Monitiva

Cookies policy

Monitiva - Paytex Solutions Ltd.
Effective Date: Upon publication (July 2026)
Last Updated: June 2026
Version: 2.0

ItemDetail
Legal EntityPaytex Solutions Ltd. dba Monitiva
FINTRAC MSB#C100000118
BoC PSPREG-3961
Cookie Questionscookies@monitiva.com
Privacy Officerprivacy@monitiva.com
Registered Office807-130 Spadina Ave, Unit 807, Toronto, Ontario, M5V 2L4, Canada
Websitehttps://monitiva.com

1. Introduction

This Cookie Policy explains how Paytex Solutions Ltd., operating under the trade name Monitiva ('we,' 'us,' or 'our'), uses cookies and similar tracking technologies on our website (https://monitiva.com), landing pages, and platform (collectively, the 'Platform').

This policy should be read together with our Privacy Policy and Terms of Use. By using our Platform, you consent to the use of cookies in accordance with this policy, subject to your consent choices as described in Section 5.

Monitiva provides cross-border domestic payment infrastructure through which users maintain a Glocal Account CAD Balance — safeguarded in trust in Canadian dollars — and execute domestic payments in destination countries through a Just-in-Time FX mechanism. Our cookie and tracking infrastructure supports our waitlist campaign, pre-launch analytics, and Platform security. It does not involve sharing any financial data, Glocal Account CAD Balance information, or transaction data with marketing platforms.

1.1 What Are Cookies?

Cookies are small text files placed on your device when you visit a website. They allow the website to recognize your device, remember your preferences, and collect information about how you interact with the site. Cookies can be session (temporary, deleted when you close your browser) or persistent (stored for a set period). They can be first-party (set directly by Monitiva) or third-party (set by external services we use).

1.2 Similar Technologies

In addition to cookies, we use: pixel tags (web beacons — invisible 1x1 images that fire when loaded, transmitting data to a server); local storage (browser-based key-value storage for functional preferences); UTM parameters (URL query string parameters appended by advertising platforms to attribute traffic to campaigns); fingerprinting (limited, for fraud detection and security only — not for advertising profiling); and server-side event tracking (server-to-server event transmission, e.g., Meta Conversions API, used to improve signal accuracy while reducing reliance on browser-based cookies).

2. Legal Basis for Cookie Use

JurisdictionApplicable LawKey Requirement
Canada (Federal)PIPEDAMeaningful consent for non-essential cookies; right to withdraw
QuebecQuebec Act 25Express consent for non-essential cookies; cannot be bundled; granular opt-out required
Canada (Federal)CASL s.7Computer program installation rules apply to persistent tracking technologies
EU / EEAGDPR + ePrivacy DirectivePrior informed consent for non-essential cookies; strictly necessary exemption

2.1 Consent Model

We apply a layered consent model: strictly necessary and security cookies require no consent — they are essential for the Platform to function or to protect against fraud. All other cookie categories require your prior, informed, granular, and freely given consent, obtained through our cookie consent banner before any non-essential cookies are set. Quebec residents and EU/EEA users must provide express, affirmative consent for each non-essential category — pre-ticked boxes are not valid. You may withdraw or modify your consent at any time by clicking the 'Cookie Preferences' link in the footer of any page.

3. Cookies We Use

3.1 Strictly Necessary Cookies

These cookies are essential for the Platform to function. They cannot be disabled. No consent is required.

Cookie / TechnologyProviderPurposeData CollectedDuration
session_idMonitiva (1st party)Maintains authenticated user sessionSession token (opaque identifier, no PII)Session
csrf_tokenMonitiva (1st party)Cross-Site Request Forgery protectionCSRF nonce (cryptographic token)Session
consent_stateMonitiva (1st party)Stores your cookie consent choicesJSON: category opt-in/out per timestamp12 months
lang_prefMonitiva (1st party)Remembers selected language (EN/FR)Language code (e.g., 'en', 'fr')12 months
cf_clearanceCloudflare (3rd party)DDoS and bot protection; verifies legitimate browserEncrypted client token; IP address30 minutes
__cf_bmCloudflare (3rd party)Bot management and automated traffic filteringBrowser fingerprint signals; IP address30 minutes

3.2 Security and Fraud Detection Cookies

Used to protect the Platform and users from fraudulent activity. Classified as strictly necessary for a regulated financial service. No consent required.

Cookie / TechnologyProviderPurposeData CollectedDuration
device_fpMonitiva (1st party)Device fingerprinting for account takeover prevention and fraud pattern detectionBrowser signals: UA, screen resolution, timezone, language, canvas hash — no persistent PII30 days
sumsub_sessionSumsub (3rd party)KYC verification session management; liveness check continuityVerification session token; device signals for liveness fraud preventionSession
risk_score_cacheMonitiva (1st party)Caches transaction risk assessment resultHashed risk result and timestamp — no raw transaction dataSession

* KYC provider cookies are necessary for identity verification — a legal obligation under PCMLTFA. Express consent for biometric processing is obtained separately within the verification flow.

