COOKIES & STORAGE · 23 SEPTEMBER 2026
Small files.
Clear choices.
Essential storage supports checkout and staff sign-in. Optional first-party visitor measurement starts only after you accept. We do not use advertising pixels, social trackers or third-party video embeds.
The checkout cookie
| Name / provider | Purpose | Lifetime and scope |
|---|---|---|
pg_checkout
OrderWorth, first party |
Associate your browser with an order, return from Stripe and recover a receipt. Contains a random token; the server stores its hash. It is not used for analytics. | Up to 24 hours from issue or refresh; server recovery is limited to 24 hours from order creation. Host-only, /api path; Secure, HttpOnly and SameSite=Lax. |
orderworth_currency
OrderWorth local storage, first party |
Remember USD, EUR, GBP, CAD or AUD only after you explicitly choose a currency. It contains no identity or purchase key. | Until you clear this preference or your browser’s site data. |
Created only when an available checkout is opened and refreshed when a purchase starts. General browsing, Free downloads, help pages and the sample demo do not create this application cookie. A disabled checkout does not create it.
This cookie supports the checkout service you request. EU guidance distinguishes strictly necessary cookies from optional tracking that requires prior consent. Blocking all cookies may prevent checkout; Free and the guides remain available.
Hosting, sign-in and Stripe
Hosting access controls and owner sign-in can use additional security or authentication storage managed by the platform. Stripe uses its own cookies after you navigate to Stripe to pay; we do not embed its checkout SDK or contact Stripe from your browser before that navigation.
Platform cookies and storage: The purchase service uses pg_checkout for browser recovery for up to 24 hours, with Secure, HttpOnly and SameSite=Lax protection. Staff sign-in cookies protect the private workspace. Cloudflare may set necessary security cookies, including __cf_bm and cf_clearance; their lifetime depends on the active security challenge and provider settings. Stripe uses its own payment and security storage on hosted checkout. Optional first-party measurement requires consent and can be rejected or withdrawn through Privacy choices. No advertising trackers are used by the application.
See Stripe’s privacy information. If optional tools are introduced, they must be blocked until the required consent is given, offer a clear rejection option and provide an equally easy withdrawal control. The optional measurement feature below follows these controls and does not load third-party analytics scripts.
Optional measurement and your choice
Choose whether OrderWorth may count your public page views, visits and approximate country. Rejecting does not restrict use of the site. The Accept and Reject choices are equally available. Change your choice here at any time; withdrawal stops future collection. Global Privacy Control and Do Not Track disable measurement. Measurement is unavailable until the operator has configured and reviewed the privacy disclosures.
Measurement starts only after acceptance when the feature is enabled.
| Name and provider | Purpose | Duration |
|---|---|---|
orderworth_analytics_choice · OrderWorth localStorage |
Remember acceptance or rejection and notice version. This preference record does not identify a visit. | 180 days from your choice. Expired choices are ignored. |
orderworth_analytics_visit · OrderWorth sessionStorage |
A random identifier to count a 30-minute visit in one tab. Created only after acceptance; cleared on withdrawal. | 30 minutes from creation or until the tab closes, whichever comes first. |
Only public page names are measured. Checkout, purchase accounts and staff pages are excluded. No advertising identifier, full URL, query string or precise location is collected by this feature. See measurement purposes, limits and server retention.
Staff sign-in storage
These first-party cookies are used when a staff member requests sign-in or account security. They are not analytics cookies.
| Name | Purpose | Duration |
|---|---|---|
__Secure-orderworth-admin.session_token
|
Signed staff session identifier; Secure, HttpOnly, SameSite=Strict, host-only, path /. | Browser session; server session expires after eight hours. Sign-out or access revocation ends access sooner. |
__Secure-orderworth-admin.dont_remember
|
Keep the requested staff login as a browser-session cookie. | Browser session. |
__Secure-orderworth-admin.two_factor
|
Temporarily associate a password check with its pending authenticator challenge. | Up to 10 minutes; cleared after verification. |
sidebar_state
|
Remember a staff member’s requested navigation expansion state. | Up to seven days. |
Authenticator setup keys, recovery codes and invitation links remain in page memory unless you choose to copy or download them. Store downloaded recovery codes securely. Platform access cookies, if present, are described in the separate verified inventory above.
Other browser storage
The purchase key, sample calculator and website tutorial use page memory. We do not store them in localStorage, sessionStorage or IndexedDB, or register a service worker. Downloaded receipts and JSON exports are files you choose to save; they remain on your device until you delete them. A copied key may remain in your clipboard.
The plugin uses WordPress settings, metadata and temporary records on your server, not this website’s cookie. Its optional scheduled email uses your own mail provider. Read the plugin data explanation.
Close this browser’s checkout recovery
Save your purchase key first. This action clears the checkout cookie and invalidates its existing server associations. It does not cancel or refund a payment, delete purchase records, sign you out of Stripe, or clear platform sign-in cookies or your display-currency preference. To remove that preference, use the button below or clear this website’s data in your browser. Your saved key still opens My purchase.
You can also manage cookies in your browser settings. To remove personal records, use a privacy request.
Storage inside the WordPress plugin
Free uses session storage in your WordPress administration to avoid repeating contextual suggestions during a browser-tab session. It is scoped to your WordPress site and account. “Hide this suggestion” also saves a persistent preference in WordPress. This storage belongs to your store’s administration and is not website tracking.