Legal

Cookie Policy

Learn how Pearlixa uses cookies and how you can control them.

Last Updated: 28 January 2026

Complete Cookie Inventory

Below is a complete list of cookies used on our website. This table is updated whenever our cookie usage changes.

Cookie NamePurposeDurationTypeProvider
session_tokenMaintains your authenticated session24 hoursEssentialNone (First-party)
csrf_tokenPrevents cross-site request forgery attacksSessionEssentialNone (First-party)
auth_stateStores authentication state for secure login7 daysEssentialNone (First-party)
rate_limit_idEnforces API rate limits and prevents abuse1 hourEssentialNone (First-party)
persona_preferenceRemembers your selected user persona (trader/investor/etc)1 yearPreferenceNone (First-party)
theme_modeStores your dark/light mode preference1 yearPreferenceNone (First-party)
cookie_consentRecords your cookie consent preferences1 yearEssentialNone (First-party)
risk_warning_acceptedRecords acceptance of risk warning popup30 daysEssentialNone (First-party)
__stripe_midFraud prevention for payment processing1 yearEssentialStripe (stripe.com/privacy)
__stripe_sidPayment session identifierSessionEssentialStripe (stripe.com/privacy)
_gaDistinguishes unique users for Google Analytics traffic analysis2 yearsAnalyticsGoogle LLC (policies.google.com/privacy)
_ga_*Maintains Google Analytics session state2 yearsAnalyticsGoogle LLC (policies.google.com/privacy)
hubspotutkTracks visitor identity for HubSpot CRM and deduplicates contacts180 daysAnalyticsHubSpot Inc. (legal.hubspot.com/privacy-policy)
__hstcTracks visitor session history across visits for HubSpot analytics180 daysAnalyticsHubSpot Inc. (legal.hubspot.com/privacy-policy)
__hsscTracks HubSpot session data for analytics30 minutesAnalyticsHubSpot Inc. (legal.hubspot.com/privacy-policy)
__hssrcDetermines if HubSpot should reset session cookieSessionAnalyticsHubSpot Inc. (legal.hubspot.com/privacy-policy)

What Are Cookies?

  • Cookies are small text files placed on your device to store information about your usage.
  • We also use similar technologies such as local storage or pixels where appropriate.
  • Cookies help keep your session secure and enable product functionality.
  • We use minimal cookies focused on security, functionality, and user preferences - NOT advertising or tracking.

Types of Cookies We Use

  • ESSENTIAL COOKIES: Required for login, session management, security controls, rate limiting, and fraud prevention. These cannot be disabled without breaking core functionality.
  • PREFERENCE COOKIES: Remember your settings such as theme, persona selection, and UI preferences. Disabling these resets your preferences on each visit.
  • ANALYTICS COOKIES: We use Google Analytics and HubSpot for website analytics and CRM. These cookies are ONLY activated after you give explicit consent via our cookie consent banner. You can withdraw consent at any time.

Consent Management

  • Essential cookies are set automatically as they are strictly necessary for the website to function.
  • Preference cookies are set when you make choices (e.g., selecting a persona). You implicitly consent by making these choices.
  • If we add analytics cookies in the future, we will present a clear consent banner before any are set.
  • Your consent preferences are stored in the "cookie_consent" cookie and honored for 1 year.
  • You can withdraw consent at any time by clearing cookies in your browser settings or contacting us.

Third-Party Cookies

  • STRIPE: Our payment processor Stripe sets cookies for fraud prevention and secure payment processing. These are essential cookies set regardless of consent. See: stripe.com/privacy
  • GOOGLE ANALYTICS: With your consent, Google Analytics sets cookies (_ga, _ga_*) to measure website traffic and user behaviour. Data is sent to Google LLC servers. Google's privacy policy: policies.google.com/privacy
  • HUBSPOT: With your consent, HubSpot sets cookies (hubspotutk, __hstc, __hssc, __hssrc) to track contacts for CRM and marketing. Data is sent to HubSpot Inc. servers. HubSpot's privacy policy: legal.hubspot.com/privacy-policy
  • NO ADVERTISING COOKIES: We do NOT use Facebook Pixel or any advertising/retargeting cookies.
  • NO CROSS-SITE TRACKING: We do not permit any third party to track you across other websites for advertising using cookies set on our platform.
  • Analytics and CRM cookies from Google and HubSpot are only set after you provide explicit consent.

