Policy

Cookie Policy

Every cookie and item of browser storage we use, what it does, and which third-party services may set their own.

Last updated:
July 12, 2026
Effective:
July 12, 2026
On this page

This Cookie Policy explains how NoHoldPay uses cookies and similar browser storage on its website, hosted checkout, and merchant dashboard.

Questions about this Policy may be submitted through the contact page.


1. Cookies and browser storage

A cookie is a small text file that a website stores through your browser. Cookies can be used to keep you signed in, remember settings, or support security controls.

NoHoldPay also uses browser storage that is not technically a cookie:

  • localStorage stores small same-browser preferences until they are changed or you clear site data.
  • sessionStorage stores temporary same-tab browser-session state and is normally cleared when the tab or session ends.

2. Cookies NoHoldPay sets

We use a small set of first-party cookies for signing in. If you block them, you will not be able to sign in or stay signed in. Except where noted, they are protected cookies that page JavaScript cannot read.

Cookie categorySet byPurposeLifetime
Merchant sessionNoHoldPayKeeps a merchant signed in. The token is read server-side for authenticated dashboard requests.Up to 24 hours
Signed-in indicatorNoHoldPayNamed noholdpay_session_hint. Tells our marketing pages to show a Dashboard link instead of Sign in. Contains only the fixed value 1 and no credential. Readable by page scripts and, in production, visible across NoHoldPay subdomains. It is never accepted as proof of identity.Up to 24 hours, aligned with the merchant session
GitHub sign-in flowNoHoldPayThree short-lived cookies used only during GitHub sign-in: a CSRF state value, a PKCE verifier, and a one-time two-factor continuation token.About 10 minutes (state, verifier), about 5 minutes (2FA token)

Google sign-in does not set any NoHoldPay cookies beyond those listed above. It uses the Google Identity Services script described in section 4, and a successful sign-in sets the same merchant session and signed-in indicator cookies as any other sign-in method.


3. Browser storage we use

These items are stored in your browser to support the product experience. They are not advertising cookies and are not used for cross-site tracking.

Storage categoryTypePurposeLifetime
Theme preferencelocalStorageRemembers light, dark, or system theme preference and helps prevent a flash of the wrong theme on page load.Until changed or site data cleared
Sidebar preferencelocalStorageRemembers whether the dashboard sidebar is collapsed.Until changed or site data cleared
Dashboard mode cachelocalStorageCaches the live/test display mode for the merchant dashboard while the server-side preference is loading.Until changed or site data cleared
Checkout last-used optionlocalStorageRemembers the last chain and coin selected on hosted checkout on that device, so the picker can show it first.Until overwritten or site data cleared
Checkout submission guardsessionStorageRecords that a connected-wallet payment was submitted on hosted checkout, or that a merchant submitted a connected-wallet balance top-up in the dashboard, to reduce accidental duplicate broadcasts.Current browser tab/session
Recovery kit reminderlocalStorageRemembers when the self-recovery kit was last downloaded in this browser so the dashboard can suggest a fresh download after wallet changes.Until changed or site data cleared
Dismissed merchant dashboard noticeslocalStorage / sessionStorageRemembers dismissed merchant dashboard notices and banners so the dashboard does not repeatedly show the same prompt.Until cleared, changed, or the browser session ends

4. Third-party cookies and storage

Some optional or security-related features involve third-party scripts, redirects, or user-selected wallet software. Those providers may set their own cookies or browser storage under their own domains or inside the wallet app.

ServiceWhen loadedPurpose
Cloudflare TurnstileWhen enabled for merchant sign-in, merchant sign-up, or the password reset request formHelps distinguish legitimate users from automated abuse
Google Identity ServicesWhen the sign-in or sign-up page is displayed and Google sign-in is offered, even if you sign in another waySupports Google OAuth sign-in
GitHubOnly if you choose GitHub sign-in. Your browser is redirected to github.com, which applies its own cookies under its own policySupports GitHub OAuth sign-in
Browser wallet extensions or wallet appsOnly if a customer uses a connected-wallet payment optionThe wallet provider may keep its own local wallet-session state

5. What we do not use

NoHoldPay does not currently use:

  • Advertising, retargeting, or cross-site marketing trackers.
  • Analytics tools that rely on persistent cross-site identifiers.
  • NoHoldPay-operated browser fingerprinting for advertising or analytics.

Our error monitoring is self-hosted. Browser error reports are sent through our own domain, set no cookies or browser storage, and are stripped of identifying data before storage. No third party receives them.


6. How to manage cookies

You can review, delete, or restrict cookies and browser storage through your browser settings. The exact controls depend on your browser.

  • Chrome / Edge / Brave / Opera - Settings > Privacy and security > Cookies and other site data.
  • Firefox - Settings > Privacy & Security > Cookies and Site Data.
  • Safari (desktop) - Safari > Settings > Privacy.
  • Safari (iOS) - Settings > Safari > Privacy & Security.

If you block strictly necessary cookies, you will not be able to sign in to NoHoldPay. If you block third-party cookies or scripts, Google sign-in, GitHub sign-in, or anti-bot checks may not work.


7. Do Not Track and Global Privacy Control

Because NoHoldPay does not run advertising or cross-site tracking, signals such as Do Not Track and Global Privacy Control do not currently change our behavior. We will update this page if that changes.


8. Changes

We may update this document. Material changes will be announced via email and/or via the dashboard at least 14 days before they take effect when reasonably practical. Changes required for legal, security, risk, chain-support, or urgent operational reasons may take effect sooner. The header of this document reflects the current version.


9. Contact

Cookie questions may be submitted through the contact page.