Effective July 20, 2026
This Cookie Policy explains how RecoupPay uses cookies and similar browser storage. A cookie is a small text value that a site asks your browser to keep. RecoupPay uses these tools to run and secure the service and to remember choices.
This policy forms part of the Privacy Policy.
1. Cookies RecoupPay uses
RecoupPay uses needed and preference cookies. It does not currently use advertising cookies or a third-party user-behavior analytics provider.
| Cookie or category | Purpose | Usual life |
|---|---|---|
| Account and sign-in cookies | Keep you signed in, protect sign-in and password-reset flows, support multi-factor checks, and prevent request forgery. | Session-based or until the set account-session expiry. |
recouppay_recovery_session | Lets a customer use one path-scoped recovery page after a secure link exchange. It is HttpOnly, Secure, and SameSite Strict. | Up to 15 minutes. |
sq_oauth_state | Matches a Square account connection request to its callback and helps block request forgery. It is HttpOnly, Secure, and SameSite Lax. | Up to 10 minutes and cleared after a successful callback. |
| Other connection-state cookies | Protect a chosen provider or sign-in connection while you leave RecoupPay and return. Stripe connection state is kept and checked on the server rather than in a Stripe-state browser cookie. | Short-lived and cleared when no longer needed. |
theme | Remembers light, dark, or system display choice. | Up to one year. |
sidebar_state | Remembers whether the signed-in navigation panel is open. | Up to seven days. |
| Language preference | Remembers the language used for the site and account email. | Session-based or until the preference expires. |
2. Third-party pages and tools
Stripe, Square, and another payment provider may set their own cookies when you open a provider-hosted sign-in, account, checkout, billing portal, or payment page. Those providers control their cookies under their own notices. RecoupPay does not receive the full card or bank details entered on those pages.
When enabled, a security check such as Cloudflare Turnstile may use device and browser data to tell people from abusive traffic. A hosting or security provider may also use short-lived cookies to protect the site and route a request.
3. Your choices
Most browsers let you view, delete, or block cookies and clear site storage. Blocking a needed cookie can stop sign-in, account connection, recovery actions, security checks, or saved preferences from working. You can delete preference cookies and choose the setting again on your next visit.
Since RecoupPay does not currently use advertising or user-behavior analytics cookies, it has no separate advertising cookie opt-out. If we add a non-needed cookie, we will update this policy and add a consent control before using it where law requires consent.
4. Changes and contact
We may update this policy when cookies, providers, or law change. We will post the new effective date and give added notice when a change is material.
For a question about cookies or privacy, email privacy@recouppay.app.