1. What Cookies Are
A cookie is a small text file a site asks your browser to store and send back on later requests. Related technologies — localStorage, sessionStorage, and tracking pixels — do much the same job by different means. Throughout this policy “cookies” means all of them, because the law that governs them does not turn on the storage mechanism.
A first-party cookie is set by this site. A third-party cookie is set by another company whose code runs on a page you visit — for us, that is Stripe on the card-update page and Google Analytics on the marketing site, and nobody else.
2. Categories We Use
We group cookies into three categories:
- Strictly necessary — the Service cannot function without them. They keep you signed in, protect forms against CSRF, and let Stripe complete a card update. These are exempt from prior-consent requirements under Article 5(3) of the ePrivacy Directive and the equivalent UK PECR exemption, because you asked for the service they deliver.
- Functional — remember preferences such as a collapsed sidebar. We currently set none; the row is kept so the categorisation stays stable if that changes.
- Analytics — aggregate, anonymised traffic measurement on the public marketing pages. These are not strictly necessary and are only set where we have a lawful basis to set them (Section 6).
We set no advertising, retargeting, or cross-site tracking cookies, and we do not embed social-media pixels.
3. Full Cookie Inventory
The table below is exhaustive as of the “last updated” date at the top of this page.
Strictly necessary
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
| authjs.session-token / __Secure-authjs.session-token | First party | Keeps you signed in to the dashboard. Issued by Auth.js after successful authentication; the __Secure- prefixed variant is used over HTTPS. | 30 days, or until sign-out |
| authjs.csrf-token / __Host-authjs.csrf-token | First party | Cross-site request forgery protection for sign-in, sign-up, and password-reset form submissions. | Session |
| authjs.callback-url | First party | Remembers which page you were on so you are returned there after signing in. | Session |
| admin_session | First party | Authenticates platform administrators in the internal admin panel. Never set on customer accounts. | Session |
| __stripe_mid, __stripe_sid | Stripe, Inc. | Set by Stripe Elements on the hosted card-update page for fraud detection and payment-session continuity. Required for a card update to complete. | __stripe_mid: 1 year · __stripe_sid: 30 minutes |
Functional
None currently in use.
Analytics
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
| _ga, _ga_<container-id> | Google Analytics 4 (Google LLC) | Distinguishes visitors and sessions so we can measure aggregate traffic to the marketing site. IP anonymisation is enabled. Only loaded when a Measurement ID is configured. | Up to 2 years |
4. Email Tracking Pixels
Recovery emails sent through the Service contain a 1×1 tracking pixel and wrapped click-through links. These record that a message was opened and which links were clicked, so that you — our Customer — can measure whether a dunning sequence is working.
This tracking runs on your behalf, not ours. You are the data controller for your end-users; we process the open and click events as your processor under our Data Processing Agreement. If your own privacy notice does not disclose email open tracking, you must either disclose it or disable tracking in your campaign settings. See also our Anti-Spam Policy.
Recipients can defeat pixel tracking by disabling remote-image loading in their mail client. Apple Mail Privacy Protection already pre-loads images, which inflates open rates — that is a property of the medium, not a defect in our reporting.
5. No Advertising Cookies
We do not sell or share personal information for cross-context behavioural advertising as those terms are defined in the California Consumer Privacy Act as amended by the CPRA, and we have no “Do Not Sell or Share My Personal Information” link because there is nothing to opt out of. If that ever changes, this policy will be updated and account owners notified before the change takes effect.
6. Consent & Legal Basis
Strictly necessary cookies are set without consent under the ePrivacy Article 5(3) exemption; our lawful basis for the underlying processing is performance of a contract (GDPR Article 6(1)(b)).
Analytics cookies are only set where we have a lawful basis to set them. Google Analytics is loaded only when a Measurement ID is configured for the deployment; where it is enabled for visitors in the EEA, the UK, or Switzerland, it must be gated behind prior opt-in consent, and we operate it with IP anonymisation and advertising features disabled.
Operator note
Analytics is disabled by default: with no Measurement ID set, no Google tag is emitted and no analytics cookie is written. If you enable Google Analytics for an audience that includes the EEA or the UK, a prior-consent banner is legally required before the tag loads — enabling the tag without one is the single most common cookie-compliance failure.
7. How to Control Cookies
- Browser settings. Every major browser can block or delete cookies — see the privacy or site-data section of Chrome, Safari, Firefox, or Edge settings.
- Google Analytics opt-out. Google publishes a browser add-on that blocks GA on every site you visit.
- Email tracking. Turn off remote image loading in your mail client, or ask the sender to disable tracking.
Blocking strictly necessary cookies will break the Service. You will not be able to sign in, and card updates will fail — Stripe Elements will not process a payment method without its own cookies. That is a technical constraint of the payment network, not a choice we make.
8. Do Not Track & Global Privacy Control
There is no industry consensus on how to interpret the DNT header, so like most services we do not act on it.
We do honour Global Privacy Control (Sec-GPC), which several U.S. state laws treat as a valid opt-out signal. Because we do not sell or share personal information, a GPC signal changes nothing about how we handle your data — but the signal is respected rather than ignored.
9. Changes to This Policy
When we add, remove, or change the purpose of a cookie we update the inventory in Section 3 and the “last updated” date at the top of this page. Material changes — a new category, or any new third party — are announced to account owners by email at least 14 days before they take effect.
10. Contact
Questions about this policy, or a cookie you saw that is not listed here:
Payment Recovery System — Privacy
Email: privacy@paymentrecoverysystem.com
Related documents: Privacy Policy · Data Processing Agreement · Sub-processors