Cookies and Tracking Technologies Policy
UffPay - Website (www.uffpay.com) and Mobile Applications | Effective date: July 1, 2026 | Version 2026.1
This Cookies and Tracking Technologies Policy (this "Policy") explains how UffPay Tech, Inc. and its subsidiary UffPay, Sociedad Anónima (together, "UffPay", "we", "us", or "our") use cookies, software development kits ("SDKs"), pixels, device identifiers, and similar technologies (collectively, "Cookies and Similar Technologies") on our website at www.uffpay.com (the "Website") and in our mobile applications (the "Apps", and together with the Website, the "Services"). It also describes the categories of information these technologies collect, the choices you have, and, for our Apps, the disclosures we make through the Apple App Store and Google Play app-store frameworks.
Please read this Policy together with our Privacy Policy and our Terms of Use / Terms of Service, which describe more fully how we handle personal information. By continuing to use the Services, and, where required by law, by giving your consent through our cookie banner or in-app permission prompts, you agree to the use of Cookies and Similar Technologies as described in this Policy. You can change your choices at any time as described in Section 12 (Your Choices and How to Manage Tracking).
1. Who We Are
The Services are operated by:
- UffPay Tech, Inc., a corporation organized under the laws of the State of Florida, United States of America (the parent company that owns the technology of the group).
- UffPay, Sociedad Anónima ("UffPay SA"), a Guatemalan company (subsidiary) that operates the licensed technology in Guatemala; registered address: Carretera a El Salvador 1-16, Apartamento 1, Fraijanes, Guatemala.
Depending on your country of residence and the Service you use, one or both entities may act as the party responsible for (controller of) the personal information processed through Cookies and Similar Technologies. For any question, or to exercise your rights, contact us at support@uffpay.com (see Section 17, Contact Us).
2. Scope of This Policy
This Policy applies to Cookies and Similar Technologies that we and our authorized service providers use:
- on the Website when you browse, register, or interact with our pages; and
- in the Apps when you download, open, or use them (through SDKs, software libraries, local storage, and device or advertising identifiers rather than browser cookies, which do not exist inside a native app).
This Policy does not govern the privacy practices of third parties that operate their own websites, apps, or services that may be linked from ours. When you follow a link to a third-party service, that third party's own privacy and cookie notices apply.
3. What Are Cookies and Similar Technologies?
Cookies are small text files that a website places on your device (computer, tablet, or phone) when you visit. They allow the site to recognize your device, keep your session active and secure, remember your preferences, and understand how the site is used. Cookies set by the site you are visiting are called first-party cookies; cookies set by another organization (for example, an analytics provider) are called third-party cookies. A session cookie is deleted when you close your browser; a persistent cookie remains for a set period or until you delete it.
In addition to cookies, we and our providers use other technologies that perform similar functions:
- Pixels, tags, and web beacons - tiny, often invisible images or code snippets embedded in a page or email that record activity, such as whether a page was viewed or an email opened.
- Local storage and session storage - data stored by your browser or by an App on your device to remember settings, cache content, or maintain state.
- Software Development Kits (SDKs) - code libraries integrated into our Apps by us and by trusted providers to enable functionality, security, analytics, crash reporting, and (where permitted) measurement.
- Device and advertising identifiers - identifiers assigned to your device, including the Apple Identifier for Advertisers (IDFA), the Google Advertising ID (AAID / GAID), and similar mobile or hardware identifiers, as well as internet protocol (IP) addresses.
- Server logs - records automatically generated when you use the Services (for example, IP address, device and browser type, timestamps, and pages or screens accessed).
For readability, we refer to all of the above collectively as "Cookies and Similar Technologies."
4. Why We Use Cookies and Similar Technologies
We use these technologies to:
- operate and secure the Services, including session management, load balancing, authentication, and fraud prevention;
- remember your settings, language, and preferences;
- understand how visitors and users interact with the Services so we can measure, maintain, and improve them;
- detect, investigate, and prevent fraudulent, unauthorized, or unlawful activity, and to protect our users, our systems, and the public;
- comply with our legal, regulatory, and anti-money-laundering / counter-terrorist-financing obligations; and
- where you have consented, measure the performance of, and (if applicable) personalize, marketing communications.
