Cookie Policy v5.0 · 26 August 2026. This Cookie Policy is the canonical English version. Where translations into other languages are provided for convenience, the English version shall prevail in case of any discrepancy.
Cookie Policy v5.0
Aligned with the Privacy Policy and the T&C v5.0 | Publication Date: 26 August 2026
This Cookie Policy is the canonical English version. Where translations into other languages are provided for convenience, the English version shall prevail in case of any discrepancy.
This Cookie Policy governs the use of cookies and similar tracking technologies by Neom Triple A Information Technology LLC, operating under the brand NEOM Funded, in respect of persons who visit the website neomfunded.com and use the Services provided therein.
§1 Introduction and Definitions
1.1 Purpose of this Policy. This Cookie Policy explains what cookies and similar tracking technologies are, how Neom Triple A Information Technology LLC (hereinafter the “Company”, “We”, “Us”) uses them on neomfunded.com and the associated Services under the brand NEOM Funded, and what rights Participants have in relation to the management of those technologies. This Cookie Policy supplements the Privacy Policy and forms an integral part of the legal framework set out in the T&C §26.7.
1.2 Definitions. For the purposes of this Cookie Policy, the following terms apply:
- Cookie — a small text file placed on a user’s device (computer, smartphone, or tablet) by a website when the user visits that website. Cookies enable the website to recognise the user’s device and to store certain information about their preferences or past actions. Cookies may be “session” cookies (deleted when the browser is closed) or “persistent” cookies (retained on the device for a set period or until explicitly deleted).
- First-party cookie — a cookie set directly by the domain of the website the user is visiting (in this case, neomfunded.com). First-party cookies are set and read exclusively by the Company.
- Third-party cookie — a cookie set by a domain other than the domain of the website being visited. Such cookies are set by third parties (advertising networks, analytics services, etc.) when their components are loaded on pages of the Website.
- Web Beacon / Pixel — a small, invisible graphic object (typically 1×1 pixel in size) embedded in a web page or HTML email message. Used to track email opens, link clicks, and page visits. Operates in conjunction with cookies and enables third parties to collect information about user behaviour.
- Local Storage — a mechanism for storing data in the user’s browser, similar to cookies but with greater capacity and without being automatically sent to the server with each HTTP request. Used to store user preferences and session data on the client side.
- Session ID — a unique identifier generated by the server and transmitted to the browser via a cookie or URL parameter in order to maintain the user’s session during a single visit.
- TTL (Time-To-Live) — the period during which a cookie or other tracking technology remains active on the user’s device.
- Participant — any natural person who visits the Website or uses the Company’s Services.
1.3 Relationship to the Privacy Policy. This Cookie Policy is a standalone document supplementing the Privacy Policy §7 (Cookies and Tracking Technologies) and §12 (Do-Not-Track and Global Privacy Control). In the event of any conflict between this Cookie Policy and the Privacy Policy, the provisions of the Privacy Policy shall prevail.
§2 Who Uses Cookies on the Website
2.1 The Company as Controller. The operator of the Website and the controller of the processing of personal data within the meaning of applicable legislation is:
Full legal name: Neom Triple A Information Technology LLC
Brand: NEOM Funded
Registered address: The Binary by Omniyat, Office 2114, Business Bay, Dubai, UAE
Website: neomfunded.com
2.2 First-party cookies. The Company independently sets first-party cookies through the domain neomfunded.com. These cookies ensure the functioning of the platform, session management, CSRF protection, storage of user preferences, and the recording of the Participant’s cookie-consent choices (in a combination of a first-party cookie and HTML5 localStorage; see §5 and §7.4).
2.3 Third-party cookies. The Company uses on the Website components and scripts provided by the following third parties, which may set their own cookies on Participants’ devices when those components are loaded:
- Google LLC (Mountain View, CA, USA) — Google Analytics (analytics), Google Ads / Google Tag Manager (advertising and conversion tracking), DoubleClick (programmatic advertising);
- Meta Platforms Ireland Ltd (Dublin, Ireland) and Meta Platforms Inc (Menlo Park, CA, USA) — Meta Pixel (Facebook Pixel) for advertising and retargeting purposes;
- Cloudflare Inc (San Francisco, CA, USA) — DDoS protection, CDN, and browser integrity check.
2.4 Third-party responsibility. The processing of data carried out by third parties via their own cookies is governed by the privacy policies of those respective third parties. The Company accepts no responsibility for the data-processing practices of third parties beyond the scope of the contractual data-processing arrangements established with them. Participants may review the privacy policies of the third parties identified above directly on their respective websites.
§3 Legal Framework
3.1 Applicable legislation. The Company’s use of cookies and similar tracking technologies is governed by the following legislation:
- Regulation (EU) 2016/679 (General Data Protection Regulation, ‘GDPR’) — establishes requirements regarding lawful bases for the processing of personal data, including data collected via cookies, in respect of data subjects located in the EU/EEA;
- Directive 2002/58/EC (ePrivacy Directive) as amended by Directive 2009/136/EC — establishes requirements for obtaining consent for the setting of cookies, including an exemption for strictly necessary cookies (Article 5(3)). The adoption of an ePrivacy Regulation replacing this Directive is anticipated at EU level; the Company will update this Policy as and when the new regulation enters into force;
- UK Privacy and Electronic Communications Regulations 2003 (UK PECR) — implements the ePrivacy Directive requirements within the UK legal system following Brexit; governs the use of cookies in respect of users located in the United Kingdom;
- California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act 2020 (CCPA/CPRA) — grants California residents the right to opt out of the sale or sharing of personal data collected, including via advertising cookies;
- UAE Federal Decree by Law No. (45) of 2021 Concerning the Protection of Personal Data (the ‘UAE PDPL’; commonly cited as ‘UAE Federal Decree-Law No. 45 of 2021’) — governs the processing of personal data by the Company as a legal entity incorporated in the UAE;
- Ley 34/2002, de 11 de julio, de Servicios de la Sociedad de la Información y de Comercio Electrónico (‘LSSI-CE’) — implements the ePrivacy Directive requirements within the Spanish legal system; governs the use of cookies in respect of users located in Spain.
