Cookie Policy
Last updated 2026-07-19 · Version 1.0
This Cookie Policy explains how PayRes (“we”, “us”) uses cookies and similar technologies on payres.co, what each one does, whether it is optional, and how you can control it. It sits alongside our Privacy Policy, which explains more generally how we handle personal data.
1. Who we are
The site payres.co is operated by PayRes. For privacy questions or to exercise your rights, contact us at privacy@payres.co.
2. What cookies and similar technologies are
A cookie is a small text file a website asks your browser to store, so it can be read on later requests. “Similar technologies” do comparable things by other means — for example localStorage and sessionStorage (browser storage that isn’t sent with every request), pixels or tags, and third-party scripts and embedded content that load from another domain. Throughout this policy we use “cookies” as shorthand for all of these.
A technology is first-party when it is set under our own domain and third-party when it is provided by another company. Some things are strictly necessary to run the site; others are optional and load only with your consent.
3. Our approach: nothing optional loads until you agree
When you first visit, only strictly necessary storage is active. Optional analytics is blocked — the Google Analytics library is not even downloaded, and no analytics request is made — until you select Accept. If you Decline, nothing analytics-related loads at all. You can change your mind at any time (see section 9), and we treat withdrawing consent as easily as giving it.
We record your choice, the date, and the version of this policy it was made against. If we materially change the cookies, providers or purposes below, we publish a new policy version, which asks you to choose again.
4. Categories we use
We group technologies into the categories below. We do not use advertising or marketing cookies, and we do not sell or share personal data for cross-context behavioural advertising.
4.1 Strictly necessary
Required to deliver the site securely and to remember your cookie choice. These cannot be switched off through the banner because the site would not work correctly without them. Under the ePrivacy Directive / UK PECR these are exempt from consent; our legal basis under the GDPR / UK GDPR is our legitimate interest in operating and securing the service (Article 6(1)(f)).
| Name | Provider | Purpose | Party | Retention | Personal data? |
|---|---|---|---|---|---|
| __cf_bm | Cloudflare (our CDN / security layer) | Distinguishes humans from bots to protect the site from automated abuse. Set at the network edge; not used for analytics or advertising. | First-party | ~30 minutes (managed by Cloudflare) | A security token tied to your request; not used to identify you. |
| payres-consent | PayRes (localStorage) | Remembers your cookie choice, the date you made it, and the policy version — so we honour it and know when to ask again. | First-party | Until you clear it or this policy's version changes | No — it stores only your preference. |
4.2 Functionality
Third-party assets used to render the site as designed. They set no cookies and store nothing on your device, but the requests do expose your IP address to the providers below. Our legal basis is legitimate interest in presenting the site correctly (Article 6(1)(f)). We are evaluating self-hosting these assets to remove the third-party requests entirely.
| Name | Provider | Purpose | Party | Retention | Personal data? |
|---|---|---|---|---|---|
| Google Fonts (fonts.googleapis.com, fonts.gstatic.com) | Google Ireland Limited / Google LLC | Loads the site's typefaces so pages render as designed. Sets no cookies, but the request exposes your IP address to Google. | Third-party | No cookie or on-device storage (per-request only) | Your IP address is processed by Google to serve the fonts. |
| Provider logos (cdn.simpleicons.org) | Simple Icons, served via the jsDelivr CDN | Displays payment-provider logos in the ecosystem grid. Sets no cookies, but the image request exposes your IP to the CDN. | Third-party | No cookie or on-device storage (per-request only) | Your IP address is processed by the CDN to serve the images. |
4.3 Analytics (optional)
Google Analytics 4 helps us understand, in aggregate, how the site is used so we can improve it. It loads only after you accept. Our legal basis is your consent (GDPR / UK GDPR Article 6(1)(a); UK PECR regulation 6). You can withdraw it at any time.
| Name | Provider | Purpose | Party | Retention | Personal data? |
|---|---|---|---|---|---|
| gtag.js (googletagmanager.com) + measurement calls to google-analytics.com | Google Ireland Limited / Google LLC | The Google Analytics 4 library and its data collection. Loaded only after you accept. | Third-party | Loaded per session after consent; sets the cookies below | Yes — usage data plus your IP and a pseudonymous identifier. |
| _ga | Google Analytics 4 | Distinguishes visitors by assigning a pseudonymous client identifier, so we can measure how the site is used in aggregate. | First-party | 2 years | Yes — a pseudonymous identifier (personal data under GDPR). |
| _ga_ZJVBJRDEEZ | Google Analytics 4 | Maintains analytics session state for this property. | First-party | 2 years | Yes — a pseudonymous identifier (personal data under GDPR). |
5. Third-party providers
Where a third party is involved, their own privacy information applies:
- Google (Analytics and Fonts): Privacy Policy, how Google uses cookies, Analytics data practices, Fonts & privacy.
- Cloudflare (CDN / security): Privacy Policy, cookie reference.
- Simple Icons / jsDelivr (logo images): Simple Icons, jsDelivr privacy.
6. International data transfers
Some providers are based in, or process data in, the United States and on global networks. Google LLC and Cloudflare, Inc. are US companies and may process data outside the EEA/UK. Where personal data is transferred internationally, those providers state that they rely on the EU-US Data Privacy Framework (and its UK extension) and/or the European Commission’s Standard Contractual Clauses as their transfer safeguards. We link to each provider’s information above so you can review the current mechanism.
7. Is any of this personal data?
The strictly necessary consent record is just your preference and does not identify you. The Cloudflare security token is not used to identify you. However, the analytics identifiers and the IP addresses processed by Google (Analytics and Fonts) and the icon CDN are personal data under the GDPR / UK GDPR. That is why analytics runs only on your consent, and why we are transparent about the functionality requests.
8. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. If you are in the EEA or UK these arise under the GDPR / UK GDPR; if you are a California resident you have rights under the CCPA/CPRA, including the right to opt out of “sale” or “sharing” (we do neither). To exercise any right, contact privacy@payres.co. More detail is in our Privacy Policy.
9. How to accept, decline, customise or withdraw
- On arrival, use the banner’s equally-weighted Accept and Decline buttons. There is no pre-selected option and no default opt-in.
- Any time after, reopen your choices with — also permanently available in the site footer. Withdrawing consent is as easy as giving it: one click stops analytics and clears the analytics cookies on your next page load.
10. Global Privacy Control and opt-out signals
Because our analytics is off by default and never loads without an explicit opt-in, a browser-level Global Privacy Control (GPC) signal is honoured automatically: if your browser sends GPC and you have not opted in, no analytics loads. We note when we detect the signal. As we do not sell or share personal data, there is nothing further to opt out of, but you can still decline analytics at any time.
11. Managing cookies in your browser
You can also block or delete cookies and storage in your browser settings — see Chrome, Safari, Firefox and Edge. Note that blocking strictly necessary storage (the Cloudflare security token or the consent record) may break parts of the site or cause the cookie banner to reappear on every visit, because we can no longer remember your choice.
12. Changes to this policy
If we change the cookies, providers or purposes described here, we will update this page, change the “Last updated” date and the version number, and — for material changes — ask you to make your cookie choice again through the banner.
13. Contact
Questions about this policy or your data? Email privacy@payres.co. See also our Privacy Policy.