Press.
§ 08 / Cookie Policy

Cookies and local storage

Press uses a small set of strictly-necessary and functional cookies (plus one browser local-storage preference) to keep you signed in, run checkout safely, and show previews correctly: no analytics, advertising, or cross-site tracking.

This Cookie Policy explains how Press uses cookies and similar technologies on https://gopress.studio (the Site). It tells you what these technologies are, exactly which ones we set, why, how long they last, and how you can control or refuse them. "Press", "we", "us" and "our" refer to PRESS STUDIO (SSM Registration No. RA0136980-M), a business registered in Malaysia with the Companies Commission of Malaysia (SSM).

Press is operated from Malaysia under the Personal Data Protection Act 2010 (as amended by the Personal Data Protection (Amendment) Act 2024), and serves customers worldwide. Where cookies process personal data, that processing is also described in our Privacy Policy.

Note

This document is provided for transparency and is a draft for review by qualified counsel. It is not legal advice. Where you have entered into a separate, signed agreement with Press that addresses these matters, that agreement governs to the extent of any conflict. Otherwise, this policy and our Terms of Service and Privacy Policy apply.

01 What cookies and similar technologies are

A cookie is a small text file that a website asks your browser to store on your device. When you return, your browser sends the cookie back, which lets the site recognise your session and remember certain choices. Cookies set by the site you are visiting are called first-party cookies; cookies set by another domain whose code runs on the page (for example, a payment provider) are called third-party cookies.

"Similar technologies" cover other ways a site can store or read information on your device, including local storage (a per-site key/value store in your browser that, unlike a cookie, is not automatically sent to a server) and session storage. We group all of these together as "cookies" in this policy for readability, but the table below tells you exactly which mechanism each item uses.

Cookies can also be described by how long they last. A session cookie is deleted when you close your browser. A persistent cookie stays until it reaches a set expiry date or you delete it.

02 The cookies and storage Press actually uses

The table below is a complete list of the cookies and local-storage items Press sets in normal operation. We do not use analytics, advertising, social-media, or any cross-site tracking cookies, and we do not sell or share personal data for cross-context behavioural advertising.

NameProviderPurposeTypeDuration
authjs.session-token (the next-auth / Auth.js session cookie; appears as __Secure-authjs.session-token over HTTPS)Press (first-party)Keeps you securely signed in to your Press account by carrying your signed JWT session. Without it, login does not work.Strictly necessaryPersistent (until the session expires or you sign out)
press_adminPress (first-party)Authenticates an internal Press operator to the staff-only admin console. It is never set on ordinary customer sessions and carries no marketing or tracking function.Strictly necessary (internal/operator only)Session-based (cleared on operator sign-out)
press_pv_<slug>Press (first-party)Attributes views of a specific shared preview to the recipient who opened a signed preview link, so the correct viewer is recorded in the preview audit log and the preview renders for the intended person. One cookie per preview viewed; scoped to that preview's path.FunctionalSession (currently set without an expiry, so it is cleared when you close your browser; see open issues)
__stripe_midStripe (third-party: Stripe, Inc., USA)Set by Stripe.js during checkout to support fraud prevention and to identify the browser/device across a payment session. Card details are entered directly into Stripe and are never seen or stored by Press.Strictly necessary (fraud prevention)Persistent (typically ~1 year; Stripe-controlled)
__stripe_sidStripe (third-party: Stripe, Inc., USA)Set by Stripe.js during checkout for fraud prevention within a single payment session.Strictly necessary (fraud prevention)Session (typically ~30 minutes; Stripe-controlled)
Note

Cookie names and lifetimes set by third parties (here, Stripe) are controlled by that provider and may change. For the most current detail on Stripe's cookies, see Stripe's own cookie and privacy notices at https://stripe.com/cookie-settings and https://stripe.com/privacy.

03 How we categorise these technologies

We group the technologies above into the categories below. The first two are the only categories Press currently uses.

Strictly necessary

These are required for the Site to provide a feature you have actively asked for: signing in, staying authenticated, and completing a payment safely. The service you requested cannot work without them, and we disclose them here for transparency. This category includes the Auth.js session cookie, the press_admin operator cookie, and Stripe's fraud-prevention cookies.

Functional

These remember a choice you made or support a feature, but the core service would still load without them. In our case this is the per-preview attribution cookie (press_pv_<slug>). It is non-marketing and limited to making the experience work the way you expect.

Not currently used: analytics and advertising

Press does not currently set any analytics, performance-measurement, advertising, retargeting, or social-media tracking cookies, and runs no third-party analytics tags. We do not build advertising profiles and do not sell or share personal data for cross-context behavioural advertising. If this changes, we will update this policy and introduce a consent mechanism (as described below) before any such technology runs.

05 How to control or refuse cookies

You can control and delete cookies through your browser settings. Most browsers let you view the cookies stored, delete them individually or all at once, block third-party cookies, and block all cookies. You can also clear local storage from the same settings area. The exact steps differ by browser; the help pages for the major browsers cover this:

Note

Blocking strictly-necessary cookies will break core features. If you block or delete the Auth.js session cookie you will be signed out and unable to log in or stay logged in. If you block Stripe's cookies, checkout may fail or be blocked by fraud-prevention controls, so you may not be able to complete a payment. Blocking functional cookies is lower-impact: a shared preview may not correctly attribute your view.

You can also use a private/incognito browsing window, which typically discards cookies and local storage when you close it, though this means you will need to sign in again each time.

06 Do Not Track and Global Privacy Control

Some browsers can send a Do Not Track (DNT) signal. There is no consistent industry or legal standard for how sites must respond to DNT, so, like most websites, Press does not currently respond to DNT signals. This has limited practical effect for our visitors because Press does not run cross-site tracking, analytics, or advertising cookies in the first place.

Some browsers and extensions can send a Global Privacy Control (GPC) signal, which is treated under the California Consumer Privacy Act (as amended by the CPRA) as a request to opt out of the "sale" or "sharing" of personal information. Press does not sell or share personal information as those terms are defined under that law, so there is currently no sale or sharing for a GPC signal to stop. If we ever introduced any data flow that qualifies as a sale or share, we would update this policy, provide the required opt-out, and treat a GPC signal as a valid opt-out request for browsers in scope.

07 Where to learn more about your data

Cookies are only one of the ways Press handles information. For the full picture, the categories of personal data we collect, the purposes for processing, the third parties we work with (including Stripe, Resend, and Google sign-in), international transfers, retention, and the privacy choices Press offers to all users as a matter of policy (including access, correction, deletion, withdrawal of consent, and obtaining a copy of your data), please read our Privacy Policy.

08 Changes to this policy

We may update this Cookie Policy from time to time, for example, if we add or remove a technology, if a provider changes its cookies, or to reflect changes in law or guidance. When we make a material change, we will post the updated policy on this page and, where appropriate, give a more prominent notice.

Changes take effect when the updated policy is posted on this page.

09 Contact us

If you have any questions about this Cookie Policy or how Press uses cookies and similar technologies, contact us:

  • Email (all enquiries, including privacy and data-protection requests, and legal notices): support@gopress.studio
  • Registered address: available on the SSM register (Companies Commission of Malaysia)

We aim to respond within a reasonable period consistent with the PDPA.

You may also raise a concern with a data-protection authority. In Malaysia, this is the Personal Data Protection Commissioner / Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi), Putrajaya.

§ The rest of the paperwork