Cookie Policy
Last updated: 2026-05-10
This Cookie Policy explains the cookies and similar browser-storage technologies PrintingPay uses on the operator portal at printingpay.com and explains the choices you have.
1. What is a cookie?
A cookie is a small text file that a website stores on your browser. We also use other browser storage (localStorage, sessionStorage) for the same kinds of purposes described below.
2. Cookies we set
Strictly necessary
These cookies make the operator portal usable. Without them you cannot log in or carry out an authenticated action. They cannot be disabled while continuing to use the Service.
- admin_session — signed session identifier issued at login. HTTP-only, Secure, SameSite=Lax. Expires when the session ends or you log out.
- csrf-token — double-submit anti-CSRF token paired with the session cookie. Required for every state-changing request.
- pp_staging_session — short-lived identifier scoping pre-order artwork uploads to the current browser. 48-hour lifetime.
Functional
These remember preferences that improve the operator experience. We do not load any third-party functional cookies on the admin surface.
Analytics
We collect aggregated, first-party telemetry (request rates, latency, error counts) to keep the Service healthy. We do not deploy third-party advertising trackers, cross-site cookies, or behavioral-advertising tags on the admin portal.
3. Third-party services
Some pages embed payment-form iframes from our payment processors (Stripe Elements, Square Web Payments SDK, PayPal Smart Buttons). Those iframes set their own cookies under the processor’s domain governed by the processor’s privacy notice. The cookies are essential to the payment flow and are not used for cross-site tracking by us. See /sub-processors for the complete vendor list.
4. Controlling cookies
Most browsers let you block or delete cookies. Blocking the strictly-necessary cookies above will make the Service unusable. Browser-storage settings are controlled in the same place.
5. Changes
Material changes to this policy will be communicated to Operators by email or in-app notice. The “Last updated” date at the top reflects the most recent revision.
6. Contact
Questions about this policy should be sent to [email protected].