What is the tsrce cookie?
tsrce is a technical cookie set by PayPal whenever a visitor interacts with a PayPal payment button, a checkout form integrated with PayPal, or logs into a PayPal account on a third-party website. It is issued from the .paypal.com domain, so it can appear on any page that loads a PayPal script or iframe.
It belongs to the family of security and risk-assessment cookies used within PayPal's payment processing infrastructure, rather than to an analytics or marketing script of the host site.
What data it stores
The cookie stores a technical identifier tied to PayPal's security/risk session, used to evaluate the context of a transaction. The exact value format is not publicly documented by PayPal and may vary, so no fixed format should be assumed.
The data is sent to PayPal's servers (the .paypal.com domain), not to the site where the payment button is embedded, and the site owner has no direct access to the cookie's contents.
What it is used for
tsrce helps PayPal detect suspicious or potentially fraudulent activity during payment and login flows, contributing to the protection of both the buyer and the merchant. For the site integrating PayPal, this cookie is a technical requirement for the payment module to function correctly, not a traffic-measurement or advertising tool.
Does it require consent?
As a security cookie essential to the operation of the PayPal payment mechanism, it is classified as strictly necessary under guidance from European data protection authorities (in Romania, ANSPDCP). Strictly necessary cookies do not require prior consent under Article 4(b) of Law 506/2004 (transposing the ePrivacy Directive).
- Site owners must still list tsrce in their cookie policy, including provider, purpose, and duration.
- If PayPal is only optionally embedded (e.g., a conditionally displayed button), check that the script loads only on interaction, to avoid setting the cookie unnecessarily.
How to block or delete tsrce
A visitor can delete or block this cookie from browser settings (Chrome, Firefox, Edge, Safari – cookie management for the paypal.com domain), but doing so may prevent completing payments via PayPal or logging into a PayPal account.
For site owners, since it is strictly necessary, it should not be blocked before consent — but the PayPal button or iframe should ideally load only when the user actually chooses the PayPal payment option, rather than being preloaded across the whole page. A CMP such as CookieFix can handle this by blocking scripts from categories that require consent until acceptance, while strictly necessary scripts like tsrce remain active so the site keeps functioning.
Frequently asked questions
No, since it is classified as strictly necessary for PayPal's payment functionality, it does not require prior consent under Law 506/2004, but it must still be disclosed in the cookie policy.
Its typical duration is about 3 days, after which it expires automatically from the browser.
The PayPal payment or login process may not work correctly or may be interrupted.
Only PayPal, since the cookie is set on the .paypal.com domain; the site where the payment button is embedded cannot read its contents.