Cookie Policy
Version 2026.09.1Effective 8 September 202613 min read
Cookie Policy
1. About this Cookie Policy
This Cookie Policy explains how PaymentFlux Ltd (“PaymentFlux”, “we”, “us”, “our”) uses cookies and similar technologies on our marketing website and customer app (together, the “Platform”).
It should be read with our Privacy Policy, which explains how we process personal data more generally.
2. What cookies and similar technologies are
Cookies are small text files stored on your device when you visit a website.
We also use similar technologies, including:
- localStorage and sessionStorage (browser storage);
- client-generated device identifiers stored in browser storage; and
- technologies that Payment Partners may set when you use embedded payment flows.
In this Policy, references to “cookies” include those similar technologies where the context allows.
3. Who sets them
Technologies on the Platform may be:
- first-party — set by PaymentFlux on PaymentFlux domains; or
- third-party — set by another organisation, such as Stripe when you enter card details through Stripe.js / Elements, Google when you choose Google sign-in, Cloudflare when bot-protection runs, or Google when optional analytics tags load.
Third parties may process information independently under their own privacy notices. PaymentFlux does not set those providers’ cookies itself. Exact names and durations can vary because the provider controls them.
4. How PaymentFlux uses them
We use cookies and similar technologies to:
- keep the Platform secure and working;
- remember whether you are likely signed in (as a routing hint only);
- store authentication tokens and related session data needed for the customer app;
- remember your cookie preference;
- support payment entry, payment confirmation continuity, duplicate-request prevention and support-access flows in the browser;
- allow Payment Partners to process card payments securely when you choose to pay; and
- where you have given the relevant optional-cookie consent, understand how the marketing website and customer app are used, using Google Analytics managed through Google Tag Manager.
We do not currently operate advertising, remarketing or marketing pixels. Selecting Accept all does not enable Meta Pixel, TikTok, remarketing or behavioural advertising as part of this analytics configuration.
Optional analytics are not strictly necessary. They are not required to make a Property Payment. They run only where they are configured for that PaymentFlux surface and only after you select Accept all. Selecting Reject optional does not activate optional analytics through PaymentFlux’s consent-controlled implementation and does not prevent you from using core parts of the Service, including making a rent payment.
Giving optional-cookie consent enables eligible optional technologies on surfaces that actually implement them. It does not mean every PaymentFlux surface uses analytics at every moment, and it does not by itself make every possible third-party technology lawful.
5. Strictly necessary technologies
Strictly necessary technologies are required to provide a service you have requested, to keep that service secure, or to remember your cookie choice.
Examples on PaymentFlux include:
- authentication and session storage needed to sign in and use the customer app;
- the
pf_sessionrouting-hint cookie; - the
pf_cookie_consentpreference record; - browser storage used for payment drafts, payment confirmation continuity and preventing duplicate payment requests;
- public support magic-link session storage;
- identity-verification return markers; and
- Cloudflare Turnstile bot-protection on protected forms.
These technologies are not consent-gated under PECR in the same way as optional analytics or advertising technologies. You can still block them in your browser, but parts of the Service may stop working.
6. Functional / preference technologies
Functional or preference technologies remember choices you make.
On PaymentFlux, the main shared example is pf_cookie_consent, which stores whether you accepted all categories or rejected optional categories, together with a timestamp and Cookie Policy version references.
That preference may be recognised across PaymentFlux web surfaces where it is technically shared (paymentflux.co.uk, www.paymentflux.co.uk and app.paymentflux.co.uk via the .paymentflux.co.uk cookie where supported).
A shared preference does not cause analytics to run on a surface that has no analytics implementation. Optional analytics described in this Policy may operate on the marketing website and the customer app, but only where they are configured for that surface and only after you select Accept all.
The customer app also uses short-lived session storage to remember that you dismissed an in-session notice (for example a continue-setup banner or a home readiness acknowledgement). Those records last for the browser session only.
7. Analytics technologies
Optional analytics technologies measure how the marketing website and customer app are used. They are not strictly necessary and are not required to make a Property Payment.
Where enabled: if you select Accept all, PaymentFlux may load Google Tag Manager on paymentflux.co.uk (including www.paymentflux.co.uk) and app.paymentflux.co.uk to manage permitted analytics tags, and Google Analytics to understand use of those surfaces (product and site analytics). Those tags do not load until that choice is stored, and they load only on a surface that is actually configured to use them.
If you select Reject optional: PaymentFlux’s consent-controlled implementation does not load Google Tag Manager or Google Analytics.
