Legal
Device signals
What the FRAPE browser agent reads when a merchant runs it on a sign-up, login or payment page, what it never reads, what it keeps on the device, and what the merchant should tell its users.
Who decides
Roles and purpose
The merchant decides to run the agent, on which pages and for which users, and what happens with the result. The merchant is the controller (the business, under US state laws). FRAPE processes the data only on the merchant's instructions, as its processor or service provider.
The agent runs inside the merchant's page and returns one encoded value. The merchant's own server sends that value to FRAPE with the action being checked. The person's browser never connects to FRAPE, and FRAPE sets no cookies.
The only purpose is fraud prevention and security: spotting automated, disguised or reused devices, recognising a returning device, and helping the merchant investigate suspected fraud. FRAPE does not use device data for advertising, marketing or credit decisions, does not sell it, and does not pool it across merchants: identifiers are hashed with a key that is different for every merchant.
When the merchant uses Decision Core, the AI decision model receives a few coarse device facts derived from these signals: browser and operating system family, primary language, yes or no flags for automation, emulators and a time zone mismatch, and how often the device was seen before at that merchant. It never receives the device identifier, the browser fingerprint or the user agent. The companies that run Decision Core are named on the sub-processor list.
Collected
What the agent reads
| Category | Examples | How it leaves the browser |
|---|---|---|
| Browser and operating systemnavigator.user_agent, navigator.ua_ch.brands, navigator.ua_ch.mobile, navigator.ua_ch.platform, navigator.platform, navigator.language, navigator.languages, navigator.cookies_enabled | User agent, the browser's basic brand and platform hints, platform, preferred languages, whether cookies are enabled. | As the browser reports them, length-limited. Detailed hints that need extra browser permission are never requested. |
| Device and displaynavigator.hardware_concurrency, navigator.device_memory, navigator.max_touch_points, navigator.touch_support, screen.width, screen.height, screen.avail_width, screen.avail_height, screen.color_depth, screen.pixel_ratio, screen.viewport_width, screen.viewport_height | Number of processor cores, approximate memory class, touch support, screen and window size, colour depth, pixel ratio. | Rounded or capped numbers. |
| Time zonetimezone.name, timezone.offset_minutes | Time zone name and offset from UTC. | As reported. This is a setting of the device, not its location. |
| Rendering characteristicsgraphics.canvas_hash, graphics.webgl_hash | How the browser draws a fixed test image, and the graphics card description reported by the browser. | One-way hashes computed in the browser. The image and the graphics description never leave the device. |
| Storage supportstorage.local_storage, storage.session_storage, storage.indexed_db | Whether local storage, session storage and IndexedDB are available. | Yes or no values. |
| Automation indicatorsautomation.webdriver, automation.hints | Signs that a script or automated browser is driving the page, such as the webdriver flag or known automation markers. | A fixed list of yes or no codes. No raw values. |
| Interaction summarybehavior.time_on_page_ms, behavior.first_interaction_ms, behavior.key_events, behavior.pointer_moves, behavior.clicks, behavior.touches, behavior.scrolls, behavior.pastes, behavior.focus_changes, behavior.visibility_changes | Time on the page, time to the first interaction, and how many key presses, pointer moves, clicks, touches, scrolls, pastes, focus changes and tab switches happened. | Counts and durations only. Never which keys, what was typed or pasted, or where the pointer was. The merchant can turn this off. |
| Device identifierdevice_id, device_id_status | A random identifier kept in the merchant website's own browser storage, used to recognise a returning device. | A random value with no meaning of its own, replaced after at most 13 months. The merchant can turn this off. |
| Session reference and metadatasession_id, schema_version, agent_version, collected_at, probe_errors, truncated | A reference the merchant chooses for the current checkout or session, the agent and format version, the time of collection by the device clock, the names of any checks that failed, and whether the payload was shortened. | A random session reference is used if the merchant does not supply one. No secrets: the merchant must not pass a session cookie or token. |
Not collected
What the agent never reads
- What you type: no key values, no per-key timing, no form field contents.
- Clipboard contents. Pastes are counted, never read.
- Pointer or touch positions and movement paths.
- Location from the browser's location service, and no network address discovery through the browser.
