Loading

Loading

Cookie
Policy

Last Updated: 21 June 2026Legal Entity: BayLeaf OÜTrading As: Tomorrow's Wallet
Registered Address: Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551, Republic of Estonia

1. Introduction

This Cookie Policy explains how BayLeaf OÜ, a private limited company incorporated under the laws of the Republic of Estonia, operating as Tomorrow's Wallet ("we", "us", or "our"), uses cookies and similar tracking technologies on tomorrowswallet.com and in our mobile application (collectively, the "Service").

As an Estonian entity, we are subject to the General Data Protection Regulation (EU) 2016/679 (GDPR) and the ePrivacy Directive (2002/58/EC). Consistent with the CJEU's rulings in Planet49 (C-673/17) and Orange România (C-61/19), we require active, prior, informed consent before placing any non-essential cookies or activating any non-essential tracking technology. Pre-ticked boxes are never used. Non-essential cookies are not placed until consent has been obtained.

This Cookie Policy is part of our legal framework and must be read alongside our Privacy Policy and Terms of Service. Your personal data collected via cookies is processed in accordance with our Privacy Policy.

2. What Are Cookies?

Cookies are small text files that a website stores on your device (browser, hard drive, or similar storage) when you visit. They allow the website to remember information about your visit, such as your session state or preferences — to make your next visit easier and the Service more useful.

We use, or may use, the following technologies on the Service:

  • Session cookies: Temporary cookies deleted when you close your browser. Used for session authentication and CSRF protection. Used on: Website.
  • Persistent cookies: Remain on your device for a set duration. Used for preference storage and trusted device recognition. Used on: Website.
  • Pixel tags / web beacons: Tiny invisible images embedded in pages or emails to confirm receipt or trigger tracking events. Used on: Website (analytics, if consented).
  • Local storage: Browser-side key-value storage used to persist UI state (e.g., theme preference, onboarding progress) across sessions without a server round-trip. Not transmitted to servers automatically. See Section 10. Used on: Website.
  • Session storage: Short-term in-browser storage cleared when the tab is closed. Used to hold temporary form state and navigation context. See Section 10. Used on: Website.
  • SDK-based device storage: Mobile-equivalent of cookies, identifiers stored by app SDKs in device storage. Used for analytics and secure device recognition in our mobile application. See Section 9. Used on: Mobile app.

3. Cookies We Use

3.1 Strictly Necessary Cookies

These cookies are exempt from consent requirements under applicable ePrivacy rules because they are strictly necessary to provide the service requested by the user. They cannot be disabled without preventing the Service from functioning. No consent banner controls apply to this category.

Cookie NameProviderPurposeRetentionRenewal
session_idBayLeaf OÜAuthenticates your logged-in session and prevents unauthorized accessSessionSet on each new login
csrf_tokenBayLeaf OÜCross-Site Request Forgery (CSRF) protection token — prevents malicious third-party requestsSessionRegenerated per session
device_trustBayLeaf OÜRecognises trusted devices after MFA verification to reduce re-authentication friction30 daysReset on re-authentication or device change
consent_prefsBayLeaf OÜStores your cookie category consent choices to avoid re-prompting on every visit12 monthsReset on consent withdrawal or policy update requiring fresh consent

3.2 Functional Cookies

These cookies remember your preferences to personalise your experience. They are not strictly necessary, the Service functions without them, but with reduced personalisation. Requires your consent.

Cookie NameProviderPurposeRetentionRenewal
ui_themeBayLeaf OÜStores your light/dark mode display preference12 monthsReset when preference is changed
lang_prefBayLeaf OÜStores your language selection12 monthsReset when language is changed
onboarding_stepBayLeaf OÜTracks your progress through the onboarding flow to allow resumption after interruption7 daysDeleted on onboarding completion or expiry

3.3 Analytics Cookies

Analytics cookies help us understand how users interact with the Service, which features are used, where users encounter difficulty, and how flows can be improved. All analytics are activated only after you provide active, informed consent. Data is aggregated and pseudonymised where technically possible.