3.2 Relationship between instruments. Nothing in this Policy reduces any right of a data subject granted by any of the instruments listed above that is in force as at the Publication Date of this Policy.
§4 Cookie Categories
The Company uses the following four categories of cookies based on their functional purpose and consent requirements:
4.1 (a) Strictly Necessary Cookies.
This category comprises cookies without which the Website and Services cannot function properly. They provide basic functions: maintaining the user’s session (Laravel application session), page navigation, access to protected sections, processing of login forms, and protection against Cross-Site Request Forgery (CSRF) attacks. The recording of the Participant’s cookie-consent choices is also strictly necessary and is implemented in a combination of a first-party consent cookie, an HTML5 localStorage entry, and a server-side consent log (see §5 and §7.4). Without these cookies, certain functions of the Website will be unavailable.
Legal basis: in accordance with Article 5(3) of Directive 2002/58/EC (ePrivacy Directive) as amended by Directive 2009/136/EC and its implementation in the national laws of EU Member States, strictly necessary cookies are exempt from the requirement to obtain the user’s prior consent. Additional legal basis: Article 6(1)(f) GDPR (the Company’s legitimate interest in ensuring the technically sound and secure functioning of the Website). The Participant’s consent is neither required nor sought for this category.
4.2 (b) Functional Cookies.
This category comprises cookies that are not strictly necessary but which enhance the convenience and personalisation of the user’s experience on the Website. They support in-app messaging continuity (Intercom messenger state and session tokens) and remember interface-language preferences between visits. Deleting these cookies does not prevent access to the Website, but may reset the in-app messenger session and require the user to re-select the interface language.
Legal basis: Article 6(1)(a) GDPR (the Participant’s explicit consent obtained via the cookie banner) in conjunction with the requirements of Article 5(3) of Directive 2002/58/EC (ePrivacy Directive) as amended by Directive 2009/136/EC. These cookies are set only upon receipt of explicit consent.
4.3 (c) Analytics Cookies.
This category comprises cookies that enable the Company to measure and analyse visitor behaviour on the Website: number of visits, traffic sources, most visited pages, time spent on a page, and other behavioural metrics. The data collected is aggregated and used exclusively to improve the functionality of the Website and to enhance the quality of the Services. The Company uses primarily Google Analytics with the IP-anonymisation feature enabled.
Legal basis: Article 6(1)(a) GDPR (the Participant’s explicit consent obtained via the cookie banner). These cookies are set only upon receipt of explicit consent.
4.4 (d) Advertising Cookies.
This category comprises cookies used for the purpose of displaying relevant advertising to the Participant both on the Company’s Website and on third-party platforms (retargeting), as well as for measuring the effectiveness of advertising campaigns. These cookies create a profile of the user’s interests based on their behaviour online (cross-context behavioural advertising within the meaning of the CCPA/CPRA). The transfer of data under this category may qualify as “sharing” of personal information within the meaning of CCPA §1798.120.
Legal basis: Article 6(1)(a) GDPR (the Participant’s explicit consent obtained via the cookie banner). These cookies are set only upon receipt of explicit consent. California residents may opt out of this category by means of a GPC signal or via the cookie-banner settings (see §10 of this Policy).
§5 Cookie Table
The table below sets out details of the specific cookies used on the Website neomfunded.com as at the Publication Date of this Policy. The table is updated as the composition of cookies used changes. Participants may request the current version of the table by writing to privacy@neomfunded.com.
In addition to the cookies listed below, the Website stores data in the Participant’s browser via HTML5 localStorage. As at the Publication Date, the following localStorage entries are used:
cookie-consent(Strictly Necessary, first-party) — stores the Participant’s cookie-consent choices as four category flags (strictly necessary, functional, analytics, advertising) together with a timestamp and the versions of this Cookie Policy and of the consent-management platform (CMP) in force at the time of the choice. No user identifier is stored in this entry. It is retained until the Participant clears browser storage or resets consent via the cookie-banner settings.cookie-consent-subject(Strictly Necessary, first-party) — stores a randomly generated identifier (UUID) linking the browser-side consent record to the corresponding server-side consent-log entry (see §7.4). The identifier is not linked to the Participant’s account and is not used for tracking. It is retained until the Participant clears browser storage or resets consent.intercom.intercom-state-cn115fd0(Intercom, Functional category) — stores the state of the Intercom in-app messenger conversation; retained until the Participant clears browser storage or withdraws Functional consent.
