Amwal Cookies and PDPL Consent
Amwal's payment integration sets session and checkout cookies. What they do, and why they do not need a consent gate.
Cookies we detect
Category: Necessary- amwal_session
- amwal_token
- amwal_tx
- amwal_checkout
Detection patterns are taken from our own cookie classifier and are limited to those confirmed in real scans. Patterns we have inferred from vendor documentation but not yet observed are deliberately not listed.
What Amwal sets
Amwal writes a payment session, a token, a transaction reference and a checkout-state cookie. Like other gateway cookies they are scoped to an in-progress payment and expire with it.
Why it is classified as necessary
The shopper initiated the payment. Without the session and transaction state the gateway cannot complete or reconcile it, so these fall squarely inside the necessary exemption. The test is causal rather than commercial: not 'is this useful to the business' but 'can the visitor finish what they started without it'.
What PDPL requires
Necessary cookies need disclosure, not consent. Your declaration should list them by name with a one-line purpose, in Arabic as well as English, and your consent record should show that the classification was a decision. An audit that finds payment cookies undeclared reads as an incomplete inventory, which undermines the parts of the declaration that are right.
How Arqam360 handles it
Classified necessary, never blocked, declared in both languages. The scanner recognises the patterns rather than reporting them as unknown, which is what a classifier built for European ad tech does with a Saudi payment gateway.
See which of these are on your store right now, and which are firing before anyone consents.
Scan your site freeOther MENA trackers
Necessary
Mada
Necessary
SMSA Express
Marketing
Tabby
Marketing
Tamara
Marketing
ArabClicks
Marketing
Lana Ads
Marketing
Tap Network
Last updated: