Cookie Policy
How and why Universal Quantum uses cookies.
This Cookie Policy explains what cookies and similar browser technologies Universal Quantum uses, why we use them, how you can manage them, and what happens if you disable them. It is read together with our Privacy Policy, which sets out the wider framework for handling your personal data.
1. 1. What cookies are
Cookies are small text files that a website places on your device when you visit. They allow the site to remember information about your visit — for example, whether you are signed in, what theme you prefer, or what language you have selected — so the site does not need to ask again on your next page load. Cookies are used by essentially every modern website.
2. 2. Why we use cookies
We use cookies to keep the Platform working, to keep your session secure, and to remember your preferences. We keep the number and scope of cookies to the minimum needed to run the Platform well. We do not use cookies for behavioural advertising, we do not build cross-site tracking profiles, and we do not sell any information collected through cookies.
3. 3. Categories of cookies we use
The cookies used on the Platform fall into three categories:
- Essential — cookies without which the Platform cannot function correctly. These include the session cookie used to keep you signed in and the token used to protect forms against cross-site request forgery.
- Preference — cookies that remember choices you have made about how the Platform looks and behaves (for example theme, layout, language).
- Analytics — cookies or local-storage entries that help us understand, in aggregate and anonymously, how the Platform is used, so we can improve it.
4. 4. Session vs persistent cookies
Some cookies are erased when you close your browser (session cookies); others remain on your device for a set period (persistent cookies). Session cookies are used for sign-in state and CSRF protection. Persistent cookies are used, for example, to remember your theme choice across visits.
5. 5. First-party vs third-party cookies
First-party cookies are set by the Platform itself. Third-party cookies are set by another service loaded within the Platform (for example, a live-chat provider or an on-chain data widget). We keep third-party cookies to the minimum required to make embedded features work, and any provider we use is expected to handle data in line with our Privacy Policy.
6. 6. Essential cookies — detail
Essential cookies typically include: a session cookie used to keep you signed in as you move between pages; a token used to defend against cross-site request forgery on forms; and a preference entry for cookie-consent state so we do not repeat the consent banner every visit. These are strictly necessary and cannot be turned off without breaking the Platform.
7. 7. Preference & display state
The Platform also uses browser local storage (a similar technology) to remember display choices such as light/dark theme, colour hue, corner radius, whether balance amounts are hidden, and any drafts of deposit or withdrawal forms you are filling in. These entries are stored on your device only and are not sent to our servers unless required for a specific action.
8. 8. Analytics cookies
Where analytics cookies or measurement entries are used, they help us understand aggregate usage — for example, which pages are the most visited, where users drop off, and how the Platform performs on different devices. These insights are used to improve the Platform. We prefer providers that respect user privacy and, where possible, that operate in a cookie-less or fully anonymised way.
9. 9. Third-party services
The Platform integrates a small number of third-party services (for example, transactional email delivery for password resets and notifications, a live-chat widget where enabled from admin settings, and translation and rate-feed providers). Where those services set their own cookies, they do so under their own privacy policies. Review the policies of any third party you interact with.
10. 10. Local storage & similar technologies
In addition to cookies, the Platform uses browser localStorage to remember short-lived state (for example cached market rates for one minute, saved deposit and withdrawal drafts, and cookie-consent state) and sessionStorage for temporary tab-level state. These entries live on your device only and are not sent to our servers automatically.
11. 11. Managing cookies in your browser
All modern browsers let you view, control and delete the cookies stored on your device. Menus vary between browsers, but the setting is typically found under Settings → Privacy and security. You can usually block all cookies, block third-party cookies only, delete existing cookies, or set exceptions for specific sites.
Blocking essential cookies will break sign-in and other core parts of the Platform. Deleting cookies will sign you out and clear your saved preferences.
12. 12. Do Not Track
Some browsers offer a "Do Not Track" (DNT) signal. There is no consistent industry standard for how sites should respond to it. Our practices are the same either way: we do not use cookies for behavioural advertising, and any analytics use is aggregated and non-identifying.
13. 13. Mobile devices
Mobile browsers store cookies and local storage in the same way as desktop browsers. Look under the browser privacy settings on your device to manage them. Any native mobile apps we release in the future will use their own storage mechanisms and will describe their behaviour in the app itself.
14. 14. Consequences of disabling
If you block or delete essential cookies you will not be able to sign in, submit forms or take any action on the Platform. If you block preference cookies and local storage, the Platform will still function but it will not remember your theme, hidden-balance state, or in-progress form drafts. If you block analytics, aggregate usage measurement will be reduced but nothing will break.
15. 15. Cookie consent
The first time you visit the Platform we display a cookie notice explaining that we use cookies and linking to this policy. Continued use of the Platform indicates that you accept the cookies described here. You can revisit or change your choice at any time by clearing your cookies and reloading the Platform.
16. 16. Data protection
Any personal data collected through cookies or similar technologies is handled in accordance with our Privacy Policy. That policy sets out our legal bases, retention periods, sharing practices and the rights you have over your personal data.
