cookie Legal

Cookie Policy

Every cookie and browser storage technology this site uses, what each one does, and how long it lasts.

Version 1.0 · Effective 20 August 2026 · Last updated 20 August 2026

The short version

  • check This site sets three cookies. All three are strictly necessary or a preference you set yourself.
  • check There is no advertising, analytics or cross-site tracking on this site — no Google Analytics, no advertising pixel, no session recording.
  • check Because we set no non-essential cookies, there is no consent banner to click through. If that ever changes, consent will be obtained before the cookie is set.
  • check We do not use localStorage or sessionStorage.

1. What a cookie is here

A cookie is a small text file a website asks your browser to store and send back on later requests. Some are essential — without them a site cannot keep you signed in or protect a form. Others exist to profile you across sites. This site uses only the first kind, plus one that remembers a preference you chose.

This policy is written against the code. Every cookie below is one the application actually sets. If you find a cookie from dorskopay.com that is not on this list, please tell us at support@dorskopay.com — it means this page is wrong and we want to fix it.

2. Cookies we set

Name Provider Purpose Duration Category
dorskopay_session DorskoPay (first party) Holds the identifier for your server-side session. Keeps you signed in to your dashboard, portal or admin area, carries flash messages between pages, and holds the CSRF token that protects every form on the site. Marked HttpOnly and SameSite=Lax, and Secure over HTTPS. Session — expires when you close the browser, and is cleared on sign-out. Strictly necessary
dp_locale DorskoPay (first party) Remembers the language you are using, so that moving from a /tr marketing page into checkout or the customer portal does not drop you back into English. Set when you choose a language, visit a language-specific URL, or when your browser's language is detected at checkout. 30 days Preferences
dp_lang_banner_dismissed DorskoPay (first party) Records that you dismissed the banner offering the site in another language, so we do not show it again. 180 days Preferences
The two preference cookies store a language code and a single flag. They contain no identifier, are not linked to your account or to a transaction, and are not shared with anyone.

3. Cookies we do not set

For the avoidance of doubt, and because these are what people are actually worried about:

  • No Google Analytics, and no other web analytics product.
  • No advertising or remarketing pixels — no Meta pixel, no Google Ads tag, no LinkedIn Insight tag, no TikTok pixel.
  • No session recording or heatmap tools.
  • No cross-site tracking, no data brokers, no advertising identifiers.
  • No A/B testing or personalisation cookies.

The usage statistics we look at come from our own server-side records of what the application did. They are not built from a tracking cookie in your browser.

4. Third-party connections that are not cookies

Two third-party connections are worth naming even though they are not cookies we set, because your browser contacts another company's servers and your IP address is visible to them when it does.

Web fonts
Pages load typefaces from Google's font hosts (fonts.googleapis.com and fonts.gstatic.com). Your browser requests the font files directly, so your IP address and basic browser information are visible to that service. It is used to render text, not to identify you, and it does not set a cookie on this site.
Address autocomplete
Where address autocomplete is enabled, the address field suggests addresses as you type, using Google's Places service. That sends the partial address text you type, and your IP address, to Google, and that service may set its own cookies. It is only active where an API key has been configured for the platform; where it has not, the address fields are ordinary text inputs and no request is made. You can always ignore the suggestions and type the address in full.

What those services do with the data is governed by their own privacy notices, not ours.

5. Why there is no consent banner

Under UK and EU cookie rules, consent is required before storing or accessing information on your device — except where the storage is strictly necessary to provide a service you have requested, and except for a preference you have actively chosen to set.

All three cookies above fall within those exceptions: the session cookie is strictly necessary to operate an account, and the two preference cookies record a choice you made. None of them is used for analytics, profiling or advertising. So there is nothing here that requires opt-in consent, and putting a banner in front of you asking permission for cookies you cannot decline anyway would be theatre.

If DorskoPay ever introduces a cookie that is not strictly necessary — an analytics tool, for example — a consent mechanism will be added first, and that cookie will not be set until consent has been given. It will not be set on page load and switched off afterwards. This page and the Privacy Policy will be updated before, not after.

6. Managing cookies

You can block or delete cookies through your browser settings, and every major browser lets you do this per site.

Be aware of what blocking the session cookie does: you will not be able to sign in to a dashboard or customer portal, and forms — including checkout — will fail their security check and be rejected. That is not a defect; it is the protection working, because the token that proves a form came from this site cannot be carried without it.

Blocking or deleting the two preference cookies is harmless. The site will simply stop remembering your language choice and may offer you the language banner again.

7. Other browser storage

DorskoPay does not use localStorage, sessionStorage, IndexedDB, web beacons, browser fingerprinting scripts or Flash storage on its public site or in its checkout.

A coarse device signal is derived server-side from request characteristics for fraud screening on a transaction. It is described in the Privacy Policy under fraud and risk data. It is not stored in your browser and is not used for advertising or tracking across sites.

8. Changes and contact

When the application's cookie use changes, this page is updated and its version number and effective date change with it.

Questions about this policy go to support@dorskopay.com.

Related documents

DORSKO LIMITED trading as DorskoPay · Company No 15104126 · Registered in England and Wales

Registered office: Unit A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE

support@dorskopay.com