3.3 Functional Cookies

Enhance usability and personalization. Require consent under Quebec Act 25 and EU ePrivacy.

Cookie / TechnologyProviderPurposeData CollectedDuration
ab_variantMonitiva (1st party)Stores landing page variant (A, B, or C) for consistent session experienceVariant letter; session timestampSession
city_variantMonitiva (1st party)Stores selected or URL-detected city variant for personalized landing pageCity slug (e.g., 'puerto-vallarta'); source: URL param or self-selectSession
utm_persistMonitiva (1st party)Persists UTM parameters from ad click through waitlist form submissionutm_source, utm_medium, utm_campaign, utm_content, utm_term30 minutes
onboarding_stepMonitiva (1st party)Remembers progress in multi-step onboarding to allow resumptionStep index (integer); no personal data7 days

3.4 Analytics and Performance Cookies

Used to understand Platform usage and improve our services. Require consent. Data is pseudonymized or anonymized where technically feasible.

Cookie / TechnologyProviderPurposeData CollectedDuration
_ga, _ga_*Google Analytics 4 (3rd party)Page views, user flow, session analysis, conversion eventsPseudonymous client ID; pages visited; session duration; device/browser; geo (country/city); events. IP anonymized.2 years (_ga); 13 months (_ga_*)
ph_*, posthog_*PostHog (3rd party — EU-hosted)Product analytics; funnel analysis; session recordings (with field masking); feature flag deliveryPseudonymous distinct_id; event stream; page URLs; referrer; device signals. PII fields masked.1 year

Analytics data is processed under a Data Processing Agreement (DPA). IP addresses are anonymized before storage. Session recordings mask all form fields. We do not enable cross-site tracking or advertising features within our analytics providers.

3.5 Marketing and Attribution Cookies

Used to measure advertising campaign effectiveness and attribute waitlist conversions to specific ads. Require consent. We do not share financial data, Local Balance information, or any data from authenticated platform sessions with marketing platforms.

Cookie / TechnologyProviderPurposeData CollectedDuration
_fbp, _fbcMeta (Facebook / Instagram)Meta Pixel: attribution of ad clicks to waitlist conversions; optimization of Meta ad delivery_fbp: browser ID; _fbc: click ID. Custom event: WaitlistSignup (city, language, profile_type). Hashed email transmitted on form submission with consent.90 days
Meta CAPI (server-side)Meta — server-to-serverMeta Conversions API: server-side duplicate of WaitlistSignup event to improve attribution accuracyHashed email (SHA-256); event name; event time; action_source. No raw PII transmitted.Not a cookie — server-side event
_gcl_aw, _gcl_auGoogle Ads (3rd party)Google Ads click ID: attribution of Google Search ad clicks to waitlist conversions_gcl_aw: Google Click ID (gclid) from ad; _gcl_au: Google Ads user ID for conversion linking90 days

Marketing cookies are used exclusively for measuring the performance of our waitlist acquisition campaigns. We do not operate retargeting campaigns based on financial product usage, transaction history, Local Balance data, or any data derived from authenticated platform sessions.

4. Cookies We Do NOT Use

Technology / PracticeClarification
Third-party advertising networksNo programmatic advertising. No ad exchange cookies. No DSP/SSP integrations.
LinkedIn Insight TagNot currently active. If enabled in future, this policy will be updated before deployment.
Behavioral retargeting based on financial dataWe never share financial transaction data, Glocal Account CAD Balance information, or KYC data with marketing platforms for targeting purposes.
Cross-device tracking (advertising)We do not match your identity across devices for advertising purposes.
Persistent device fingerprinting for advertisingDevice fingerprinting is used exclusively for fraud detection and account security — never for advertising profiling.
Social media tracking from authenticated sessionsNo social media pixels fire from authenticated (logged-in) platform pages. Marketing pixels are restricted to public-facing landing pages only.

5. Your Consent Choices and Controls

5.1 Cookie Consent Banner

Monitiva uses a Consent Management Platform (CMP) to present, record, and manage cookie consent preferences in compliance with PIPEDA, Quebec Act 25, and GDPR/ePrivacy requirements. The CMP captures a timestamped record of each user's consent choices, including the specific categories accepted or rejected and the version of this Cookie Policy in effect at the time.

When you first visit our Platform, the CMP displays a cookie consent banner before any non-essential cookies are set. The banner presents each non-essential cookie category separately and allows you to accept all, accept only selected categories, or reject all non-essential cookies. Your choices are saved in the consent_state cookie for 12 months. Consent records are retained for a minimum of 3 years as required by CASL s.13.

5.2 Changing Your Preferences

You may update your consent choices at any time by clicking 'Cookie Preferences' in the footer of any page. Changes take effect immediately for new page loads. Previously set non-essential cookies from rejected categories will be cleared upon preference update.

5.3 Quebec Residents — Express Consent

If you are a Quebec resident, each cookie category requires a separate, affirmative action to consent. Pre-selected options do not constitute valid consent under Quebec Act 25. You can access and manage your individual category preferences at any time through the Cookie Preferences panel.

