Cookie Policy

Effective Date: January 1, 2026 · Last Revised: June 11, 2026 · Version 2.10 · Reading time: computing…

Save Policy PDF

Welcome. This Cookie Policy explains how Upmos uses cookies and similar technologies across our marketplace and member services — what they do, what categories we use, who else sets them, and the choices you have. Read it together with our Privacy Policy. By using our Services with cookies enabled, you accept the practices described here.

In Plain English (Non-Binding Summary)

Cookies and similar technologies are small files we use to run Upmos. They keep you signed in, remember your preferences, secure your session, measure performance, and personalize content. We use a mix of first-party and third-party cookies across strictly-necessary, functional, analytics, and advertising categories — the full list is in the Detailed Cookie Table. You can manage or block cookies from your browser, our consent banner, and your Upmos account preferences. We respect Do Not Track and Global Privacy Control signals where required by law, and we do not knowingly drop targeting cookies on visitors known to be under 13.

This plain-language box is provided for accessibility and readability only. It is not a substitute for the full Policy below, which controls in case of any conflict.

Key Points

Below is a summary of the most important aspects of the Upmos Cookie Policy. For full details, refer to the relevant sections throughout this document.

What Cookies We Use

  • Essential (Strictly Necessary): Required for security, authentication, and basic site functionality — cannot be disabled.
  • Functional: Remember your language, currency, theme, and accessibility preferences.
  • Analytics: Help us understand how visitors use our site to improve performance and user experience.
  • Marketing & Advertising: Enable personalized ads, retargeting, and campaign tracking — always require your consent.

Your Control & Rights

  • Consent Required: All non-essential cookies require your explicit opt-in consent before activation.
  • Withdraw Anytime: Change your preferences at any time via our Cookie Preferences page or the cookie banner.
  • Browser Controls: Manage or block cookies directly through your browser settings.
  • GPC Supported: We honor Global Privacy Control signals — marketing cookies are automatically disabled.

Third-Party Cookies

  • Analytics: Google Analytics, Mixpanel, Hotjar — for usage tracking and performance optimization.
  • Marketing: Facebook, Google Ads, Pinterest, LinkedIn, Criteo — for advertising and retargeting.
  • Payments & Security: Stripe (payment processing), Cloudflare (DDoS protection).
  • Data Processing Agreements: All third parties are bound by DPAs and must comply with GDPR, CCPA, and applicable laws.

Compliance & Transparency

  • GDPR Compliant: Lawful basis for each cookie category documented with prior consent for non-essential cookies.
  • CCPA/CPRA Compliant: No sale of personal information collected through cookies.
  • Children Protected: We do not knowingly collect data from children under 16 via cookies.
  • Retention: Session cookies are deleted on browser close; persistent cookies have defined maximum retention periods (30 days to 2 years).

Contact & Support

1. What Are Cookies?

Upmos Inc. (“Upmos,” “we,” “us,” or “our”) is a Delaware corporation (registered office c/o Republic Registered Agent LLC, 262 Chapman Rd Ste 240, Newark, DE 19702, New Castle County), with its principal place of business at 9896 Bissonnet St, Houston, TX 77036, United States. Upmos operates an e-commerce marketplace at upmos.com. This Cookie Policy (the “Policy”) describes how Upmos uses cookies and similar tracking technologies on the marketplace and explains the choices you have. It supplements our Privacy Policy.

Cookies are small text files stored on your device (computer, tablet, smartphone) when you visit our website. They contain information about your interactions with our Services and help us recognize you on future visits.

Types of Cookies by Duration:

  • Session Cookies: Deleted when you close your browser (temporary)
  • Persistent Cookies: Stored for a fixed period ranging from days to years

Other Technologies:

We also use similar tracking technologies including:

  • Pixels & Web Beacons: Tiny images that track page views and user behavior
  • Local Storage: Browser storage for preferences and data
  • Log Files: Server-side records of your interactions
  • Device Identifiers: Unique codes on mobile devices

2. Why We Use Cookies

Cookies help us provide better experiences while respecting your privacy choices.

Primary Purposes:

  • Authentication & Security: Keep you logged in, prevent fraud, protect account access
  • Functionality: Remember your language, currency, cart contents, preferences
  • Analytics: Understand how users interact with our Services to improve them
  • Marketing & Personalization: Show relevant products, track campaign effectiveness
  • Compliance: Meet legal obligations and user consent requirements
First-Party vs. Third-Party Cookies: First-party cookies are set directly by Upmos (upmos.com and our affiliate-tracking sub-domain impact.upmos.com) for essential functions, preferences, and affiliate attribution. Third-party cookies are set by external services we integrate (Google Analytics, Facebook, Stripe, etc.) for analytics, marketing, and payment processing. You can control third-party cookies independently via our Cookie Preferences.

*Essential / strictly necessary cookies are exempt from the consent requirement under the ePrivacy Directive (Directive 2002/58/EC, as amended) Article 5(3), which permits storage of, or access to, information on a user’s device where it is “strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.” The underlying personal-data processing relies on GDPR Article 6(1)(b) (performance of the contract for the Services) and, for fraud-prevention and security elements, Article 6(1)(f) (legitimate interests).

5. Third-Party Cookies

We allow trusted third-party service providers to set cookies on our Services for:

Analytics Partners:

  • Google Analytics – Usage analytics and behavior tracking
  • Mixpanel – Advanced analytics and event tracking
  • Hotjar – User session recording and heatmaps

Marketing & Advertising:

  • Facebook – Conversion tracking and audience building
  • Google Ads – Performance marketing and retargeting
  • Pinterest Ads – Visual commerce and audience targeting
  • LinkedIn Ads – B2B advertising and lead generation
  • Criteo – Dynamic product retargeting

Affiliate & Partner Tracking:

Payments & Security:

  • Stripe – Payment processing and fraud detection
  • Cloudflare – DDoS protection and security

These third parties are bound by Data Processing Agreements and must comply with GDPR, CCPA, and other privacy laws.

6. Other Tracking Technologies

Pixels & Web Beacons

These are transparent 1×1 pixel images embedded in emails and pages to track:

  • Email open rates and click-through rates
  • Page views and engagement
  • Conversion tracking

Device Fingerprinting

We may use device fingerprinting (non-PII identifiers like browser type, OS, screen resolution) to:

  • Detect and prevent fraud
  • Recognize returning users without cookies
  • Comply with security requirements

Legal basis: device fingerprinting receives the same treatment as cookies under ePrivacy Directive Article 5(3) — where fingerprinting is strictly necessary for fraud prevention and security (an essential function of the Services), it is exempt from consent; otherwise we obtain consent and rely on GDPR Article 6(1)(f) (legitimate interests in security and abuse prevention).

Local Storage & IndexedDB

We use browser storage to:

  • Cache essential data for faster loading
  • Store offline functionality data
  • Remember user preferences

You can clear local storage via browser settings.

7. Your Rights & Control

Cookie Consent Management

When you first visit our website, we present a consent banner allowing you to:

  • Accept All: Accept all non-essential cookies
  • Reject All: Reject all non-essential cookies (only essential cookies used)
  • Customize: Choose which categories to accept/reject
  • Manage Later: Update preferences anytime at Cookie Preferences

Browser Cookie Management

Most browsers allow you to control cookies. See guides for:

Disabling Cookies

Warning: Disabling essential cookies may limit website functionality (login, shopping cart, security).

Opting Out of Targeted Advertising

Opt out of behavioral advertising via:

Withdrawal of Consent (GDPR Art. 7(3))

Per GDPR Article 7(3), withdrawing your cookie consent is as easy as giving it. The same one-click mechanism that records your consent also records its withdrawal:

  • Click the “Cookie Preferences” link in our site footer (same surface as the acceptance banner)
  • Toggle any cookie category off to withdraw consent for that category
  • Changes take effect immediately across every page of the site

No emails, forms, or follow-up confirmations are required. Withdrawal does not affect the lawfulness of any cookies that were set before you withdrew consent (GDPR Art. 7(3) second sentence).

Managing Your Choices Later

You can also manage cookies the following ways:

8. Do Not Track & Global Privacy Control

Do Not Track (DNT)

Some browsers include a “Do Not Track” feature. We honor DNT signals where technically feasible, but DNT standards are not yet uniform across the industry. See EFF guidance on DNT.

