Skip to content

Cookie policy

Last updated 16 September 2026

This policy lists every cookie AF Technologies FZE (“AF Ads”, “we”, “us”) sets on this website and platform, what each one is for, and how long it lasts. It is a short list: the cookies that keep you signed in, and the two third-party tags on the public pages — Google Analytics, which measures how the site is used, and the Meta Pixel, which measures our advertising and allows us to show ads to people who have visited us. Neither loads once you sign in, and neither loads at all until you allow it.

What a cookie is

A cookie is a small text file a website asks your browser to store and send back on later requests. It is what lets a site recognise the same browser from one page to the next — without one, signing in would not survive a single click.

Your choice

When you first arrive, a banner asks whether we may load the two third-party tags described below. Until you answer it, neither runs: no analytics cookie is set, no advertising pixel loads, and nothing about your visit is sent to Google or Meta. Declining takes one click, the same as accepting, and accepting or declining covers both tags together. The cookies in the next section are not part of the choice — without them you cannot sign in, so there would be nothing to decide.

You can change your answer whenever you like: reopens the banner, and the link sits in the footer of every public page. Withdrawing stops the tags on your next page view; anything already sent cannot be recalled by us, which is why Google’s and Meta’s own controls are named in the sections below.

If your browser sends a Global Privacy Controlsignal — Firefox’s strict mode, Brave, DuckDuckGo and some privacy extensions do — we treat that as a refusal and do not show the banner at all. You have already answered, and asking again would be the behaviour that signal exists to prevent.

Your answer is stored in your own browser, not on our servers, and is not linked to your account. That has one consequence worth knowing: a different browser, a different device or a cleared cache means the question is asked again, because the answer was never anywhere else.

Cookies we set

All of the following are strictly necessary: the platform cannot provide the service you asked for without them. None of these cookies is used to profile you, build an advertising audience, or follow you to other websites — the third-party tags on the public pages are covered in their own sections below.

  • af_session — keeps you signed in. It holds a random token, not your identity: your details stay on our server and the token only points at them. It is set when you sign in and removed when you sign out, and it expires on its own after a period of inactivity. It is marked HttpOnly, so scripts running in the page cannot read it, SameSite=Lax, so it is not sent from other people’s websites, and Secure, so it is only ever transmitted over HTTPS.
  • af_tiktok_oauth_state — a security cookie set only for our own administrators, and only during the few seconds it takes to connect our TikTok integration. It carries a random value used to verify that the response coming back from TikTok belongs to the request we sent, which is what stops a third party forging that step. It lasts ten minutes and is never set for clients or visitors.

Analytics

If you allow it, the public pages of this website — everything you can read without signing in — load Google Analytics, so that we can see which pages people find useful and where they arrive from. It sets two cookies:

  • _ga — distinguishes one browser from another so repeat visits are not counted as new people. It lasts two years.
  • _ga_X9PJQKSL5T — holds the state of the current visit for our specific property. It also lasts two years.

Neither is used for advertising and neither carries your name or email. Google receives the address of the page you are reading, roughly where in the world you are, and what kind of device and browser you use.

It does not run once you sign in. The tag is loaded only on the public website, never on the client dashboard, the administration console, or the sign-in, registration and password pages. What you do inside your own account — the accounts you hold, what you spend, what you request — is never sent to Google.

You can refuse it, and the simplest way is to say no on the banner — reopens it if you have already answered. Independently of us, browser settings will block third-party scripts and Google publishes an opt-out add-on that stops Analytics on every site at once. Refusing changes nothing about how this site works for you, and the signed-in platform is unaffected either way.

Advertising and the Meta Pixel

If you allow it, the public pages of this website load the Meta Pixel, which is an advertising tool rather than a measurement one. It tells Meta that a browser visited a page here, so that we can see whether our advertising works and can show ads on Facebook and Instagram to people who have visited us. If you are signed in to Facebook or Instagram in the same browser, Meta can connect that visit to your account there.

Two limits on it are worth stating plainly, because they are the ones that matter to a client rather than a visitor. It runs on the public pages only — never on the signed-in dashboard, the admin console or the sign-in pages — so what you do inside your account never reaches Meta: not the advertising accounts you hold, not your balance, not your top-ups, not your requests. And we send Meta no email address, name or customer list; the pixel sees a page visit and nothing we add to it.

You can refuse it, and the simplest way is to decline on the banner — reopens it if you have already answered. Independently of us, browser settings that block third-party scripts or trackers stop it, as do most content blockers, and Facebook’s own advertising settings control how your activity is used for ads. Refusing changes nothing about how this site works for you, and the signed-in platform is unaffected either way.

Cookies we do not set

Apart from Google Analytics and the Meta Pixel on the public pages — and only if you have allowed them — no third-party scripts run on this site. Nothing runs on the signed-in platform at all: no analytics, no advertising tag, and nothing that could connect what you do inside your account to any outside company.

Local storage

Separately from cookies, we store one value in your browser’s local storage: afads.consent, holding the answer you gave on the banner and the date you gave it. It never leaves your browser and is never sent to us, which is also why we cannot tell you what you chose on a different device.

Clearing your browsing data removes it and the banner appears once more, which is the only way we know to withdraw consent that does not depend on us. An older value, afads.cookie-notice, was used by the notice this banner replaced; nothing reads it any more and it is deleted the next time you answer.

Controlling cookies

Every browser lets you view, block and delete cookies, usually under privacy or site settings. You can block ours if you wish, but be aware that af_session is what keeps you signed in: block or delete it and you will be signed out and unable to sign back in until you allow it again. The public pages of this website — everything you can read without an account — work with cookies blocked entirely, analytics included.

Changes to this policy

If we add a cookie, we will list it here and change the date at the top of this page before it is set. Where a new cookie is not strictly necessary, we will ask for your consent first rather than relying on this page having been updated.

Contact

Questions about this policy, or about anything we store, can go to support@afads.tech. Our privacy policy covers the information we hold beyond cookies, and our terms of service cover the service itself.