Cookie Policy
Last updated: 2 August 2026
This policy is issued by HTM Legacy (Pty) Ltd (“the Supplier”, “we”) and describes the storage mechanisms employed by the Services within the Customer’s browser. The Supplier does not employ third-party advertising or tracking cookies, and does not operate any analytics or marketing pixel that tracks a user across unrelated websites. What the Services do employ is a limited quantity of first-party browser storage, principally the browser’s localStorage mechanism, together with the sign-in session maintained by the Supplier’s identity provider, in furtherance of the Services’ ordinary functioning. This policy identifies each such mechanism and should be read together with our Privacy Policy.
1. What a “cookie” is, and why this policy also covers localStorage
A cookie, strictly speaking, is a small text record a website asks a browser to store and to send back with every subsequent request to that same site. Modern web applications, including HTM LEDGR, more commonly rely on a related but distinct browser mechanism, localStorage, which a site can read and write directly but which is not automatically transmitted with every request. For simplicity, and because the practical concern (what is a browser remembering about you, and why) is the same either way, this policy uses “cookie” loosely to cover both, and specifies which mechanism applies to each item listed below.
2. Strictly necessary — session authentication
Upon sign-in, the Supplier’s identity provider stores a session token within the Customer’s browser so as to obviate the need for re-authentication on each page. The Services cannot function without this mechanism, which exists solely to keep the Customer signed in and is not deployed for advertising or cross-site tracking purposes. It is cleared upon sign-out and expires automatically after a period of inactivity determined by the identity provider.
3. Functional storage — preferences
The following are ordinary localStorage entries, accessible only to htmledgr.com, never transmitted to the Supplier or any third party as part of an ordinary page request, and removable at any time by clearing the browser’s site data for this domain:
| Key | Purpose |
|---|---|
ledgr:theme | Records the Customer’s preference for light, dark, or system-matched appearance. |
ledgr:fontSize | Records the Customer’s preferred text size (S/M/L). |
ledgr:fontFamily | Records the Customer’s preferred font (Inter, System, or Serif). |
ledgr:lastSignInEmail | Records the email address last used to sign in on this device, so it need not be re-entered. |
ledgr:healthPeriod | Records whether the dashboard’s Business Health card is displayed on a weekly or monthly basis. |
ledgr:dismissedAnnouncements | Records which service/outage notices this browser has already dismissed, so a read notice does not reappear on every page. |
| Support widget state | Records whether the in-app support button has been minimised. |
| Device identifier | A randomly generated identifier (not derived from device hardware) used to count active devices against the Customer’s plan limit, and to recognise a returning browser for sign-in security alerts. |
4. Security signals not stored in the browser
Separately from browser storage described above, the Supplier computes a coarse device fingerprint and records it server-side, solely for the purpose of detecting repeated free-trial signups originating from the same business, as more fully described in our Privacy Policy. This mechanism does not constitute a cookie, and no data is written to the Customer’s browser in connection with it beyond the random device identifier referred to in clause 3.
5. Third-party services
Signing in through a third-party sign-in provider may involve cookies set by that provider as an incident of its own sign-in flow, governed exclusively by that provider’s own privacy and cookie practices, over which the Supplier exercises no control and accepts no responsibility. The Supplier’s payment gateway provider may similarly set its own cookies while the Customer is present on that provider’s hosted payment page during checkout; the Supplier likewise exercises no control over, and accepts no responsibility for, such cookies, and recommends the Customer consult that provider’s own published policies for further detail.
6. No consent banner, and why
The Services do not display a cookie-consent banner. This is not an oversight: every mechanism described in this policy is either strictly necessary for the Services to function (clause 2), or is a functional preference the Customer directly and voluntarily sets by using the Services (clause 3), rather than a tracking, profiling, or advertising mechanism of the kind cookie-consent regimes are principally directed at. Should the Supplier introduce a cookie or similar mechanism in the future that does require consent under applicable law, this policy will be updated and consent obtained before that mechanism is deployed.
7. “Do Not Track” signals
Some browsers transmit a “Do Not Track” or Global Privacy Control signal. Because the Supplier does not use tracking cookies or cross-site tracking of any kind, the Services do not respond differently to the presence or absence of such a signal; the same limited, functional storage described in this policy applies regardless.
8. Managing or clearing browser storage
The Customer may clear localStorage and cookies associated with htmledgr.com at any time via its browser’s own settings, typically found under a “Privacy”, “Site settings”, or “Clear browsing data” menu, from which htmledgr.com (or all sites) may be selected. Doing so will sign the Customer out, reset appearance preferences to their default values, and cause the browser to be treated as a “new” device upon the next sign-in, with the consequences described in our Privacy Policy. The Supplier does not control, and is not responsible for, the exact menu names or steps in any particular browser, which change from time to time at that browser’s vendor’s discretion.
9. Changes to this policy
The Supplier reserves the right to vary the storage mechanisms described herein as the Services evolve, and will update this page accordingly. The “Last updated” date above reflects the version currently in force.
10. Contact us
Questions: email support@htmledgr.com or use our contact page.
Questions about any of this? Reach us here: