Finloop logo
English

English

  • language.TranslationKey
  • language.TranslationKey
  • language.TranslationKey
  • Solutions
    • Borrowers
    • Lenders
    • Advisors
    • White Label
  • Company
  • Media
    • Blog
    • Press
  • Pricing
  • Sign In
Get Started

Cookies Policy

FINLOOP COOKIE POLICY
  1. What this policy covers

    Cookies and similar technologies (including local and session storage) used on the covered websites: what they are, who provides them, what they do, how long they last, and how you control them.


  2. Your choices

    When you first visit, a banner offers Accept all, Reject all and Settings with equal prominence. Before you opt in, FinLoop does not load an optional provider's script or send analytics or experience-measurement requests to that provider; the consent tool stores only the information strictly necessary to remember and enforce your choice. Closing or ignoring the banner leaves all optional technologies disabled. You can change or withdraw your choices at any time via [Cookie settings], also linked in the footer and inside the platform.

    Where the same visitor uses multiple FinLoop-controlled domains with the same controller, purposes and approved provider configuration, FinLoop may use a minimal consent token to apply the visitor's most recent choice on that browser or, where the visitor is signed in, on that account. We do not reuse a FinLoop choice for a white-label domain controlled by another organisation unless the controller, purposes and providers are the same and the relevant notice expressly explains the arrangement. If no valid preference is available, optional technologies remain disabled until a new choice is made. Your most recent valid withdrawal overrides an earlier consent on the browser, device or signed-in account to which the preference can validly be linked.

    Rejecting optional technologies does not prevent you from browsing the public website. Before an optional embedded feature loads, we identify the provider, the feature's purposes, the main categories of data transmitted, the relevant storage technologies, transfer destinations and safeguards, and the applicable retention period or criteria; the feature loads only after you activate it.

    Legal bases. Optional analytics, functional and experience technologies are used on the basis of your consent. Technologies necessary to operate requested authentication, security and consent-preference functions do not require cookie consent; where they involve personal data, FinLoop processes that data to provide and secure the requested service and to remember and demonstrate your privacy choices, as further described in the [Privacy Policy].


  3. Categories and choices

    Each optional category below has its own switch in [Cookie settings], off by default:

    • Strictly necessary (no consent required) — the authenticated session and security (anti-forgery) tokens, and the consent-preference token itself, set only on the routes where they are needed.
    • Functional (consent) — convenience features such as remembering your time zone.
    • Audience measurement — Google Analytics (consent) — measures visits, navigation and website performance.
    • Experience analytics — Hotjar (consent) — records selected interactions on approved public information pages to identify usability problems. Hotjar is never loaded on logged-in platform pages, sign-in, sign-up or password pages, contact or demo forms, or pages containing personal data, tokens or identifiers.
    • Advertising and cross-site targeting — not used. FinLoop does not currently deploy advertising pixels, remarketing, audience matching, Google Signals or behavioural-advertising technologies on the covered domains. A future deployment would require prior legal review, an updated inventory and a new consent choice.

    You can accept audience measurement without accepting experience analytics, and vice versa.


  4. Inventory

    The table reflects the technologies identified in the production scan dated [SCAN DATE]; FinLoop's release process requires newly proposed optional technologies to be added to the inventory and consent controls before activation. "Stored on" describes where the technology is stored (first-party = the FinLoop domain); the provider may still be a separate company.

