1. Introduction
This Cookie Policy explains how Paytex Solutions Ltd., operating under the trade name Monitiva ('we,' 'us,' or 'our'), uses cookies and similar tracking technologies on our website (https://monitiva.com), landing pages, and platform (collectively, the 'Platform').
This policy should be read together with our Privacy Policy and Terms of Use. By using our Platform, you consent to the use of cookies in accordance with this policy, subject to your consent choices as described in Section 5.
Monitiva provides cross-border domestic payment infrastructure through which users maintain a Glocal Account CAD Balance — safeguarded in trust in Canadian dollars — and execute domestic payments in destination countries through a Just-in-Time FX mechanism. Our cookie and tracking infrastructure supports our waitlist campaign, pre-launch analytics, and Platform security. It does not involve sharing any financial data, Glocal Account CAD Balance information, or transaction data with marketing platforms.
1.1 What Are Cookies?
Cookies are small text files placed on your device when you visit a website. They allow the website to recognize your device, remember your preferences, and collect information about how you interact with the site. Cookies can be session (temporary, deleted when you close your browser) or persistent (stored for a set period). They can be first-party (set directly by Monitiva) or third-party (set by external services we use).
1.2 Similar Technologies
In addition to cookies, we use: pixel tags (web beacons — invisible 1x1 images that fire when loaded, transmitting data to a server); local storage (browser-based key-value storage for functional preferences); UTM parameters (URL query string parameters appended by advertising platforms to attribute traffic to campaigns); fingerprinting (limited, for fraud detection and security only — not for advertising profiling); and server-side event tracking (server-to-server event transmission, e.g., Meta Conversions API, used to improve signal accuracy while reducing reliance on browser-based cookies).
2. Legal Basis for Cookie Use
| Jurisdiction | Applicable Law | Key Requirement |
|---|
| Canada (Federal) | PIPEDA | Meaningful consent for non-essential cookies; right to withdraw |
| Quebec | Quebec Act 25 | Express consent for non-essential cookies; cannot be bundled; granular opt-out required |
| Canada (Federal) | CASL s.7 | Computer program installation rules apply to persistent tracking technologies |
| EU / EEA | GDPR + ePrivacy Directive | Prior informed consent for non-essential cookies; strictly necessary exemption |
2.1 Consent Model
We apply a layered consent model: strictly necessary and security cookies require no consent — they are essential for the Platform to function or to protect against fraud. All other cookie categories require your prior, informed, granular, and freely given consent, obtained through our cookie consent banner before any non-essential cookies are set. Quebec residents and EU/EEA users must provide express, affirmative consent for each non-essential category — pre-ticked boxes are not valid. You may withdraw or modify your consent at any time by clicking the 'Cookie Preferences' link in the footer of any page.
3. Cookies We Use
3.1 Strictly Necessary Cookies
These cookies are essential for the Platform to function. They cannot be disabled. No consent is required.
| Cookie / Technology | Provider | Purpose | Data Collected | Duration |
|---|
| session_id | Monitiva (1st party) | Maintains authenticated user session | Session token (opaque identifier, no PII) | Session |
| csrf_token | Monitiva (1st party) | Cross-Site Request Forgery protection | CSRF nonce (cryptographic token) | Session |
| consent_state | Monitiva (1st party) | Stores your cookie consent choices | JSON: category opt-in/out per timestamp | 12 months |
| lang_pref | Monitiva (1st party) | Remembers selected language (EN/FR) | Language code (e.g., 'en', 'fr') | 12 months |
| cf_clearance | Cloudflare (3rd party) | DDoS and bot protection; verifies legitimate browser | Encrypted client token; IP address | 30 minutes |
| __cf_bm | Cloudflare (3rd party) | Bot management and automated traffic filtering | Browser fingerprint signals; IP address | 30 minutes |
3.2 Security and Fraud Detection Cookies
Used to protect the Platform and users from fraudulent activity. Classified as strictly necessary for a regulated financial service. No consent required.