| Cookie Name | Provider | Category | Purpose | TTL | Type |
|---|---|---|---|---|---|
neom_funded_session | Neom Triple A Information Technology LLC | Strictly Necessary | Application session identifier issued by the Company’s Laravel backend to maintain authenticated user state and preserve form input across navigation. Marked HttpOnly, Secure, SameSite=Lax; not accessible to JavaScript. | 120 minutes (idle expiry) | First-party |
XSRF-TOKEN | Neom Triple A Information Technology LLC | Strictly Necessary | Cross-Site Request Forgery (CSRF) protection token issued by the Company’s Laravel backend. Prevents CSRF attacks against session-authenticated endpoints. Marked Secure, SameSite=Lax; readable by the application’s JavaScript layer in order to attach the token to state-changing requests. | 120 minutes | First-party |
neomaaa_consent | Neom Triple A Information Technology LLC | Strictly Necessary | Records the Participant’s cookie-consent choices as a compact three-flag value (functional / analytics / advertising) mirroring the localStorage cookie-consent entry. Ensures the banner is not re-displayed on subsequent visits and that non-essential categories are only activated when the corresponding flag is set. Marked Secure, SameSite=Lax, path /. No user identifier is stored in this cookie. | 180 days | First-party |
neomaaa_gpc | Neom Triple A Information Technology LLC | Strictly Necessary | Records that the Participant’s browser sent a Global Privacy Control (Sec-GPC: 1) header and that the Advertising category has therefore been opted out for CCPA/CPRA purposes (see §10.2). Set only when a GPC signal is detected. Marked Secure, SameSite=Lax. Value: 1. No user identifier is stored in this cookie. | 180 days | First-party |
NEXT_LOCALE | Neom Triple A Information Technology LLC | Strictly Necessary | Stores the interface-language preference selected by the Participant so that the Website renders in the correct language on subsequent requests. Marked SameSite=Lax. | 365 days | First-party |
neomaaa_aff_ref | Neom Triple A Information Technology LLC | Strictly Necessary | Stores the identifier of the affiliate whose referral link the Participant used to reach the Website, so that the referral can be attributed for the purposes of the Company’s affiliate-payout obligations (contract-performance interest under Article 6(1)(b) GDPR). No behavioural profiling is performed with this cookie. | 60 days | First-party |
neomaaa_attribution | Neom Triple A Information Technology LLC | Strictly Necessary | Stores first-touch and last-touch campaign-attribution parameters (UTM values and referrer channel) that the Participant carried to the Website, for the purpose of allocating any purchase to the correct acquisition source in the Company’s internal reporting. Does not identify the Participant to third parties. | 90 days | First-party |
cf_clearance | Cloudflare Inc | Strictly Necessary | Records confirmation that the user has passed a Cloudflare security challenge (Managed Challenge / Turnstile). Set only if Cloudflare presents a security challenge in response to a specific request; not set on ordinary requests to the Website. Prevents repeated completion of the challenge during the applicable period. | 30 minutes (when set) | Third-party |
intercom-id-cn115fd0 | Intercom R&D Unlimited Company | Functional | Intercom persistent user identifier. Recognises returning Participants across sessions in the Intercom in-app messenger; enables continuity of conversations with support and personalised messaging. | 270 days | First-party |
intercom-device-id-cn115fd0 | Intercom R&D Unlimited Company | Functional | Intercom persistent device identifier. Identifies the browser/device used to interact with the Intercom in-app messenger; enables cross-session device recognition. | 270 days | First-party |
intercom-session-cn115fd0 | Intercom R&D Unlimited Company | Functional | Intercom session token. Maintains the state of an active in-app messenger session; refreshed with each user interaction. Ensures continuity within a chat conversation. | 7 days | First-party |
_ga | Google LLC (Google Analytics 4) | Analytics | Primary Google Analytics 4 identifier: distinguishes unique visitors by assigning a randomly generated identifier. Used to calculate metrics including session count, traffic sources, and visit statistics. | 400 days | Third-party |
_ga_EZC1YFN5FP | Google LLC (Google Analytics 4) | Analytics | Google Analytics 4 session state cookie for the Company’s GA4 property (measurement ID G-EZC1YFN5FP): persists session state across pageviews within a session. | 400 days | Third-party |
_fbp | Meta Platforms Ireland Ltd / Meta Platforms Inc | Advertising | Meta Pixel browser identifier: used for conversion tracking, retargeting, measurement of advertising effectiveness on Facebook/Instagram, and building Look-alike audiences. | 90 days | Third-party |
fr | Meta Platforms Ireland Ltd / Meta Platforms Inc | Advertising | Facebook’s primary advertising cookie: delivers personalised advertising, measures its effectiveness, and tracks behaviour across websites to show relevant advertisements. | 90 days | Third-party |
_gcl_au | Google LLC (Google Ads) | Advertising | Used by Google AdSense/Google Ads for experimenting with advertising effectiveness and storing a conversion identifier to attribute conversions to clicks on advertisements. | 90 days | Third-party |
IDE | DoubleClick (Google LLC) | Advertising | Used by Google’s DoubleClick advertising network to serve targeted advertising, limit impression frequency, and measure the effectiveness of advertising campaigns; stores an encrypted user identifier. | 13 months | Third-party |
test_cookie | DoubleClick (Google LLC) | Advertising | A test cookie set by DoubleClick to verify that the user’s browser supports cookies. Contains no personal data. | 15 minutes | Third-party |
_sp_id.6222 | TradingView, Inc. | Advertising | TradingView Snowplow persistent visitor identifier. Assigned by TradingView’s embedded charting widgets and Snowplow-based analytics for attribution and cross-session recognition. | 400 days | Third-party |
_sp_ses.6222 | TradingView, Inc. | Advertising | TradingView Snowplow persistent session-tracking cookie (90-day lifetime, not a browser-session cookie). Maintains the identifier of an active session within TradingView widget interactions. | 90 days | Third-party |
sp | TradingView, Inc. | Advertising | TradingView Snowplow pixel-tracking cookie set from snowplow-pixel.tradingview.com. Used for pixel-based attribution and measurement of interactions with embedded TradingView widgets. | 365 days | Third-party |
Note on TradingView cookies. The three TradingView Snowplow cookies listed above (_sp_id.6222, _sp_ses.6222, sp) are set only on the single page that embeds a TradingView widget, namely /tools/economic-calendar. They are not set on any other page of the Website. TradingView, Inc. acts as an independent controller in respect of these cookies (see §8.1(f)).
