Cookie Policy
TradeFinanceAI sets four cookies. Three are strictly necessary — without them you cannot sign in or stay signed in safely — and one records the cookie choice you make, so we do not have to ask you again. We set no advertising cookies and no third-party tracking cookies at all.
01Strictly necessary cookies
These cannot be turned off, because the platform cannot authenticate you without them. They are set only once you sign in, and they are removed when you sign out.
| Cookie | Purpose | Lifetime |
|---|---|---|
| tfa_user | Your customer session. An opaque random identifier — it contains no personal data and cannot be
read by page scripts (httpOnly). Sent only over HTTPS, and not sent when another site
links to us (SameSite=Lax). |
Session, or up to 30 days with "Keep me signed in" |
| tfa_admin | The equivalent session cookie for platform staff signing in to the administration portal. Never set on a customer account. | Session |
| tfa_csrf | A security token bound to your session. Every action that changes something must echo this token
back in a request header, which is what stops another website from making your browser act on your
account. Deliberately readable by our own page scripts — and useless without the session cookie,
which is not. Never sent cross-site (SameSite=Strict). |
8 hours |
| tfai_consent_v1 | Stored in your browser's local storage rather than as a cookie: the choice you made below, so the notice is not shown again. Contains only your own preference. | Until you clear it |
02Optional cookies
Two optional categories exist, and both are off unless you switch them on. Nothing is set for either category before you consent, and withdrawing consent stops it immediately.
| Category | What it would be used for | Default |
|---|---|---|
| Product analytics | Aggregate measurement of which features are used, to prioritise work. Never used to build a profile of you, and never shared with an advertising network. | Off |
| Product marketing | Emails about new capabilities. Your existing service and billing notices are contractual and are sent whatever you choose here. | Off |
03Third parties
Two external origins are loaded by the application, and the platform's Content Security Policy permits no others:
- PayPal — the checkout SDK, loaded only on the checkout screen. PayPal sets its own cookies in that context under its own policy, which is what allows it to take a payment without card data ever reaching us.
- Google Fonts — the typefaces the interface is set in. Fonts are static files and set no cookies.
There are no advertising tags, no social media pixels, no session recording and no cross-site trackers on this platform.
04Changing your mind
Open Settings → Privacy and your data and adjust the analytics and marketing toggles. The change is recorded against your account with a timestamp and takes effect at once. You can also delete cookies for this site in your browser at any time — doing so signs you out, because the session cookie is one of them.
05Consent records
Every choice you make is recorded with the policy version it applied to, the time, and the address it came from, so we can demonstrate what you were asked and what you answered. Those records are covered by the Data Retention Policy.