Global Privacy Control (GPC)

Pursuant to Cal. Civ. Code § 1798.135 and 11 CCR § 7025, we recognize the Global Privacy Control (GPC) signal in your browser as a valid opt-out of sale/sharing request. The signal functions as an opt-out request for:

  • Sale of personal information
  • Sharing of personal information
  • Targeted advertising

When GPC is enabled, we disable marketing and advertising cookies.

9. Amendments & Updates

Changes to This Policy

We may update this Cookie Policy to reflect changes in our practices, technology, or regulations. Material changes will be communicated via:

  • Email notification to registered users
  • Website notice
  • Updated “Last Updated” date

Your continued use of our Services after updates constitutes acceptance of the revised Cookie Policy.

The change log for this Policy is maintained in the Version History table at the end of this document.

10. Children & Minors

Our Services are not directed to children under the age of 16 (or 13, where applicable under local law). We do not knowingly collect personal information from children through cookies or other tracking technologies.

Age-Gated Content

If we discover that cookies have collected data from a child under the applicable minimum age without verified parental consent, we will:

  • Delete all associated cookie data and tracking information promptly
  • Disable any analytics or marketing cookies that may have been activated
  • Notify the parent or guardian if contact information is available

Applicable Laws

  • COPPA (US): Children’s Online Privacy Protection Act, 15 U.S.C. § 6501 et seq.; implementing regulations at 16 CFR Part 312 — verifiable parental consent required before knowingly collecting personal information from a child under 13.
  • UK Age Appropriate Design Code (Children’s Code): Information Commissioner’s Office statutory code of practice under Data Protection Act 2018 § 123 — applies to information society services likely to be accessed by children under 18. Upmos applies the “high privacy by default” standard for users we identify as minors: no marketing or analytics cookies, no behavioural advertising, no nudge techniques, no geolocation by default.
  • GDPR Art. 8(1) (EU): Information-society services offered to a child require parental consent where the child is below the digital-consent age set by the member state (between 13 and 16, varying by member state).
  • CPRA (California): Cal. Civ. Code § 1798.120(c) — affirmative opt-in required before selling or sharing personal information of consumers under 16; for children under 13, verifiable parental consent.
  • GDPR (EU/EEA): Article 8(1) — for information society services offered directly to children, the age of digital consent is 16 by default; Member States may lower this floor to a minimum of 13.
  • UK Age Appropriate Design Code: ICO statutory code under Data Protection Act 2018 § 123 — 15 standards for information society services likely to be accessed by children under 18.

12. Jurisdiction-Specific Rights

Depending on your location, you may have additional rights regarding cookies and tracking technologies:

European Union / EEA (GDPR & ePrivacy)

  • Right to access data collected through cookies
  • Right to erasure of cookie-collected data
  • Right to data portability for cookie-collected information
  • Right to lodge a complaint with your local Data Protection Authority
  • Prior consent required for all non-essential cookies (ePrivacy Directive Art. 5(3))

Supervisory Authorities (GDPR Art. 77). You have the right to lodge a complaint with your national Data Protection Authority. Representative supervisory authorities include:

A full list of EEA supervisory authorities is published by the European Data Protection Board at edpb.europa.eu.

California (CCPA / CPRA)

  • Right to know what personal information cookies collect
  • Right to delete personal information from cookies
  • Right to opt out of the “sale” or “sharing” of personal information via cookies
  • Right to limit the use of sensitive personal information
  • No discrimination for exercising your rights

California Privacy Protection Agency (CPPA). You may file a complaint with the California Privacy Protection Agency under Cal. Civ. Code § 1798.155 if you believe your CCPA/CPRA rights have been violated. You may also notify the California Attorney General at oag.ca.gov/privacy/ccpa.