Note on the consent-recording mechanism. When the Participant records their choices in the cookie banner (Accept All / Reject All / Customize), the Website (a) writes the four-flag preference set to the localStorage entry cookie-consent, (b) writes the compact three-flag mirror value to the first-party cookie neomaaa_consent, and (c) transmits the consent record (choices, timestamp, Policy version, CMP version, and the randomly generated identifier from the localStorage entry cookie-consent-subject) to the endpoint /api/consent-log for storage in the Company’s server-side consent log. The server-side consent log is retained for twenty-four (24) months from the date of the choice for the purpose of demonstrating compliance with the accountability principle under Article 5(2) GDPR and Article 7(1) GDPR. The Company does not link the consent identifier to the Participant’s account.
Note: the TTL values stated above are standard default values. Actual values may vary slightly depending on the versions of third-party scripts. The Company takes reasonable steps to keep this table current and undertakes to update it upon each material change to the composition of cookies used.
§6 Legal Basis for Each Category
6.1 Strictly Necessary Cookies. The legal basis for the processing of data via strictly necessary cookies is:
- Article 5(3) of Directive 2002/58/EC (ePrivacy Directive) as amended by Directive 2009/136/EC (and its national implementations): strictly necessary cookies are exempt from the consent requirement provided that the user has been duly informed of their use;
- Article 6(1)(f) GDPR — the Company’s legitimate interest in ensuring the secure, stable, and technically sound functioning of the Website and Services. The Company’s interests do not override the data subject’s rights, as these cookies are functionally necessary to provide the requested Service;
- In respect of the mechanism that records the Participant’s cookie-consent choices (the first-party cookie
neomaaa_consent, the localStorage entriescookie-consentandcookie-consent-subject, and the server-side consent log maintained at/api/consent-log): Article 6(1)(c) GDPR — compliance with the legal obligation to document and maintain records of consent in accordance with Article 7(1) GDPR and Article 5(2) GDPR (the accountability principle).
6.2 Functional Cookies. The legal basis is:
- Article 6(1)(a) GDPR — the Participant’s explicit consent expressed through interaction with the cookie banner (a separate toggle for the “Functional” category);
- Article 5(3) of Directive 2002/58/EC (ePrivacy Directive) as amended by Directive 2009/136/EC — requires prior consent for cookies that are not strictly necessary.
6.3 Analytics Cookies. The legal basis is:
- Article 6(1)(a) GDPR — the Participant’s explicit consent expressed through interaction with the cookie banner (a separate toggle for the “Analytics” category);
- Article 5(3) of Directive 2002/58/EC (ePrivacy Directive) as amended by Directive 2009/136/EC — requires prior consent for analytics cookies.
6.4 Advertising Cookies. The legal basis is:
- Article 6(1)(a) GDPR — the Participant’s explicit consent expressed through interaction with the cookie banner (a separate toggle for the “Advertising” category);
- Article 5(3) of Directive 2002/58/EC (ePrivacy Directive) as amended by Directive 2009/136/EC — requires prior consent for advertising cookies.
6.5 Consent quality requirements. The consent obtained by the Company in respect of categories (b), (c), and (d) meets the requirements of Article 4(11) GDPR and Article 7 GDPR: it is freely given, specific, informed, and unambiguous. Consent is not a condition of access to the Website or Services; refusal does not result in any reduction in the quality of the Services provided.
6.6 Spain — additional requirements. In respect of users located in Spain, the requirements of Ley 34/2002, de 11 de julio, de Servicios de la Sociedad de la Información y de Comercio Electrónico (‘LSSI-CE’) apply in addition to the above. The LSSI-CE requires that users be clearly informed of the use of cookies prior to their installation, except where cookies are strictly necessary. The consent mechanisms described in §7 of this Policy satisfy the requirements of the LSSI-CE as well as those of the ePrivacy Directive.
§7 Consent Management (Cookie Consent Banner)
7.1 Cookie consent management banner. Upon first visiting the Website, the Participant is shown a cookie-consent management banner (Consent Management Platform, “CMP”). That banner:
- informs the Participant of the categories of cookies used and their purposes;
- provides the option of granular consent — the Participant selects their preferences for each category of cookies (§4) individually by clicking “Customise” or “Cookie Settings”;
- contains an “Accept All” button enabling the Participant to consent to all optional categories of cookies in a single action;
- contains a “Reject All” button enabling the Participant to refuse all optional categories of cookies (Functional, Analytics, Advertising) in a single action. Upon clicking “Reject All”, only strictly necessary cookies are set in accordance with §4.1.
7.2 Privacy by Default. By default, prior to the Participant making an active selection, all optional categories of cookies are disabled. Strictly necessary cookies operate regardless of the Participant’s choice.
7.3 Withdrawal of consent. The Participant may withdraw a previously given consent or change their preferences at any time, and is not limited to doing so at the time of their initial visit. To change cookie settings, the Participant should use the “Cookie Settings” / “Manage Consent” link located in the footer of the Website, or contact the Company at privacy@neomfunded.com. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal (Article 7(3) GDPR).