5. Categories of Cookies and Similar Technologies We Use
We group the technologies we use into the following categories. Only Strictly Necessary technologies are used without your consent; all others are used only where you have consented (or as otherwise permitted by applicable law).
Strictly necessary (essential)
Required to operate the Services securely and to provide features you request. They enable core functions such as session management, load balancing, authentication and log-in, network security, and fraud prevention. Because the Services cannot function properly without them, they are not subject to consent and cannot be switched off through our cookie controls; you may block them through your browser, but parts of the Services may then not work.
Functional (preferences)
Enable enhanced functionality and personalization, such as remembering your language, region, display preferences, and choices you have made. If you do not allow these, some features may not work as intended.
Analytics and performance
Help us understand how visitors and users find and use the Services - for example, which pages or screens are visited most, how users move through the Services, and whether errors occur - so we can improve our content, design, and reliability. This information is used in aggregated or de-identified form and is not used to identify you personally.
Platform, hosting, and security
Set by the platform that powers the Website and by our hosting and security providers to deliver the site, balance traffic, protect against attacks, and maintain basic functionality.
Advertising and measurement (only if enabled and consented)
Where we run marketing campaigns, these technologies help us measure whether a campaign was effective and, if applicable, show more relevant content. We use them only with your consent, and, in our Apps, only after you grant permission through the applicable app-store framework (see Section 8). We do not sell your personal information for money.
6. Specific Cookies and Providers
The specific Cookies and Similar Technologies in use, their providers, purposes, and durations can change as we improve the Services. The current, itemized list, including each item's name, provider, category, and retention period, is made available and kept up to date through our Cookie Preferences tool on the Website (and through the in-app privacy settings for the Apps). Representative examples by category include:
- Strictly necessary - first-party session and security cookies (for example, session, authentication, load-balancing, and anti-fraud tokens); typically session-based or short-lived.
- Functional - first-party preference cookies (for example, language or region); typically persistent for up to 12 months.
- Analytics and performance - first- and third-party analytics cookies and SDKs used to generate aggregated usage statistics; typically persistent for up to 24 months.
- Platform, hosting, and security - cookies set by our website platform and hosting/security providers for delivery and protection; duration as set by those providers.
Where a durable cookie table is required by local law, it is provided through the Cookie Preferences tool and forms part of this Policy by reference.
7. Third Parties and Data Recipients
Some Cookies and Similar Technologies are set, or the information they collect is received, by trusted third parties that provide services to us, such as:
- Hosting and website-platform providers, which host and deliver the Website and its security features;
- Analytics providers, which help us measure and improve the Services;
- Security, fraud-prevention, and payment-network providers (for example, card-network risk tools), which help us keep the Services and transactions secure; and
- Communications and support providers, which help us respond to your inquiries.
These third parties process information under contract and only for the purposes we specify. They may act as our processors or, in limited cases and only where permitted by law and your choices, as independent controllers under their own privacy notices. We do not authorize them to use the information for their own unrelated purposes.
8. Mobile Apps - App-Store Tracking and Data Disclosures
Native mobile apps do not use browser cookies; instead, our Apps use SDKs, local storage, and device or advertising identifiers. In addition to this Policy, Apple and Google require us to disclose our data practices through their respective app-store frameworks, and we maintain those disclosures consistently with this Policy.
8.1 Apple App Store - App Privacy and App Tracking Transparency (ATT)
For our iOS App, Apple requires an App Privacy disclosure (the "privacy label") on the App Store product page describing the categories of data we and our partners collect and how they are used. Consistent with Apple's framework, we classify data as:
- Data Used to Track You - data linked to your identity that is used to track you across apps and websites owned by other companies, or shared with a data broker. We do this only if you grant permission (see below), and we do not use your data for such cross-context tracking without it.
- Data Linked to You - data associated with your identity or account (such as account identifiers or transaction information).
- Data Not Linked to You - data collected in a way that is not tied to your identity (such as aggregated diagnostics).
Consistent with Apple's App Tracking Transparency (ATT) requirement, our App will request your permission through the system prompt before it tracks you or accesses your device's advertising identifier (IDFA) for tracking across apps and websites owned by other companies. If you do not grant permission, we will not track you in that way. You can review or change this choice at any time in your device settings under Settings > Privacy & Security > Tracking.
