Cookie and browser storage details

Prepared October 4, 2026. This dated supplement explains observed website and payment-feature storage. It supplements Timastra's privacy notice; it does not alter the archived legal release or record acceptance on anyone's behalf.

Cloudflare website security

Cloudflare protects timastra.com and may place a cf_clearance cookie on your browser even when you only read a page. Cloudflare describes it as storing challenge and JavaScript-detection state. It is separate from Timastra's aggregate traffic statistics and is not an analytics cookie of Timastra's own.

In our public check on October 4, 2026, this cookie used domain .timastra.com, path /, Secure, HttpOnly and SameSite=None attributes, and a partition key for https://timastra.com. The browser showed an expiry about one year later. Whether the cookie is set and its expiry can vary with the site's security configuration and your visit. This observed browser expiry is not a maximum retention period for associated provider records.

Requested local prices and payment recovery

Reading the tested pricing page or homepage contacted no payment-provider origin in this check. After requesting local prices with Paddle or choosing to open Paddle payment recovery, a __cf_bm cookie appeared on domain .paddle.com, path /, with Secure, HttpOnly and SameSite=None attributes and an expiry about 30 minutes later. Cloudflare identifies this cookie with bot protection and describes its expiry as 30 minutes of continuous inactivity.

Requesting local prices contacted cdn.paddle.com, api.paddle.com and public.profitwell.com. Opening payment recovery contacted cdn.paddle.com and public.profitwell.com. Providers receive information needed for the requested feature, including request/device information described in Paddle's privacy notice. Choosing a feature is not consent to unrelated advertising or analytics.

Browser storage and limits of this observation

With new isolated Chrome browser contexts, we observed no local-storage or session-storage keys in the accessible main or child frames during the tested states. We did not open a buyer transaction, supply payment details, follow a customer recovery email or update a payment method. The payment page without a transaction and a recovery-ready message do not exercise those flows.

This is a dated interaction snapshot, not a complete provider inventory. Different checkout and recovery states, devices, locations or provider changes may create other storage or collection. No observed storage does not establish that a provider never tracks or processes information on its servers. Provider documents describe their purposes and handling; territorial consent or exception requirements depend on the actual feature and applicable law.

Your choices

You can read product descriptions and published list prices without requesting payment-provider features. The appearance switch stores your chosen theme locally on your device; you can change it or clear the site's browser data. Clearing security cookies may cause another security check. Browser privacy controls can affect quotes, checkout or recovery. Contact support@timastra.com if you need more information before proceeding.

See Cloudflare's cookie documentation and Paddle's privacy notice for provider information. Provider descriptions alone do not certify that a particular legal exception applies.