7.4 Record-keeping and storage of consent. The Company maintains a technical consent log recording, for each interaction with the cookie banner:
- the timestamp of the action;
- the version of the Policy in force at the time of consent;
- the Participant’s selection for each cookie category;
- the banner version identifier (CMP version);
- where a Global Privacy Control (GPC) signal is detected, the following additional fields:
gpc_header— the raw value of theSec-GPCHTTP request header;gpc_client_signal— the JavaScript-level GPC signal (navigator.globalPrivacyControl);gpc_applied— a boolean flag confirming whether GPC was honoured for the session;- the requested-vs-applied consent state (audit trail comparing the Participant’s toggle selections to the state actually applied after GPC enforcement).
Consent records are retained for the period specified in the Privacy Policy §8.2(i): twenty-four (24) months from the date of the choice — to demonstrate compliance with the accountability principle under Article 5(2) GDPR and the record-keeping obligation under Article 7(1) GDPR. This retention period is aligned with §5 of this Cookie Policy (Note on the consent-recording mechanism).
7.5 Limitation on re-requesting consent. The Company does not re-request consent in respect of the same processing purpose without a material change in the circumstances of processing. Where an update to this Cookie Policy entails a change in the purposes or composition of cookies, the Participant will be invited to review their preferences.
7.6 Google Consent Mode Disclosure.
7.6.1 Advanced configuration. The Company uses Google Consent Mode in its advanced configuration with Google Analytics 4 and Google Ads. Their tags load when the Participant arrives on the Website but, until the Participant makes a choice through the cookie-consent banner (§7.1), those tags store nothing on the Participant’s device — no cookies, no local storage, no advertising identifiers.
7.6.2 Cookieless pings before consent. Prior to the Participant’s choice, Google LLC receives only cookieless pings comprising: (i) technical information passively added by the browser (timestamp, user agent, referrer, and — as an ordinary component of HTTP traffic — the Participant’s IP address); (ii) coarse information (an indication of whether the current or a prior page in the Participant’s navigation contained ad-click information such as GCLID or DCLID, a Boolean consent state, a random number generated on each page load, and an identifier of the consent management platform in use). IP addresses are used solely to derive country of origin and are not logged by Google Ads or Floodlight systems; Google Analytics does not store or log IP addresses. These signals cannot on their own identify the Participant and are used in aggregate to model conversions. See Google’s reference documentation on Consent Mode (Google Analytics Help — “Consent mode on websites and mobile apps”).
7.6.3 Ad-click redaction. The Company enables the ads_data_redaction parameter to redact ad-click identifiers (GCLID / DCLID) in consent and key-event pings sent to Google Ads before Participant consent for the Advertising category (§4.4).
7.6.4 Enhanced Conversions upon consent. If the Participant accepts the Advertising category (§4.4), the Company will additionally transmit the Participant’s hashed email address (SHA-256) to Google Ads for the Enhanced Conversions attribution feature. This transmission is governed by §8 of this Cookie Policy and the Privacy Policy. Google’s own processing of that data is governed by the Google Privacy Policy. The Participant may withdraw or change this choice at any time under §7.3.
7.7 GPC banner behaviour. Where a valid Global Privacy Control (GPC) signal is detected in the Participant’s HTTP request header (Sec-GPC: 1), the cookie-consent banner:
- displays a GPC-notice informing the Participant that a GPC signal has been detected;
- locks the Advertising category toggle in the “denied” position; the Participant cannot override the GPC signal by manually selecting the Advertising category through the banner.
This behaviour ensures that the Participant’s browser-level opt-out preference (as expressed via GPC) prevails over any subsequent inconsistent banner interaction. Detailed GPC handling and record-keeping are set out in §10.2 and §7.4 respectively.
§8 Third-Party Recipients and International Transfers
8.1 Identified recipients. Data collected via third-party cookies is transferred to the following recipients:
- Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) — Google Analytics (measurement ID G-EZC1YFN5FP), Google Ads (conversion tracking ID AW-18330614498), and Google Tag Manager (container GTM-P4VFT72P). In accordance with the judgment of the Court of Justice of the European Union in Case C-40/17 (Fashion ID), the Company and Google LLC act as joint controllers within the meaning of Article 26 GDPR in respect of the collection of Personal Data via Google Analytics and Google Ads on the Website. Google LLC subsequently acts as an independent controller in respect of its own processing of that data for the operation, improvement, security, and aggregate benchmarking of its services. The essential terms of the joint-controller arrangement are set out in the Google Ads Data Processing Terms — Controller-Controller and in the Google Analytics — Measurement Controller-Controller Data Protection Terms. The Company has enabled the IP-anonymisation function in Google Analytics (
_anonymizeIp). Google’s Privacy Policy: https://policies.google.com/privacy. - Meta Platforms Ireland Ltd (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, D02X525, Ireland) as data controller for users in the EEA/UK; data may be transferred to Meta Platforms Inc (1 Hacker Way, Menlo Park, CA 94025, USA) — for the purpose of providing Meta Pixel (Facebook Pixel), advertising, and retargeting services. Meta’s Privacy Policy: https://www.facebook.com/privacy/policy/.
- Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) — for the purpose of providing content-delivery network (CDN), DDoS protection, browser-integrity check, and Real User Monitoring (RUM) services on the Website (including the RUM beacon script loaded from static.cloudflareinsights.com). Cloudflare acts as a processor on behalf of the Company under the Cloudflare Customer Data Processing Addendum, which incorporates the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) for transfers of personal data to the United States. Cloudflare’s Privacy Policy: https://www.cloudflare.com/privacypolicy/.
