Skip to Content
Data & PrivacyCookie Policy

Cookie Policy

Version 1.0 · Effective from 1 September 2026 · Last reviewed 23 July 2026

Download PDF

Applies to: cashxchain.com, app.cashxchain.com, auth.cashxchain.com, dev.cashxchain.com, docs.cashxchain.com, demo.cashxchain.com and their sandbox equivalents (*.sandbox.cashxchain.com).

1. Introduction

This Cookie Policy explains how CashXChain Inc. (Delaware, USA) and its operating entity CashXChain UG (haftungsbeschränkt) (Feldkirchen-Westerham, Germany) — together “CashXChain”, “we”, “us” — use cookies and similar technologies on our websites and web applications listed above.

It should be read together with our Privacy Policy, which explains how we process personal data more generally. This document describes what is stored on your device, why, for how long, and how you can control it.

2. Summary — what we do and do not do

We do not use advertising, marketing, or cross-site tracking cookies. We run no Google Analytics, Google Tag Manager, Meta/Facebook Pixel, LinkedIn Insight, or comparable third-party analytics or ad-tech on any CashXChain property. We do not sell or share personal data with advertisers.

The cookies we set fall into three groups only:

• Strictly necessary — required to sign you in and keep your session secure. These cannot be switched off.

• Functional — remember minor preferences such as language and interface layout.

• Security / anti-abuse — provided by our infrastructure partner Cloudflare to protect against bots and fraud.

Our public marketing site (cashxchain.com) sets no cookies at all on a normal visit; a language cookie is written only if you actively switch language, and your theme choice is stored in your browser’s local storage (not a cookie).

3. What are cookies and similar technologies?

A cookie is a small text file placed on your device by a website. Cookies can be session (deleted when you close the browser) or persistent (kept for a defined period). A first-party cookie is set by the site you are visiting; a third-party cookie is set by another domain.

We also use similar technologies that are not cookies but are treated the same way under EU law — chiefly the browser’s localStorage. These are listed in Section 7.

4. Strictly necessary cookies

Set by our authentication service (auth.cashxchain.com, powered by our self-hosted Better Auth on Cloudflare). They are essential to log you in, keep you logged in across our sub-domains, and protect your account. Without them the service cannot function, so they are exempt from consent. In production these names carry a __Secure- prefix and are served only over HTTPS (Secure, HttpOnly, SameSite=Lax). Example names below use the sandbox prefix cxc-sandbox; production uses the equivalent production prefix.

Cookie / keyProviderPurposeDuration
cxc-sandbox.session_tokenCashXChain (auth)Maintains your authenticated login session.7 days (refreshed daily)
cxc-sandbox.session_dataCashXChain (auth)Short-lived cached copy of session data to reduce database lookups.5 minutes
cxc-sandbox.dont_rememberCashXChain (auth)Records that you chose not to stay signed in, so the session ends when the browser closes.Session
cxc-sandbox.oauth_stateCashXChain (auth)CSRF, PKCE and nonce protection during social sign-in (Google, Apple, Microsoft, GitHub, LinkedIn).Transient (deleted when sign-in completes)
cxc-sandbox.two_factorCashXChain (auth)Carries state while you complete two-factor (2FA) verification.Transient
cxc-sandbox.trust_deviceCashXChain (auth)Set only if you choose “trust this device” so 2FA is not re-prompted on it.Up to ~60 days
cxc-sandbox passkey challengeCashXChain (auth)One-time challenge during passkey / WebAuthn registration or login.Transient
cxc-sandbox.admin_sessionCashXChain (auth)Only present when authorised staff (admin/compliance/support) securely act on an account.Session

Note: the 2FA, passkey and staff cookies appear only for users who actually use those features. The “up to ~60 days” trust-device duration is the framework default and should be confirmed against the final production configuration.

5. Functional cookies

These remember minor choices to improve your experience. They hold no identifying or tracking data.

Cookie / keyProviderPurposeDuration
NEXT_LOCALECashXChain (website)Remembers your language choice (English / German). Written only when you actively switch language.1 year
sidebar_stateCashXChain (web app)Remembers whether the dashboard sidebar is expanded or collapsed.7 days

6. Security and anti-abuse cookies (Cloudflare)

All CashXChain domains are served through Cloudflare, our infrastructure and security provider. Cloudflare sets its own cookies at the network edge to protect the service against bots, abuse and fraud. We also use Cloudflare Turnstile (a privacy-preserving CAPTCHA alternative) on sign-in, sign-up, password-reset and the contact form. These are provided by Cloudflare, Inc. and are treated as third-party.

Cookie / keyProviderPurposeDuration
__cf_bmCloudflareBot-management: distinguishes humans from automated traffic. Cannot be read by page scripts (HttpOnly).30 minutes
cf_clearanceCloudflare / TurnstileRecords that your browser passed a security challenge, so you are not re-challenged.~30 minutes (set only if challenged)
_cfuvid / __cfruidCloudflareSupports Cloudflare rate-limiting rules; not used for cross-site tracking.Session

As deployed, Turnstile uses server-side verification (“siteverify”) and issues a one-time token; Cloudflare’s pre-clearance cookie mode is not enabled. Cloudflare states these cookies do not track individuals across unrelated sites. See Cloudflare’s cookie documentation for the authoritative, current list.

7. Third-party sign-in providers

If you choose to sign in with Google, Apple, Microsoft, GitHub or LinkedIn, that provider will set its own cookies on its own domain during the sign-in redirect, under its own privacy and cookie policies. CashXChain does not control those cookies and receives only the account information you authorise. If you sign in with an email and password instead, no third-party sign-in cookies are involved.

8. Similar technologies (local storage)

The following are stored in your browser’s local storage rather than as cookies. They are not transmitted to our servers and remain on your device until cleared.

KeyPurposeWhere
cashxchain-themeRemembers your light / dark / system theme preference.Marketing site & web app (localStorage)
Session cache (Better Auth)Client-side cache of non-sensitive session state for performance.Web app (localStorage)

Under the EU ePrivacy Directive and the German TDDDG (formerly TTDSG), storing or reading information on your device requires your consent unless it is strictly necessary to provide the service you requested. We rely on:

• Strict necessity — for the authentication and security cookies in Sections 4 and 6, which are required to deliver a service you have asked for and to keep it secure.

• Consent (Art. 6(1)(a) GDPR  / § 25(1) TDDDG) — where required for non-essential cookies. Because we currently deploy no analytics or advertising cookies, no consent banner is required for those categories; functional cookies are minimal and privacy-neutral.

If analytics or marketing technologies are added in future, a compliant consent-management banner (opt-in, granular, with easy withdrawal) must be implemented before they are activated, and this policy must be updated accordingly.

10. How to manage or delete cookies

You can control cookies through your browser settings — view, delete, or block them. Blocking strictly necessary cookies will prevent you from signing in and using the web application.

• Chrome: Settings → Privacy and security → Third-party cookies / Site data.

• Safari: Settings → Privacy → Manage Website Data.

• Firefox: Settings → Privacy & Security → Cookies and Site Data.

• Edge: Settings → Cookies and site permissions.

You can also sign out at any time from your account menu, which clears your session cookies.

11. Changes to this policy

We may update this Cookie Policy to reflect changes to our technologies or legal obligations. Material changes will be dated at the top of this document and, where required, notified to you.

12. Contact

CashXChain UG (haftungsbeschränkt) — Munich, Germany

CashXChain Inc. — Delaware, USA (holding)

Email: [email protected]

Website: https://cashxchain.com