| Cookie / Technology | Provider | Purpose | Data Collected | Duration |
|---|
| device_fp | Monitiva (1st party) | Device fingerprinting for account takeover prevention and fraud pattern detection | Browser signals: UA, screen resolution, timezone, language, canvas hash — no persistent PII | 30 days |
| sumsub_session | Sumsub (3rd party) | KYC verification session management; liveness check continuity | Verification session token; device signals for liveness fraud prevention | Session |
| risk_score_cache | Monitiva (1st party) | Caches transaction risk assessment result | Hashed risk result and timestamp — no raw transaction data | Session |
3.3 Functional Cookies
Enhance usability and personalization. Require consent under Quebec Act 25 and EU ePrivacy.
| Cookie / Technology | Provider | Purpose | Data Collected | Duration |
|---|
| ab_variant | Monitiva (1st party) | Stores landing page variant (A, B, or C) for consistent session experience | Variant letter; session timestamp | Session |
| city_variant | Monitiva (1st party) | Stores selected or URL-detected city variant for personalized landing page | City slug (e.g., 'puerto-vallarta'); source: URL param or self-select | Session |
| utm_persist | Monitiva (1st party) | Persists UTM parameters from ad click through waitlist form submission | utm_source, utm_medium, utm_campaign, utm_content, utm_term | 30 minutes |
| onboarding_step | Monitiva (1st party) | Remembers progress in multi-step onboarding to allow resumption | Step index (integer); no personal data | 7 days |
3.4 Analytics and Performance Cookies
Used to understand Platform usage and improve our services. Require consent. Data is pseudonymized or anonymized where technically feasible.
| Cookie / Technology | Provider | Purpose | Data Collected | Duration |
|---|
| _ga, _ga_* | Google Analytics 4 (3rd party) | Page views, user flow, session analysis, conversion events | Pseudonymous client ID; pages visited; session duration; device/browser; geo (country/city); events. IP anonymized. | 2 years (_ga); 13 months (_ga_*) |
| ph_*, posthog_* | PostHog (3rd party — EU-hosted) | Product analytics; funnel analysis; session recordings (with field masking); feature flag delivery | Pseudonymous distinct_id; event stream; page URLs; referrer; device signals. PII fields masked. | 1 year |
Analytics data is processed under a Data Processing Agreement (DPA). IP addresses are anonymized before storage. Session recordings mask all form fields. We do not enable cross-site tracking or advertising features within our analytics providers.
3.5 Marketing and Attribution Cookies
Used to measure advertising campaign effectiveness and attribute waitlist conversions to specific ads. Require consent. We do not share financial data, Local Balance information, or any data from authenticated platform sessions with marketing platforms.
| Cookie / Technology | Provider | Purpose | Data Collected | Duration |
|---|
| _fbp, _fbc | Meta (Facebook / Instagram) | Meta Pixel: attribution of ad clicks to waitlist conversions; optimization of Meta ad delivery | _fbp: browser ID; _fbc: click ID. Custom event: WaitlistSignup (city, language, profile_type). Hashed email transmitted on form submission with consent. | 90 days |
| Meta CAPI (server-side) | Meta — server-to-server | Meta Conversions API: server-side duplicate of WaitlistSignup event to improve attribution accuracy | Hashed email (SHA-256); event name; event time; action_source. No raw PII transmitted. | Not a cookie — server-side event |
| _gcl_aw, _gcl_au | Google Ads (3rd party) | Google Ads click ID: attribution of Google Search ad clicks to waitlist conversions | _gcl_aw: Google Click ID (gclid) from ad; _gcl_au: Google Ads user ID for conversion linking | 90 days |
Marketing cookies are used exclusively for measuring the performance of our waitlist acquisition campaigns. We do not operate retargeting campaigns based on financial product usage, transaction history, Local Balance data, or any data derived from authenticated platform sessions.
5. Your Consent Choices and Controls
5.1 Cookie Consent Banner
Monitiva uses a Consent Management Platform (CMP) to present, record, and manage cookie consent preferences in compliance with PIPEDA, Quebec Act 25, and GDPR/ePrivacy requirements. The CMP captures a timestamped record of each user's consent choices, including the specific categories accepted or rejected and the version of this Cookie Policy in effect at the time.
When you first visit our Platform, the CMP displays a cookie consent banner before any non-essential cookies are set. The banner presents each non-essential cookie category separately and allows you to accept all, accept only selected categories, or reject all non-essential cookies. Your choices are saved in the consent_state cookie for 12 months. Consent records are retained for a minimum of 3 years as required by CASL s.13.
