Legal

Cookies Policy

Website tracking technologies and privacy choices

Legal EntityCyrafa LLC, a Montana domestic limited liability company
Federal StatusFinCEN-registered Money Services Business (MSB), Registration No. 31000307129357
Registered ActivitiesMoney transmission and dealing in foreign exchange, as stated in Cyrafa's FinCEN registration record
Effective DateAugust 18, 2026
Last UpdatedAugust 18, 2026
Contact Email[email protected]

Summary: Cyrafa uses cookies and similar technologies to operate and secure its website and services, remember choices, prevent fraud, support account and payment workflows, and understand performance. Optional technologies are controlled through Cookie Settings where required. Cyrafa does not intentionally use advertising cookies for cross-context behavioral advertising as of the effective date.

1. About Cyrafa and This Policy

Cyrafa LLC ("Cyrafa," "we," "us," or "our") is a Montana limited liability company with its principal office at 1001 S Main St, Suite 600, Kalispell, Montana 59901, United States. Cyrafa is registered with the U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) as a Money Services Business (MSB), registration number 31000307129357. FinCEN registration is a federal registration under the Bank Secrecy Act. It is not a bank charter, deposit insurance, a state money-transmitter license, an endorsement, or approval by FinCEN or another government agency. Banking, payment, custody, digital-asset, foreign-exchange, settlement, account or card functions may be provided by independent regulated or contracted partners. This Cookies Policy explains how cookies, software development kits, local storage, pixels, tags, scripts, device identifiers and related technologies are used on cyrafa.com and any Cyrafa dashboard, portal, application or online service that links to this Policy (collectively, the "Online Services"). It supplements the Cyrafa Privacy Policy and any product-specific or financial privacy notice.

2. Definition - Cookies and Similar Technologies

2.1 Cookies. Small text files or identifiers stored by a browser or device. Session cookies usually expire when the browser closes; persistent cookies remain until their stated expiration, deletion or replacement.

2.2 Local storage and device storage. Browser or application storage used to retain settings, tokens, consent records or feature information. It can store more information than a traditional cookie.

2.3 Pixels, tags and web beacons. Small code elements or images that record when a page, message or feature is viewed or used and may transmit related device or interaction information.

2.4 Software development kits and application technologies. Code incorporated into an application or service to enable security, analytics, communications, identity verification or other functionality.

2.5 Server logs, APIs and device signals. Technical records and signals generated when a browser, application or system communicates with Cyrafa or a service provider. These may function without placing a cookie on the device. For simplicity, this Policy uses the term "cookies" to refer collectively to these technologies unless the context requires a distinction.

3. Information Collected Via Cookies

Depending on the technology, feature and user choices, cookies may collect or generate:

3.1 Online and device identifiers. IP address, cookie identifier, device or browser identifier, session identifier, advertising identifier where lawfully enabled, and similar pseudonymous identifiers.

3.2 Device and network information. Browser type, operating system, device type, language, time zone, screen settings, network information, approximate location derived from IP address, and diagnostic attributes.

3.3 Usage and interaction information. Pages and features viewed, links selected, navigation paths, referring page, dates and times, visit frequency, session duration, downloads, form interactions, errors, load times and performance data.

3.4 Account and session information. Login state, authentication and security events, assigned user role, session continuity, consent choice and preferences. Passwords, private keys and wallet seed phrases are not stored in ordinary website cookies.

3.5 Security and risk signals. Bot indicators, suspicious access patterns, device or session reputation, failed authentication, fraud signals and information needed to investigate abuse or protect a payment or onboarding flow.

3.6 Campaign and communication information. Referral source, campaign parameters, whether a service message was delivered or opened, support-chat state and scheduling or contact-form interactions where those features are enabled. Cookie-linked information may be personal data when it identifies, relates to, describes, or can reasonably be linked with an individual, household, browser or device. Cyrafa handles such information in accordance with the Cyrafa Privacy Policy and applicable law.

4. First-Party and Third-Party Technologies

First-party technologies. These are set by Cyrafa or through a Cyrafa -controlled domain. They may support security, sessions, user choices, performance and core functionality. Third-party technologies. These are set or operated by another organization, such as a hosting, cybersecurity, identity-verification, analytics, communications, support, scheduling or embedded -content provider. The provider may process information for Cyrafa under contract or, for a separate purpose, under its own privacy notice. Cyrafa seeks to use providers subject to appropriate privacy and security terms and, where practicable, configures analytics and similar providers to act as service providers or processors rather than to use Cyrafa website data for their own cross-context advertising. A third party's independent processing remains governed by its own notice.