- Ahrefs Pte. Ltd. (16 Raffles Quay #33-03, Hong Leong Building, Singapore 048581) — for the purpose of providing the Ahrefs Web Analytics service (ahrefs.com/web-analytics), which measures aggregated Website traffic and user-behaviour metrics. Ahrefs Pte. Ltd. acts as an independent controller in respect of the data collected via its Web Analytics service. Ahrefs Web Analytics is a cookieless analytics service and does not set advertising or profiling cookies on the Participant’s device. Transfers of personal data from the EEA or the United Kingdom to Singapore are carried out under an appropriate transfer mechanism as described in the Ahrefs Data Processing Addendum. Ahrefs’ Privacy Policy: https://ahrefs.com/privacy.
- Intercom R&D Unlimited Company (2nd Floor, Stephen Court, 18-21 St. Stephen’s Green, Dublin 2, D02 PH42, Ireland) — for the purpose of providing in-app messaging, live chat, and help-desk services on the Website. Intercom R&D Unlimited Company acts as a processor on behalf of the Company. Data may be transferred to Intercom, Inc. (55 2nd Street, 4th Floor, San Francisco, CA 94105, USA) under Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2: controller-to-processor) as incorporated in the Intercom Data Processing Agreement. Intercom’s Privacy Policy: https://www.intercom.com/legal/privacy. The cookies set by Intercom on the Participant’s device (
intercom-id-cn115fd0,intercom-device-id-cn115fd0,intercom-session-cn115fd0) and the localStorage entry (intercom.intercom-state-cn115fd0) are identified in §5 above; their retention periods are set out in §9.2. - TradingView, Inc. (222 Broadway, Floor 19, New York, NY 10038, USA) — for the purpose of providing embedded charting widgets, price data, and market-analysis tools loaded on the Website from
tradingview.comand related domains. TradingView, Inc. acts as an independent controller in respect of the data it collects through its widgets, pixel-tracking scripts, and Snowplow-based analytics (including the tracker domainsnowplow-pixel.tradingview.com). Cookies set by TradingView through these mechanisms (_sp_id.6222,_sp_ses.6222,sp) are classified as advertising cookies under §4.4 of this Policy and are set only after the Participant grants consent to the Advertising category. Transfers of personal data from the EEA or the United Kingdom to the United States are governed by TradingView’s own privacy notice and any transfer mechanisms it operates as controller. TradingView’s Privacy Policy: https://www.tradingview.com/policies/. - BunnyWay d.o.o. (Cesta komandanta Staneta 4A, 4470 Jesenice, Slovenia) — for the purpose of serving web fonts to the Website from the
fonts.bunny.netcontent-delivery network (Bunny Fonts). When a Participant’s browser requests a font file, BunnyWay d.o.o. receives the Participant’s IP address,User-Agentstring, and standard HTTP request headers. Bunny Fonts is a cookieless service and does not set any cookies, tracking pixels, or profiling identifiers on the Participant’s device. BunnyWay d.o.o. acts as a processor on behalf of the Company under the BunnyWay Data Processing Agreement. BunnyWay’s Privacy Policy: https://bunny.net/privacy. - Vexapayments Technology Services FZCO (Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, UAE; UAE Free Zone Registration No. 68981) — for the purpose of providing payment processing services on the Website (marketed under the product name Paymaxis). When a Participant initiates a deposit or withdrawal, the Participant is redirected to Paymaxis’ hosted payment page on Paymaxis’ own domain, where card details are entered directly by the Participant. The Company transmits to Vexapayments Technology Services FZCO the following data per transaction: transaction amount, currency, the Company’s pseudonymous order reference, and the Participant’s email address, full name, phone number, and billing address. Card details (PAN, CVV, expiry) are never entered on the Website and are not transmitted through the Company’s systems. No payment-related cookies are set on the Website by Vexapayments Technology Services FZCO or Paymaxis. Vexapayments Technology Services FZCO acts as a processor on behalf of the Company under a signed services agreement that incorporates GDPR-aligned data protection commitments.
8.2 International transfer mechanisms. Cross-border transfers of data from the EEA/UK to the recipients identified in §8.1 are governed by the following mechanisms, grouped by destination:
- United States — for recipients located in the USA acting as processors on behalf of the Company (Cloudflare, Inc. under §8.1(c); Intercom, Inc. under §8.1(e)), transfers are carried out on the basis of Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module 2: controller-to-processor) as incorporated in the respective vendor DPAs. For recipients acting as joint or independent controllers (Google LLC under §8.1(a); Meta Platforms Inc under §8.1(b); TradingView, Inc. under §8.1(f)), the transfer mechanisms are those operated by the recipient as controller and are set out in the respective recipient privacy notices and vendor terms referenced in §8.1;
- Singapore — Ahrefs Pte. Ltd. under §8.1(d) acts as an independent controller. Transfers of personal data from the EEA/UK to Singapore are carried out under the appropriate transfer mechanism operated by Ahrefs Pte. Ltd. as controller, as described in the Ahrefs Data Processing Addendum;
- United Arab Emirates — Vexapayments Technology Services FZCO under §8.1(h) acts as a processor on behalf of the Company. In the absence of an adequacy decision in respect of the UAE, the transfer is governed by the signed services agreement between the Company and Vexapayments Technology Services FZCO, which incorporates GDPR-aligned data-protection commitments and the supplementary measures set out in (e) below;
- Intra-EEA (Slovenia) — BunnyWay d.o.o. under §8.1(g) is established within the European Economic Area; no cross-border transfer mechanism is required for data processed by BunnyWay d.o.o. under Chapter V GDPR;
- Supplementary measures applicable to all cross-border transfers in accordance with EDPB Recommendations 01/2020 (as revised by 02/2021): encryption in transit (TLS 1.2+), encryption at rest (AES-256), contractual restrictions on onward transfers, and pseudonymisation where applicable;
- Meta-specific arrangements — Meta Platforms Ireland Ltd transfers data to Meta Platforms Inc (USA) on the basis of SCCs 2021/914 and/or other mechanisms recognised by the competent supervisory authority (Irish DPC) as adequate.