Session Duration & Security

  • Login sessions expire after 24 hours of inactivity for security.
  • If you select "Remember me" during login, sessions may last up to 7 days.
  • Sessions are invalidated immediately when you log out.
  • CSRF tokens are regenerated with each session to prevent request forgery attacks.
  • We use secure, HTTP-only cookies for sensitive tokens to prevent JavaScript access.

Local Storage & Similar Technologies

  • We use browser local storage to store: UI state, cached API responses for performance, and feature flags.
  • Local storage data remains until you clear browser data or we programmatically remove it.
  • We do NOT store sensitive information (tokens, passwords) in local storage.
  • Local storage is used to persist your risk warning acceptance (30 days) to avoid repeated popups.

How to Control Cookies

  • BROWSER SETTINGS: You can configure your browser to refuse all cookies or alert you when cookies are set.
  • DISABLING ESSENTIAL COOKIES: Warning - this will prevent login and break core functionality.
  • CLEARING COOKIES: You can delete all cookies at any time through your browser settings. This will log you out and reset preferences.
  • OPT-OUT OF ANALYTICS: If we implement analytics cookies, you can opt out via our cookie banner or by enabling "Do Not Track" in your browser.
  • Contact privacy@pearlixa.com if you need assistance managing your cookie preferences.

Legal Basis & Regulatory Compliance

  • EU ePRIVACY DIRECTIVE (2002/58/EC): Our cookie practices comply with the EU ePrivacy Directive (Cookie Directive) as implemented across EU member states. Essential cookies are set on the basis of legitimate interest (strictly necessary for the service). All non-essential cookies require your prior informed consent.
  • UK PECR (Privacy and Electronic Communications Regulations 2003): For UK users, we comply with PECR, the UK equivalent of the ePrivacy Directive. The same consent model applies — essential cookies only without consent, all others require opt-in.
  • GDPR ARTICLE 6 BASIS: Where cookies process personal data, the lawful basis is: (a) Consent (Art. 6(1)(a)) for preference cookies; (b) Legitimate interests (Art. 6(1)(f)) for strictly necessary security and fraud-prevention cookies.
  • DO NOT TRACK (DNT): We respect the DNT browser signal. If your browser sends a DNT=1 header, we will not activate any non-essential tracking or preference cookies beyond what is strictly necessary for security.
  • WITHDRAWAL OF CONSENT: You may withdraw your cookie consent at any time by clearing your cookies in browser settings or contacting privacy@pearlixa.com. Withdrawal does not affect the lawfulness of processing before withdrawal.
  • SUPERVISORY AUTHORITY: EU users may lodge a complaint regarding our cookie practices with their national data protection authority. UK users may contact the Information Commissioner's Office (ICO) at ico.org.uk.

No Warranty

  • We strive to keep this cookie information accurate but do not guarantee third-party practices beyond our control.
  • Changes to your browser, device, or third-party services may affect cookie behaviour.
  • This policy forms part of our Terms of Service and Privacy Policy.
  • We may update this policy as our cookie usage changes. Material changes will be notified.

Important Service Disclaimer

  • Pearlixa is a technology and information service provider ONLY. We are NOT a registered investment adviser, broker-dealer, or financial institution.
  • We are NOT registered with the SEC, FCA, or any other financial regulatory authority. Nothing on this website constitutes financial advice.
  • Cookies and analytics data are used solely to improve our information service. No data collected influences or constitutes investment recommendations.
  • All investment decisions are your sole responsibility. Always consult qualified, licensed financial professionals before investing.