5.4 Browser-Level Controls

Most browsers allow you to control cookies at the browser level. You can configure your browser to block all cookies, block third-party cookies only, delete existing cookies, or be notified before a cookie is set. Note: disabling strictly necessary cookies will prevent the Platform from functioning correctly.

5.5 Opt-Out Links for Third-Party Providers

ProviderOpt-Out / Control Mechanism
Google Analytics 4Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout — or via our Cookie Preferences panel
Meta (Facebook / Instagram)Facebook Ad Preferences: https://www.facebook.com/ads/preferences — or via our Cookie Preferences panel. Note: Meta CAPI server-side events are controlled by withholding consent in our panel.
Google AdsGoogle Ads Settings: https://adssettings.google.com — or via our Cookie Preferences panel
PostHogManaged via our Cookie Preferences panel. PostHog respects opt-out signals from our consent management system.
CloudflareCloudflare security cookies (cf_clearance, __cf_bm) are strictly necessary and cannot be opted out of without disabling DDoS protection for your connection.

5.6 Global Privacy Control (GPC) and Do Not Track (DNT)

Our Platform honors the Global Privacy Control (GPC) signal as equivalent to a withdrawal of consent for non-essential cookies for users in applicable jurisdictions (including Quebec residents under Act 25). We acknowledge the legacy Do Not Track (DNT) signal as an expression of user preference and apply it where technically feasible.

6. Cookie Retention Periods

CategoryMax DurationConsentNotes
Strictly NecessaryUp to 12 monthsNot requiredConsent record (consent_state) retained 12 months; session cookies deleted on browser close
Security / Fraud DetectionUp to 30 daysNot requiredDevice fingerprint refreshed on each session
FunctionalUp to 7 daysRequiredUTM persistence limited to 30 minutes; onboarding step up to 7 days
AnalyticsUp to 2 yearsRequiredGA4 client ID up to 2 years; PostHog up to 1 year
Marketing / AttributionUp to 90 daysRequiredMeta _fbp/_fbc and Google _gcl_aw/_gcl_au: 90 days. Server-side events are point-in-time transmissions — not stored as cookies.

7. International Data Transfers via Cookies

ProviderData LocationSafeguardNotes
Google (GA4, Ads)US; EU (if EU data residency enabled)Standard Contractual Clauses (SCCs); Google EU Data Boundary availableIP anonymized before storage; no cross-product linking
Meta (Pixel + CAPI)USSCCs; Meta's GDPR Data Transfer MechanismOnly hashed email and anonymized event data transmitted. No financial data.
PostHogEU (EU Cloud selected)SCCs; EU hosting option selected by MonitivaDPA in place; data minimization applied
CloudflareGlobal CDN (processed regionally)SCCs; Cloudflare DPASecurity function only; minimal data retention
Sumsub (KYC verification)EU (primary); data residency options availableSCCs; GDPR-compliant DPA; ISO 27001 certifiedKYC data only — separate consent for biometric processing

8. Cookies and the Waitlist Campaign

Our current campaigns run on Meta (Facebook and Instagram) and Google Search, targeting Canadians in Canada and Canadians physically located in Mexico. The following tracking flows apply:

8.1 Landing Page Tracking Flow

#EventData Transmitted
1User clicks ad on Meta or GoogleUTM parameters and click IDs (_fbc, gclid) appended to landing page URL by advertising platform
2User lands on monitiva.com/?v=A/B/C&city=xxxCookie consent banner displayed. No non-essential cookies set until consent granted.
3User accepts analytics and/or marketing cookiesGA4 PageView event fired. Meta Pixel PageView fired. UTM parameters persisted to utm_persist cookie.
4User fills and submits waitlist formWaitlistSignup event fired: city, language, profile_type. Hashed email transmitted to Meta CAPI if marketing consent granted.
5Post-submissionNo additional tracking. No cookies set from authenticated platform pages.

8.2 A/B Test Variant Tracking

Landing page variant (A, B, or C) is determined by the URL parameter ?v= and stored in the ab_variant functional cookie for the session duration. Variant data is included in analytics events to measure performance differences between messaging and creative treatments. No personal data is required for variant assignment.

8.3 City Variant Tracking

City-specific landing page content is controlled by the ?city= URL parameter (e.g., puerto-vallarta, los-cabos, cancun). The city value is stored in the city_variant functional cookie and included in the WaitlistSignup event payload to measure geographic demand. City data is self-declared through URL navigation — it does not represent the user's IP-detected location.

9. Updates to This Policy

We may update this Cookie Policy to reflect new technologies, regulatory changes, or modifications to our tracking practices. Material changes will be communicated by updating the version number and effective date, posting a notice on the Platform, and re-presenting the cookie consent banner to collect fresh consent for any newly added categories.

VersionDateSummary
1.0April 2026Initial version
2.0June 2026Removed plan_selected from the WaitlistSignup event (§3.5, §8.1) following the migration from subscription plans to per-transaction pricing. Migrated to the Local/Destination lexicon ("Local Balance"). Named Sumsub as the KYC verification provider (§3.2, §7). Removed the "pricing treatment" reference from A/B testing (§8.2).