Cookie Policy
Cookie Policy
Effective Date: April 25, 2026
Version: 5
1. Introduction
This Cookie Policy explains how Ctrl+Shift (trading as Ctrl+Shift) uses cookies and similar tracking technologies on https://ctrlshiftapp.org/ ("the Platform"). It should be read together with our Privacy Policy.
By continuing to use the Platform, you consent to the use of strictly necessary cookies. For all other cookies, we seek your consent through our cookie banner the first time you visit, and you can change your preferences at any time (see section 5).
2. What are cookies?
Cookies are small text files that websites place on your browser or device to store information about you or your preferences. They may be "session" cookies (deleted when you close your browser) or "persistent" cookies (kept for a defined period). "First-party" cookies are set by the domain you are visiting; "third-party" cookies are set by another domain — for example, a payment gateway or analytics provider.
We also use related technologies such as local storage, session storage, IndexedDB entries, and server-side session identifiers which perform a similar function to cookies and are covered by this Policy where relevant.
3. Categories of cookies we use
3.1. Strictly necessary — always on
These cookies are essential for the Platform to function. They do not require consent under Kenya's KDPA or the EU ePrivacy Directive.
| Cookie | Purpose | Retention |
|---|---|---|
| sessionid | Maintains your authenticated session. | Session / 14 days |
| csrftoken | Protects against cross-site request forgery on POST forms. | 12 months |
| cookie_consent | Records your consent preferences. | 12 months |
| messages | Stores one-time status messages after form submissions. | Session |
3.2. Functional — consent required
These cookies remember your preferences and improve your experience.
| Cookie | Purpose | Retention |
|---|---|---|
| theme_override | Remembers your preferred UI theme. | 6 months |
| sidebar_state | Remembers collapsed / expanded sidebar sections. | 6 months |
| language_pref | Stores the language selected if different from the browser default. | 12 months |
3.3. Analytics — consent required
We use analytics cookies to understand how Users interact with the Platform so we can improve it. Where enabled, analytics cookies are listed here. We do not currently use Google Analytics, Meta Pixel or other cross-site tracking; any future use will be opt-in and disclosed in advance.
3.4. Payment and security — set by third parties
Our payment gateway partners may set cookies on the checkout flow for fraud detection and session continuity. We have no direct control over third-party cookies; please consult the relevant provider's policy.
| Third party | Purpose | More information |
|---|---|---|
| Payment gateway(s) | Transaction fraud detection, 3-D Secure challenge flow. | See our Privacy Policy §3.3 |
| Cloudinary (media CDN) | Video/image delivery optimisation. | cloudinary.com/privacy |
3.5. Marketing — consent required
We do not currently set marketing cookies. Any future marketing or advertising cookies will be opt-in and disclosed in advance with updated disclosure below.
4. How we obtain your consent
- On your first visit, a banner will ask you to Accept all, Reject non-essential or Manage preferences.
- Strictly necessary cookies are set regardless of your choice because the Platform cannot operate without them.
- Your choice is stored in the cookie_consent cookie for 12 months. After 12 months, or if you clear your cookies, you will be prompted again.
5. Managing your preferences
You can change your cookie preferences at any time:
- Via the "Cookie preferences" link in the Platform footer.
- Via your browser settings — see:
Disabling strictly necessary cookies will prevent the Platform from working correctly — you will not be able to log in or submit forms.
6. Do Not Track and Global Privacy Control
Where your browser sends a Do Not Track header or a Global Privacy Control signal, we treat that as an opt-out of all non-essential cookies for the duration of the session. We do not sell or "share" personal data in the CCPA / CPRA sense.
7. Changes to this Policy
We may update this Policy from time to time to reflect changes to the cookies we use, or to comply with updated law. Material changes will be announced via in-app notification at least 14 days before they take effect. The current version is always available at /legal/cookie-policy/.
8. Contact
For any questions about this Policy or our cookie practices:
- Data Protection Officer: dpo@ctrlshiftapp.org
- General enquiries: info@ctrlshiftapp.org
- Address: {{ registered_office_address }}