Cookie Policy
Version 1.1 · Effective 2026-09-10 · Last updated 2026-09-10 · Operator: Auren LLC
1. The short version
CROSSPAD, a product operated by Auren LLC, sets one cookie. It keeps you signed in after you verify your email address with a one-time code. It is strictly necessary for the service, so we do not ask for consent to set it. We set no analytics, advertising or third-party cookies at launch, and there is no cookie banner because there is nothing to opt in to.
2. What a cookie is
A cookie is a small text file a website stores in your browser and reads back on later requests so it can recognize your session. "First-party" cookies are set by the site you are visiting; "third-party" cookies are set by another domain through that site.
3. The cookie we set
| Name | cp_session |
|---|---|
| Set by | crosspad.co (first-party) |
| Purpose | Keeps you signed in after email-code verification so you can reach your Account, Orders and Delivery Bundles without re-entering a code on every page |
| Type | Strictly necessary |
| Contents | A signed session identifier — no name, email or file data |
| Lifetime | 7 days from sign-in, or until you sign out |
| Attributes | httpOnly (not readable by page scripts), Secure (sent only over HTTPS), SameSite=Lax (not sent on most cross-site requests) |
| Consent | Not required. The cookie is exempt under Article 5(3) of the EU ePrivacy Directive and regulation 6(4) of the UK PECR because it is strictly necessary to provide a service you asked for — being signed in. The Account it links to is processed under our Privacy Policy on the basis of our contract with you |
If you delete or block this cookie you are signed out and must request a new one-time code. The service does not work without it.
4. Cookies we do not set
At launch CROSSPAD sets no analytics or measurement cookies, no advertising, retargeting or social-media cookies, and no third-party cookie on crosspad.co. We do not use browser fingerprinting or similar cookie-less tracking. Our hosting provider keeps standard server and edge logs (IP address, request path, timestamp) for security and availability; those are described in the Privacy Policy, section 3, and are not cookies.
5. Stripe's checkout page
When you pay, you are redirected to Stripe's hosted checkout page at checkout.stripe.com. That page is operated by Stripe, Inc. and sets its own cookies for payment processing and fraud prevention, governed by Stripe's cookie policy (https://stripe.com/cookies-policy/legal) and privacy policy (https://stripe.com/privacy), not by this policy. When you return to crosspad.co, only cp_session is present on our domain.
6. If we ever add non-essential cookies
If we ever want a cookie that is not strictly necessary — to measure how the site is used, for example — we commit to the following before it is set:
- Consent first. A banner will ask you, the cookie will not be set until you agree, choices will be unchecked by default, "reject" will be as easy as "accept", and you will be able to change your mind from a footer link.
- This policy updated. A new version with a new number and effective date will list each cookie's name, provider, purpose, lifetime and type.
- List maintained. Section 3 will always reflect every cookie actually set on
crosspad.co. - Strictly necessary cookies stay consent-free and are listed here.
7. How to control cookies in your browser
You can view, delete and block cookies in your browser settings:
- Chrome: Settings → Privacy and security → Third-party cookies / See all site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari (macOS): Settings → Privacy → Manage Website Data
- Safari (iOS): Settings → Safari → Advanced → Website Data
- Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data
Blocking cp_session prevents you from staying signed in to CROSSPAD.
8. Changes to this policy
Each version has a version number, effective date and last-updated date. We update it whenever the cookies we set change. Adding any non-essential cookie is announced on the website and, for Account holders, by email at least 14 days before it takes effect.
9. Contact
Questions about cookies: privacy@orkoottrae.resend.app. Postal address: Auren LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States.
Related documents: Privacy Policy (/privacy) · Terms of Service (/terms) · Security, File Retention and Deletion Policy (/security).
SHA-256 2a24c3c937afc07115846df29fd6f3329084b3bc762fb4a256335b2f6181e0b7
Version 1.1, effective 2026-09-10. Prior versions available on request at legal@orkoottrae.resend.app.