Cookie Policy
Last updated: 23 August 2026
This policy is issued by HTM Legacy (Pty) Ltd (“the Supplier”, “we”) and describes the storage mechanisms employed by the Services within the Customer’s browser. The Supplier does not employ third-party advertising cookies, does not sell or disclose browser-derived data to any advertising network, and operates no mechanism that tracks a user across unrelated websites. The Supplier does employ a first-party, aggregate product-measurement facility, described at clause 5A, which is directed exclusively at the Supplier’s own legitimate interest in the operation, security and improvement of the Services. What the Services do employ is a limited quantity of first-party browser storage, principally the browser’s localStorage mechanism, together with the sign-in session maintained by the Supplier’s identity provider, in furtherance of the Services’ ordinary functioning. This policy identifies each such mechanism and should be read together with our Privacy Policy.
1. What a “cookie” is, and why this policy also covers localStorage
A cookie, strictly speaking, is a small text record a website asks a browser to store and to send back with every subsequent request to that same site. Modern web applications, including HTM LEDGR, more commonly rely on a related but distinct browser mechanism, localStorage, which a site can read and write directly but which is not automatically transmitted with every request. For simplicity, and because the practical concern (what is a browser remembering about you, and why) is the same either way, this policy uses “cookie” loosely to cover both, and specifies which mechanism applies to each item listed below.
The status of this policy. This policy forms part of, and is to be read together with, our Privacy Policy, and through it forms part of the notification contemplated in section 18(1) of the Protection of Personal Information Act 4 of 2013 (“POPIA”). It is in addition subject to our Terms of Service in the event of any inconsistency. Each mechanism described below is deployed either because it is necessary for the performance of the agreement between the Supplier and the Customer, within the meaning of section 11(1)(b) of POPIA, or because it is necessary for the pursuit of the Supplier’s legitimate interest in the security and integrity of the Services, within the meaning of section 11(1)(f) thereof, that interest not being, in the Supplier’s assessment, overridden by the interests or fundamental rights of the data subject, given the narrow and functional purpose to which each mechanism is put. None of them is deployed for advertising, profiling, cross-site tracking, or any purpose of onward disclosure.
2. Strictly necessary — session authentication
Upon sign-in, the Supplier’s identity provider stores a session token within the Customer’s browser so as to obviate the need for re-authentication on each page. The Services cannot function without this mechanism, which exists solely to keep the Customer signed in and is not deployed for advertising or cross-site tracking purposes. It is cleared upon sign-out and expires automatically after a period of inactivity determined by the identity provider.
3. Functional storage — preferences
The following are ordinary localStorage entries, accessible only to htmledgr.com, never transmitted to the Supplier or any third party as part of an ordinary page request, and removable at any time by clearing the browser’s site data for this domain:
| Key | Purpose |
|---|---|
ledgr:theme | Records the Customer’s preference for light, dark, or system-matched appearance. |
ledgr:fontSize | Records the Customer’s preferred text size (S/M/L). |
ledgr:fontFamily | Records the Customer’s preferred font (Inter, System, or Serif). |
ledgr:lastSignInEmail | Records the email address last used to sign in on this device, so it need not be re-entered. |
ledgr:healthPeriod | Records whether the dashboard’s Business Health card is displayed on a weekly or monthly basis. |
ledgr:dismissedAnnouncements | Records which service/outage notices this browser has already dismissed, so a read notice does not reappear on every page. |
| Support widget state | Records whether the in-app support button has been minimised. |
| Device identifier | A randomly generated identifier (not derived from device hardware) used to count active devices against the Customer’s plan limit, and to recognise a returning browser for sign-in security alerts. |
4. Security signals not stored in the browser
Separately from browser storage described above, the Supplier computes a coarse device fingerprint and records it server-side, solely for the purpose of detecting repeated free-trial signups originating from the same business, as more fully described in our Privacy Policy. This mechanism does not constitute a cookie, and no data is written to the Customer’s browser in connection with it beyond the random device identifier referred to in clause 3.
5. Third-party services, over which the Supplier has no control
Signing in through a third-party sign-in provider may involve cookies set by that provider as an incident of its own sign-in flow, governed exclusively by that provider’s own privacy and cookie practices, over which the Supplier exercises no control and accepts no responsibility. The Supplier’s payment gateway provider may similarly set its own cookies while the Customer is present on that provider’s hosted payment page during checkout; the Supplier likewise exercises no control over, and accepts no responsibility for, such cookies, and recommends the Customer consult that provider’s own published policies for further detail.