Under Apple's rules, "tracking" means linking data collected from our App about you or your device (such as a user ID or device ID) with data collected about you from other companies' apps, websites, or offline properties for targeted advertising or advertising measurement, or sharing such data with a data broker. We do not condition any App feature on your granting tracking permission, and we do not offer incentives to obtain it. Importantly, when we use data solely for fraud detection, fraud prevention, or security purposes, that use is not considered "tracking" under Apple's rules; as a financial-services provider, we use data for these protective purposes independently of your ATT choice.
8.2 Google Play - Data Safety
For our Android App, Google Play requires a Data Safety disclosure on the store listing describing the data our App collects (transmits off your device) and shares (transfers to a third party), the purposes, and our security practices, including data handled through any third-party libraries or SDKs. Consistent with that framework, our Data Safety disclosure states, for each applicable data type: whether it is collected, shared, or both; the purposes of processing (such as app functionality, analytics, fraud prevention and security, developer communications, and, where applicable, advertising); whether data is encrypted in transit; whether you can request that your data be deleted; and whether the collection of that data type is required or optional. We keep our Data Safety declaration accurate and aligned with this Policy and our Privacy Policy.
Where our App accesses or collects personal or sensitive data in a way that may not be within your reasonable expectation, we provide a prominent in-app disclosure and obtain your affirmative consent (for example, by tapping to accept) before that collection begins, consistent with Google Play's User Data policy.
8.3 Advertising identifiers and controls on mobile
Our Apps may access the Apple IDFA or the Google Advertising ID (AAID) only where permitted and, for tracking, only with your consent. For non-advertising purposes such as analytics, security, and fraud prevention, we rely on non-advertising identifiers (for example, the Android App Set ID) rather than the advertising identifier, and we declare the required advertising-ID permission on Android where applicable. You can control the advertising identifiers at the operating-system level:
- iOS - manage tracking under Settings > Privacy & Security > Tracking; you may turn off "Allow Apps to Request to Track."
- Android - under Settings > Privacy > Ads, you can delete your Advertising ID or reset it, which prevents apps from using it to build a profile or serve personalized ads; when deleted, requests for the identifier return only zeros.
9. Categories of Information Collected Through These Technologies
Through Cookies and Similar Technologies (and, for the Apps, the store frameworks described above), we and our providers may collect the following categories of information. This mapping is designed to align with the Apple App Privacy and Google Play Data Safety categories. The specific data actually collected depends on how you use the Services and the choices you make.
- Identifiers - device identifiers, advertising identifiers (IDFA / AAID), cookie and SDK identifiers, IP address, and account or user identifiers.
- Usage data - interactions with the Services, pages or screens viewed, features used, referring pages, and session information.
- Diagnostics / performance data - crash logs, performance metrics, and error data used to keep the Services reliable.
- Device and connection information - device type and model, operating system and version, browser type, language, and approximate location derived from IP address (we do not collect precise GPS location through cookies).
- Financial and transaction information - where relevant to a secured or authenticated session or to fraud prevention, limited information about your activity within the Services (handled in accordance with our Privacy Policy and applicable financial-services and anti-fraud rules).
- Communications - information you provide when you contact support or submit a form.
We collect these categories for the purposes described in Section 4 (operation and security, fraud prevention, analytics and improvement, legal compliance, and, with consent, measurement and personalization). We do not knowingly use these technologies to collect special-category or sensitive data for advertising, and we do not sell your personal information for money.
10. Legal Bases and Consent
We rely on the following legal bases, depending on where you are located and the category of technology:
- Strictly necessary technologies - used on the basis of our legitimate interest in operating and securing the Services and in performing the contract to provide them to you; consent is not required for these.
- All other technologies - used only with your consent, obtained through our cookie banner (Website) or the applicable permission prompt (Apps), which you may withdraw at any time.
Region-specific notes:
- European Economic Area, United Kingdom, and similar regimes - under the ePrivacy rules and the General Data Protection Regulation (GDPR), we obtain your prior opt-in consent before placing non-essential cookies or similar technologies, and you may withdraw consent at any time.
