Cookie & GDPR Policy

Last updated: September 7, 2026

This Cookie and GDPR Policy explains how Hirepay uses cookies and similar technologies on our website and services, and how we comply with the General Data Protection Regulation (GDPR) and other privacy laws.

What Are Cookies

Cookies are small text files that are placed on your device when you visit our website. They help us provide you with a better experience by remembering your preferences and understanding how you use our services.

Types of Cookies We Use

Essential Cookies

These cookies are necessary for our website to function properly and cannot be disabled. They enable core functionality such as security, network management, and accessibility.

Cookie NamePurposeDuration
hirepay_sessionMaintains your login sessionSession
csrf_tokenSecurity protection against cross-site attacksSession
cookie_consentRemembers your cookie preferences1 year

Analytics Cookies

These cookies help us understand how visitors interact with our website by collecting and reporting information anonymously. This helps us improve our services.

Cookie NamePurposeDuration
_gaGoogle Analytics — distinguishes users2 years
_gidGoogle Analytics — distinguishes users24 hours
_gatGoogle Analytics — throttles request rate1 minute

Functional Cookies

These cookies enable enhanced functionality and personalization, such as remembering your preferences and settings.

Cookie NamePurposeDuration
user_preferencesStores your display and language preferences1 year
dashboard_layoutRemembers your dashboard configuration6 months

You can control cookie settings through your browser preferences. Most browsers allow you to:

  • View cookies stored on your device
  • Delete existing cookies
  • Block cookies from specific websites
  • Block all cookies (note: this may affect website functionality)

Important Note

Disabling certain cookies may affect the functionality of our services. Essential cookies cannot be disabled as they are necessary for the website to function properly.

GDPR Compliance

As a company operating in the European Union and providing services to EU residents, Hirepay is committed to full compliance with the General Data Protection Regulation (GDPR).

Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to fulfill our service agreement
  • Legitimate Interests: Improving our services and preventing fraud
  • Legal Compliance: Meeting regulatory and tax reporting requirements
  • Consent: Where you have given specific consent for processing

Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

Right of Access

Request access to your personal data and information about how we process it.

Right of Rectification

Request correction of inaccurate or incomplete personal data.

Right of Erasure

Request deletion of your personal data in certain circumstances.

Right of Portability

Request a copy of your data in a structured, machine-readable format.

Right to Restrict Processing

Request limitation of processing your personal data in certain situations.

Right to Object

Object to processing based on legitimate interests or for direct marketing.

Exercising Your Rights

To exercise any of your GDPR rights, please contact us using the information provided below. We will respond to your request within 30 days as required by GDPR.

Data Protection Officer

While not legally required to appoint a Data Protection Officer (DPO), we have designated a privacy team to handle data protection matters and ensure GDPR compliance.

Data Transfers

When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions for countries with adequate data protection levels
  • Binding Corporate Rules where applicable

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. Specific retention periods vary by data type and are outlined in our Privacy Policy.

Security Measures

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and audits
  • Access controls and authentication measures
  • Staff training on data protection
  • Incident response procedures

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.

Complaints

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local data protection supervisory authority.

Contact Us

If you have any questions about this Cookie and GDPR Policy, or wish to exercise your data protection rights, please contact us:

  • Email: info@hirepayonline.com
  • Phone: +44-02073624993
  • Address: Hirepay, London, United Kingdom

Updates to This Policy

We may update this Cookie and GDPR Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.

Book a free demo See pricing