- Page addresses, page titles, referrers or other text on the page.
- Advertising identifiers, third-party cookies, or storage belonging to other websites.
- Installed fonts, plugins, battery, camera, microphone or motion sensors.
On the device
Storage disclosure
The agent sets no cookies. These are the only items it writes to the browser, all on the merchant's own website.
| Name | Type | Purpose | Duration | First or third party | Can be turned off |
|---|---|---|---|---|---|
| frape_did | Local storage | Holds a random device identifier so the merchant's fraud checks can recognise a returning device and spot one device behind many accounts. | Up to 13 months (395 days) from when it was issued; the merchant can choose a shorter period. After that the agent replaces it with a new random identifier. It is also removed when the person clears site data for the merchant's website. | First party (the merchant's own website). Not readable by other websites. | Yes. The merchant can turn it off; the agent then writes no identifier. |
| __frape_probe__ | Local storage and session storage | A test value written and removed straight away to check that storage works. It holds no information about the person. | Removed in the same step it is written. | First party (the merchant's own website). | Yes. Only written when the device identifier is on. With the identifier off, the agent does not read or write browser storage at all. |
For merchants
Consent and lawful basis
In the EU and UK, reading device characteristics and storing an identifier on the device fall under the storage-and-access rules, whether or not the data is personal. Separately, the data protection rules need a lawful basis; for fraud prevention that is usually legitimate interest. The merchant chooses its position with its own counsel.
- Option A: ask first
- Load the agent only after the person agrees through your consent tool. Turning off just the device identifier is not enough, because reading device characteristics is covered by the same rules. This is the cautious choice for the EU and avoids the open legal question in option B. Fraud checks still run without the device signals, with fewer inputs.
- Option B: run it as a security measure
- Run the agent without asking, only on pages where a protected action happens (sign-up, login, payment, payout, account changes), relying on the exemption for storage or access that is strictly necessary for a service the person asked for. UK law now gives fraud prevention as an example of that exemption. In the EU, data protection authorities do not all agree on whether device checks for fraud prevention fit it, so take this option there only after your own legal assessment. Either way, use the data for nothing else and disclose it clearly.
Either way, run the agent only where a protected action happens, not across the whole site, and use the switches that turn off the device identifier or the interaction summary when you do not need them.
Retention
What FRAPE keeps
- FRAPE does not store the raw payload from the agent. It keeps the fraud signals derived from it with the decision, and stores identifiers such as the device identifier and IP address only as keyed hashes that differ for every merchant.
- If the merchant turns on device recognition, FRAPE also keeps a short device profile: first and last seen, a counter, browser and operating system family, and keyed hashes. It is deleted once the device has not been seen for longer than the merchant's retention period.
- The merchant sets that retention period within the limits of its plan; it is 395 days unless changed. All of a merchant's data is deleted when its account is purged.
Template
What your privacy notice should say
A suggested paragraph for your own privacy notice. Fill in the bracketed parts and adapt it with your counsel.
Fraud prevention and security. When you sign up, log in, pay, request a payout or change your account details, our pages run a security script. It reads technical details of your browser and device (such as browser type and version, operating system, language, time zone, screen and hardware properties, and signs that an automated tool is in use) and counts how you interact with the page, for example how many keys were pressed, without recording what you type, what you paste or where you click.
The script may keep a random identifier in your browser's local storage so that we can recognise a device we have seen before. We send this information, together with details of the action you are taking and the IP address of your connection, to our fraud-prevention service provider, which processes it on our behalf and only to detect and prevent fraud and to protect accounts. It is not used for advertising and is not combined with data from the provider's other customers.
We rely on [our legitimate interest in preventing fraud and keeping accounts secure / your consent]. We keep this information for [period], or longer where we need it to investigate or defend a fraud case. [If you decline these technologies in our cookie settings, some actions may need extra verification.] For your rights, including how to object, see [link].
Changes
Version history
- · version 0.2 (draft)Device identifier now replaced after at most 13 months; no storage access at all when the identifier is off; full field list; coarse device facts sent to Decision Core disclosed.
- · version 0.1 (draft)First published draft, pending counsel review.
See also the sub-processor list and Security & privacy.