Skip to content
MENA Tracker Guides

Amwal Cookies and PDPL Consent

Amwal's payment integration sets session and checkout cookies. What they do, and why they do not need a consent gate.

Cookies we detect

Category: Necessary
  • amwal_session
  • amwal_token
  • amwal_tx
  • amwal_checkout

Detection patterns are taken from our own cookie classifier and are limited to those confirmed in real scans. Patterns we have inferred from vendor documentation but not yet observed are deliberately not listed.

What Amwal sets

Amwal writes a payment session, a token, a transaction reference and a checkout-state cookie. Like other gateway cookies they are scoped to an in-progress payment and expire with it.

Why it is classified as necessary

The shopper initiated the payment. Without the session and transaction state the gateway cannot complete or reconcile it, so these fall squarely inside the necessary exemption. The test is causal rather than commercial: not 'is this useful to the business' but 'can the visitor finish what they started without it'.

What PDPL requires

Necessary cookies need disclosure, not consent. Your declaration should list them by name with a one-line purpose, in Arabic as well as English, and your consent record should show that the classification was a decision. An audit that finds payment cookies undeclared reads as an incomplete inventory, which undermines the parts of the declaration that are right.

How Arqam360 handles it

Classified necessary, never blocked, declared in both languages. The scanner recognises the patterns rather than reporting them as unknown, which is what a classifier built for European ad tech does with a Saudi payment gateway.

See which of these are on your store right now, and which are firing before anyone consents.

Scan your site free