You can change your choice at any time through Cookie settings.
Google may set its own cookies or similar storage when those tags load. PaymentFlux does not create those Google cookies itself. Exact names and durations are controlled by Google and may change.
PaymentFlux does not currently identify you to Google Analytics using a PaymentFlux account identifier. Where Google Analytics loads after Accept all, measurement uses Google’s own client identifier.
PaymentFlux does not intend to send card numbers, bank-account details, identity documents, or similar sensitive payment and verification data to Google Analytics.
Microsoft Clarity is not currently configured for production and is not loaded. The Platform includes fail-closed support that could load Clarity in future only if a project identifier were configured and you had accepted optional cookies. That is a possible later configuration, not the current production configuration.
8. Advertising / marketing technologies
Advertising, remarketing or marketing pixels are used to promote products or measure campaigns.
Status: not currently used. PaymentFlux does not operate advertising or remarketing tags. Selecting Accept all does not, by itself, turn on an advertising product that PaymentFlux has not implemented, including Meta Pixel, TikTok, remarketing or behavioural advertising.
9. Fraud, security and payment technologies
Some technologies support security and payments, including:
- device identifiers used with authentication and risk evaluation;
- Stripe.js / Elements technologies used when you enter or confirm card details;
- session storage that helps prevent duplicate payment requests; and
- Cloudflare Turnstile, which helps distinguish genuine users from automated abuse on protected forms (including sign-in, registration, password reset, payment confirmation and support contact where bot-protection is enabled).
Turnstile is a security control for a requested form. It is not an analytics tracker.
We classify PaymentFlux’s own authentication, session, preference, payment-journey, identity-return and support-session storage as strictly necessary for the requested service.
Stripe, Google (sign-in) and Cloudflare may set their own cookies or similar identifiers when their interfaces load. Those technologies are provided by those organisations. Exact cookie names and durations can vary. See section 11 and our Privacy Policy for how card data is handled.
10. Third-party technologies
| Third party | When it appears | Purpose | Classification |
|---|---|---|---|
| Stripe | When you use card entry / payment confirmation through Stripe.js Elements | Process card payments, support authentication and fraud controls for card transactions | Strictly necessary for card payment |
| Google (sign-in) | Only if you choose Google sign-in / account linking | Authentication with your Google account | Strictly necessary for that chosen sign-in method |
| Cloudflare Turnstile | On protected forms where bot-protection is enabled | Help distinguish genuine users from automated abuse | Strictly necessary security for those forms |
| Google Tag Manager | Marketing website and customer app, where configured, and only after Accept all | Manage permitted analytics tags where optional analytics are enabled | Optional analytics |
| Google Analytics | Marketing website and customer app, where configured, and only after Accept all, delivered through Tag Manager | Understand use of the marketing website and customer app | Optional analytics |
These organisations may process information under their own terms and privacy notices. PaymentFlux does not control all third-party retention or secondary use.
Microsoft Clarity is not currently configured and is not loaded in production.
11. Current cookie and storage inventory
The tables below list first-party cookies and browser storage PaymentFlux uses on the Platform.
Third-party technologies that may appear when you use embedded payment, sign-in, bot-protection or consented analytics features are summarised in section 10. Exact third-party cookie names and durations can vary by provider.
This inventory describes the production configuration for optional analytics on PaymentFlux web surfaces (paymentflux.co.uk, www.paymentflux.co.uk and app.paymentflux.co.uk): Google Tag Manager and Google Analytics where those tags are configured for that surface, still consent-gated. A surface that is not configured does not load those tags even if you selected Accept all.
