Legal
Cookie Policy
Effective September 16, 2026
This website sets one cookie, and only if you create or open a guest pass. It keeps one other thing in your browser — a note that you’ve seen this notice, so it doesn’t come back — and this page is the whole story of both.
What cookies are
Cookies, and their cousins like local storage, are small pieces of data a website keeps in your browser. Sites use them to remember you between visits, to keep you signed in, to measure traffic, and — most of the time — to track you for advertising. Laws such as the EU’s ePrivacy Directive and GDPR require a site to tell you about them and to ask before using any that aren’t strictly necessary.
What this site uses
One cookie, fp_guest. Someone who receives a plan invite can see that plan on this site without installing the app, as a guest — and this cookie is what lets them come back to it. It is set only in three cases: when you create a guest pass from an invite link; when you open the link we emailed you on a device that isn’t already remembering a different pass; or when a device that is remembering a different pass taps “Use this pass on this device” to switch to this one. No other page on this site sets it, and it is never set just for visiting.
It is httpOnly — no script on this page, ours or anyone else’s, can read it — and what it holds is a session token: a value our server issues to this browser and no other. It is not the link we emailed you. Those links are a separate thing: they work for 7 days, and when one runs out another can be sent — from your pass, or by the plan’s owner from the app — which is why this site never needs to keep one. The cookie lasts at most a year from the last time it was issued: we swap it for a fresh one from time to time as you use the pass, and each new one starts its own year. It is never used for analytics or advertising: it identifies a guest pass to our server and nothing else. This is the kind of cookie the law calls strictly necessary — it exists only because you asked for the thing it does — which is why nothing on this site ever asks permission for it, the same as the local storage entry below.
One local storage entry. When you dismiss the cookie notice, the site writes a single key, fp-cookie-notice, to your browser’s local storage so it knows not to show the notice again. It holds no information about you, is never sent anywhere, and is visible only to this site. It too is strictly necessary, which is why the notice only has an OK button and not a choice — there is nothing to choose.
Nothing else. No sign-in for anyone but a guest, no analytics, no advertising, no social widgets, and no third-party script of any kind; the fonts are served from this domain.
The app
The FlexaPay app has no cookies and no trackers either. It keeps your sign-in token in your phone’s secure storage so you stay signed in, and that is described in the Privacy Policy.
Managing it
Clearing this site’s data in your browser’s settings (usually under Privacy, then Site data or Cookies) removes both the cookie and the notice flag at once — there is no separate control for one and not the other. Both simply come back the next time you need them: the notice shows again, and opening a link from your email writes a fresh session. If that link has since run out, the page at flexapay.net/g will email you another. A guest pass is cleared too, but not until you next open the plan after the pass stops being live — the plan’s owner revoked it, say — which is what discovers it is dead and lands you on the recovery page instead of a stale one. Blocking storage for this site entirely breaks nothing except that the notice reappears on every visit and a guest pass cannot stay signed in between them.
If this changes
If we ever add something that needs consent — analytics, say — this page will describe it, the notice will change to ask you first, and nothing will be set until you say yes.
Contact
Questions can reach us through the Support page.