Cookie NameProviderPurposeRetentionRenewal
ph_phc_*PostHogProduct usage analytics — feature interaction, session recording (where enabled), funnel analysis, error event capture. IP anonymisation enabled. Data stored in EU PostHog Cloud (eu.posthog.com) where available.12 monthsRenewed on each active session; reset on consent withdrawal

PostHog analytics are activated only after you click "Accept Analytics" in our Cookie Preference Centre. If you decline, no ph_phc_* cookies are set and no event data is collected. You may change this choice at any time via Cookie Settings in our footer.

3.4 Marketing Cookies

We do not currently use marketing, advertising, or behavioural retargeting cookies. If this changes, we will update this policy, deploy a new consent category in our Cookie Preference Centre, and obtain your explicit, fresh consent before any such cookie is placed.

4. Device Identification and Fraud Prevention Technologies

In addition to standard cookies, we use fraud prevention technologies that collect device characteristics to protect user accounts and the integrity of the Service. These technologies are classified as strictly necessary for platform security.

4.1 Device Attributes Collected

Our fraud prevention and security layer may collect the following device attributes to generate a device fingerprint or risk score:

  • IP address (hashed or truncated for storage after analysis)
  • Browser type, version, and rendering engine
  • Operating system and version
  • Device type, screen resolution, and colour depth
  • Installed fonts and plugins (enumerated, not individually stored)
  • Timezone and language settings
  • Network characteristics (connection type, ISP ASN)
  • WebGL renderer and GPU information (for canvas fingerprinting detection)
  • Cookie and JavaScript support flags

4.2 Purpose and Use

Device characteristic data is processed exclusively for the following security purposes:

  • Account takeover prevention: Detecting anomalous login attempts from unrecognised devices
  • Fraud and AML risk scoring: Assigning a session risk indicator to support transaction monitoring obligations under Estonia's MLTFPA and India's PMLA
  • Bot and automation detection: Distinguishing legitimate user sessions from automated scripts or credential-stuffing attacks
  • Trusted device management: Recognising previously verified devices to reduce MFA friction for legitimate users

Device characteristics are never used for advertising, profiling, or behavioural targeting.

4.3 Retention and Legal Basis

Cookie / SignalRetentionLegal Basis
fp_token — Device fingerprint token90 daysLegitimate Interests (GDPR Art. 6(1)(f)) + Legal Obligation (AML)
risk_score — Session risk indicatorSession onlyLegitimate Interests (GDPR Art. 6(1)(f)) + Legal Obligation (AML)
Raw device attribute signals90 days (security logs)Legitimate Interests (fraud detection) + Legal Obligation

A three-part Legitimate Interests Assessment (LIA) has been conducted for device fingerprinting and risk scoring.

5. Legal Basis for Each Cookie Category

CategoryLegal BasisConsent Required?Can Be Disabled?Impact If Disabled
Strictly NecessaryContract necessity and service delivery (Art. 6(1)(b))No — exemptNoService non-functional
Security / Fraud PreventionLegitimate Interests (Art. 6(1)(f)) + Legal Obligation (Art. 6(1)(c)) for AMLNo — exemptNoIncreased fraud/account risk
FunctionalConsent (Art. 6(1)(a))YesYesReduced personalisation
AnalyticsConsent (Art. 6(1)(a))YesYesNo product impact to user
MarketingConsent (Art. 6(1)(a))YesYesNot currently used

6. Third-Party Cookie Providers

The following third-party providers may set cookies or collect data through the Service. All are bound by GDPR Article 28 Data Processing Agreements (DPAs). We provide a direct link to each provider's privacy notice for your independent review.

ProviderCategoryPurposeData LocationPrivacy Notice
PostHogAnalyticsProduct usage analytics, session analysis, funnel tracking, error eventsEU (eu.posthog.com) — SCC fallback for non-EU sub-processorsposthog.com/privacy
Amazon Web Services (AWS)InfrastructureCloud hosting, content delivery, and application infrastructureEU-West primary; SCC + TIA for non-EU processingaws.amazon.com/privacy
TurnkeySecurityNon-custodial wallet infrastructure; device trust tokens for wallet operationsUS — SCC + TIA on fileturnkey.com/privacy-policy

Note: Where payment processing services are activated (subscription billing), a payment processor will set security tokens. This section will be updated with the processor's name, cookie details, and privacy notice when payment infrastructure is finalised.

