Home / Cookies

Cookies and device tracking

Last updated 26 August 2026. What we store on your device, what we read from it, and what you can switch off.

The short version

We use a small number of cookies to keep you signed in and to remember your display preferences. We also read a device fingerprint at three moments — registration, sign-in and purchase — to detect duplicate accounts and payment fraud.

We do not use advertising or social-media tracking. No Google Analytics, no advertising pixel, no heat-mapping, no session recording, and nothing on this site sends your visit to a third party.

We do count visits to the public website, using our own measurement that stores nothing on your device. There is no cookie and no identifier that follows you: the key we use to avoid counting one person twice is derived from a value that changes every day, so the same browser is a different, unlinkable key tomorrow. Your IP address is never stored. Details are in section 3.

1. What this notice covers

The rules here are not only about cookies. Both UK and EU law regulate storing information on your device or reading information already on it, whatever the technique. That covers cookies, browser storage and device fingerprinting alike, so all three are described below.

2. The public website

NameWhyTypeLifetime
fundedportal-sessionTies a page request to your visit; needed for forms to workStrictly necessary2 hours
XSRF-TOKENLets a form prove the submission came from you and not from another siteStrictly necessary2 hours
fp_sesCarries your sign-in across the website and the trading panel, so moving between them does not ask you to sign in again. It holds your access tokenStrictly necessarySame as the token: 30 days if you chose to stay signed in, otherwise 12 hours

All three are set with Secure and SameSite=Lax. The first two are additionally HttpOnly, so page scripts cannot read them; fp_ses is not — it is written by the page itself in order to be readable by both the website and the panel, and it is scoped to .fundedportal.com so both can see it. That is the complete list: no other cookie of any kind is set, and there is no preference cookie, because the appearance of these pages is fixed rather than chosen.

There is no third-party embedded content on the marketing pages, so no third party sets a cookie through them.

3. How we count visits

We measure how many people reach the public website and which pages they open. It runs on our own servers and it is deliberately built so that it needs no consent — under both UK/EU and Turkish guidance, audience measurement is exempt when it is first-party, aggregate and cannot follow a person around.

What is recorded for each page view: the date, the page address, the entry page for that visit, a coarse device class (phone, tablet or desktop), the first two letters of your browser language, your country, the domain that linked you here, and any campaign tags in the address you clicked.

What is not recorded, and cannot be reconstructed:

  • Nothing is written to your device. No cookie, no browser storage, no script of ours runs in your browser for this.
  • No identifier that lasts. To avoid counting one visitor twice in a day we compute a one-way key from your IP address, browser signature and a secret that rotates daily. The next day the same browser produces a different key, so visits cannot be joined across days and no profile can be built.
  • Your IP address is never stored. It is used only inside that one-way calculation and then discarded.
  • For this count, your country comes from a database on our own server, not from an outside lookup service. (Registration and purchase are different: there we check the country and region behind your address against our restricted-jurisdiction list, and that check uses an outside lookup service — see the privacy policy.)
  • Only the linking domain is kept, never the full address of the page you came from, because a full address can itself carry personal data.
  • No third party. The data stays in our database and is not shared, sold or exported.

Detailed records are deleted after 90 days; only the daily totals are kept after that. Because there is no lasting identifier, we cannot tell you whether a particular visit was yours, and we cannot single out your visits to delete them — the same design that protects you also limits what we could look up on request.

4. The trading panel

The panel at trader.fundedportal.com stores more, because it has to: your sign-in session, your interface preferences and a local cache so charts and tables do not reload from scratch on every screen. All of it exists to deliver the service you asked for.

The panel sets one cookie — fp_ses, the shared sign-in cookie described in section 2 — and keeps everything else in your browser's local storage, which stays on your device and is not attached to the requests it sends us. What is held in local storage falls into four groups:

GroupWhat it holdsLifetime
Sign-inYour access token and the account you last had open, so a page refresh does not sign you outUntil the token expires — 30 days if you chose to stay signed in, otherwise 12 hours — or until you sign out or clear site data
PreferencesLanguage, display currency, time zone, light or dark appearance, and whether side panels are openUntil you change or clear them
WorkspaceWatchlists, chart indicators and drawings, order-ticket layout, position-list viewUntil you change or clear them
NoticesWhich announcements you have already dismissed, so they are not shown againUntil you clear site data

None of it is analytics, and none of it is shared with a third party. Clearing site data for trader.fundedportal.com removes all four groups; you will be signed out and your workspace returns to its defaults.

5. Device fingerprinting

This is the part most sites hide in a footnote, so here it is in full.

4.1 What it is

When you register, sign in or buy, we compute a value from your browser and device configuration and store that value — not the underlying details — together with your IP address and browser identification string.

4.2 Why we do it

To detect one person holding accounts that the rules require to be one per person, and to detect payment fraud. It is the mechanism behind the account-matching described in our privacy policy.

4.3 The legal position, stated honestly

Reading a device fingerprint engages the same rule as setting a cookie. We rely on it being necessary to deliver a service you asked for — an assessment whose result means something depends on the one-account-per-person rule actually holding.

We will not pretend this is beyond argument. Fraud prevention serves us as well as you, and a regulator could take the view that consent is required.

Our recorded position has two parts, because two different rules apply to the same act. Reading the value from your device is done on the basis that it is strictly necessary to deliver the service you asked for — an assessment whose result means anything depends on the one-account-per-person rule actually holding. Everything we do with the value afterwards — storing it, matching it against other accounts, acting on a match — is done on the basis of our legitimate interest in keeping one person to one account and preventing payment fraud, which is the same basis recorded in the privacy policy.

We have written down the balancing test behind that second limb and will give it to you if you ask. If a regulator or a court tells us the first limb needs consent instead, we will ask for consent rather than argue about it.

We do not use the fingerprint for advertising, analytics or profiling for any purpose other than the two named above. If we ever wanted to, that would require your consent and we would ask for it.

6. Automated decisions

Signals from this data can suspend an account or hold a payout automatically. You can ask a person to review any such decision — how to do that is on the complaints page, and your rights are set out in the privacy policy.

7. When a consent banner becomes mandatory

Right now we do not show one. Everything above is either strictly necessary, a preference you chose yourself, or the visit counting in section 3 — and that counting is exempt precisely because it writes nothing to your device, keeps no lasting identifier and shares nothing with anyone. Take any one of those three properties away and the exemption goes with it.

So the banner becomes mandatory the moment we add any advertising pixel, third-party analytics service, heat-map, session recorder, A/B testing tool or third-party embed — or if our own counting ever started using a cookie or an identifier that survives the day. A consent banner is a precondition of that change, not a follow-up task, and it must ask before the tag loads rather than after.

8. Your controls

You can clear or block cookies and site data in your browser at any time. Blocking the session cookie means sign-in stops working — that is a technical consequence, not a penalty.

You cannot clear a device fingerprint the way you clear a cookie, because nothing is written to your device to be cleared. If you object to it, write to support@fundedportal.com; we will consider the objection and tell you the outcome and our reasons.

9. How long we keep it

Cookies expire as shown above. Fingerprint records and the associated IP and browser strings are kept for 24 months from the last time we saw the value, and are then deleted — unless they are attached to an open investigation or to a record we are required to retain. The period is what it is because duplicate-account patterns typically surface across successive purchases rather than within one; keeping the records shorter would defeat the purpose, and keeping them longer would not add anything.

10. Who else sees it

The data described here stays with us and our hosting provider. It is not sold, and it is not shared with advertisers or data brokers. Our servers are in France, operated on our behalf by Contabo GmbH, a provider established in Germany. Because that is inside the EEA, the transfer out of the United Kingdom relies on the UK's adequacy regulations for the EEA rather than on standard contractual clauses.

11. Changes

If we start using a technology that is not listed here, we update this page before we switch it on. Each version is dated and retained, so it is possible to establish what you were told and when.

12. Contact

Questions about anything on this page: support@fundedportal.com. Our supervisory authority is the Information Commissioner's Office, and you can complain to them whether or not you come to us first.

Privacy policy Complaints Legal information