Cookies

Legal

Effective Date: 28 June 2026 Version: 1.0

This Cookie Policy is a specific, POPIA-compliant statement of the cookies, local storage and tracking technologies the Toker Platform uses. It supplements the Privacy Policy.

1. What this policy covers

This policy describes cookies set by go-toker.com, local storage / IndexedDB used by the Platform, tracking technologies embedded in the Platform, and cookies set by third parties on our pages (payment processors, map providers, push networks). It does not cover cookies set by third-party websites linked from the Platform.

2. The legal basis for each cookie

POPIA s.11(1) requires consent for processing of personal information, including by means of cookies that identify you or your device. We classify cookies into four categories:

  • Strictly necessary — performance of contract (POPIA s.11(2)(a)) + legal obligation. No consent required.
  • Functional — consent (POPIA s.11(1)). Default-on with opt-out.
  • Analytics — consent. Opt-in only.
  • Marketing — we use none.

3. The cookies we use

3.1 Strictly necessary cookies

  • __Host-session — HMAC-signed session cookie, 30 days rolling, HttpOnly + Secure + SameSite=Lax.
  • csrf — double-submit CSRF token, session-only.
  • cf_clearance / __cf_bm — Cloudflare bot-management cookies.
  • locale — chosen language (1 year).
  • toker-cookie-consent — records your cookie consent choice (1 year).

3.2 Functional cookies

  • theme — light/dark preference (1 year).
  • map-style — street/satellite preference (1 year).
  • radius — last search radius (30 days).
  • tour-state — onboarding tour progress (90 days).

3.3 Analytics

We use Cloudflare Web Analytics, which is cookieless. It does not set cookies in your browser, does not fingerprint your device, and does not track you across sites. We do not use Google Analytics, Facebook Pixel, or any other third-party analytics that sets identifying cookies.

3.4 Marketing cookies

We do not use marketing cookies. Toker is not financed by third-party advertising or ad networks. The Platform is itself a marketing and discovery service for cannabis shops, but Toker does not run external ad campaigns, sell ad slots to third parties, or share user data with ad networks.

4. Cookies set by third parties

4.1 Payment processors (checkout only)

The active payment processor — currently the payment processor shown at checkout — sets cookies on its own domain when you reach checkout, governed by its own privacy policy in addition to this policy.

4.2 Map tiles

The map is rendered in your browser by MapLibre GL using vector tiles from OpenFreeMap (built from OpenStreetMap data). Tiles are fetched as ordinary static files: no cookies are set and no account or API key is involved.

Google Maps does not run in your browser here and sets no cookies. We use a Google service only on our own servers, and only to turn a shop address typed in during shop setup into map coordinates. That request is made by our server, so no Google cookie reaches your device.

4.3 Web Push network

Your browser vendor (Mozilla, Google, Apple, Microsoft) sets cookies to manage the push subscription endpoint. Governed by the browser vendor's privacy policy.

5. Local & session storage

Local storage persists until you clear your browser data; session storage is discarded when you close the tab.

5.1 Local storage

  • auth-storage — your signed-in session state
  • toker_user — your cached account record, so the app can render before the server replies
  • toker_session_token, toker_session_expires_at — your session token and its expiry
  • toker_geo_consent — whether you approved or declined sharing your location
  • toker_shop_preview_end_user — shop owners only: whether you are previewing your shop as a customer
  • pendingDayPassClaim — a shared Day Pass you tapped before signing in, held so the claim survives login
  • toker:payment-success — a one-shot flag so the success message shows once after checkout
  • toker-experience-stream-v1 — local record of milestones and hints you have already seen
  • toker:screenreading:pending-batches — product-analytics events that failed to send, queued for retry (test and preview environments only; never set on go-toker.com)

5.2 Session storage

  • toker_geo_skipped — that you dismissed the location prompt, so it does not re-ask this visit
  • intendedPath — the page you were heading to before being asked to sign in
  • toker_referral_invite_token — the invite code from a friend's referral link, held until you finish signing up so they get credit
  • toker_pin_checkin_<shop id>, toker_pin_drawbox_<shop id> — shop owners only: your counter and draw-box PINs for this session
  • toker:screenreading:session-id, toker:screenreading:session-event-count, toker:screenreading:operator-id — identifiers attached to product-analytics events (test and preview environments only; never set on go-toker.com)

The PWA also uses the Cache Storage API to store static assets for offline use. This is strictly necessary for the PWA and is exempt from consent.

6. Do Not Track & Global Privacy Control

We honour:

  • Do Not Track (DNT) — if your browser sends DNT: 1, we disable all non-essential cookies.
  • Global Privacy Control (GPC) — if your browser sends Sec-GPC: 1, we treat it as a request to disable non-essential cookies and opt out of any "sale" or "share" (in any event, we do not sell or share personal information).

7. How to control cookies

From the Platform:

Visit Settings → Cookies at /dashboard/client/profile (clients) or/dashboard/shop (shop owners) to view and change preferences.

From your browser:

Blocking strictly necessary cookies will prevent the Platform from working.

8. Changes to this policy

We may update this Cookie Policy from time to time. Material changes are posted on the Platform with 30 calendar days' notice.

9. Contact

For questions about this Cookie Policy, email privacy@go-toker.com.