Cookie Policy
Last Updated: July 2026 · v2.6
This Cookie Policy explains how Mango Technologies Ltd. (DIFC Licensed CL5222) uses cookies on maiviswealth.com. maivis uses cookies for authentication, analytics (opt-in), and conversion measurement (opt-in). We do not use retargeting cookies, lookalike audience technology, or cross-site behavioral advertising.
Note: maivis uses PostHog Cloud EU for in-product analytics. PostHog is a third-party processor on EU infrastructure, it runs in your browser, and it sets a first-party analytics cookie. It is optional and does nothing until you accept analytics cookies. See Section 2.3.
1. What Are Cookies
Cookies are small text files stored on your device when you visit a website. Under the EU ePrivacy Directive (2002/58/EC, as amended by 2009/136/EC) and UK PECR, certain cookies require explicit consent; others are exempt as strictly necessary.
2. Cookies We Use
2.1 Firebase Auth Session Token
Category: Strictly Necessary
Maintains authenticated session after FIDO2/passkey or TOTP sign-in. HttpOnly, Secure, SameSite=Strict. 30-day expiry with refresh; 30-minute idle timeout. Exempt from consent under ePrivacy Article 5(3) (Article 29 Working Party Opinion 04/2012).
2.2 Firebase Analytics (GA4)
Category: Analytics (Optional), Consent Required
Tracks anonymized page views, scroll depth, CTA clicks, and conversion funnels on the maiviswealth.com landing page. IP anonymization enabled. Google processes data within the EEA under a GDPR-compliant DPA. 2-year cookie persistence. Analytics cookies do not qualify for the strictly necessary exemption (confirmed by ICO and CNIL). For EU/UK members, GA4 cookies are blocked until explicit opt-in consent.
2.3 PostHog Product Analytics
Category: Analytics (Optional), Consent Required
Records how the product is used: feature interactions, screen views, funnel completion, heatmaps, and session replay on a small number of pre-login pages. Provided by PostHog Cloud EU, a third-party processor on EU infrastructure, under a Data Processing Agreement. Sets a first-party cookie (ph_*) alongside browser localStorage, 1-year persistence. Session replay masks all form inputs, so values you type are not captured. Analytics cookies do not qualify for the strictly necessary exemption: nothing is set and no event is sent until you give explicit opt-in consent, and a browser Global Privacy Control or Do Not Track signal keeps it off.
2.4 Stripe Payment Cookies (not currently set)
Category: Functional
maivis is free of charge and has no checkout page, so no Stripe cookie is set on any maivis page today. This entry describes what would apply only if a paid plan were introduced in the future: session-only cookies, active exclusively on a checkout page, for fraud detection and payment processing of the maivis subscription itself. Stripe is PCI DSS Level 1 compliant. Payment-processing cookies directly related to a user-initiated transaction are likely exempt from consent; Stripe fraud-detection cookies are assessed individually. No cookie described here relates in any way to your own bank accounts, which maivis only ever reads.
2.5 CSRF Protection Token
Category: Strictly Necessary
Session-only security token preventing cross-site request forgery. Exempt from consent as strictly necessary for security.
3. Cookie Categories Summary
| Cookie | Provider | Category | Purpose | Duration | Consent? |
|---|---|---|---|---|---|
| __session | Firebase Auth | Strictly Necessary | Auth session (HttpOnly, Secure, SameSite=Strict) | 30 days | No, exempt ePrivacy Art. 5(3) |
| ph_* | PostHog | Analytics (Optional) | Product analytics: feature usage, funnels, heatmaps, session replay (inputs masked). Opt-in only; not set until consent accepted. | Cookie + localStorage (1 year) | Yes, opt-in (DIFC DPL 2020) |
| _ga, _ga_* | Firebase Analytics (GA4) | Analytics (Optional) | Page views, scroll, CTA clicks (landing page only) | 2 years | Yes, opt-in (EU/UK) |
| __stripe_* | Stripe | Functional | Not currently set. maivis is free and has no checkout page. Would apply only to a future paid plan: payment fraud detection on a checkout page (Section 2.4). | Session | Exempt for payment; assess fraud cookies |
| _csrf | maivis | Strictly Necessary | CSRF prevention | Session | No, exempt as security |
4. Third-Party Cookies
PostHog: EU-hosted (PostHog Cloud EU). PostHog DPA in place. Sets a first-party analytics cookie and stores an anonymous identifier. Opt-in only; nothing is set and no event leaves your browser until you accept analytics cookies.
Firebase Analytics (GA4): Google-hosted with EEA data processing. GDPR-compliant DPA with Google LLC (via GCP CDPA). IP anonymization enabled.