17. 17. Changes to this policy
We may update this Cookie Policy from time to time to reflect changes in the Platform, the third-party services we use, or the law. Material changes are announced on the Platform. The effective date at the top of the document shows when the current version came into force.
18. 18. Detailed cookie reference & technical detail
Specific cookies and storage entries. The primary browser-stored items used by the Platform include: a PHP session cookie (name typically PHPSESSID or similar) that identifies your session while you are signed in; a CSRF token entry that lets us verify that form submissions come from a page you loaded; a cookie-consent flag that remembers whether you have seen the cookie notice; theme and colour preferences saved to localStorage; and short-lived caches (for example market rates cached for one minute) saved to localStorage to reduce network round-trips.
Purpose of each item. The session cookie keeps you signed in and is essential. The CSRF token protects your Account from cross-site request-forgery attacks and is essential. The consent flag prevents us from repeating the cookie notice on every visit. Preference entries make the Platform match your look-and-feel choices between visits. Rate caches spare our providers rate-limit pressure and make page loads snappier.
Expiry. Session cookies expire when you close the browser. CSRF tokens are session-scoped. The consent flag is persistent for typically one year. Preference entries persist until you clear them. Rate caches are short-lived by design (a minute or so) and are refreshed automatically.
Storage location. Cookies are stored by your browser in its cookie store. localStorage and sessionStorage are stored by your browser in a separate area from cookies and are not sent to our servers automatically. Clearing site data in your browser also clears these stores.
Not used. The Platform does not use, and does not rely on, third-party advertising cookies, cross-site tracking pixels, browser fingerprinting to build an identity, session-replay recordings, or shared cookies with unrelated services.
Browser fingerprinting. We do not intentionally fingerprint your device (that is, combine device attributes to identify you across sites). Any technical data we collect for security purposes is used for that purpose only.
Global Privacy Control (GPC). Where your browser sends a Global Privacy Control signal, we treat it as an opt-out signal for non-essential processing. This is consistent with the fact that the Platform does not use behavioural advertising or cross-site tracking in the first place.
Tag managers. We do not use a general tag manager that would load arbitrary third-party scripts into the Platform. Every script that runs on the Platform is either first-party code we control or a carefully chosen integration with a specific, disclosed purpose.
Managing cookies — step by step. In Chrome: Settings → Privacy and security → Cookies and other site data. In Firefox: Settings → Privacy & Security → Cookies and Site Data. In Safari: Preferences → Privacy → Manage Website Data. In Edge: Settings → Cookies and site permissions → Cookies and site data. From each of those screens you can view stored items for a specific site, delete them, and set default rules for future visits.
Clearing local storage. Local storage and session storage are cleared from the same "Site data" menu in modern browsers. Alternatively, opening the Platform in a private or incognito window skips the persistent stores entirely for that session.
Impact of blocking cookies. Blocking essential cookies means you cannot sign in or submit any form. Blocking preference cookies and local storage means the Platform will still function but will not remember your theme or in-progress drafts, and the cookie notice may reappear. Blocking analytics reduces aggregate measurement but does not affect functionality.
Mobile browsers. Mobile browsers store cookies and local storage the same way. On iOS Safari: Settings app → Safari → Advanced → Website Data. On Android Chrome: Settings → Site settings → Cookies.
Retention of cookie data. Data collected via cookies is retained in line with the retention rules in our Privacy Policy. Session data is discarded when your session ends; consent state is kept for typically one year; short-lived caches are refreshed automatically.
Changes to third-party providers. If we start or stop using a third-party integration that sets its own cookies (for example a new live-chat provider or a new translation service), this Policy will be updated to reflect the change and the effective date at the top of the document will be updated.
Contact & questions. Detailed questions about a specific cookie or entry can be raised through the contact page with the subject "Cookies". We will provide the requested detail within a reasonable time.
19. 19. Glossary
Cookie — A small text file that a website places on your device to remember information between page loads.
Session cookie — A cookie that is erased when you close the browser.
Persistent cookie — A cookie that remains on your device for a set period.
First-party cookie — A cookie set by the site you are visiting.
Third-party cookie — A cookie set by a service loaded within the site you are visiting.
Essential cookie — A cookie strictly necessary for the site to work (for example sign-in state).
Preference cookie — A cookie that remembers a display or behaviour choice.
Analytics cookie — A cookie used to measure aggregate usage of the site.
localStorage — Browser storage separate from cookies, used for larger client-side state; not sent to servers automatically.
sessionStorage — Browser storage that lives for the tab session only.
CSRF token — A short random value stored to defend against cross-site request-forgery attacks on form submissions.
Do Not Track (DNT) — An older browser signal indicating a user preference not to be tracked.
Global Privacy Control (GPC) — A more recent standard browser signal indicating an opt-out preference for non-essential processing.
Fingerprinting — Combining device attributes to identify a device or user across sites without using cookies.
20. 20. Contact
Questions about our use of cookies or about this policy can be raised through the contact page or by emailing support@universalquantum.net.