally to the United States. We ensure such transfers are lawful under GDPR Chapter V.
| Provider | Data Transferred | Destination | Transfer Mechanism |
|---|---|---|---|
| PostHog | Analytics event data, pseudonymous user identifiers, session metadata | EU (primary); US (sub-processors) | EU hosting elected; SCCs + TIA for any non-EEA processing |
| Turnkey | Device trust tokens, wallet operation security identifiers | United States | Standard Contractual Clauses (Module 2) + Transfer Impact Assessment on file |
| AWS | Server-side logs, session tokens (encrypted at rest) | EU-West (primary); US (DR failover) | AWS EU regions primary; SCCs + AWS DPA for non-EU failover |
8. Your Choices
8.1 Cookie Preference Centre
On your first visit to the Service, our consent banner will present you with granular category choices. You may:
- Accept all non-essential cookie categories
- Accept strictly necessary and security cookies only (minimum functional level)
- Customise consent by individual category (functional, analytics, marketing)
Your choices are stored in the consent_prefs cookie (strictly necessary) so you are not re-prompted on every visit. You can update your preferences at any time by clicking "Cookie Settings" in the footer of every page.
Withdrawal of Consent
You may withdraw your consent at any time via the Cookie Preference Centre. Withdrawal will not affect processing conducted before withdrawal. Upon withdrawal, non-essential cookies are deleted from your device and no new non-essential data collection will occur during future sessions.
We maintain records of consent preferences as required by GDPR Article 7(1), including the timestamp of consent, the version of the policy in effect at the time, and the categories accepted.
8.2 Browser-Level Cookie Controls
You can also manage cookies directly through your browser settings:
- Google Chrome: support.google.com/chrome/answer/95647
- Mozilla Firefox: support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
- Apple Safari: support.apple.com/en-gb/guide/safari/sfri11471/mac
- Microsoft Edge: support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge
Note: Deleting or blocking strictly necessary cookies via your browser will prevent the Service from functioning correctly. Browser-level deletions do not update your recorded consent preferences in our system, use the Cookie Preference Centre for that purpose.
8.3 Do Not Track (DNT)
The "Do Not Track" browser signal lacks a universally agreed standard, and its legal status is not definitively established under GDPR or ePrivacy. Our approach is as follows: we do not rely on DNT signals as a substitute for the consent mechanism described in Section 8.1. Non-essential cookies are only activated upon your explicit consent through our Cookie Preference Centre, regardless of DNT signal status. If you wish to prevent non-essential tracking, please use the Cookie Preference Centre.
9. Mobile Application
Our mobile application does not use browser cookies. Instead, it uses SDK-based identifiers stored in secure device storage. The PostHog mobile SDK collects equivalent analytics event data (feature interactions, session metadata) on the basis of your in-app consent, obtained during onboarding through an equivalent consent flow to our web Cookie Preference Centre.
You can opt out of device-level tracking at the operating system level via:
- iOS 14.5+: Settings → Privacy & Security → Tracking → Disable per-app or globally
- Android 12+: Settings → Privacy → Ads → Opt out of Ads Personalisation (or equivalent per manufacturer)
Opting out at the OS level will disable analytics SDK event collection. Security and authentication identifiers (equivalent to strictly necessary cookies) are not affected by OS-level tracking opt-outs and remain active to ensure account security.
10. Browser Storage Technologies
In addition to cookies, the Service uses two browser-native storage mechanisms. Unlike cookies, these are not transmitted automatically with every HTTP request, they exist only in your browser and are accessed only by our JavaScript running on the page.
| Technology | What We Store | Purpose | Retention | Legal Basis |
|---|---|---|---|---|
| Local Storage | UI theme preference (light/dark), onboarding progress indicator, last-seen dashboard tab | Persistent UI state across browser sessions to avoid re-configuring interface on each visit | Until cleared by user or app reset | Consent (functional preference data) |
| Session Storage | Temporary multi-step form state, in-progress rule builder data, navigation breadcrumbs | Preserves form data during a single browser session to prevent data loss on back-navigation | Cleared automatically when the browser tab is closed | Contract necessity / strictly necessary for service delivery |
Local storage used for functional preferences (theme, tab state) is cleared when you withdraw consent from the Functional category in our Cookie Preference Centre. Session storage data is strictly necessary and not subject to consent controls.