7. International Transfers Related to Cookie Data

Some cookie data, including analytics event data collected by PostHog and device identifiers processed by Turnkey, may be transferred to servers located outside the European Economic Area (EEA), principally to the United States. We ensure such transfers are lawful under GDPR Chapter V.

ProviderData TransferredDestinationTransfer Mechanism
PostHogAnalytics event data, pseudonymous user identifiers, session metadataEU (primary); US (sub-processors)EU hosting elected; SCCs + TIA for any non-EEA processing
TurnkeyDevice trust tokens, wallet operation security identifiersUnited StatesStandard Contractual Clauses (Module 2) + Transfer Impact Assessment on file
AWSServer-side logs, session tokens (encrypted at rest)EU-West (primary); US (DR failover)AWS EU regions primary; SCCs + AWS DPA for non-EU failover

8. Your Choices

8.1 Cookie Preference Centre

On your first visit to the Service, our consent banner will present you with granular category choices. You may:

  • Accept all non-essential cookie categories
  • Accept strictly necessary and security cookies only (minimum functional level)
  • Customise consent by individual category (functional, analytics, marketing)

Your choices are stored in the consent_prefs cookie (strictly necessary) so you are not re-prompted on every visit. You can update your preferences at any time by clicking "Cookie Settings" in the footer of every page.

Withdrawal of Consent

You may withdraw your consent at any time via the Cookie Preference Centre. Withdrawal will not affect processing conducted before withdrawal. Upon withdrawal, non-essential cookies are deleted from your device and no new non-essential data collection will occur during future sessions.

We maintain records of consent preferences as required by GDPR Article 7(1), including the timestamp of consent, the version of the policy in effect at the time, and the categories accepted.

8.2 Browser-Level Cookie Controls

You can also manage cookies directly through your browser settings:

  • Google Chrome: support.google.com/chrome/answer/95647
  • Mozilla Firefox: support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
  • Apple Safari: support.apple.com/en-gb/guide/safari/sfri11471/mac
  • Microsoft Edge: support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge

Note: Deleting or blocking strictly necessary cookies via your browser will prevent the Service from functioning correctly. Browser-level deletions do not update your recorded consent preferences in our system, use the Cookie Preference Centre for that purpose.

8.3 Do Not Track (DNT)

The "Do Not Track" browser signal lacks a universally agreed standard, and its legal status is not definitively established under GDPR or ePrivacy. Our approach is as follows: we do not rely on DNT signals as a substitute for the consent mechanism described in Section 8.1. Non-essential cookies are only activated upon your explicit consent through our Cookie Preference Centre, regardless of DNT signal status. If you wish to prevent non-essential tracking, please use the Cookie Preference Centre.

9. Mobile Application

Our mobile application does not use browser cookies. Instead, it uses SDK-based identifiers stored in secure device storage. The PostHog mobile SDK collects equivalent analytics event data (feature interactions, session metadata) on the basis of your in-app consent, obtained during onboarding through an equivalent consent flow to our web Cookie Preference Centre.

You can opt out of device-level tracking at the operating system level via:

  • iOS 14.5+: Settings → Privacy & Security → Tracking → Disable per-app or globally
  • Android 12+: Settings → Privacy → Ads → Opt out of Ads Personalisation (or equivalent per manufacturer)

Opting out at the OS level will disable analytics SDK event collection. Security and authentication identifiers (equivalent to strictly necessary cookies) are not affected by OS-level tracking opt-outs and remain active to ensure account security.

10. Browser Storage Technologies

In addition to cookies, the Service uses two browser-native storage mechanisms. Unlike cookies, these are not transmitted automatically with every HTTP request, they exist only in your browser and are accessed only by our JavaScript running on the page.

