Cookie Policy

Effective July 28, 2026 · Last updated July 28, 2026

This policy lists every cookie and browser-storage key Payment Recovery System sets, what each one does, and how long it lives. It supplements our Privacy Policy, which governs personal data generally.
ePrivacy / PECRNo advertising cookiesGPC honoured

1. What Cookies Are

A cookie is a small text file a site asks your browser to store and send back on later requests. Related technologies — localStorage, sessionStorage, and tracking pixels — do much the same job by different means. Throughout this policy “cookies” means all of them, because the law that governs them does not turn on the storage mechanism.

A first-party cookie is set by this site. A third-party cookie is set by another company whose code runs on a page you visit — for us, that is Stripe on the card-update page and Google Analytics on the marketing site, and nobody else.


2. Categories We Use

We group cookies into three categories:

  • Strictly necessary — the Service cannot function without them. They keep you signed in, protect forms against CSRF, and let Stripe complete a card update. These are exempt from prior-consent requirements under Article 5(3) of the ePrivacy Directive and the equivalent UK PECR exemption, because you asked for the service they deliver.
  • Functional — remember preferences such as a collapsed sidebar. We currently set none; the row is kept so the categorisation stays stable if that changes.
  • Analytics — aggregate, anonymised traffic measurement on the public marketing pages. These are not strictly necessary and are only set where we have a lawful basis to set them (Section 6).

We set no advertising, retargeting, or cross-site tracking cookies, and we do not embed social-media pixels.


3. Full Cookie Inventory

The table below is exhaustive as of the “last updated” date at the top of this page.

Strictly necessary

CookieSet byPurposeDuration
authjs.session-token / __Secure-authjs.session-tokenFirst partyKeeps you signed in to the dashboard. Issued by Auth.js after successful authentication; the __Secure- prefixed variant is used over HTTPS.30 days, or until sign-out
authjs.csrf-token / __Host-authjs.csrf-tokenFirst partyCross-site request forgery protection for sign-in, sign-up, and password-reset form submissions.Session
authjs.callback-urlFirst partyRemembers which page you were on so you are returned there after signing in.Session
admin_sessionFirst partyAuthenticates platform administrators in the internal admin panel. Never set on customer accounts.Session
__stripe_mid, __stripe_sidStripe, Inc.Set by Stripe Elements on the hosted card-update page for fraud detection and payment-session continuity. Required for a card update to complete.__stripe_mid: 1 year · __stripe_sid: 30 minutes

Functional

None currently in use.

Analytics

CookieSet byPurposeDuration
_ga, _ga_<container-id>Google Analytics 4 (Google LLC)Distinguishes visitors and sessions so we can measure aggregate traffic to the marketing site. IP anonymisation is enabled. Only loaded when a Measurement ID is configured.Up to 2 years

4. Email Tracking Pixels

Recovery emails sent through the Service contain a 1×1 tracking pixel and wrapped click-through links. These record that a message was opened and which links were clicked, so that you — our Customer — can measure whether a dunning sequence is working.

This tracking runs on your behalf, not ours. You are the data controller for your end-users; we process the open and click events as your processor under our Data Processing Agreement. If your own privacy notice does not disclose email open tracking, you must either disclose it or disable tracking in your campaign settings. See also our Anti-Spam Policy.

Recipients can defeat pixel tracking by disabling remote-image loading in their mail client. Apple Mail Privacy Protection already pre-loads images, which inflates open rates — that is a property of the medium, not a defect in our reporting.


5. No Advertising Cookies

We do not sell or share personal information for cross-context behavioural advertising as those terms are defined in the California Consumer Privacy Act as amended by the CPRA, and we have no “Do Not Sell or Share My Personal Information” link because there is nothing to opt out of. If that ever changes, this policy will be updated and account owners notified before the change takes effect.



7. How to Control Cookies

  • Browser settings. Every major browser can block or delete cookies — see the privacy or site-data section of Chrome, Safari, Firefox, or Edge settings.
  • Google Analytics opt-out. Google publishes a browser add-on that blocks GA on every site you visit.
  • Email tracking. Turn off remote image loading in your mail client, or ask the sender to disable tracking.

Blocking strictly necessary cookies will break the Service. You will not be able to sign in, and card updates will fail — Stripe Elements will not process a payment method without its own cookies. That is a technical constraint of the payment network, not a choice we make.


8. Do Not Track & Global Privacy Control

There is no industry consensus on how to interpret the DNT header, so like most services we do not act on it.

We do honour Global Privacy Control (Sec-GPC), which several U.S. state laws treat as a valid opt-out signal. Because we do not sell or share personal information, a GPC signal changes nothing about how we handle your data — but the signal is respected rather than ignored.


9. Changes to This Policy

When we add, remove, or change the purpose of a cookie we update the inventory in Section 3 and the “last updated” date at the top of this page. Material changes — a new category, or any new third party — are announced to account owners by email at least 14 days before they take effect.


10. Contact

Questions about this policy, or a cookie you saw that is not listed here:

Payment Recovery System — Privacy