Skip to main content
Legal

Cookie Policy

This Policy explains how The Vision Corporation Holdings Ltd (the "Bank", "we", "our") uses cookies and similar technologies on thevisionbank.io, its subdomains and our mobile applications. Our approach is deliberately minimal: cookies are used to keep you signed in, protect your Account from fraud, and remember basic preferences — not for behavioural advertising.

Version
v2.0
Effective
15 January 2026
Last updated
15 January 2026
Reading time
~8 min
Jurisdictions
EEA, United Kingdom, Switzerland
Important

What sets our cookie policy apart.

Security over marketing

Where we have to choose between what is convenient for marketing and what is safer for Clients, we choose safer. That is why our cookie set is small and security-driven.

No advertising profiles

We do not build behavioural-advertising profiles, we do not use retargeting pixels, and we do not share cookie data with ad networks.

Essentials are required

Login, account recovery, secure payments and fraud protection depend on essential and security cookies. Blocking them will break the Platform.

Section

01

Introduction

The Vision Corporation Holdings Ltd (the "Bank", "we", "our"), registered in England & Wales (Company No. 16767315), uses a small number of cookies and similar technologies on thevisionbank.io, its subdomains and our mobile applications. This Policy explains what they are, why we use them and how you can manage them. It sits alongside our Privacy Policy, which describes our broader Personal Data practices.

Section

02

What Are Cookies?

Cookies are small text files placed on your device by websites you visit. They let a site recognise your browser between page views and between sessions, so it can keep you signed in, remember your preferences and detect suspicious behaviour.

We also use similar technologies — HTML5 Local Storage, Session Storage and secure browser storage — to hold short-lived session identifiers, cached UI state and cryptographic material used by authentication flows. Where this Policy refers to "cookies" we mean all of these together.

Section

03

Why We Use Cookies

The Bank uses cookies for a narrow set of security- and compliance-driven reasons rather than for advertising. In particular they help us with:

  • Secure login sessions and keeping you signed in across pages.
  • Multi-factor authentication and passkey / WebAuthn flows.
  • Device recognition, so a new device triggers step-up verification.
  • Fraud prevention and account-takeover detection.
  • Detecting suspicious logins from unusual IPs, geographies or user-agents.
  • Session timeout and automatic sign-out on shared devices.
  • CSRF protection for state-changing requests.
  • Bot mitigation, challenge-response and rate-limiting.
  • Load balancing and routing to the closest healthy region.
  • Remembering your language, display currency and cookie-consent choices.

Section

04

Categories of Cookies

We group the technologies we use into five categories. Essential and Security are strictly necessary for the Platform to work safely; the others are optional and only set with your consent where required.

Category
Purpose & requirement
Essential
Login, authentication, CSRF protection — required (Yes)
Security
Fraud detection, session integrity, bot mitigation — required (Yes)
Preferences
Language, display currency, timezone, theme — optional
Performance
Reliability, latency and error monitoring — optional
Analytics
Aggregated platform-usage insights — optional (consent)

Essential

Session, authentication, CSRF, load balancing. The Platform does not work without these.

Always on

Security

Device recognition, step-up-auth state, bot-mitigation tokens, fraud signals.

Always on

Preferences

Language, region, display currency, timezone, appearance, consent choices.

You can opt out

Performance

Error monitoring, latency and reliability telemetry.

You can opt out

Analytics

Aggregated usage statistics that help us improve the Platform.

You can opt out

Section

05

Essential Cookies

Essential cookies are strictly necessary to deliver the Services you request. They include the session identifier that keeps you signed in, a CSRF token that protects state-changing requests, load-balancer affinity cookies, and region-routing cookies that direct your traffic to the correct data centre.

Because they are strictly necessary, essential cookies do not require consent under the UK PECR / EU ePrivacy framework. Disabling them will prevent the Platform from working.

Section

06

Security Cookies

Security cookies help protect your Account from fraud and unauthorised access. They include a hashed device identifier that lets us recognise trusted devices, step-up-authentication state, bot-mitigation challenge tokens, and short-lived IP-reputation caches. They do not identify you personally to third parties.

The legal basis is our legitimate interest in preventing fraud, protecting Client funds and complying with our AML and safeguarding obligations.

RelatedSecurity

Section

07

Preference Cookies

Preference cookies remember choices you make so you do not have to make them again: language, display currency, timezone, theme, and the cookie-consent record itself. They do not track you across other websites. Where required by law we set optional preference cookies only after you have consented.

