Cloud

Cookies and outside services

No tracking or advertising cookies. This site sets one cookie of its own: a session cookie that keeps you signed in and protects its forms. On the billing page, Stripe adds two fraud-prevention cookies.

This page lists every cookie on this site and every outside service its pages load directly. It is built from the same list the site's code is checked against.

Cookies on this site

PHPSESSID

Keeps you signed in and protects forms against forged requests.

Set by
This site
How long
Until you close your browser
Where
Every page
Category
Strictly necessary

__stripe_mid

Fraud prevention: lets Stripe recognize this browser across payments.

Set by
Stripe
How long
1 year
Where
Set on billing settings (signed in), then sent with every request to this site until it expires
Category
Fraud prevention (Stripe; under review)

__stripe_sid

Fraud prevention: lets Stripe recognize this browser within one visit.

Set by
Stripe
How long
30 minutes
Where
Set on billing settings (signed in), then sent with every request to this site until it expires
Category
Fraud prevention (Stripe; under review)

Outside services

Each one loads only on the pages named here. These companies may set their own cookies; their policies say which. Stripe's payment frames also load services Stripe chooses, such as Google Pay, Apple Pay and hCaptcha.

Where: Billing settings (signed in)

https://js.stripe.com
Card and wallet entry on the billing page. Stripe.js also collects device and activity signals to detect payment fraud, and Stripe may set its own cookies for that.
https://*.js.stripe.com
Parts of Stripe.js served from Stripe subdomains.
https://hooks.stripe.com
Your card issuer's security check (3D Secure) when you save a card.
https://api.stripe.com
Sends the card you enter straight to Stripe; this site never sees the number.
https://*.stripe.com
Images Stripe.js shows on the billing page.

Where: Billing settings (signed in)

https://pay.google.com
The Google Pay button, when your browser offers it.