United Kingdom (UK GDPR & PECR)

  • Same rights as EU GDPR plus UK-specific protections under PECR
  • ICO guidance on cookies applies
  • Age Appropriate Design Code protections for minors

Brazil (LGPD)

  • Right to confirmation and access to cookie data
  • Right to correction and deletion of cookie data
  • Right to object to processing based on cookies

Canada (PIPEDA + Quebec Law 25)

  • Right to know about cookie data collection practices
  • Right to access and correct cookie-collected data
  • Meaningful consent required for non-essential cookies (Office of the Privacy Commissioner of Canada guidance)
  • Quebec residents: additional rights under An Act respecting the protection of personal information in the private sector as amended by Law 25 (2021), including default-private settings and Privacy-by-Design

Japan (APPI)

  • Right to disclosure, correction, and cessation of use of personal data, including data derived from cookies (Act on the Protection of Personal Information, Act No. 57 of 2003, as amended)
  • Consent and joint-use disclosure for third-party transfers, including international transfers

Switzerland (nFADP)

  • Rights under the revised Federal Act on Data Protection (in force 1 September 2023) closely paralleling GDPR access, rectification, and objection rights
  • Right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC)

United States (State Privacy Laws — 2024-2026 Wave)

In addition to federal and California rights, you may have additional privacy rights under emerging state legislation:

  • Connecticut (CTDPA): Conn. Pub. Act 22-15 (eff. Jul 1, 2023) — access, correct, delete, opt-out of sale/sharing/targeted advertising
  • Texas (TDPSA): Tex. Bus. & Com. Code Ch. 541 (eff. Jul 1, 2024) — know, delete, correct, opt-out of sale/processing
  • Oregon (ORCPA): ORS Ch. 646A.570 (eff. Jul 1, 2024) — access, delete, portability, opt-out of sale/sharing
  • Montana (MCDPA): Mont. Code §§ 30-14-2801 et seq. (eff. Oct 1, 2024) — access, delete, correct, opt-out of targeted advertising
  • Delaware (DPDPA): Del. Code Ch. 12D (eff. Jan 1, 2025) — know, delete, correct, opt-out of targeted advertising/profiling, portability
  • Iowa (CDPA): Iowa Code Ch. 715D (eff. Jan 1, 2025) — access, delete, opt-out of sale/targeted advertising, correction
  • New Hampshire: N.H. Rev. Stat. Ann. ch. 507-H (eff. Jan 1, 2025) — access, correction, deletion, opt-out of sale/targeted advertising
  • New Jersey (NJDPA): N.J. Stat. Ann. §§ 56:8-166.4 et seq. (eff. Jan 15, 2025) — know, delete, correct, portability, opt-out of targeted advertising/sale
  • Tennessee (TIPA): Tenn. Code Ann. §§ 47-18-3201 et seq. (eff. Jul 1, 2025) — access, delete, portability, opt-out of sale/sharing/targeted advertising
  • Minnesota (MCDPA): Minn. Stat. ch. 325O (eff. Jul 31, 2025) — access, delete, correct, portability, opt-out of targeted advertising/sale/profiling
  • Maryland (MODPA): Md. Code, Commercial Law §§ 14-4601 et seq. (eff. Oct 1, 2025) — access, delete, correct, portability, opt-out of targeted advertising/sale/profiling
  • Indiana (CDPA): Ind. Code §§ 24-15-1 et seq. (eff. Jan 1, 2026) — know, delete, opt-out of sale/targeted advertising

13. Cross-Border Data Transfers

Cookie data collected on our Services may be transferred to, stored in, and processed in countries outside your country of residence, including the United States.

Safeguards

When we transfer cookie data internationally, we ensure adequate protections through:

