Cookies
LegalEffective Date: 28 June 2026 Version: 1.0
This Cookie Policy is a specific, POPIA-compliant statement of the cookies, local storage and tracking technologies the Toker Platform uses. It supplements the Privacy Policy.
1. What this policy covers
This policy describes cookies set by go-toker.com, local storage / IndexedDB used by the Platform, tracking technologies embedded in the Platform, and cookies set by third parties on our pages (payment processors, map providers, push networks). It does not cover cookies set by third-party websites linked from the Platform.
2. The legal basis for each cookie
POPIA s.11(1) requires consent for processing of personal information, including by means of cookies that identify you or your device. We classify cookies into four categories:
- Strictly necessary — performance of contract (POPIA s.11(2)(a)) + legal obligation. No consent required.
- Functional — consent (POPIA s.11(1)). Default-on with opt-out.
- Analytics — consent. Opt-in only.
- Marketing — we use none.
3. The cookies we use
3.1 Strictly necessary cookies
__Host-session— HMAC-signed session cookie, 30 days rolling, HttpOnly + Secure + SameSite=Lax.csrf— double-submit CSRF token, session-only.cf_clearance/__cf_bm— Cloudflare bot-management cookies.locale— chosen language (1 year).toker-cookie-consent— records your cookie consent choice (1 year).
3.2 Functional cookies
theme— light/dark preference (1 year).map-style— street/satellite preference (1 year).radius— last search radius (30 days).tour-state— onboarding tour progress (90 days).
3.3 Analytics
We use Cloudflare Web Analytics, which is cookieless. It does not set cookies in your browser, does not fingerprint your device, and does not track you across sites. We do not use Google Analytics, Facebook Pixel, or any other third-party analytics that sets identifying cookies.
3.4 Marketing cookies
We do not use marketing cookies. Toker is not financed by third-party advertising or ad networks. The Platform is itself a marketing and discovery service for cannabis shops, but Toker does not run external ad campaigns, sell ad slots to third parties, or share user data with ad networks.
4. Cookies set by third parties
4.1 Payment processors (checkout only)
The active payment processor — currently the payment processor shown at checkout — sets cookies on its own domain when you reach checkout, governed by its own privacy policy in addition to this policy.
4.2 Map tiles
The map is rendered in your browser by MapLibre GL using vector tiles from OpenFreeMap (built from OpenStreetMap data). Tiles are fetched as ordinary static files: no cookies are set and no account or API key is involved.
Google Maps does not run in your browser here and sets no cookies. We use a Google service only on our own servers, and only to turn a shop address typed in during shop setup into map coordinates. That request is made by our server, so no Google cookie reaches your device.
4.3 Web Push network
Your browser vendor (Mozilla, Google, Apple, Microsoft) sets cookies to manage the push subscription endpoint. Governed by the browser vendor's privacy policy.
5. Local & session storage
Local storage persists until you clear your browser data; session storage is discarded when you close the tab.
5.1 Local storage
auth-storage— your signed-in session statetoker_user— your cached account record, so the app can render before the server repliestoker_session_token,toker_session_expires_at— your session token and its expirytoker_geo_consent— whether you approved or declined sharing your locationtoker_shop_preview_end_user— shop owners only: whether you are previewing your shop as a customerpendingDayPassClaim— a shared Day Pass you tapped before signing in, held so the claim survives logintoker:payment-success— a one-shot flag so the success message shows once after checkouttoker-experience-stream-v1— local record of milestones and hints you have already seentoker:screenreading:pending-batches— product-analytics events that failed to send, queued for retry (test and preview environments only; never set on go-toker.com)
5.2 Session storage
toker_geo_skipped— that you dismissed the location prompt, so it does not re-ask this visitintendedPath— the page you were heading to before being asked to sign intoker_referral_invite_token— the invite code from a friend's referral link, held until you finish signing up so they get credittoker_pin_checkin_<shop id>,toker_pin_drawbox_<shop id>— shop owners only: your counter and draw-box PINs for this sessiontoker:screenreading:session-id,toker:screenreading:session-event-count,toker:screenreading:operator-id— identifiers attached to product-analytics events (test and preview environments only; never set on go-toker.com)
The PWA also uses the Cache Storage API to store static assets for offline use. This is strictly necessary for the PWA and is exempt from consent.
6. Do Not Track & Global Privacy Control
We honour:
- Do Not Track (DNT) — if your browser sends
DNT: 1, we disable all non-essential cookies. - Global Privacy Control (GPC) — if your browser sends
Sec-GPC: 1, we treat it as a request to disable non-essential cookies and opt out of any "sale" or "share" (in any event, we do not sell or share personal information).
7. How to control cookies
From the Platform:
Visit Settings → Cookies at /dashboard/client/profile (clients) or/dashboard/shop (shop owners) to view and change preferences.
From your browser:
- Chrome: support.google.com/chrome/answer/95647
- Firefox: support.mozilla.org/.../clear-cookies
- Safari: support.apple.com/guide/safari
Blocking strictly necessary cookies will prevent the Platform from working.
8. Changes to this policy
We may update this Cookie Policy from time to time. Material changes are posted on the Platform with 30 calendar days' notice.
9. Contact
For questions about this Cookie Policy, email privacy@go-toker.com.