A. Cookies
| Name / key | Technology | Provider | First / third party | Purpose | Category | Duration | Consent required? |
|---|---|---|---|---|---|---|---|
pf_cookie_consent |
Cookie (production PaymentFlux domains) or localStorage (localhost / non-shared hosts) | PaymentFlux | First-party | Stores cookie preference (accepted_all or rejected_optional), timestamp and Cookie Policy version references; shared across paymentflux.co.uk, www.paymentflux.co.uk and app.paymentflux.co.uk via .paymentflux.co.uk where supported |
Preference / strictly necessary to remember choice | Up to 365 days (Max-Age), refreshed when you change preference; the banner may ask again if the published Cookie Policy version changes |
No — needed to store your choice. Choice itself is an active Accept all / Reject optional action |
pf_session |
Cookie | PaymentFlux | First-party | Soft signed-in routing hint for the customer app root page only; not proof of authentication | Strictly necessary | Session cookie, or up to 30 days if you choose a durable (“remember me”) sign-in | No |
B. localStorage / sessionStorage and similar first-party storage
| Name / key | Technology | Provider | First / third party | Purpose | Category | Duration | Consent required? |
|---|---|---|---|---|---|---|---|
pf_access_token |
localStorage or sessionStorage | PaymentFlux | First-party | Access token for authenticated API calls | Strictly necessary | Until sign-out, expiry or browser/session end (depends on remember-me choice) | No |
pf_refresh_token |
localStorage or sessionStorage | PaymentFlux | First-party | Refresh token for session continuity | Strictly necessary | Until sign-out, expiry or browser/session end | No |
pf_user |
localStorage or sessionStorage | PaymentFlux | First-party | Cached user snapshot for app bootstrap | Strictly necessary | Until sign-out or storage clear | No |
pf_access_expires_at_ms |
localStorage or sessionStorage | PaymentFlux | First-party | Access-token expiry helper | Strictly necessary | Until sign-out or storage clear | No |
pf_consent_gating |
localStorage or sessionStorage | PaymentFlux | First-party | Client snapshot of whether Platform Terms acceptance is still required | Strictly necessary | Until sign-out or storage clear | No |
pf_device_id |
localStorage or sessionStorage | PaymentFlux | First-party | Client-generated device id sent with authentication | Strictly necessary (security for requested service) | Until cleared with auth storage | No |
pf_risk_device_id |
localStorage (sessionStorage fallback) | PaymentFlux | First-party | Stable client-generated device id used with security and risk checks | Strictly necessary (security for requested service) | Until you clear site data | No |
pf_risk_device_first_seen_utc |
localStorage (sessionStorage fallback) | PaymentFlux | First-party | First-seen time for that device id | Strictly necessary (security for requested service) | Until you clear site data | No |
pf_risk_device_last_seen_utc |
localStorage (sessionStorage fallback) | PaymentFlux | First-party | Last-seen time for that device id | Strictly necessary (security for requested service) | Until you clear site data | No |
pf_risk_device_fingerprint_hash |
localStorage (sessionStorage fallback) | PaymentFlux | First-party | Coarse browser-environment helper used with security and risk checks | Strictly necessary (security for requested service) | Until you clear site data | No |
paymentflux_mock_payment_draft_v1 |
sessionStorage | PaymentFlux | First-party | Temporary payment-entry draft while you complete the payment journey | Strictly necessary | Browser session / until cleared after the journey | No |
paymentflux_pending_payment_confirm_v1 |
sessionStorage | PaymentFlux | First-party | Continuity for a pending payment confirmation | Strictly necessary | Browser session / until cleared | No |
paymentflux_payment_create_idempotency_v1 |
sessionStorage | PaymentFlux | First-party | Prevents duplicate payment-create requests | Strictly necessary | Browser session / until cleared | No |
paymentflux_payment_confirm_idempotency_v1 |
sessionStorage | PaymentFlux | First-party | Prevents duplicate payment-confirm requests | Strictly necessary | Browser session / until cleared | No |
paymentflux_payment_cancel_idempotency_v1 |
sessionStorage | PaymentFlux | First-party | Prevents duplicate payment-cancel requests | Strictly necessary | Browser session / until cleared | No |
paymentflux_payment_confirm_consent_v1:{paymentId} |
sessionStorage | PaymentFlux | First-party | Remembers payment-authorisation choices during the current payment journey | Strictly necessary | Browser session / until cleared | No |
paymentflux_payment_review_save_card_v1:{paymentId} |
sessionStorage | PaymentFlux | First-party | Remembers whether you chose to save a card during payment review | Strictly necessary | Browser session / until cleared | No |
paymentflux_same_intent_replacement_v1:{paymentId} |
sessionStorage | PaymentFlux | First-party | Continuity if a payment method on the same payment needs to be replaced | Strictly necessary | Browser session / until cleared | No |
payment-card-declines:{paymentId} |
sessionStorage | PaymentFlux | First-party | Counts card-entry declines for that payment so the journey can stop repeating a failed attempt | Strictly necessary | Browser session / until cleared | No |
paymentflux_public_support_session_v1:{caseId} |
sessionStorage | PaymentFlux | First-party | Public support magic-link session for a specific case | Strictly necessary | Browser session / until expiry or clear | No |
pf_identity_callback_pending |
sessionStorage | PaymentFlux | First-party | Marks a return from identity verification so the app can finish that step | Strictly necessary | Browser session / until cleared | No |
payment-continue-setup-dismissed:{paymentId} |
sessionStorage | PaymentFlux | First-party | Remembers that you dismissed a continue-setup notice in this session | Preference / strictly necessary for that notice | Browser session | No |
home-ready-recipients-dismissed:{fingerprint} |
sessionStorage | PaymentFlux | First-party | Remembers that you dismissed a home readiness acknowledgement in this session | Preference / strictly necessary for that notice | Browser session | No |
payment-milestone-dismissed:{paymentId}:{variant}:{heading} |
sessionStorage | PaymentFlux | First-party | Remembers that you dismissed a payment-progress notice in this session | Preference / strictly necessary for that notice | Browser session | No |
C. Optional analytics storage (marketing website and customer app, where configured)
These technologies appear only after you select Accept all, and only on a PaymentFlux surface where Google Tag Manager is configured.
