1. What cookies are
Cookies are small browser data used for sign-in, preferences and security.
2. CashLink cookies
Session, CSRF, anonymous visitor, short-URL owner, guest terms and remember-me cookies support required access, anti-fraud, visitor lists and preferences. Retention follows the settings shown on this site.
3. Analytics, ads and third parties
After explicit consent, CashLink sets a random first-party analytics cookie to measure feature use, traffic sources, countries, registration attribution, and anonymous LCP, INP and CLS performance ranges. Web Vitals retain only hourly route category, device category, range and count, without raw samples or identity; other identifiable analytics store only a versioned HMAC. Closing the cookie notice records a rejection, uses essential cookies only, and includes traffic only in aggregates without a cross-day visitor identity. CashLink does not use third-party analytics cookies.
4. Managing cookies
Use Cookie settings in the footer to change your choice or withdraw analytics consent; withdrawal deletes linkable visitor detail while anonymous aggregates remain. You can also view, block or delete cookies in your browser. Blocking required cookies may break sign-in, form security, language or theme controls.
5. Local Storage
Guest reminders, price alerts, anonymous image history and development warnings may use Local Storage. Clearing it cannot be undone by the server.
6. Contact
For questions about cookies or tracking, use the privacy report portal or email [email protected].
7. Admin trusted devices
The admin trusted-device cookie contains a random credential. The server stores only its hash and supports revocation; remember-me alone cannot bypass the check.
8. Faucet guest-browser cookie
The guest faucet uses a dedicated necessary first-party HttpOnly, SameSite=Lax cookie, with Secure enabled on HTTPS deployments. It lasts 365 days, and the server stores only its hash for abuse-prevention cooldown, this browser's claim status, and approved reclaims. Deleting it permanently removes the original-browser authorization.
9. Guest space and recovery
cashlink_guest_owner is a required first-party cookie with a distinct credential on each imported device so they can manage one guest space. It is HttpOnly, SameSite=Lax, Secure on HTTPS, and follows a 365-day inactivity limit; refreshing recovery credentials revokes all old devices. It is not analytics or advertising consent.