Legal

Cookie Policy

Cookies, local storage and similar technologies on nas.cards and the Partner-facing Surfaces. Default-off posture for analytics and marketing.

Last revised: 25 May 2026

This Cookie Policy explains how Nano Advanced Services Limited (“NAS”, “we”, “us”) uses cookies, local storage, and similar technologies on nas.cards and on the Partner-facing web Surfaces (the Business Portal, the Support Portal, and the Admin Back-office). It is published alongside our Privacy Policy and our Partner Privacy Policy, which describe how we handle personal data more generally.

This Cookie Policy is written to comply with the ePrivacy Directive (Directive 2002/58/EC, as amended) and corresponding national implementations in the EU/EEA, the UK Privacy and Electronic Communications Regulations 2003, and the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486).


1. What are cookies and similar technologies?

A cookie is a small text file that a website stores on your browser or device. Local storage and session storage are browser-provided storage mechanisms similar in purpose to cookies. Pixel tags (or web beacons) are tiny images included in web pages or emails that allow a site or sender to detect activity. We refer to all of these collectively as “cookies” in this Policy.

Cookies can be either:

They can also be either:


2. Our default position

We do not set any cookies on first visit other than as required to deliver the page you requested. We do not use analytics, marketing, or advertising cookies by default.

If you make a choice in our cookie banner, we record that choice in your browser’s local storage (not in a cookie). Storing the choice this way is permitted under the ePrivacy rules where the storage is strictly necessary to comply with your expressed preference.

If you later choose to enable analytics or marketing tracking (for example, by adjusting your preferences via the “Cookie preferences” link in the footer), additional cookies may be set, and we will describe them transparently before enabling them.


3. Categories of cookies we may use

3.1 Strictly necessary

These cookies and storage entries are required to deliver the Services you have requested. We do not need your consent for these.

3.2 Anti-bot / fraud-prevention

We use Google reCAPTCHA Enterprise on our contact form (and may use it on other interactive forms across our Surfaces) to detect and deter automated abuse. The service may set cookies on your device and may collect technical information about your interaction with the page (such as mouse-movement patterns, timing data, and a token issued by the service).

There are two legal bases at work, and they are separate:

reCAPTCHA Enterprise is provided by Google LLC (United States). Transfers of personal data to Google in the United States are made under the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Agreement / UK Addendum to the SCCs as applicable), supplemented by additional technical and organisational measures.

3.3 Functional preferences

If you customise any aspect of a Partner-facing Surface (for example, language preference, theme, or table-view settings), we may store that preference in browser local storage on the device you are using. These preferences are not transmitted off your device except to apply your preference when the page reloads.

3.4 Analytics — currently not used by default

We do not use first-party or third-party analytics cookies on nas.cards by default. If we introduce analytics in future, we will require consent through the cookie banner before the analytics cookies are set, and we will update this Cookie Policy to describe the analytics provider and the cookies in question.

3.5 Marketing and advertising — not used

We do not use marketing or advertising cookies on nas.cards.


4. Cookies set on Partner-branded Customer Surfaces

The Consumer Web client, Business Portal, and other Partner-branded Surfaces operated by NAS on behalf of a Partner may set cookies and use local storage to enable authentication, session management, customer-preference recording, and security functions. These cookies are set in the operation of the Services on the Partner’s behalf, and the Partner’s own customer-facing privacy notice is the primary place to look for the cookies set in respect of the Partner’s Customers.

We may also use the third-party anti-bot service on Customer-facing forms (registration, sign-in, password recovery) on these Surfaces, on the legitimate-interests basis described above.


5. How to control cookies

You can decline non-essential cookies in our cookie banner when it appears (typically on first visit). You can change your choice at any time via the “Cookie preferences” link in the page footer.

5.2 In your browser

Most browsers let you view, manage, delete, and block cookies through the browser settings. Restricting or blocking cookies may break Services that depend on strictly-necessary cookies (for example, you may not be able to stay signed in to the Business Portal). The Help section of your browser explains how. Useful starting points:

5.3 Opting out of tracking signals (Do Not Track, Global Privacy Control)

We respect the Global Privacy Control (GPC) signal where it is recognised under Applicable Law. If your browser sends a GPC signal, we treat it as a request not to be subject to non-essential tracking, even where you have not made an explicit choice in our cookie banner. We do not currently honour the legacy “Do Not Track” signal because it is not consistently defined; we apply the GPC standard instead.


Because we operate a default-off posture, the cookie list below is intentionally short. We will update this list as Surfaces and integrations evolve.

Name Type Set by Purpose Duration
nas-cookie-consent local-storage NAS (first-party) Records your cookie-preference choice so we don’t ask again on each visit. Until you clear local storage or change preferences
JSESSIONID or equivalent session cookie NAS (first-party, on Partner-facing Surfaces) Maintains your authenticated session. End of browser session
XSRF-TOKEN or equivalent session cookie NAS (first-party, on Partner-facing Surfaces and on nas.cards contact form) Protects against cross-site request forgery on form submissions. End of browser session
Cookies set by the third-party anti-bot service third-party Third-party service provider Detect and deter automated abuse on interactive forms. Per the service provider’s policy; typically up to 6 months

A more detailed list of the cookies set on a given Partner-branded Surface is available from the Partner that operates the relevant Program.


7. International transfers

Where a third-party service used in connection with a cookie may transfer information internationally (for example, to a service provider located outside the EU/EEA, the UK, or Hong Kong), we rely on the transfer mechanisms described in our Privacy Policy and our Data Processing Addendum.


We may update this Cookie Policy from time to time. The “Last revised” date at the top reflects the most recent revision. If we introduce new categories of cookies (for example, if we add analytics in future), we will update the Cookie Policy and the cookie banner before the new cookies are set.


9. How to contact us

For any cookie-related question, please contact privacy@nas.cards.