| Name / pattern | Technology | Provider | First / third party | Purpose | Category | Duration | Consent required? |
|---|---|---|---|---|---|---|---|
| Google Tag Manager / Google Analytics cookies and similar storage (names set by Google; commonly include identifiers used to distinguish visits) | Cookies and/or browser storage set by Google after Tag Manager loads | Third-party, often first-party on PaymentFlux domains | Understand use of the marketing website and customer app; Tag Manager delivers permitted Google Analytics tags | Optional analytics | Controlled by Google; may change | Yes — Accept all. Reject optional does not load these tags through PaymentFlux’s implementation |
PaymentFlux does not list invented Google cookie names or fixed durations. Google controls that inventory.
Microsoft Clarity storage is not present in the current production configuration.
12. Consent choices
Where non-essential technologies are used, they are not used until you make an active choice through our cookie banner or Cookie settings.
On PaymentFlux:
- the banner offers Accept all and Reject optional as equivalent primary actions;
- continued browsing is not treated as consent;
- optional analytics on the marketing website and customer app run only after Accept all, and only where that surface is configured to use them;
- Reject optional does not activate optional analytics through PaymentFlux’s consent-controlled implementation and does not prevent core use of the Service;
- rejecting optional categories is as easy as accepting them; and
- your preference is stored in
pf_cookie_consent.
If we add further optional technologies later, we will update this Policy and only enable them according to your stored preference and the configuration of that surface.
13. How to change or withdraw consent
You can change or withdraw your cookie preference at any time by:
- selecting Cookie settings in the site footer (marketing site and customer app); or
- clearing
pf_cookie_consentin your browser, which will cause the banner to appear again.
Withdrawal does not affect the lawfulness of processing carried out before you withdrew consent.
Strictly necessary technologies cannot generally be switched off through PaymentFlux Cookie settings. Your browser may still block them, which may break sign-in, payments or other requested features.
14. Browser and device controls
Most browsers let you block or delete cookies and clear localStorage / sessionStorage. Device settings may also restrict tracking or storage.
If you block strictly necessary technologies, you may be unable to sign in, complete a Property Payment, or use support access links.
15. Consequences of blocking technologies
| If you block… | Likely consequence |
|---|---|
| Authentication / session storage | You may be signed out or unable to use the customer app |
pf_cookie_consent |
The preference banner may reappear; we may be unable to remember a previous optional-category choice |
| Payment journey storage | Payment entry or confirmation continuity may fail or duplicate-protection may be weaker |
| Stripe technologies | Card payment entry may not work |
| Cloudflare Turnstile | Protected forms may not submit |
| Optional analytics (Google Tag Manager / Google Analytics) | We will have less information about how the marketing website and customer app are used; the Service itself should still work, including making a Property Payment |
| All cookies/storage | Core parts of the Service are likely to break |
16. Updates
We may update this Cookie Policy when our use of cookies or similar technologies changes. The version label and effective date below identify the current draft. Material changes will be published through our consent catalogue, and the preference banner may reappear when the published Cookie Policy version changes.
17. Contact
Questions about this Cookie Policy or cookie preferences:
- Support Centre — https://paymentflux.co.uk/support/contact/; or
- [email protected]
18. Version information
| Field | Value |
|---|---|
| Document | Cookie Policy |
| Version label | 2026.09.1 |
| Effective from | 8 September 2026 (UTC) |
| Locale | en-GB |
This Policy applies from the effective date above once published through our consent catalogue for that version. Until published, earlier published versions continue to apply where already in use. The actual publication timestamp is set when that catalogue version is published.