Stripe: US-hosted. PCI DSS Level 1. EU-US adequacy decision + SCCs. Sets no cookie on maivis today: maivis is free of charge and has no checkout page. This entry would apply only during the payment flow of a future paid plan.
Google Search Grounding (AI market data): No cookies are set. Google Search Grounding is used server-side only, via the Gemini Enterprise Agent Platform (Google Cloud global endpoint, US/EU data centers with Zero Data Retention), to retrieve real-time market information (e.g. FX rates, central bank rates, regulatory updates). Only anonymized query text is sent. Never family data, names, account numbers, or asset values. No data is stored or used for training by Google under the ZDR agreement. Governed by Google Cloud DPA. See the DPA for full sub-processor terms.
maivis does not use retargeting cookies, lookalike audience technology, cross-site behavioral advertising, or any third-party advertising pixels. Analytics are limited to PostHog and Firebase Analytics, both opt-in only and blocked until you explicitly accept analytics cookies via our consent banner.
Separately from cookies, we may analyze aggregate, anonymized patterns across our user base (for example, general demographic or asset-holding characteristics) to inform which broad audience categories we target when running advertising campaigns on third-party platforms. This does not involve any cookie, pixel, or tracking technology on maiviswealth.com beyond those listed in this Policy, and it never involves uploading, sharing, or matching any individual member's name, email address, phone number, or other personal contact information with an advertising platform. See our Privacy Policy, Section 8A, for detail.
5. Jurisdiction-Specific Requirements
5.1 EU/UK (GDPR + ePrivacy + PECR)
Opt-in model: GA4 cookies blocked until explicit consent. Our consent banner offers a clear binary choice with equal visual prominence: "Accept" (opt in to analytics) and "Decline" (the equivalent of "Reject All"). No analytics cookies are set. We do not load any analytics cookies before you accept, so declining is identical to a granular rejection of every optional category. No pre-checked boxes, no cookie walls. Each choice is documented with a timestamp and the policy version (see Section 6). Renewal: 12-month cycle (CNIL recommends 6 months, German DPAs 6-12, Spanish AEPD 24).
5.2 US/California (CCPA/CPRA)
Opt-out model. maivis does not sell/share PI via cookies. GPC browser signals honored automatically.
5.3 DIFC/UAE
DIFC DP Law does not impose specific cookie consent requirements. We apply the EU/UK opt-in standard as best practice.
5.4 India (DPDPA 2023)
No specific cookie provisions. We apply the EU/UK consent mechanism for Indian members.
6. Consent Storage
When you interact with our cookie banner, your consent preference is stored in your browser’s localStorage under the key maivis_consent as a JSON object containing your choice and a timestamp. This preference persists for 365 days, after which the banner reappears for renewed consent.
PostHog analytics is initialized with opt_out_capturing_by_default: true. No PostHog analytics data is collected until you explicitly accept via the cookie banner, at which point PostHog opt-in is activated. Rejecting or dismissing the banner keeps PostHog opted out. This ensures compliance with DIFC DPL 2020 Article 11.
In addition to the browser-side preference, each accept, decline, or withdrawal is recorded server-side as a consent receipt containing a timestamp, the policy version you were shown, and whether a browser privacy signal (GPC/DNT) was present. The receipt contains no name, email, or account identifier; you are referenced only by a random browser-local token. This gives us demonstrable proof of consent as required by GDPR Article 7(1) and DIFC DPL 2020, without collecting additional personal data.
7. How to Manage Cookies
Cookie banner on first visit: Accept or Decline. You can change or withdraw your choice at any time using the "Manage cookies" link in the site footer, which re-opens the banner. Browser settings: Chrome (chrome://settings/cookies), Safari (Preferences > Privacy), Firefox (about:preferences#privacy). To opt out of analytics: decline on the banner (or withdraw later via "Manage cookies"), email privacy@maiviswealth.com, or enable DNT/GPC in your browser.
8. Do Not Track and Global Privacy Control
maivis respects DNT and GPC signals. When detected, GA4 analytics cookies are not set and no usage data is collected. Strictly necessary and functional cookies are unaffected. GPC signals are treated as valid CCPA opt-out requests.
9. Changes
Reviewed annually or when new cookies are added. Material changes notified via site banner. Consent renewal requested at least every 12 months for EU/UK members.
10. Contact
- Privacy:
- privacy@maiviswealth.com
- DPO:
- dpo@maiviswealth.com
- Postal:
- Mango Technologies Ltd., DIFC Innovation Hub, Gate Avenue, Dubai, UAE
Cookie Policy v2.6 · July 2026