Legal & safety
Cookie Policy
Last updated:
Paym uses cookies and similar browser technologies where they are needed to operate, secure and improve the service. This Policy explains the technologies currently used on Paym websites and how you can control optional technologies.
Paym is currently under development and has not yet completed its general commercial launch. Some account and identity features may already be available. Other products, payment methods and jurisdictions described by Paym are planned, in development or available only for controlled testing. Where a regulated financial service is made available, Paym will identify the entity providing that service, its regulatory status and the applicable terms before the customer uses it.
This Policy is based on the technologies present in the current Paym applications, not a generic cookie inventory.
Cookies, sessionStorage, localStorage and other browser storage are technically different. They are discussed together here where that helps explain what Paym uses. sessionStorage is not a cookie.
Strictly necessary
Strictly necessary cookies and similar technologies may be used without optional analytics or marketing consent where legally permitted. They operate the site, keep a signed-in session, or protect the service.
Public website — paym.com
The public Paym website does not use authentication cookies. Checkout pages may store a local appearance preference in localStorage, a receipt reference in sessionStorage, and a short-lived checkout-session capability as described below.
First-party cookies this site may set:
| Technology | Host/service | Purpose | Duration | Category |
|---|---|---|---|---|
paym.profile_preview | paym.com | Lets a Paym ID owner preview unpublished extra details after opening a short-lived preview link. HttpOnly; scoped to that Paym ID path; not a sign-in cookie. | 1 hour | Strictly necessary |
paym_co_{session} | paym.com | Lets the original payer continue one child checkout they started. One cookie per child so two tabs do not overwrite each other. Path-scoped to /pay; readable by the checkout page (not HttpOnly); not an authentication cookie; not placed in the payment URL. | 15 minutes | Strictly necessary |
paym.checkout_access | paym.com | Legacy single checkout-capability cookie. Still accepted on read for in-flight sessions. Not written for new checkouts. Path-scoped to /pay; not an authentication cookie. | 15 minutes | Strictly necessary |
Signed-in application — my.paym.com
The Paym application authenticates with host-only HttpOnly cookies. Those cookies are not sent to paym.com. Depending on the environment, names may include a __Secure- prefix on HTTPS.
| Technology | Host/service | Purpose | Duration | Category |
|---|---|---|---|---|
paym.session_token | my.paym.com | Identifies a signed-in session. | Up to 7 days, extended while the session remains active | Strictly necessary |
paym.session_data | my.paym.com | Short-lived signed session cache so an authenticated request does not always need a database lookup. | 60 seconds | Strictly necessary |
paym.trust_device | my.paym.com | Remembers a device after additional verification, where that feature is used. | Up to 30 days | Strictly necessary |
paym.two_factor | my.paym.com | Completes a two-factor sign-in challenge when a second factor is required. | Challenge / session lifetime | Strictly necessary |
paym_co_{session} | my.paym.com | Host-only HttpOnly checkout capability for one authenticated child payment. Set by the API through the account proxy. Not shared with paym.com. The public code in the cookie name locates the session; it is not authorization. | 15 minutes | Strictly necessary |
Paym uses origin checks as the CSRF defence for cookie authentication. There is no separate CSRF cookie.
Operator tools on admin.paym.com use the same class of authentication cookies for signed-in operators.
Hosting, content-delivery or bot-protection platforms may also set strictly necessary cookies to operate or protect the site. Paym does not use those cookies for advertising.
Functional / preference
These cookies remember a choice you have made in the product. They are not analytics or advertising cookies.
| Technology | Host/service | Purpose | Duration | Category |
|---|---|---|---|---|
paym_profile | my.paym.com | Remembers the last Paym profile you selected, so a later visit can open that profile. Set by the browser as a first-party preference cookie; not HttpOnly. | 1 year | Functional / preference |
The selected profile can still be used if this cookie is missing: Paym falls back to another profile this signed-in account can access. The cookie is sent to my.paym.com on later requests so the application can restore that preference. It is not used for authentication and does not grant access to a profile.
Analytics
We do not currently use optional analytics cookies on Paym.
There is no Google Analytics, Google Tag Manager, Plausible, PostHog, Hotjar or similar measurement SDK in the current Paym websites.
Advertising / marketing
We do not currently use advertising or cross-site marketing cookies on Paym.
There is no Meta Pixel or other advertising network in the current Paym websites.
Local storage and similar technology
These are not cookies. They are covered here because they are similar browser storage.
Checkout and public profile pages on the public website (paym.com) may use localStorage for a device-local appearance preference, and checkout may use sessionStorage to hold payer-private checkout state:
| Technology | Host/service | Purpose | Duration | Category |
|---|---|---|---|---|
paym.checkout_appearance | paym.com | Remembers Light or Dark on paym.com/pay/…. Missing or invalid values fall back to Light. | Until you clear site data | Functional / preference |
paym.profile_appearance | paym.com | Remembers Light or Dark on paym.com/<username> when you use the header switch. Missing or invalid values keep the profile owner’s appearance. | Until you clear site data | Functional / preference |
paym.receipt.… | paym.com | Shows you the receipt for the payment you just made, including after a bank or wallet redirect back to paym.com/pay/…. Not readable by anyone else opening the same link. | Until the tab or session ends | Strictly necessary |
paym.checkout.… | paym.com | Holds the original payer’s checkout-session capability for a child payment they started, so another browser with only the public URL cannot take over that payment. | Until the tab or session ends | Strictly necessary |
Other public pages do not use localStorage or sessionStorage beyond the rows above.
The signed-in application (my.paym.com) may use sessionStorage for short-lived, device-local state, including:
| Technology | Host/service | Purpose | Duration | Category |
|---|---|---|---|---|
paym_pay_draft | my.paym.com | An in-progress pay draft (recipient, amount and related fields) for the current profile | Until the tab or session ends | Functional / preference |
paym.close-account.idempotency | my.paym.com | Prevents a close-account request being submitted twice | Until the tab or session ends | Strictly necessary |
paym.verification.continueFlash | my.paym.com | A one-time status message after a verification step | Until the tab or session ends | Functional / preference |
localStorage is not used for Paym sessions. Session tokens are held in cookies that page script cannot read. Paym does not currently use IndexedDB or service-worker storage for these websites.
If a payment partner’s hosted payment fields are presented, that partner may set its own cookies or storage inside its frame. Those are not Paym analytics or advertising technologies.
Consent
Because this service does not currently use optional analytics or marketing cookies, no consent banner is shown and no optional tracker is loaded.
If optional technologies are added later, this Policy will be updated first. Where consent is required, those technologies will not run until valid consent is given, and withdrawing consent will be as easy as giving it.
Controls
There is no separate in-product cookie-settings page, because there are currently no optional analytics or marketing cookies to turn off.
You can block or delete cookies through your browser settings. Blocking strictly necessary cookies may prevent sign-in, draft preview or other requested features from working. Blocking the profile-preference cookie may mean Paym does not remember which profile you last selected.
sessionStorage used by the signed-in application, and the checkout receipt reference on paym.com, are cleared when the browser tab or session ends, or when you clear site data. Clearing site data also removes paym.checkout_appearance and paym.profile_appearance on paym.com.
Updates and contact
We may update this Policy when the technologies Paym uses change. The current version and update date will always be published here.
Questions about this Policy can be sent to legal@findech.com.