5. Categories of Cookies Used

CategoryPurpose and examplesTypical durationControl treatment
Strictly necessaryProvide requested pages and services; route traffic; maintain secure sessions; authenticate users; prevent cross-site request forgery; remember consent choices; and support core account or transaction workflows.Session or provider-specificAlways active because the service cannot operate securely without them.
Security, fraud and complianceDetect bots, abuse, account takeover and suspicious access; support device and session risk; protect onboarding and payment flows; and help satisfy security, fraud-prevention and legal obligations.Session or justified persistent periodUsually treated as necessary. Cyrafa limits use to security, compliance and service protection.
Preferences and functionalityRemember language, region, interface settings and other choices; enable optional support or convenience features; and improve continuity between visits.Provider-specificOptional where required. Disabling them may reduce functionality but should not block core services.
Analytics and performanceMeasure visits, navigation, referrals, errors, load times, feature use and aggregate trends so Cyrafa can maintain and improve the website and services.Provider-specificOptional where consent is required. Cyrafa seeks to configure providers as service providers or processors and to reduce unnecessary identifiers.
Communications and supportOperate chat, scheduling, forms, help-desk, video or customer-support features and understand whether service communications function correctly.Provider-specificMay be necessary for a requested feature or optional in other cases. The relevant tool may provide an additional notice.
Advertising or targetingMeasure campaigns or personalize advertising across unrelated services. Cyrafa does not intentionally use this category for cross-context behavioral advertising as of the effective date.Not currently intended for deploymentMust remain disabled unless lawfully implemented with required notice, consent and opt-out controls.
Embedded content and social mediaLoad third-party videos, maps, social content or other embedded features. The provider may recognize the browser or apply its own technologies.Provider-specificOptional where required. Users may be asked to activate the content before the provider is contacted.

The live Cookie Settings tool identifies each active technology by name, provider or domain, category, purpose, first- or third-party status, and expiration or retention period. That live inventory controls if it is more specific than this summary.

6. How Cookie Information are used

6.1 Operate requested services. Deliver pages and account features, maintain sessions, route traffic, balance workloads, process forms and support requested dashboard, onboarding, account, payment, payout, treasury and transaction functions.

6.2 Protect users and the platform. Authenticate access, detect bots and account takeover, prevent fraud and abuse, investigate suspicious activity, maintain audit trails and protect the confidentiality, integrity and availability of systems.

6.3 Support compliance. Protect KYC, KYB and enhanced -due-diligence workflows; preserve the integrity of required records; support sanctions, fraud and transaction controls; and comply with lawful obligations applicable to Cyrafa or its partners.

6.4 Remember settings. Retain language, region, display, consent and other choices so the Online Services operate consistently.

6.5 Measure and improve performance. Understand aggregate traffic and feature use, diagnose errors, test reliability and improve content, navigation, accessibility and service design.

6.6 Communicate and provide support. Enable help, chat, appointment, contact, feedback and service-notification tools selected by the user.

6.7 Measure permitted campaigns. Understand the source of a visit or the performance of a business -to-business campaign without using sensitive financial, identity or transaction information for behavioral advertising.

7. Financial Services, Security and Regulatory Processing

Because Cyrafa supports financial and digital -asset workflows, certain technologies are necessary to protect accounts and transactions, verify that a request is genuine, prevent fraud, maintain system integrity and comply with legal or partner requirements. A choice to reject optional cookies does not prevent Cyrafa from using necessary security, authentication, fraud-prevention, compliance or recordkeeping technologies. Where cookie -linked information is nonpublic personal information or customer information subject to the Gramm-Leach-Bliley Act, Regulation P, the FTC Financial Privacy Rule or the FTC Safeguards Rule, Cyrafa processes it in accordance with the applicable financial-privacy and security requirements. This Cookies Policy does not replace a model financial privacy notice that may apply to a personal, family or household financial relationship. Security reminder: Cyrafa will never use a cookie or support request to ask for a wallet private key or seed phrase. Do not enter private keys, seed phrases, passwords or one -time authentication codes into an unverified form.

8. Consent and the Cookie Settings Tool

The Online Services provide a Cookie Settings link or comparable control where required. The control allows a user to accept, reject or adjust optional categories and displays the active cookie inventory. Strictly necessary and qualifying security technolo gies remain active because they are required to deliver and protect the requested service. Where prior consent is required, optional cookies are not placed or activated until the user makes an affirmative choice. Choices are not inferred from silence, inactivity, continued browsing or preselected options. Withdrawing consent is as easy as giving it. A changed choice applies prospectively and may not delete data already lawfully collected or records that must be retained for security, legal or compliance purposes. Cyrafa may record the consent or preference selected, the date and time, the relevant policy or banner version, the jurisdiction or language presented, and a limited browser or device identifier. This record is used to apply the choice and demonstrate compliance.

9. How to Manage Cookies

9.1 Use Cookie Settings. Select the Cookie Settings link in the website footer or reopen the cookie banner to review and change optional categories.