5.2 Changing Your Preferences
You may update your consent choices at any time by clicking 'Cookie Preferences' in the footer of any page. Changes take effect immediately for new page loads. Previously set non-essential cookies from rejected categories will be cleared upon preference update.
5.3 Quebec Residents — Express Consent
If you are a Quebec resident, each cookie category requires a separate, affirmative action to consent. Pre-selected options do not constitute valid consent under Quebec Act 25. You can access and manage your individual category preferences at any time through the Cookie Preferences panel.
5.4 Browser-Level Controls
Most browsers allow you to control cookies at the browser level. You can configure your browser to block all cookies, block third-party cookies only, delete existing cookies, or be notified before a cookie is set. Note: disabling strictly necessary cookies will prevent the Platform from functioning correctly.
5.5 Opt-Out Links for Third-Party Providers
| Provider | Opt-Out / Control Mechanism |
|---|
| Google Analytics 4 | Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout — or via our Cookie Preferences panel |
| Meta (Facebook / Instagram) | Facebook Ad Preferences: https://www.facebook.com/ads/preferences — or via our Cookie Preferences panel. Note: Meta CAPI server-side events are controlled by withholding consent in our panel. |
| Google Ads | Google Ads Settings: https://adssettings.google.com — or via our Cookie Preferences panel |
| PostHog | Managed via our Cookie Preferences panel. PostHog respects opt-out signals from our consent management system. |
| Cloudflare | Cloudflare security cookies (cf_clearance, __cf_bm) are strictly necessary and cannot be opted out of without disabling DDoS protection for your connection. |
5.6 Global Privacy Control (GPC) and Do Not Track (DNT)
Our Platform honors the Global Privacy Control (GPC) signal as equivalent to a withdrawal of consent for non-essential cookies for users in applicable jurisdictions (including Quebec residents under Act 25). We acknowledge the legacy Do Not Track (DNT) signal as an expression of user preference and apply it where technically feasible.
8. Cookies and the Waitlist Campaign
Our current campaigns run on Meta (Facebook and Instagram) and Google Search, targeting Canadians in Canada and Canadians physically located in Mexico. The following tracking flows apply:
8.1 Landing Page Tracking Flow
| # | Event | Data Transmitted |
|---|
| 1 | User clicks ad on Meta or Google | UTM parameters and click IDs (_fbc, gclid) appended to landing page URL by advertising platform |
| 2 | User lands on monitiva.com/?v=A/B/C&city=xxx | Cookie consent banner displayed. No non-essential cookies set until consent granted. |
| 3 | User accepts analytics and/or marketing cookies | GA4 PageView event fired. Meta Pixel PageView fired. UTM parameters persisted to utm_persist cookie. |
| 4 | User fills and submits waitlist form | WaitlistSignup event fired: city, language, profile_type. Hashed email transmitted to Meta CAPI if marketing consent granted. |
| 5 | Post-submission | No additional tracking. No cookies set from authenticated platform pages. |
8.2 A/B Test Variant Tracking
Landing page variant (A, B, or C) is determined by the URL parameter ?v= and stored in the ab_variant functional cookie for the session duration. Variant data is included in analytics events to measure performance differences between messaging and creative treatments. No personal data is required for variant assignment.
8.3 City Variant Tracking
City-specific landing page content is controlled by the ?city= URL parameter (e.g., puerto-vallarta, los-cabos, cancun). The city value is stored in the city_variant functional cookie and included in the WaitlistSignup event payload to measure geographic demand. City data is self-declared through URL navigation — it does not represent the user's IP-detected location.
9. Updates to This Policy
We may update this Cookie Policy to reflect new technologies, regulatory changes, or modifications to our tracking practices. Material changes will be communicated by updating the version number and effective date, posting a notice on the Platform, and re-presenting the cookie consent banner to collect fresh consent for any newly added categories.
| Version | Date | Summary |
|---|
| 1.0 | April 2026 | Initial version |
| 2.0 | June 2026 | Removed plan_selected from the WaitlistSignup event (§3.5, §8.1) following the migration from subscription plans to per-transaction pricing. Migrated to the Local/Destination lexicon ("Local Balance"). Named Sumsub as the KYC verification provider (§3.2, §7). Removed the "pricing treatment" reference from A/B testing (§8.2). |