11. Blockchain Interactions
When you connect a non-custodial wallet and execute transactions through the Service, those transactions are broadcast to and recorded on a public distributed ledger. This data is not governed by this Cookie Policy.
Public blockchain records, including your wallet address and transaction history, may remain visible indefinitely and cannot generally be modified or deleted by any party, including BayLeaf OÜ. These records are public by design and do not constitute personal data under our control for the purposes of GDPR erasure rights. See our Privacy Policy (§6) for full disclosure.
12. Cookie Retention Overview
| Cookie / Technology | Category | Max Retention | Renewal Trigger |
|---|---|---|---|
| session_id | Strictly Necessary | Session (tab close) | Each new login |
| csrf_token | Strictly Necessary | Session (tab close) | Each new session |
| device_trust | Strictly Necessary | 30 days | Re-authentication or new device |
| consent_prefs | Strictly Necessary | 12 months | Consent change or policy update |
| fp_token | Security | 90 days | Device change or security event |
| risk_score | Security | Session | Each page load |
| ui_theme | Functional | 12 months | Preference change or consent withdrawal |
| lang_pref | Functional | 12 months | Language change or consent withdrawal |
| onboarding_step | Functional | 7 days | Onboarding completion or consent withdrawal |
| ph_phc_* (PostHog) | Analytics | 12 months | Consent withdrawal; reset to anonymous on withdrawal |
| Local Storage (UI/UX state) | Functional | Persistent until cleared | Cleared on functional consent withdrawal |
| Session Storage (form state) | Strictly Necessary | Tab/session close | Automatic on close |
13. Compliance Commitments
13.1 Cookie Audit Commitment
We periodically review our use of cookies and tracking technologies to ensure continued compliance with GDPR, the ePrivacy Directive, and guidance from the Estonian Data Protection Inspectorate (AKI) and the European Data Protection Board (EDPB). Our cookie audit cycle targets review at least every 12 months, or immediately following:
- Addition of a new third-party service that places cookies
- Material changes to the purpose or retention of existing cookies
- New regulatory guidance from AKI, EDPB, or a competent court
13.2 Consent Records
We maintain records of consent preferences where required by law (GDPR Article 7(1)). Our consent management system logs the following for each consent event:
- Timestamp of the consent action
- Categories consented to and categories declined
- Cookie Policy version in effect at time of consent
- Pseudonymous session identifier (not personal data)
These records are retained for 3 years and are available to competent supervisory authorities upon lawful request.
13.3 ePrivacy and CJEU Compliance
Our consent mechanism is designed to meet the standards established in Planet49 (C-673/17) and Orange România (C-61/19). Specifically: consent is obtained through an unambiguous affirmative action (a button click, not a pre-ticked box); refusing non-essential cookies is as easy as accepting them; and the consent banner clearly explains the purpose of each cookie category before consent is requested.
14. Changes to This Policy
We update this Cookie Policy as we add new tools, in response to regulatory developments, or following our periodic cookie audit. We distinguish between two categories of change:
- Material changes: adding a new cookie category, adding a new third-party processor, or changing the purpose or retention of an existing cookie. These require a new consent event through the Cookie Preference Centre and are communicated via an in-banner notice or email at least 14 days before taking effect.
- Non-material changes: clarifying language, corrected provider links, or administrative updates. The "Last Updated" date is updated, but no fresh consent is required unless a new cookie category is activated.
The authoritative version of this policy is always the current version at tomorrowswallet.com/cookies.