9.2 Use browser or device controls. Most browsers allow users to view, block or delete cookies, limit third -party cookies and clear site data. Device and application settings may provide similar controls.

9.3 Enable a recognized preference signal. Users may enable GPC or another legally recognized universal opt -out mechanism in a supported browser or extension.

9.4 Adjust third-party settings. Some analytics, communications, video, social or advertising providers offer their own privacy controls. Those choices may apply across services operated by that provider.

9.5 Contact Cyrafa. Email [email protected] with the subject line "Cookie Privacy Request" if a required control is unavailable or if assistance is needed. Browser instructions vary and may change. Clearing cookies may delete stored choices, sign a user out, or require the user to select preferences again. Private browsing, cookie blockers and network-level tools may also affect how controls operate.

10. Upon Disabling Cookies

Blocking strictly necessary, authentication, security or compliance technologies may prevent the Online Services from loading correctly, maintaining a secure session, completing onboarding, authenticating an account, processing a request or protecting a tr ansaction. Cyrafa may be unable to provide a requested feature where the necessary technology is disabled. Rejecting analytics, preference or embedded -content cookies should not prevent access to the basic public website, but may cause settings to be forgotten, reduce personalization, disable optional content or make it harder for Cyrafa to diagnose performance issues.

11. Retention and Deletion

Session cookies generally expire when the browser or application session ends. Persistent cookies expire after the period shown in the live Cookie Settings inventory, are replaced, or are deleted by the user. Cyrafa reviews durations with the aim of using the shortest period reasonably necessary for the stated purpose. Information generated from cookies may be retained separately from the cookie itself for security, fraud prevention, diagnostics, consent records, legal compliance, dispute resolution or audit purposes. Those records are retained under the criteria and sch edules described in the Cyrafa Privacy Policy and applicable financial-crime, tax, accounting, litigation-hold or other legal requirements. Aggregated or deidentified information may be retained where legally permitted.

12. Security and Data Minimization

Cyrafa uses administrative, technical and physical safeguards designed to protect cookie -linked information in light of its nature and risk. Measures may include encryption in transit, secure and HttpOnly attributes where appropriate, SameSite controls, limited domain and path scope, session expiration, access controls, logging, monitoring, vulnerability management and contractual controls for providers. Cyrafa seeks to avoid placing sensitive identity documents, full financial -account numbers, passwords, authentication codes, private keys or wallet seed phrases directly in cookie values. No internet transmission or storage method is completely secure, and users should protect their devices and account credentials.

13. Third-Party Websites, Partners and Embedded Services

The Online Services may link to or integrate with banks, payment providers, identity-verification services, digital asset providers, scheduling tools, support services, social platforms or other third parties. When a user leaves Cyrafa's domain, is redirected to a partner, activates embedded content or uses a partner-hosted feature, that third party may apply its own cookies and privacy notice. Cyrafa does not control an independent third party's technologies merely because the Online Services link to or interoperate with the third party. Users should review the provider's notice and controls. Where Cyrafa selects a processor to act on its behalf, Cyra fa seeks appropriate contractual privacy, confidentiality and security protections.

14. Children and Minors

The Online Services are designed for businesses and are not directed to children under 13 or to minors. Cyrafa does not knowingly use cookies to profile children for targeted advertising or knowingly sell or share children's personal information. If Cyrafa learns that cookie -linked information was collected from a child contrary to applicable law, it will take reasonable steps to delete or restrict it. Where Cyrafa has actual knowledge or willfully disregards that a user is between 13 and 15 years old, it will not sell the user's personal data or use it for targeted advertising without the affirmative authorization required by applicable law. A parent or guardian may contact Cyrafa using Section 22.

15. Changes, Accessibility and Language

Cyrafa may update this Policy when its technologies, providers, services or legal obligations change. The Last updated date identifies the current version. If a change materially expands the use of previously collected cookie data, Cyrafa will provide the notice, renewed consent or opportunity to withdraw required by applicable law before applying the materially different practice. Cyrafa makes this Policy and the Cookie Settings tool reasonably accessible to individuals with disabilities. Where required, Cyrafa will make the notice available in each language in which it provides a covered product or service. Users who need this Policy in an alternative format may contact Cyrafa.

16. Contact and Privacy Requests

Questions, consent withdrawals, cookie complaints and privacy requests may be sent to: Cyrafa LLC 1001 S Main St, Suite 600 Kalispell, Montana 59901 United States Email: [email protected] Suggested subject line: Cookie Privacy Request Do not email passwords, private keys, seed phrases, authentication codes, full payment -card details or unrequested identity documents. Cyrafa may provide a secure channel if additional information is reasonably necessary to address a request. This Cookies Policy should be read together with the Cyrafa Privacy Policy and any product-specific or financial privacy notice presented for a particular service.