8.3 Additional measures for Google Analytics. In order to minimise the risks associated with data transfers via Google Analytics, the Company has:
- enabled the IP-anonymisation function (
_anonymizeIp) in all Google Analytics tag instances; - disabled the transmission of data to Google advertising features to the extent compatible with analytics purposes, without prejudice to the Enhanced Conversions flow described in §7.6.4, which operates only upon the Participant’s affirmative consent to the Advertising category (§4.4) and is governed by §7.6 as a whole;
- entered into the Google Analytics — Measurement Controller-Controller Data Protection Terms and the Google Ads Data Processing Terms — Controller-Controller, which set out the joint-controller allocation of responsibilities under Article 26 GDPR and incorporate the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) for transfers of personal data to Google LLC in the United States.
8.4 Participants located in the EEA or the United Kingdom may request a copy of the applicable SCCs (or the UK International Data Transfer Addendum / UK Addendum to the EU SCCs, as applicable) by writing to privacy@neomfunded.com. For information on the Company’s EU Representative under Article 27 GDPR (Prighter GmbH, Paragon 1, Schwarzenbergplatz 4, 1030 Vienna, Austria) and UK Representative under Article 27 UK-GDPR (Prighter Ltd, 20 Mortlake High Street, London, SW14 8JN, United Kingdom; Companies House № 12854033), and on the Company’s EU Data Act Representative under Article 37 of Regulation (EU) 2023/2854 (Data Act), see the Privacy Policy §16.1 and §16.2.
§9 Retention Periods
9.1 General principle. Data collected via cookies is retained only for the period necessary to achieve the purposes for which it was collected, and not beyond the periods set out in this Policy and the Privacy Policy §8.2. This section is aligned with the Privacy Policy §8.2(e).
9.2 Specific retention periods by category.
- Strictly necessary cookies:
neom_funded_session(Laravel application session): 120 minutes idle expiry;XSRF-TOKEN(CSRF protection token): 120 minutes;neomaaa_consent(consent-record cookie): 180 days;neomaaa_gpc(GPC opt-out record, when set): 180 days;NEXT_LOCALE(interface-language preference): 365 days;neomaaa_aff_ref(affiliate referral identifier): 60 days;neomaaa_attribution(campaign-attribution parameters): 90 days;cf_clearance(Cloudflare security challenge, when set): 30 minutes;- Server-side consent log at
/api/consent-log: twenty-four (24) months from the date of the choice; - Consent records at the Privacy-Policy level: retained in accordance with the Privacy Policy §8.2(i).
- Functional cookies:
intercom-id-cn115fd0(Intercom persistent user identifier): 270 days;intercom-device-id-cn115fd0(Intercom persistent device identifier): 270 days;intercom-session-cn115fd0(Intercom session token): 7 days;intercom.intercom-state-cn115fd0(Intercom messenger state, localStorage): retained until the Participant clears browser storage or withdraws Functional consent.
- Analytics cookies:
_ga: 400 days (Chrome cookie-lifetime cap); analytics data on Google Analytics servers — maximum thirteen (13) months in accordance with the Privacy Policy §8.2(e);_ga_EZC1YFN5FP(GA4 session ID cookie): 400 days.
- Advertising cookies:
_fbp,fr(Meta): 90 days;_gcl_au(Google Ads): 90 days;IDE(DoubleClick): 13 months;test_cookie(DoubleClick): 15 minutes;_sp_id.6222(TradingView Snowplow persistent identifier): 400 days;_sp_ses.6222(TradingView Snowplow session cookie): 90 days;sp(TradingView Snowplow pixel,snowplow-pixel.tradingview.com): 365 days.
9.3 Deletion upon expiry. Upon expiry of the applicable periods, first-party cookies are automatically deleted from the user’s device; third-party cookies are deleted by the respective third parties in accordance with their own data-retention policies. Server-side analytics data is retained for no longer than thirteen (13) months.
9.4 Early deletion. The Participant may delete all or specific cookies at any time by using their browser settings (see §11) or the cookie-management tools provided by the relevant platforms (Google, Meta, etc.).
§10 Do-Not-Track and Global Privacy Control
10.1 Do-Not-Track (DNT). A number of browsers and mobile operating systems include a Do-Not-Track (“DNT”) feature or setting that allows the user to signal to websites their preference not to be tracked. Due to the absence of a uniform agreed standard for recognising and interpreting DNT signals within the industry, and in the absence of a single technical specification that has achieved widespread adoption, the Company does not currently respond to DNT signals. This position is consistent with the Privacy Policy §12.1.
10.2 Global Privacy Control (GPC). The Company honours the Global Privacy Control (GPC) signal as a valid opt-out request from the sale and sharing of personal information in accordance with:
- CCPA §1798.135 and the guidance of the California Attorney General;
- CCPA §1798.120 — the right of California residents to opt out of the sale or sharing of their personal information, including the opt-out from cross-context behavioural advertising.
