Version 2026.09.1Effective 8 September 202613 min read
This Cookie Policy explains how PaymentFlux Ltd (“PaymentFlux”, “we”, “us”, “our”) uses cookies and similar technologies on our marketing website and customer app (together, the “Platform”).
It should be read with our Privacy Policy, which explains how we process personal data more generally.
Cookies are small text files stored on your device when you visit a website.
We also use similar technologies, including:
In this Policy, references to “cookies” include those similar technologies where the context allows.
Technologies on the Platform may be:
Third parties may process information independently under their own privacy notices. PaymentFlux does not set those providers’ cookies itself. Exact names and durations can vary because the provider controls them.
We use cookies and similar technologies to:
We do not currently operate advertising, remarketing or marketing pixels. Selecting Accept all does not enable Meta Pixel, TikTok, remarketing or behavioural advertising as part of this analytics configuration.
Optional analytics are not strictly necessary. They are not required to make a Property Payment. They run only where they are configured for that PaymentFlux surface and only after you select Accept all. Selecting Reject optional does not activate optional analytics through PaymentFlux’s consent-controlled implementation and does not prevent you from using core parts of the Service, including making a rent payment.
Giving optional-cookie consent enables eligible optional technologies on surfaces that actually implement them. It does not mean every PaymentFlux surface uses analytics at every moment, and it does not by itself make every possible third-party technology lawful.
Strictly necessary technologies are required to provide a service you have requested, to keep that service secure, or to remember your cookie choice.
Examples on PaymentFlux include:
pf_session routing-hint cookie;pf_cookie_consent preference record;These technologies are not consent-gated under PECR in the same way as optional analytics or advertising technologies. You can still block them in your browser, but parts of the Service may stop working.
Functional or preference technologies remember choices you make.
On PaymentFlux, the main shared example is pf_cookie_consent, which stores whether you accepted all categories or rejected optional categories, together with a timestamp and Cookie Policy version references.
That preference may be recognised across PaymentFlux web surfaces where it is technically shared (paymentflux.co.uk, www.paymentflux.co.uk and app.paymentflux.co.uk via the .paymentflux.co.uk cookie where supported).
A shared preference does not cause analytics to run on a surface that has no analytics implementation. Optional analytics described in this Policy may operate on the marketing website and the customer app, but only where they are configured for that surface and only after you select Accept all.
The customer app also uses short-lived session storage to remember that you dismissed an in-session notice (for example a continue-setup banner or a home readiness acknowledgement). Those records last for the browser session only.
Optional analytics technologies measure how the marketing website and customer app are used. They are not strictly necessary and are not required to make a Property Payment.
Where enabled: if you select Accept all, PaymentFlux may load Google Tag Manager on paymentflux.co.uk (including www.paymentflux.co.uk) and app.paymentflux.co.uk to manage permitted analytics tags, and Google Analytics to understand use of those surfaces (product and site analytics). Those tags do not load until that choice is stored, and they load only on a surface that is actually configured to use them.
If you select Reject optional: PaymentFlux’s consent-controlled implementation does not load Google Tag Manager or Google Analytics.
You can change your choice at any time through Cookie settings.
Google may set its own cookies or similar storage when those tags load. PaymentFlux does not create those Google cookies itself. Exact names and durations are controlled by Google and may change.
PaymentFlux does not currently identify you to Google Analytics using a PaymentFlux account identifier. Where Google Analytics loads after Accept all, measurement uses Google’s own client identifier.
PaymentFlux does not intend to send card numbers, bank-account details, identity documents, or similar sensitive payment and verification data to Google Analytics.
Microsoft Clarity is not currently configured for production and is not loaded. The Platform includes fail-closed support that could load Clarity in future only if a project identifier were configured and you had accepted optional cookies. That is a possible later configuration, not the current production configuration.
Advertising, remarketing or marketing pixels are used to promote products or measure campaigns.
Status: not currently used. PaymentFlux does not operate advertising or remarketing tags. Selecting Accept all does not, by itself, turn on an advertising product that PaymentFlux has not implemented, including Meta Pixel, TikTok, remarketing or behavioural advertising.
Some technologies support security and payments, including:
Turnstile is a security control for a requested form. It is not an analytics tracker.
We classify PaymentFlux’s own authentication, session, preference, payment-journey, identity-return and support-session storage as strictly necessary for the requested service.
Stripe, Google (sign-in) and Cloudflare may set their own cookies or similar identifiers when their interfaces load. Those technologies are provided by those organisations. Exact cookie names and durations can vary. See section 11 and our Privacy Policy for how card data is handled.
| Third party | When it appears | Purpose | Classification |
|---|---|---|---|
| Stripe | When you use card entry / payment confirmation through Stripe.js Elements | Process card payments, support authentication and fraud controls for card transactions | Strictly necessary for card payment |
| Google (sign-in) | Only if you choose Google sign-in / account linking | Authentication with your Google account | Strictly necessary for that chosen sign-in method |
| Cloudflare Turnstile | On protected forms where bot-protection is enabled | Help distinguish genuine users from automated abuse | Strictly necessary security for those forms |
| Google Tag Manager | Marketing website and customer app, where configured, and only after Accept all | Manage permitted analytics tags where optional analytics are enabled | Optional analytics |
| Google Analytics | Marketing website and customer app, where configured, and only after Accept all, delivered through Tag Manager | Understand use of the marketing website and customer app | Optional analytics |
These organisations may process information under their own terms and privacy notices. PaymentFlux does not control all third-party retention or secondary use.
