Skip to main content

Legal & safety

Cookie Policy

Last updated:

Paym uses cookies and similar browser technologies where they are needed to operate, secure and improve the service. This Policy explains the technologies currently used on Paym websites and how you can control optional technologies.

Paym is currently under development and has not yet completed its general commercial launch. Some products, features, payment methods and jurisdictions described by Paym are planned, in development or available only for controlled testing. Where a regulated financial service is made available, Paym will identify the entity providing that service, its regulatory status and the applicable terms before the customer uses it.

This Policy is based on the technologies present in the current Paym applications, not a generic cookie inventory.

Strictly necessary

Strictly necessary cookies and similar technologies may be used without optional analytics or marketing consent where legally permitted. They operate the site, keep a signed-in session, protect the service, or remember a choice you have asked Paym to keep.

Public website — paym.com

The public Paym website does not use authentication cookies. It does not use localStorage or sessionStorage.

The only first-party cookie this site may set is:

TechnologyProviderPurposeDurationCategory
paym.profile_previewPaymLets a Paym ID owner preview an unpublished public page after opening a short-lived preview link. HttpOnly; scoped to that Paym ID path; not a sign-in cookie.1 hourStrictly necessary

Signed-in application — my.paym.com

The Paym application authenticates with host-only HttpOnly cookies. Those cookies are not sent to paym.com. Depending on the environment, names may include a __Secure- prefix on HTTPS.

TechnologyProviderPurposeDurationCategory
paym.session_tokenPaymIdentifies a signed-in session.Up to 7 days, extended while the session remains activeStrictly necessary
paym.session_dataPaymShort-lived signed session cache so an authenticated request does not always need a database lookup.60 secondsStrictly necessary
paym.trust_devicePaymRemembers a device after additional verification, where that feature is used.Up to 30 daysStrictly necessary
paym.two_factorPaymCompletes a two-factor sign-in challenge when a second factor is required.Challenge / session lifetimeStrictly necessary
paym_profilePaymRemembers the last Paym profile you selected. Set as a first-party preference cookie.1 yearStrictly necessary

Paym uses origin checks as the CSRF defence for cookie authentication. There is no separate CSRF cookie.

Operator tools on admin.paym.com use the same class of authentication cookies for signed-in operators.

Hosting, content-delivery or bot-protection platforms may also set strictly necessary cookies to operate or protect the site. Paym does not use those cookies for advertising.

Analytics

We do not currently use optional analytics cookies on this service.

There is no Google Analytics, Google Tag Manager, Plausible, PostHog, Hotjar or similar measurement SDK in the current Paym websites.

Advertising / marketing

We do not currently use advertising or cross-site marketing cookies on this service.

There is no Meta Pixel or other advertising network in the current Paym websites.

Local storage and similar technology

These are not cookies. They are covered here because they are similar browser storage.

The public website (paym.com) does not use localStorage or sessionStorage.

The signed-in application (my.paym.com) may use sessionStorage for short-lived, device-local state, including:

TechnologyPurpose
paym_pay_draftAn in-progress pay draft (recipient, amount and related fields) for the current profile
paym.close-account.idempotencyPrevents a close-account request being submitted twice
paym.verification.continueFlashA one-time status message after a verification step

localStorage is not used for Paym sessions. Session tokens are held in cookies that page script cannot read.

If a payment partner’s hosted payment fields are presented, that partner may set its own cookies or storage inside its frame. Those are not Paym analytics or advertising technologies.

Because this service does not currently use optional analytics or marketing cookies, no consent banner is shown and no optional tracker is loaded.

If optional technologies are added later, this Policy will be updated first. Where consent is required, those technologies will not run until valid consent is given, and withdrawing consent will be as easy as giving it.

Controls

There is no separate in-product cookie-settings page, because there are currently no optional cookies to turn off.

You can block or delete cookies through your browser settings. Blocking strictly necessary cookies may prevent sign-in, profile switching, draft preview or other requested features from working.

sessionStorage used by the signed-in application is cleared when the browser tab or session ends, or when you clear site data.

Updates and contact

We may update this Policy when the technologies Paym uses change. The current version and update date will always be published here.

Questions about this Policy can be sent to legal@paym.com.