    Technology / storage key Stored on Type Service provider Purpose Data accessed or transmitted Duration Consent
    [CMP preference token per deployed tool] FinLoop domain (first-party) Cookie / local storage [CMP provider legal entity] Remember and enforce your consent choice Choice, banner/policy version, timestamp 6 months Strictly necessary
    .AspNetCore.Cookies FinLoop domain (first-party) Cookie FinLoop Authenticated session Session identifier Session [verify: no persistent "remember me" variant] Strictly necessary
    .AspNetCore.Antiforgery.* FinLoop domain (first-party) Cookie FinLoop Form security Security token Session Strictly necessary
    _flTZ FinLoop domain (first-party) Cookie FinLoop Time-zone display Time-zone value 365 days Functional
    [Each GA4 cookie per deployed configuration, incl. suffixes] FinLoop domain (first-party) Cookie [Google contracting entity] Audience measurement Usage events, device/browser data [per configuration export] [per configuration] Audience measurement
    [Each Hotjar cookie / local-storage / session-storage item per scan] FinLoop domain (first-party) [per item] Hotjar Limited Experience analytics on approved public pages Interaction data, masked page content [per configuration] [per item] Experience analytics
    [Each embedded feature per scan] [per item] [per item] [provider legal entity] Loaded only on your request, disclosed at the feature [per feature] [per provider] Feature-level consent

    The server-side consent evidence record is not browser storage; it is described in section 6.


  5. Providers, roles and transfers

    For analytics data processed to provide the configured service, the named provider entity acts as FinLoop's processor under its data-processing terms; a provider may act as an independent controller for limited account, security or legal-compliance processing described in its own notice, which we link in the settings panel. A provider-by-provider record — legal entity, role, data categories, hosting and support locations, and the transfer mechanism applied per exporting regime (EEA: adequacy including the EU-US Data Privacy Framework for currently certified providers, or the EU Standard Contractual Clauses; UK: UK adequacy, the IDTA or the UK Addendum; Switzerland: FADP adequacy or recognised clauses adapted to Swiss law) — is maintained and aligned with section 6 of the [Privacy Policy]. Destination countries currently include Switzerland, the EEA states, the United Kingdom and the United States. You can request a copy of the applicable safeguards via dpo@finloop.com.


  6. Your preference and our evidence record

    We store a preference token on your browser for six (6) months so that we can remember and apply your choice; we then ask you to choose again, and earlier only where a genuinely new provider, purpose or materially different technology is introduced. We do not re-prompt during the same visit or repeatedly after a rejection.

    Separately, we retain a restricted evidence record containing a pseudonymous consent identifier, the relevant domain and controller, the banner and policy versions, the language shown, the purposes and providers presented, your granular choices and the timestamp. It does not contain your full IP address or other unnecessary device details, is not used for analytics or profiling, and is retained for up to five (5) years under FinLoop's documented compliance-retention schedule, unless an earlier deletion is appropriate or a legal hold applies.


  7. Withdrawal and browser controls

    When you withdraw a choice, FinLoop immediately prevents the affected optional technologies from loading and deletes or expires the optional cookies and local-storage items that FinLoop controls. We cannot directly delete a cookie stored only on another provider's domain, but we stop loading that provider and explain in the settings panel how remaining browser storage can be removed. Withdrawal does not affect processing lawfully completed before withdrawal, and it takes no more steps than acceptance.

    You can also delete or block cookies in your browser or device settings. Deleting cookies in the browser alone removes files from your device but does not update our consent record — use [Cookie settings] for that. Blocking strictly necessary cookies may prevent logged-in use of the platform.


  8. The settings panel

    The [Cookie settings] panel lists the technologies in our current approved deployment inventory, with a separate switch per optional category, provider details and privacy links; we update the inventory when our tooling changes, before activation. The panel is accessible without logging in and from inside the authenticated platform.


  9. Changes

    Changes to this policy and to the deployed technologies are versioned; material changes trigger a renewed banner. The version and effective date appear at the top; prior versions are archived and available on request.

    Privacy contact: dpo@finloop.com

Services

  • Borrowers
  • Lenders
  • Advisors
  • White Label
  • Company
  • Media
  • Pricing
  • Contact
  • LinkedIn
  • Sign In
  • Join FinLoop
  • © 2026 FinLoop

  • Privacy Policy
  • Terms and Conditions
  • Cookies Policy

Finloop logo

By using this site, you agree to our cookie policy. OK