Section

08

Performance & Analytics Cookies

Performance cookies help us detect errors, measure latency and understand how the Platform is used in aggregate. Analytics cookies produce statistics that inform product decisions. Both are optional and consent-based where required by law. We do not use analytics data to build advertising profiles or target individual users.

Section

09

Third-Party Cookies & Providers

A limited set of trusted providers may set cookies on our behalf, strictly for functional and security purposes. They are contractually bound by GDPR Article 28 data-processing agreements and may only use the data for the specific service we have engaged them for. We do not use ad networks, retargeting pixels or behavioural-advertising cookies, and we do not sell cookie-derived data.

  • Cloud infrastructure — session routing, load balancing, DDoS mitigation.
  • Fraud prevention — device intelligence, bot detection, anti-abuse signals.
  • Identity verification — short-lived cookies used during KYC / liveness flows.
  • Performance monitoring — error reporting and latency telemetry.
  • Email and notification delivery — transactional message tracking (open / bounce).

Section

10

Local & Session Storage

In addition to cookies, we use browser Local Storage and Session Storage to hold short-lived items such as your active session state, cached UI preferences, offline resilience data, and cryptographic material used by passkey and TOTP flows. These entries live only on your device, are cleared when you sign out or clear site data, and are never transmitted to advertisers.

Section

11

Mobile Applications

Our mobile applications do not use browser cookies but rely on equivalent technologies to deliver the same functions: device identifiers, push-notification tokens, and secure keychain / keystore entries used for authentication and preferences. The same principles apply — data is used for security, compliance and platform functionality, never for behavioural advertising.

Section

12

Cookie Retention

Cookies are kept only for as long as needed for the purpose they were set. Session cookies expire when you sign out or close your browser; persistent cookies expire on the schedule below or when you clear them from your browser or the Cookie Preferences page.

Item
Retention
Session cookies
Expire when you sign out or close the browser
Consent record
Up to 12 months — so we do not ask again on every visit
Security / device tokens
Typically 30 – 90 days, refreshed on each secure sign-in
Preference cookies
Up to 12 months
Analytics cookies
Up to 13 months (aggregated, non-identifying)
Local & session storage
Cleared on sign-out or when you clear site data

Section

13

Managing Cookie Preferences

You can change your consent choices for optional cookies at any time from the Cookie Preferences page. Your choice is stored in a preference cookie and applied on every subsequent visit. Withdrawing consent does not affect the lawfulness of any processing carried out beforehand.

Section

14

Browser Controls

All modern browsers — including Chrome, Safari, Firefox, Edge, Brave and Arc — let you view, block and delete cookies through their built-in settings. You can also open the Platform in a private / incognito window, which discards non-essential cookies when the window is closed. Blocking essential or security cookies at the browser level will prevent the Platform from working correctly.

Section

15

Do Not Track & Global Privacy Control

Because we do not use behavioural-advertising cookies, DNT and Global Privacy Control (GPC) signals do not change what we set. Your explicit consent choices on the Cookie Preferences page continue to govern optional analytics and preference cookies.

Section

16

What Happens If Cookies Are Disabled

Disabling essential and security cookies will affect core functionality. Specifically, you may find that:

  • Sign-in is blocked or you are signed out immediately after each request.
  • Account recovery, password reset and MFA flows cannot complete.
  • Secure payment confirmations fail.
  • Sessions do not persist across pages or refreshes.
  • Fraud and account-takeover protections are reduced.
  • Preferences (language, currency, theme) reset on every visit.

Section

17

Changes to This Policy

We may update this Policy to reflect changes in the technologies we use, our providers, or applicable law. Material changes will be notified in-app or by email at least 30 days before they take effect, except where a shorter period is required by law. The version and effective date at the top of this page always reflect the current Policy.

Section

18

Contact Information

For questions about this Cookie Policy, cookie-related data-subject requests, or complaints, use the contacts below. Our target response time for rights requests is 30 days.

Contact

Reach the right team.

Data Protection Officer
dpo@thevisionbank.io
Security Reporting
security@thevisionbank.io
Cookie Preferences
Manage your choices
Registered Office
London, England & Wales
Company Number
16767315
Business Hours
Monday – Friday, 09:00 – 18:00 GMT/BST
Target response
Within 30 days for rights requests

This document is informational and does not constitute legal advice. For clarifications, open a ticket from your Account or write to one of the addresses above.