What this notice covers
This Notice explains how comPayr uses cookies, local browser storage, and similar technologies across the public site, login and signup flows, and the authenticated service.
Certain technologies are essential because they maintain secure sessions, support multi-factor authentication, remember trusted devices when requested by the user, and preserve continuity across signup, invitation, and account-recovery steps.
Other technologies are used for analytics and operational measurement. Those non-essential tools are intended to remain off until a visitor elects to allow them through our consent controls.
Essential cookies and security technologies
Essential cookies and related technologies help operate the service requested by the user. They support sign-in, secure sessions, trusted-device recognition, anti-forgery protection, and short-lived continuity steps used during account setup, login, recovery, invitation acceptance, and similar security-sensitive workflows.
- compayr_session_id: authenticated session cookie used to maintain signed-in access to the product
- compayr_trusted_device: remembered-device token used to reduce repeated MFA challenges when a user explicitly chooses that option
- compayr_google_signup_token and g_csrf_token: short-lived protections used in signup and Google-authentication flows
- compayr_auth_account_workspace_selection and similar handoff cookies: short-lived tokens used to preserve continuity in account selection, bootstrap, invitation, password-reset, and recovery flows
- compayr_cookie_consent: records the visitor’s analytics preference so that the selected choice can be honored on subsequent visits
Analytics and measurement tools
When a visitor permits analytics, comPayr may enable first-party product analytics through PostHog and web measurement through Ahrefs Analytics, where those tools are configured for the environment.
These tools help us understand site usage, measure product interest, identify operational issues, and improve the public site and application experience.
If analytics are rejected, essential technologies will continue to operate, but non-essential browser analytics should remain disabled.
Separately, when a person submits a signup form, login request, contact message, privacy request, security report, or related account workflow, comPayr may create server-side operational records tied to that submission to process the request, prevent abuse, investigate failed flows, and measure workflow reliability. Those server-side records are governed by the Privacy Policy and are not controlled by the public-site analytics toggle.
How to manage your choices
Visitors can accept or reject non-essential analytics from the consent banner when it first appears.
Those preferences may be updated later at any time through the Cookie Settings control available in the footer of the public site and legal pages.
Advertising, sale or sharing, and Global Privacy Control
comPayr does not use cookies for cross-context behavioral advertising, and we do not sell personal information.
Because our current public-site controls are focused on essential operations and optional analytics, a browser-based Global Privacy Control signal will generally align with the same no-sale and no-sharing posture described in our Privacy Policy.
If comPayr later introduces advertising, sale, or sharing activities that create additional legal opt-out obligations, we would need to update these controls and related disclosures accordingly.
If a later paid rollout introduces billing providers or other third-party tools that place new browser technologies on the public site, we would also need to update this Notice before those tools are activated.
Questions and updates
We may update this Notice as our product, infrastructure, service providers, or legal obligations change. Material updates will be reflected by revising the “Last updated” date on this page.
Questions about cookies, tracking technologies, or privacy requests may be sent through our public contact flow.