- United States - depending on your state (for example, under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and comparable comprehensive state privacy laws), you may have the right to opt out of the "sale" or "sharing" of personal information and of targeted or cross-context behavioral advertising, and to limit the use of your sensitive personal information. We honor recognized universal opt-out preference signals, including the Global Privacy Control (GPC), and we treat such a signal as a valid opt-out request across the U.S. states that require it; where applicable, we also display a confirmation that your opt-out preference signal has been processed. We do not sell your personal information for money. Certain data we process is governed by federal financial-privacy laws (such as the Gramm-Leach-Bliley Act) and may be exempt from some state-law rights; the choices in this Policy apply to the cookie and tracking data that remains in scope.
- Guatemala - we process personal data on the basis of your consent and in accordance with the constitutional right of habeas data and applicable Guatemalan law, and consistently with the data-protection commitments in our Privacy Policy.
11. International Transfers
UffPay operates as a group with its parent in the United States and operations in Guatemala, and it uses service providers that may process information in other countries. As a result, information collected through Cookies and Similar Technologies may be transferred to, stored in, or accessed from countries other than your own, including the United States. Where such transfers occur, we apply appropriate safeguards consistent with applicable law and with our Privacy Policy.
12. Your Choices and How to Manage Tracking
You have several ways to control Cookies and Similar Technologies:
- Cookie Preferences tool (Website) - use the cookie banner or the "Cookie Preferences" / "Manage Cookies" link on the Website to accept, reject, or customize non-essential categories, and to withdraw consent at any time.
- Browser settings - most browsers let you view, block, or delete cookies and clear local storage. Blocking strictly necessary cookies may cause parts of the Services to stop working. Guidance is available in your browser's help pages.
- Mobile device settings - control app tracking and advertising identifiers through your device settings, as described in Section 8.3 (iOS Tracking controls; Android delete/reset Advertising ID).
- Universal opt-out signals - we honor the Global Privacy Control (GPC) and similar browser- or device-based universal opt-out signals as a valid request to opt out of the sale or sharing of personal information where the law requires it, and, where applicable, we confirm that your signal has been processed.
- "Do Not Sell or Share My Personal Information" and "Limit the Use of My Sensitive Personal Information" - where applicable, use the corresponding links or controls we provide to exercise these rights.
- Analytics and advertising opt-outs - where offered by our providers, you can use their opt-out mechanisms; industry opt-out tools may also be available in your region.
You may also have the right, depending on where you live, to access, correct, delete, or port the personal information we hold about you, and to not be discriminated against for exercising your rights. These rights, and how to exercise them (including through an authorized agent), are described in our Privacy Policy; you can also contact us using the details in Section 17.
Your choices are specific to each browser and device, so you may need to set your preferences on each one you use.
13. Data Retention
Cookies and Similar Technologies are retained only for as long as needed for the purpose for which they were set: session technologies expire when you end your session; persistent technologies expire after the period stated in our Cookie Preferences tool or until you delete them. Information collected through these technologies is retained in accordance with our Privacy Policy and applicable legal, regulatory, and record-keeping requirements, after which it is deleted or de-identified.
14. Security
We protect information collected through Cookies and Similar Technologies using appropriate technical and organizational measures, including encryption in transit, access controls on a least-privilege basis, and monitoring. No method of transmission or storage is completely secure, but we work to protect your information and to maintain the integrity of the Services.
15. Children's Privacy
The Services are intended for adults and are not directed to children. We do not knowingly use Cookies and Similar Technologies to collect personal information from children in violation of applicable law. If you believe a child has provided information to us, please contact us so we can take appropriate action.
16. Changes to This Policy
We may update this Policy from time to time to reflect changes in technology, our practices, or legal requirements, including updates to the Apple App Store and Google Play disclosure frameworks. When we make material changes, we will update the "Effective date" above and, where appropriate, provide additional notice. The latest version will always be available on this page. We keep this Policy consistent with our Apple App Privacy label, our Google Play Data Safety disclosure, our in-app consent prompts, and our website consent-management tool, and we work to keep all of them accurate and current.
17. Contact Us
If you have questions about this Policy or our use of Cookies and Similar Technologies, or if you wish to exercise your privacy rights, contact us:
- Email: support@uffpay.com
- UffPay Tech, Inc. - Florida, United States (parent company).
- UffPay, Sociedad Anónima - Carretera a El Salvador 1-16, Apartamento 1, Fraijanes, Guatemala.
- Website form: you may also use the contact form on www.uffpay.com.
We will respond to your inquiry within a reasonable time and in accordance with applicable law.