Upon detection of a valid GPC signal in the HTTP request header originating from the Participant’s device, the Company: (i) treats that signal as a valid opt-out request from the sale and sharing of personal information within the meaning of the CCPA/CPRA; (ii) immediately ceases setting advertising cookies (category (d) under §4) and other tracking tools for cross-context behavioural advertising in respect of that Participant; (iii) processes such a request automatically, without any further action being required on the part of the Participant; (iv) sets the Google Consent Mode signals ad_storage, ad_user_data, and ad_personalization to denied for that Participant, so that Google Analytics 4 and Google Ads tags do not use advertising cookies or transmit personal data for advertising purposes (see §7.6); (v) records the GPC event in the technical consent log with the additional fields gpc_header, gpc_client_signal, gpc_applied, and the requested-vs-applied consent state (see §7.4); (vi) locks the Advertising category toggle in the cookie-consent banner in the “denied” position and displays a GPC-notice to the Participant, ensuring that the browser-level opt-out prevails over any subsequent inconsistent banner interaction (see §7.7).
10.3 Scope of GPC. The application of GPC as an opt-out mechanism from advertising cookies extends to California residents in accordance with the CCPA/CPRA. The Company reserves the right to extend the application of this mechanism to other jurisdictions as the regulatory framework evolves.
10.4 Right to limit use of sensitive personal information. California residents may limit the use and disclosure of their sensitive personal information in accordance with CCPA §1798.121 by sending a request to privacy@neomfunded.com with the subject line “Limit Use of Sensitive PI”.
§11 Managing Cookies in the Browser
11.1 Participant’s right. The Participant may at any time manage cookies through their browser settings: viewing installed cookies, blocking their installation (in full or by category), and deleting cookies already installed. It should be noted that restricting or deleting strictly necessary cookies may impair the functioning of the Website or render certain features unavailable.
11.2 Instructions for major browsers. The following links lead to official guidance on managing cookies in the most widely used browsers:
- Google Chrome: https://support.google.com/chrome/answer/95647
- Mozilla Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
- Apple Safari (macOS): https://support.apple.com/guide/safari/manage-cookies-and-website-data-sfri11471/mac
- Microsoft Edge: https://support.microsoft.com/en-us/microsoft-edge
- Opera: https://help.opera.com/en/latest/web-preferences/#cookies
11.3 Third-party cookie opt-out tools. In addition to browser settings, the Participant may use the following industry opt-out tools for targeted tracking:
- Google Analytics Opt-out Add-on: https://tools.google.com/dlpage/gaoptout — a browser extension that prevents the collection of data by Google Analytics;
- Google Ads Settings: https://adssettings.google.com/ — management of Google advertising personalisation;
- Meta Ad Preferences: https://www.facebook.com/ads/preferences/ — management of Meta advertising preferences;
- European Interactive Digital Advertising Alliance (EDAA) — Your Online Choices: https://www.youronlinechoices.com/ — opt-out tool for targeted advertising for users in the EU/EEA;
- Network Advertising Initiative (NAI) Opt-Out: https://optout.networkadvertising.org/ — for users in the USA.
11.4 Mobile devices. Users of mobile devices may also limit advertising tracking through the system settings of their device: “Privacy Settings” → “Tracking” (iOS) or “Google” → “Ads” → “Opt out of Ads Personalisation” (Android).
§12 Contact and Updates
12.1 Cookie contact details. For any questions relating to the use of cookies on the NEOM Funded Website, the manner in which data is collected, processed, and stored via cookies, and for the exercise of rights under this Policy, Participants may contact:
Cookie and privacy enquiries: privacy@neomfunded.com (Privacy Contact; outsourced DPO engagement in progress for the purposes of Article 37 GDPR — see Privacy Policy §16.3)
General enquiries and support: support@neomfunded.com
Registered address: Neom Triple A Information Technology LLC The Binary by Omniyat, Office 2114 Business Bay, Dubai, UAE
Website: neomfunded.com
12.2 Data-subject rights. All data-subject rights in respect of personal data processed by the Company (right of access, rectification, erasure, restriction of processing, portability, objection, withdrawal of consent, complaint to a supervisory authority) are set out in the Privacy Policy §11. To exercise any of those rights, please send a request to privacy@neomfunded.com.
12.3 EU and UK Representatives; EU Data Act Representative. The Company has appointed Prighter GmbH (Paragon 1, Schwarzenbergplatz 4, 1030 Vienna, Austria) as its EU Representative under Article 27 GDPR and Prighter Ltd (20 Mortlake High Street, London, SW14 8JN, United Kingdom; Companies House № 12854033) as its UK Representative under Article 27 UK-GDPR. Full details are set out in the Privacy Policy §16.1. Details of the Company’s EU Data Act Representative under Article 37 of Regulation (EU) 2023/2854 (Data Act) are set out in the Privacy Policy §16.2. Participants located in the EEA or the United Kingdom may contact the relevant Representative on all matters relating to the processing of their personal data by the Company; data-holder and user matters under the Data Act may be addressed to the Data Act Representative via the Prighter Trust Center.
12.4 Updates to this Policy. The Company reserves the right to amend this Cookie Policy at any time in connection with:
- changes to the composition of cookies and tracking technologies used;
- changes in applicable legislation or regulatory guidance;
- changes to the technical infrastructure of the Website.
The current version of this Policy is always available at neomfunded.com. The date of the most recent update and the version number are indicated in the document header. Participants will be notified of material changes by means of a prominent notice on the Website or by email to the address registered to their account.
12.5 Archive versions. Previous versions of this Policy are available on request at privacy@neomfunded.com.
This Policy supersedes all prior versions of the cookie policy published by Neom Triple A Information Technology LLC under the brand NEOM Funded.
Cookie Policy v5.0 | Neom Triple A Information Technology LLC (NEOM Funded) | Publication Date: 26 August 2026