Skip to content

Legal

Device signals

What the FRAPE browser agent reads when a merchant runs it on a sign-up, login or payment page, what it never reads, what it keeps on the device, and what the merchant should tell its users.

Who decides

Roles and purpose

The merchant decides to run the agent, on which pages and for which users, and what happens with the result. The merchant is the controller (the business, under US state laws). FRAPE processes the data only on the merchant's instructions, as its processor or service provider.

The agent runs inside the merchant's page and returns one encoded value. The merchant's own server sends that value to FRAPE with the action being checked. The person's browser never connects to FRAPE, and FRAPE sets no cookies.

The only purpose is fraud prevention and security: spotting automated, disguised or reused devices, recognising a returning device, and helping the merchant investigate suspected fraud. FRAPE does not use device data for advertising, marketing or credit decisions, does not sell it, and does not pool it across merchants: identifiers are hashed with a key that is different for every merchant.

When the merchant uses Decision Core, the AI decision model receives a few coarse device facts derived from these signals: browser and operating system family, primary language, yes or no flags for automation, emulators and a time zone mismatch, and how often the device was seen before at that merchant. It never receives the device identifier, the browser fingerprint or the user agent. The companies that run Decision Core are named on the sub-processor list.

Collected

What the agent reads

Signals read by the FRAPE browser agent
CategoryExamplesHow it leaves the browser
Browser and operating systemnavigator.user_agent, navigator.ua_ch.brands, navigator.ua_ch.mobile, navigator.ua_ch.platform, navigator.platform, navigator.language, navigator.languages, navigator.cookies_enabledUser agent, the browser's basic brand and platform hints, platform, preferred languages, whether cookies are enabled.As the browser reports them, length-limited. Detailed hints that need extra browser permission are never requested.
Device and displaynavigator.hardware_concurrency, navigator.device_memory, navigator.max_touch_points, navigator.touch_support, screen.width, screen.height, screen.avail_width, screen.avail_height, screen.color_depth, screen.pixel_ratio, screen.viewport_width, screen.viewport_heightNumber of processor cores, approximate memory class, touch support, screen and window size, colour depth, pixel ratio.Rounded or capped numbers.
Time zonetimezone.name, timezone.offset_minutesTime zone name and offset from UTC.As reported. This is a setting of the device, not its location.
Rendering characteristicsgraphics.canvas_hash, graphics.webgl_hashHow the browser draws a fixed test image, and the graphics card description reported by the browser.One-way hashes computed in the browser. The image and the graphics description never leave the device.
Storage supportstorage.local_storage, storage.session_storage, storage.indexed_dbWhether local storage, session storage and IndexedDB are available.Yes or no values.
Automation indicatorsautomation.webdriver, automation.hintsSigns that a script or automated browser is driving the page, such as the webdriver flag or known automation markers.A fixed list of yes or no codes. No raw values.
Interaction summarybehavior.time_on_page_ms, behavior.first_interaction_ms, behavior.key_events, behavior.pointer_moves, behavior.clicks, behavior.touches, behavior.scrolls, behavior.pastes, behavior.focus_changes, behavior.visibility_changesTime on the page, time to the first interaction, and how many key presses, pointer moves, clicks, touches, scrolls, pastes, focus changes and tab switches happened.Counts and durations only. Never which keys, what was typed or pasted, or where the pointer was. The merchant can turn this off.
Device identifierdevice_id, device_id_statusA random identifier kept in the merchant website's own browser storage, used to recognise a returning device.A random value with no meaning of its own, replaced after at most 13 months. The merchant can turn this off.
Session reference and metadatasession_id, schema_version, agent_version, collected_at, probe_errors, truncatedA reference the merchant chooses for the current checkout or session, the agent and format version, the time of collection by the device clock, the names of any checks that failed, and whether the payload was shortened.A random session reference is used if the merchant does not supply one. No secrets: the merchant must not pass a session cookie or token.

Not collected

What the agent never reads

  • What you type: no key values, no per-key timing, no form field contents.
  • Clipboard contents. Pastes are counted, never read.
  • Pointer or touch positions and movement paths.
  • Location from the browser's location service, and no network address discovery through the browser.
  • Page addresses, page titles, referrers or other text on the page.
  • Advertising identifiers, third-party cookies, or storage belonging to other websites.
  • Installed fonts, plugins, battery, camera, microphone or motion sensors.

On the device

Storage disclosure

The agent sets no cookies. These are the only items it writes to the browser, all on the merchant's own website.

Browser storage used by the FRAPE browser agent
NameTypePurposeDurationFirst or third partyCan be turned off
frape_didLocal storageHolds a random device identifier so the merchant's fraud checks can recognise a returning device and spot one device behind many accounts.Up to 13 months (395 days) from when it was issued; the merchant can choose a shorter period. After that the agent replaces it with a new random identifier. It is also removed when the person clears site data for the merchant's website.First party (the merchant's own website). Not readable by other websites.Yes. The merchant can turn it off; the agent then writes no identifier.
__frape_probe__Local storage and session storageA test value written and removed straight away to check that storage works. It holds no information about the person.Removed in the same step it is written.First party (the merchant's own website).Yes. Only written when the device identifier is on. With the identifier off, the agent does not read or write browser storage at all.

Retention

What FRAPE keeps

  • FRAPE does not store the raw payload from the agent. It keeps the fraud signals derived from it with the decision, and stores identifiers such as the device identifier and IP address only as keyed hashes that differ for every merchant.
  • If the merchant turns on device recognition, FRAPE also keeps a short device profile: first and last seen, a counter, browser and operating system family, and keyed hashes. It is deleted once the device has not been seen for longer than the merchant's retention period.
  • The merchant sets that retention period within the limits of its plan; it is 395 days unless changed. All of a merchant's data is deleted when its account is purged.

Template

What your privacy notice should say

A suggested paragraph for your own privacy notice. Fill in the bracketed parts and adapt it with your counsel.

Fraud prevention and security. When you sign up, log in, pay, request a payout or change your account details, our pages run a security script. It reads technical details of your browser and device (such as browser type and version, operating system, language, time zone, screen and hardware properties, and signs that an automated tool is in use) and counts how you interact with the page, for example how many keys were pressed, without recording what you type, what you paste or where you click.

The script may keep a random identifier in your browser's local storage so that we can recognise a device we have seen before. We send this information, together with details of the action you are taking and the IP address of your connection, to our fraud-prevention service provider, which processes it on our behalf and only to detect and prevent fraud and to protect accounts. It is not used for advertising and is not combined with data from the provider's other customers.

We rely on [our legitimate interest in preventing fraud and keeping accounts secure / your consent]. We keep this information for [period], or longer where we need it to investigate or defend a fraud case. [If you decline these technologies in our cookie settings, some actions may need extra verification.] For your rights, including how to object, see [link].

Changes

Version history

  1. · version 0.2 (draft)Device identifier now replaced after at most 13 months; no storage access at all when the identifier is off; full field list; coarse device facts sent to Decision Core disclosed.
  2. · version 0.1 (draft)First published draft, pending counsel review.

See also the sub-processor list and Security & privacy.