Microsoft Clarity is not currently configured and is not loaded in production.
The tables below list first-party cookies and browser storage PaymentFlux uses on the Platform.
Third-party technologies that may appear when you use embedded payment, sign-in, bot-protection or consented analytics features are summarised in section 10. Exact third-party cookie names and durations can vary by provider.
This inventory describes the production configuration for optional analytics on PaymentFlux web surfaces (paymentflux.co.uk, www.paymentflux.co.uk and app.paymentflux.co.uk): Google Tag Manager and Google Analytics where those tags are configured for that surface, still consent-gated. A surface that is not configured does not load those tags even if you selected Accept all.
| Name / key | Technology | Provider | First / third party | Purpose | Category | Duration | Consent required? |
|---|---|---|---|---|---|---|---|
pf_cookie_consent |
Cookie (production PaymentFlux domains) or localStorage (localhost / non-shared hosts) | PaymentFlux | First-party | Stores cookie preference (accepted_all or rejected_optional), timestamp and Cookie Policy version references; shared across paymentflux.co.uk, www.paymentflux.co.uk and app.paymentflux.co.uk via .paymentflux.co.uk where supported |
Preference / strictly necessary to remember choice | Up to 365 days (Max-Age), refreshed when you change preference; the banner may ask again if the published Cookie Policy version changes |
No — needed to store your choice. Choice itself is an active Accept all / Reject optional action |
pf_session |
Cookie | PaymentFlux | First-party | Soft signed-in routing hint for the customer app root page only; not proof of authentication | Strictly necessary | Session cookie, or up to 30 days if you choose a durable (“remember me”) sign-in | No |
| Name / key | Technology | Provider | First / third party | Purpose | Category | Duration | Consent required? |
|---|---|---|---|---|---|---|---|
pf_access_token |
localStorage or sessionStorage | PaymentFlux | First-party | Access token for authenticated API calls | Strictly necessary | Until sign-out, expiry or browser/session end (depends on remember-me choice) | No |
pf_refresh_token |
localStorage or sessionStorage | PaymentFlux | First-party | Refresh token for session continuity | Strictly necessary | Until sign-out, expiry or browser/session end | No |
pf_user |
localStorage or sessionStorage | PaymentFlux | First-party | Cached user snapshot for app bootstrap | Strictly necessary | Until sign-out or storage clear | No |
pf_access_expires_at_ms |
localStorage or sessionStorage | PaymentFlux | First-party | Access-token expiry helper | Strictly necessary | Until sign-out or storage clear | No |
pf_consent_gating |
localStorage or sessionStorage | PaymentFlux | First-party | Client snapshot of whether Platform Terms acceptance is still required | Strictly necessary | Until sign-out or storage clear | No |
pf_device_id |
localStorage or sessionStorage | PaymentFlux | First-party | Client-generated device id sent with authentication | Strictly necessary (security for requested service) | Until cleared with auth storage | No |
pf_risk_device_id |
localStorage (sessionStorage fallback) | PaymentFlux | First-party | Stable client-generated device id used with security and risk checks | Strictly necessary (security for requested service) | Until you clear site data | No |
pf_risk_device_first_seen_utc |
localStorage (sessionStorage fallback) | PaymentFlux | First-party | First-seen time for that device id | Strictly necessary (security for requested service) | Until you clear site data | No |
pf_risk_device_last_seen_utc |
localStorage (sessionStorage fallback) | PaymentFlux | First-party | Last-seen time for that device id | Strictly necessary (security for requested service) | Until you clear site data | No |
pf_risk_device_fingerprint_hash |
localStorage (sessionStorage fallback) | PaymentFlux | First-party | Coarse browser-environment helper used with security and risk checks | Strictly necessary (security for requested service) | Until you clear site data | No |
paymentflux_mock_payment_draft_v1 |
sessionStorage | PaymentFlux | First-party | Temporary payment-entry draft while you complete the payment journey | Strictly necessary | Browser session / until cleared after the journey | No |
paymentflux_pending_payment_confirm_v1 |
sessionStorage | PaymentFlux | First-party | Continuity for a pending payment confirmation | Strictly necessary | Browser session / until cleared | No |
paymentflux_payment_create_idempotency_v1 |
sessionStorage | PaymentFlux | First-party | Prevents duplicate payment-create requests | Strictly necessary | Browser session / until cleared | No |
paymentflux_payment_confirm_idempotency_v1 |
sessionStorage | PaymentFlux | First-party | Prevents duplicate payment-confirm requests | Strictly necessary | Browser session / until cleared | No |
paymentflux_payment_cancel_idempotency_v1 |
sessionStorage | PaymentFlux | First-party | Prevents duplicate payment-cancel requests | Strictly necessary | Browser session / until cleared | No |
paymentflux_payment_confirm_consent_v1:{paymentId} |
sessionStorage | PaymentFlux | First-party | Remembers payment-authorisation choices during the current payment journey | Strictly necessary | Browser session / until cleared | No |
paymentflux_payment_review_save_card_v1:{paymentId} |