TechnologyWhat We StorePurposeRetentionLegal Basis
Local StorageUI theme preference (light/dark), onboarding progress indicator, last-seen dashboard tabPersistent UI state across browser sessions to avoid re-configuring interface on each visitUntil cleared by user or app resetConsent (functional preference data)
Session StorageTemporary multi-step form state, in-progress rule builder data, navigation breadcrumbsPreserves form data during a single browser session to prevent data loss on back-navigationCleared automatically when the browser tab is closedContract necessity / strictly necessary for service delivery

Local storage used for functional preferences (theme, tab state) is cleared when you withdraw consent from the Functional category in our Cookie Preference Centre. Session storage data is strictly necessary and not subject to consent controls.

11. Blockchain Interactions

When you connect a non-custodial wallet and execute transactions through the Service, those transactions are broadcast to and recorded on a public distributed ledger. This data is not governed by this Cookie Policy.

Public blockchain records, including your wallet address and transaction history, may remain visible indefinitely and cannot generally be modified or deleted by any party, including BayLeaf OÜ. These records are public by design and do not constitute personal data under our control for the purposes of GDPR erasure rights. See our Privacy Policy (§6) for full disclosure.

12. Cookie Retention Overview

Cookie / TechnologyCategoryMax RetentionRenewal Trigger
session_idStrictly NecessarySession (tab close)Each new login
csrf_tokenStrictly NecessarySession (tab close)Each new session
device_trustStrictly Necessary30 daysRe-authentication or new device
consent_prefsStrictly Necessary12 monthsConsent change or policy update
fp_tokenSecurity90 daysDevice change or security event
risk_scoreSecuritySessionEach page load
ui_themeFunctional12 monthsPreference change or consent withdrawal
lang_prefFunctional12 monthsLanguage change or consent withdrawal
onboarding_stepFunctional7 daysOnboarding completion or consent withdrawal
ph_phc_* (PostHog)Analytics12 monthsConsent withdrawal; reset to anonymous on withdrawal
Local Storage (UI/UX state)FunctionalPersistent until clearedCleared on functional consent withdrawal
Session Storage (form state)Strictly NecessaryTab/session closeAutomatic on close

13. Compliance Commitments

13.1 Cookie Audit Commitment

We periodically review our use of cookies and tracking technologies to ensure continued compliance with GDPR, the ePrivacy Directive, and guidance from the Estonian Data Protection Inspectorate (AKI) and the European Data Protection Board (EDPB). Our cookie audit cycle targets review at least every 12 months, or immediately following:

  • Addition of a new third-party service that places cookies
  • Material changes to the purpose or retention of existing cookies
  • New regulatory guidance from AKI, EDPB, or a competent court

13.2 Consent Records

We maintain records of consent preferences where required by law (GDPR Article 7(1)). Our consent management system logs the following for each consent event:

  • Timestamp of the consent action
  • Categories consented to and categories declined
  • Cookie Policy version in effect at time of consent
  • Pseudonymous session identifier (not personal data)

These records are retained for 3 years and are available to competent supervisory authorities upon lawful request.

13.3 ePrivacy and CJEU Compliance

Our consent mechanism is designed to meet the standards established in Planet49 (C-673/17) and Orange România (C-61/19). Specifically: consent is obtained through an unambiguous affirmative action (a button click, not a pre-ticked box); refusing non-essential cookies is as easy as accepting them; and the consent banner clearly explains the purpose of each cookie category before consent is requested.

14. Changes to This Policy

We update this Cookie Policy as we add new tools, in response to regulatory developments, or following our periodic cookie audit. We distinguish between two categories of change:

  • Material changes: adding a new cookie category, adding a new third-party processor, or changing the purpose or retention of an existing cookie. These require a new consent event through the Cookie Preference Centre and are communicated via an in-banner notice or email at least 14 days before taking effect.
  • Non-material changes: clarifying language, corrected provider links, or administrative updates. The "Last Updated" date is updated, but no fresh consent is required unless a new cookie category is activated.

The authoritative version of this policy is always the current version at tomorrowswallet.com/cookies.