COOKIES & STORAGE · 23 SEPTEMBER 2026

Small files.
Clear choices.

Essential storage supports checkout and staff sign-in. Optional first-party visitor measurement starts only after you accept. We do not use advertising pixels, social trackers or third-party video embeds.

The checkout cookie

Name / provider Purpose Lifetime and scope
pg_checkout
OrderWorth, first party
Associate your browser with an order, return from Stripe and recover a receipt. Contains a random token; the server stores its hash. It is not used for analytics. Up to 24 hours from issue or refresh; server recovery is limited to 24 hours from order creation. Host-only, /api path; Secure, HttpOnly and SameSite=Lax.
orderworth_currency
OrderWorth local storage, first party
Remember USD, EUR, GBP, CAD or AUD only after you explicitly choose a currency. It contains no identity or purchase key. Until you clear this preference or your browser’s site data.

Created only when an available checkout is opened and refreshed when a purchase starts. General browsing, Free downloads, help pages and the sample demo do not create this application cookie. A disabled checkout does not create it.

This cookie supports the checkout service you request. EU guidance distinguishes strictly necessary cookies from optional tracking that requires prior consent. Blocking all cookies may prevent checkout; Free and the guides remain available.

Hosting, sign-in and Stripe

Hosting access controls and owner sign-in can use additional security or authentication storage managed by the platform. Stripe uses its own cookies after you navigate to Stripe to pay; we do not embed its checkout SDK or contact Stripe from your browser before that navigation.

Platform cookies and storage: The purchase service uses pg_checkout for browser recovery for up to 24 hours, with Secure, HttpOnly and SameSite=Lax protection. Staff sign-in cookies protect the private workspace. Cloudflare may set necessary security cookies, including __cf_bm and cf_clearance; their lifetime depends on the active security challenge and provider settings. Stripe uses its own payment and security storage on hosted checkout. Optional first-party measurement requires consent and can be rejected or withdrawn through Privacy choices. No advertising trackers are used by the application.

See Stripe’s privacy information. If optional tools are introduced, they must be blocked until the required consent is given, offer a clear rejection option and provide an equally easy withdrawal control. The optional measurement feature below follows these controls and does not load third-party analytics scripts.

Optional measurement and your choice

Choose whether OrderWorth may count your public page views, visits and approximate country. Rejecting does not restrict use of the site. The Accept and Reject choices are equally available. Change your choice here at any time; withdrawal stops future collection. Global Privacy Control and Do Not Track disable measurement. Measurement is unavailable until the operator has configured and reviewed the privacy disclosures.

Measurement starts only after acceptance when the feature is enabled.

Name and provider Purpose Duration
orderworth_analytics_choice · OrderWorth localStorage Remember acceptance or rejection and notice version. This preference record does not identify a visit. 180 days from your choice. Expired choices are ignored.
orderworth_analytics_visit · OrderWorth sessionStorage A random identifier to count a 30-minute visit in one tab. Created only after acceptance; cleared on withdrawal. 30 minutes from creation or until the tab closes, whichever comes first.

Only public page names are measured. Checkout, purchase accounts and staff pages are excluded. No advertising identifier, full URL, query string or precise location is collected by this feature. See measurement purposes, limits and server retention.

Staff sign-in storage

These first-party cookies are used when a staff member requests sign-in or account security. They are not analytics cookies.

Name Purpose Duration
__Secure-orderworth-admin.session_token Signed staff session identifier; Secure, HttpOnly, SameSite=Strict, host-only, path /. Browser session; server session expires after eight hours. Sign-out or access revocation ends access sooner.
__Secure-orderworth-admin.dont_remember Keep the requested staff login as a browser-session cookie. Browser session.
__Secure-orderworth-admin.two_factor Temporarily associate a password check with its pending authenticator challenge. Up to 10 minutes; cleared after verification.
sidebar_state Remember a staff member’s requested navigation expansion state. Up to seven days.

Authenticator setup keys, recovery codes and invitation links remain in page memory unless you choose to copy or download them. Store downloaded recovery codes securely. Platform access cookies, if present, are described in the separate verified inventory above.

Other browser storage

The purchase key, sample calculator and website tutorial use page memory. We do not store them in localStorage, sessionStorage or IndexedDB, or register a service worker. Downloaded receipts and JSON exports are files you choose to save; they remain on your device until you delete them. A copied key may remain in your clipboard.

The plugin uses WordPress settings, metadata and temporary records on your server, not this website’s cookie. Its optional scheduled email uses your own mail provider. Read the plugin data explanation.

Close this browser’s checkout recovery

Save your purchase key first. This action clears the checkout cookie and invalidates its existing server associations. It does not cancel or refund a payment, delete purchase records, sign you out of Stripe, or clear platform sign-in cookies or your display-currency preference. To remove that preference, use the button below or clear this website’s data in your browser. Your saved key still opens My purchase.

You can also manage cookies in your browser settings. To remove personal records, use a privacy request.

Storage inside the WordPress plugin

Free uses session storage in your WordPress administration to avoid repeating contextual suggestions during a browser-tab session. It is scoped to your WordPress site and account. “Hide this suggestion” also saves a persistent preference in WordPress. This storage belongs to your store’s administration and is not website tracking.