Skip to main content

Legal & safety

Cookie Policy

Last updated:

Paym uses cookies and similar browser technologies where they are needed to operate, secure and improve the service. This Policy explains the technologies currently used on Paym websites and how you can control optional technologies.

Paym is currently under development and has not yet completed its general commercial launch. Some account and identity features may already be available. Other products, payment methods and jurisdictions described by Paym are planned, in development or available only for controlled testing. Where a regulated financial service is made available, Paym will identify the entity providing that service, its regulatory status and the applicable terms before the customer uses it.

This Policy is based on the technologies present in the current Paym applications, not a generic cookie inventory.

Cookies, sessionStorage, localStorage and other browser storage are technically different. They are discussed together here where that helps explain what Paym uses. sessionStorage is not a cookie.

Strictly necessary

Strictly necessary cookies and similar technologies may be used without optional analytics or marketing consent where legally permitted. They operate the site, keep a signed-in session, or protect the service.

Public website — paym.com

The public Paym website does not use authentication cookies. Checkout pages may store a local appearance preference in localStorage, a receipt reference in sessionStorage, and a short-lived checkout-session capability as described below.

First-party cookies this site may set:

TechnologyHost/servicePurposeDurationCategory
paym.profile_previewpaym.comLets a Paym ID owner preview unpublished extra details after opening a short-lived preview link. HttpOnly; scoped to that Paym ID path; not a sign-in cookie.1 hourStrictly necessary
paym_co_{session}paym.comLets the original payer continue one child checkout they started. One cookie per child so two tabs do not overwrite each other. Path-scoped to /pay; readable by the checkout page (not HttpOnly); not an authentication cookie; not placed in the payment URL.15 minutesStrictly necessary
paym.checkout_accesspaym.comLegacy single checkout-capability cookie. Still accepted on read for in-flight sessions. Not written for new checkouts. Path-scoped to /pay; not an authentication cookie.15 minutesStrictly necessary

Signed-in application — my.paym.com

The Paym application authenticates with host-only HttpOnly cookies. Those cookies are not sent to paym.com. Depending on the environment, names may include a __Secure- prefix on HTTPS.

TechnologyHost/servicePurposeDurationCategory
paym.session_tokenmy.paym.comIdentifies a signed-in session.Up to 7 days, extended while the session remains activeStrictly necessary
paym.session_datamy.paym.comShort-lived signed session cache so an authenticated request does not always need a database lookup.60 secondsStrictly necessary
paym.trust_devicemy.paym.comRemembers a device after additional verification, where that feature is used.Up to 30 daysStrictly necessary
paym.two_factormy.paym.comCompletes a two-factor sign-in challenge when a second factor is required.Challenge / session lifetimeStrictly necessary
paym_co_{session}my.paym.comHost-only HttpOnly checkout capability for one authenticated child payment. Set by the API through the account proxy. Not shared with paym.com. The public code in the cookie name locates the session; it is not authorization.15 minutesStrictly necessary

Paym uses origin checks as the CSRF defence for cookie authentication. There is no separate CSRF cookie.

Operator tools on admin.paym.com use the same class of authentication cookies for signed-in operators.

Hosting, content-delivery or bot-protection platforms may also set strictly necessary cookies to operate or protect the site. Paym does not use those cookies for advertising.

Functional / preference

These cookies remember a choice you have made in the product. They are not analytics or advertising cookies.

TechnologyHost/servicePurposeDurationCategory
paym_profilemy.paym.comRemembers the last Paym profile you selected, so a later visit can open that profile. Set by the browser as a first-party preference cookie; not HttpOnly.1 yearFunctional / preference

The selected profile can still be used if this cookie is missing: Paym falls back to another profile this signed-in account can access. The cookie is sent to my.paym.com on later requests so the application can restore that preference. It is not used for authentication and does not grant access to a profile.

Analytics

We do not currently use optional analytics cookies on Paym.

There is no Google Analytics, Google Tag Manager, Plausible, PostHog, Hotjar or similar measurement SDK in the current Paym websites.

Advertising / marketing

We do not currently use advertising or cross-site marketing cookies on Paym.

There is no Meta Pixel or other advertising network in the current Paym websites.

Local storage and similar technology

These are not cookies. They are covered here because they are similar browser storage.

Checkout and public profile pages on the public website (paym.com) may use localStorage for a device-local appearance preference, and checkout may use sessionStorage to hold payer-private checkout state:

TechnologyHost/servicePurposeDurationCategory
paym.checkout_appearancepaym.comRemembers Light or Dark on paym.com/pay/…. Missing or invalid values fall back to Light.Until you clear site dataFunctional / preference
paym.profile_appearancepaym.comRemembers Light or Dark on paym.com/<username> when you use the header switch. Missing or invalid values keep the profile owner’s appearance.Until you clear site dataFunctional / preference
paym.receipt.…paym.comShows you the receipt for the payment you just made, including after a bank or wallet redirect back to paym.com/pay/…. Not readable by anyone else opening the same link.Until the tab or session endsStrictly necessary
paym.checkout.…paym.comHolds the original payer’s checkout-session capability for a child payment they started, so another browser with only the public URL cannot take over that payment.Until the tab or session endsStrictly necessary

Other public pages do not use localStorage or sessionStorage beyond the rows above.

The signed-in application (my.paym.com) may use sessionStorage for short-lived, device-local state, including:

TechnologyHost/servicePurposeDurationCategory
paym_pay_draftmy.paym.comAn in-progress pay draft (recipient, amount and related fields) for the current profileUntil the tab or session endsFunctional / preference
paym.close-account.idempotencymy.paym.comPrevents a close-account request being submitted twiceUntil the tab or session endsStrictly necessary
paym.verification.continueFlashmy.paym.comA one-time status message after a verification stepUntil the tab or session endsFunctional / preference

localStorage is not used for Paym sessions. Session tokens are held in cookies that page script cannot read. Paym does not currently use IndexedDB or service-worker storage for these websites.

If a payment partner’s hosted payment fields are presented, that partner may set its own cookies or storage inside its frame. Those are not Paym analytics or advertising technologies.

Because this service does not currently use optional analytics or marketing cookies, no consent banner is shown and no optional tracker is loaded.

If optional technologies are added later, this Policy will be updated first. Where consent is required, those technologies will not run until valid consent is given, and withdrawing consent will be as easy as giving it.

Controls

There is no separate in-product cookie-settings page, because there are currently no optional analytics or marketing cookies to turn off.

You can block or delete cookies through your browser settings. Blocking strictly necessary cookies may prevent sign-in, draft preview or other requested features from working. Blocking the profile-preference cookie may mean Paym does not remember which profile you last selected.

sessionStorage used by the signed-in application, and the checkout receipt reference on paym.com, are cleared when the browser tab or session ends, or when you clear site data. Clearing site data also removes paym.checkout_appearance and paym.profile_appearance on paym.com.

Updates and contact

We may update this Policy when the technologies Paym uses change. The current version and update date will always be published here.

Questions about this Policy can be sent to legal@findech.com.