Cookies and measurement
Who this is for: anyone visiting metropay.app or using MetroPay, including people opening an invoice they were sent.
What we set, and why
Every cookie MetroPay sets is first-party and functional. There is no consent banner on this site because there is nothing to consent to — none of these follows you anywhere, and removing any of them would break something you asked the product to do.
| Cookie | What it does | How long |
|---|---|---|
| Session cookie | Keeps you signed in as you move between pages | Expires shortly after you stop using the app |
XSRF-TOKEN |
Proves a form submission came from you and not another site | The browsing session |
remember_web_* |
Set only if you tick "remember me" when signing in | Until it expires or you sign out |
sidebar_state |
Remembers whether you collapsed the sidebar | One week |
appearance |
Remembers whether you chose light, dark or system theme | One year |
If you are here because you received an invoice, only the first two ever apply to you, and only while the page is open.
What we do not set
No advertising cookies. No tracking pixels. No third-party analytics script on our pages by default. We do not run remarketing, we do not embed social buttons that phone home, and nothing here is shared with an ad network.
Product measurement
MetroPay can measure how new workspaces get set up — which first-run screens people reach, and where they get stuck — so those screens can be made better.
It is off unless someone switches it on, under Settings, Privacy. Nothing is pre-selected there, and no answer on record is treated as a refusal.
When it is on, what is sent is a short list of fixed labels naming a screen and its state. It never includes:
- your name or email address;
- your customers, or anything about them;
- invoice numbers or amounts;
- anything you type;
- your IP address.
An organization can also exclude itself entirely, which overrides every individual choice inside it. And there is a platform-wide switch above both — when that is off, nothing is collected from anyone, whatever anyone has chosen.
If a setting is being overridden by one of the switches above it, the Settings page says so plainly rather than letting you believe your choice is doing something it is not.
Turning things off
You can clear or block cookies in your browser at any time. Blocking the session and XSRF-TOKEN
cookies will stop you being able to sign in — they are how signing in works, not an optional extra.
To stop product measurement, set it to "Do not allow" under Settings, Privacy. The change takes effect immediately.