sessionStorage | PaymentFlux | First-party | Remembers whether you chose to save a card during payment review | Strictly necessary | Browser session / until cleared | No |
paymentflux_same_intent_replacement_v1:{paymentId} |
sessionStorage | PaymentFlux | First-party | Continuity if a payment method on the same payment needs to be replaced | Strictly necessary | Browser session / until cleared | No |
payment-card-declines:{paymentId} |
sessionStorage | PaymentFlux | First-party | Counts card-entry declines for that payment so the journey can stop repeating a failed attempt | Strictly necessary | Browser session / until cleared | No |
paymentflux_public_support_session_v1:{caseId} |
sessionStorage | PaymentFlux | First-party | Public support magic-link session for a specific case | Strictly necessary | Browser session / until expiry or clear | No |
pf_identity_callback_pending |
sessionStorage | PaymentFlux | First-party | Marks a return from identity verification so the app can finish that step | Strictly necessary | Browser session / until cleared | No |
payment-continue-setup-dismissed:{paymentId} |
sessionStorage | PaymentFlux | First-party | Remembers that you dismissed a continue-setup notice in this session | Preference / strictly necessary for that notice | Browser session | No |
home-ready-recipients-dismissed:{fingerprint} |
sessionStorage | PaymentFlux | First-party | Remembers that you dismissed a home readiness acknowledgement in this session | Preference / strictly necessary for that notice | Browser session | No |
payment-milestone-dismissed:{paymentId}:{variant}:{heading} |
sessionStorage | PaymentFlux | First-party | Remembers that you dismissed a payment-progress notice in this session | Preference / strictly necessary for that notice | Browser session | No |
These technologies appear only after you select Accept all, and only on a PaymentFlux surface where Google Tag Manager is configured.
| Name / pattern | Technology | Provider | First / third party | Purpose | Category | Duration | Consent required? |
|---|---|---|---|---|---|---|---|
| Google Tag Manager / Google Analytics cookies and similar storage (names set by Google; commonly include identifiers used to distinguish visits) | Cookies and/or browser storage set by Google after Tag Manager loads | Third-party, often first-party on PaymentFlux domains | Understand use of the marketing website and customer app; Tag Manager delivers permitted Google Analytics tags | Optional analytics | Controlled by Google; may change | Yes — Accept all. Reject optional does not load these tags through PaymentFlux’s implementation |
PaymentFlux does not list invented Google cookie names or fixed durations. Google controls that inventory.
Microsoft Clarity storage is not present in the current production configuration.
Where non-essential technologies are used, they are not used until you make an active choice through our cookie banner or Cookie settings.
On PaymentFlux:
pf_cookie_consent.If we add further optional technologies later, we will update this Policy and only enable them according to your stored preference and the configuration of that surface.
You can change or withdraw your cookie preference at any time by:
pf_cookie_consent in your browser, which will cause the banner to appear again.Withdrawal does not affect the lawfulness of processing carried out before you withdrew consent.
Strictly necessary technologies cannot generally be switched off through PaymentFlux Cookie settings. Your browser may still block them, which may break sign-in, payments or other requested features.
Most browsers let you block or delete cookies and clear localStorage / sessionStorage. Device settings may also restrict tracking or storage.
If you block strictly necessary technologies, you may be unable to sign in, complete a Property Payment, or use support access links.
| If you block… | Likely consequence |
|---|---|
| Authentication / session storage | You may be signed out or unable to use the customer app |
pf_cookie_consent |
The preference banner may reappear; we may be unable to remember a previous optional-category choice |
| Payment journey storage | Payment entry or confirmation continuity may fail or duplicate-protection may be weaker |
| Stripe technologies | Card payment entry may not work |
| Cloudflare Turnstile | Protected forms may not submit |
| Optional analytics (Google Tag Manager / Google Analytics) | We will have less information about how the marketing website and customer app are used; the Service itself should still work, including making a Property Payment |
| All cookies/storage | Core parts of the Service are likely to break |
We may update this Cookie Policy when our use of cookies or similar technologies changes. The version label and effective date below identify the current draft. Material changes will be published through our consent catalogue, and the preference banner may reappear when the published Cookie Policy version changes.
Questions about this Cookie Policy or cookie preferences:
| Field | Value |
|---|---|
| Document | Cookie Policy |
| Version label | 2026.09.1 |
| Effective from | 8 September 2026 (UTC) |
| Locale | en-GB |
This Policy applies from the effective date above once published through our consent catalogue for that version. Until published, earlier published versions continue to apply where already in use. The actual publication timestamp is set when that catalogue version is published.