  • Standard Contractual Clauses (SCCs): European Commission Implementing Decision (EU) 2021/914 — the modular contractual safeguards used for transfers to third countries lacking an adequacy decision, in light of Schrems II (Case C-311/18)
  • Adequacy Decisions: Transfers to countries deemed adequate by the European Commission
  • EU-US Data Privacy Framework (DPF): Commission Implementing Decision (EU) 2023/1795 (eff. Jul 10, 2023) replaced Privacy Shield following the CJEU’s Schrems II decision. Upmos’s and our service providers’ DPF certification status (where applicable) can be verified at dataprivacyframework.gov. The DPF is currently subject to legal challenge before the CJEU (la Quadrature du Net v. European Commission); accordingly, Standard Contractual Clauses remain in place as a supplementary safeguard.
  • Binding Corporate Rules: Internal rules for multinational data transfers
  • Supplementary Measures: Technical and organizational measures including encryption, pseudonymization, and access controls
  • UK Extension to the EU-US Data Privacy Framework: UK Secretary of State adequacy decision (eff. Oct 12, 2023) extending the DPF to UK-to-US transfers
  • Swiss-US Data Privacy Framework: Swiss FDPIC recognition (eff. Sep 15, 2023) enabling DPF-certified transfers between Switzerland and the United States, aligned with the Swiss nFADP
Third-Party Transfers: Our third-party cookie providers (Google, Facebook, Stripe, Cloudflare, etc.) may transfer data internationally. Each provider maintains their own transfer safeguards. See their privacy policies for details.

14. Data Protection Officer

Our Data Protection Officer (DPO) oversees cookie compliance and data protection matters:

Data Protection Officer

Subject Lines
Cookie Inquiry, Data Access Request, Consent Withdrawal
Response Time
Within 30 days (extendable to 60 days for complex requests)

You may also contact your local Data Protection Authority if you are not satisfied with our response.

15. Frequently Asked Questions

Strictly necessary cookies are essential for the basic functioning of the website. They enable core features like security, session management, and CSRF protection. These cookies cannot be disabled and do not require your consent under GDPR/ePrivacy regulations.

You can withdraw consent at any time by clicking “Manage Cookies” in our cookie banner, visiting the Cookie Preferences page, adjusting your browser settings, or contacting privacy@upmos.com.

First-party cookies are set directly by Upmos (upmos.com domain) and are used for essential functions and preferences. Third-party cookies are set by external services like Google Analytics, Facebook, or Stripe that we integrate for analytics, marketing, and payment processing.

No. We do not use cookies for automated decision-making or profiling that produces legal effects concerning you. Cookie data is used solely for the purposes described in this policy.

Session cookies are deleted when you close your browser. Persistent cookies have variable retention periods: functional cookies last up to 1 year, analytics cookies up to 2 years, and marketing cookies typically 90 days to 2 years. See our Detailed Cookie Table for specific durations.

No. Upmos does not sell personal information collected through cookies. We may share cookie data with trusted third-party service providers for analytics and marketing purposes, but only under strict Data Processing Agreements.

If you block all cookies, essential features like login, shopping cart, and security protections may not work properly. We recommend allowing at least essential/strictly necessary cookies for the best experience.

localStorage stores data with no expiration date; sessionStorage clears when the browser tab closes. Both are browser-based storage mechanisms covered by the same consent framework as cookies under ePrivacy regulations.

16. Contact Us

For questions or concerns about our use of cookies:

Email: privacy@upmos.com
Phone: 1-855-637-2433
Manage Preferences: https://upmos.com/cookie-preferences

Mailing Address:
Upmos Inc.
9896 Bissonnet St
Houston, TX 77036
United States

↑ Top

How Can You Contact Us About This Policy?

If you have any further questions or comments or wish to report any problematic Content or Contribution, you may contact us by:

General Contact

Department Directory

Department Email Purpose
General Support support@upmos.com Account help, general inquiries
Legal legal@upmos.com Legal questions, appeals, terms inquiries
DMCA / Copyright dmca@upmos.com Copyright infringement notices & counter-notices
Privacy privacy@upmos.com Data requests, CCPA/GDPR inquiries
Fraud fraud@upmos.com Report fraudulent activity (24/7)
Security security@upmos.com Vulnerability reports, bug bounty
Disputes disputes@upmos.com Transaction & seller disputes
Refunds refunds@upmos.com Refund requests & status
Accessibility accessibility@upmos.com Accessibility issues & feedback

Mailing Address

Upmos Inc.
9896 Bissonnet St
Houston, TX 77036
United States

Version History

Material revisions to this Policy are tracked below. Minor typographical fixes are not separately enumerated.

Version Date Changes
v2.10 June 11, 2026 JSON-LD hoursAvailable corrected from 09:00–17:00 to 07:00–20:00.


HomeMenuWishlistCompareTo Top