5A. Aggregate product measurement
The Services incorporate Google Analytics 4, operated by Google LLC and its affiliates (the “Measurement Operator”), for the sole purpose of the compilation of aggregate, statistical measures of the manner in which the Services are used, being an activity undertaken in the pursuance of the legitimate interests of the Supplier within the meaning of section 11(1)(f) of the Protection of Personal Information Act 4 of 2013 (“POPIA”), and disclosed in satisfaction of section 18 thereof. The Measurement Operator acts as an operator within the meaning of section 1 of POPIA and is bound by written terms concluded in accordance with section 21 thereof.
(a) Scope of the data processed. The facility is configured such that it receives page-level, device-class, approximate-locality and referral-source data only. It does not receive, and the Supplier does not transmit to it, any identifier of a data subject, any account or workspace identifier, any credential, or any element of the financial records, client information, banking particulars or document content processed by the Customer within the Services, and the Supplier contractually and technically prohibits the enrichment of such data with any of the foregoing.
(b) Trans-border flow. The Customer acknowledges that the processing contemplated in this clause entails a trans-border flow of the limited data described in paragraph (a) to recipients in foreign jurisdictions, and consents to such flow for the purposes of section 72(1) of POPIA, such flow being in any event permitted under section 72(1)(a) thereof by reason of the recipient’s subjection to binding corporate rules and contractual undertakings affording an adequate level of protection substantially similar to the conditions for lawful processing under POPIA.
(c) Election to withhold. A data subject may prevent the processing described in this clause by transmitting a “Do Not Track” or Global Privacy Control signal (clause 7), by installing the Measurement Operator’s own opt-out facility, or by restricting browser storage in the manner described at clause 8. The Supplier records, as an acknowledgement of fact within the meaning of section 49(1)(d) of the CPA, that no function, entitlement or level of service within the Services is conditioned upon, degraded by, or otherwise affected by such an election.
6. No consent banner, and why
The Services do not display a cookie-consent banner. This is not an oversight: every mechanism described in this policy is either strictly necessary for the Services to function (clause 2), or is a functional preference the Customer directly and voluntarily sets by using the Services (clause 3), or is the aggregate, non-identifying measurement described at clause 5A, which is undertaken on the lawful basis of legitimate interest, is subject to the election to withhold recorded at clause 5A(c), and is not a tracking, profiling, or advertising mechanism of the kind cookie-consent regimes are principally directed at. Should the Supplier introduce a cookie or similar mechanism in the future that does require consent under applicable law, this policy will be updated and consent obtained before that mechanism is deployed.
7. “Do Not Track” signals
Some browsers transmit a “Do Not Track” or Global Privacy Control signal. Where such a signal is transmitted, the Services suppress the aggregate product measurement described at clause 5A in its entirety, and no measurement facility is initialised. The strictly necessary and functional storage described at clauses 2 and 3 is unaffected by such a signal, that storage being indispensable to the operation of the Services and to the preferences the Customer has itself elected.
8. Managing or clearing browser storage
The Customer may clear localStorage and cookies associated with htmledgr.com at any time via its browser’s own settings, typically found under a “Privacy”, “Site settings”, or “Clear browsing data” menu, from which htmledgr.com (or all sites) may be selected. Doing so will sign the Customer out, reset appearance preferences to their default values, and cause the browser to be treated as a “new” device upon the next sign-in, with the consequences described in our Privacy Policy. The Supplier does not control, and is not responsible for, the exact menu names or steps in any particular browser, which change from time to time at that browser’s vendor’s discretion.
Your attention is specifically drawn to the following provisions, which limit the liability of the Supplier and of others and place a risk upon the Customer — section 49 of the Consumer Protection Act 68 of 2008
In short, and in plain language: when you sign in with a third-party provider, or when you are on the payment provider’s own checkout page, those companies may set their own cookies. That happens on their systems, under their policies, and we have no control over it and are not responsible for it. Clearing your browser storage will sign you out, reset your appearance settings, and make your browser look new to us. Nothing here takes away a right that South African law does not permit us to take away, and sub-clause (d) says so in terms.
- (a) Acknowledgements of fact. The Customer acknowledges, each of these being an acknowledgement of fact within the meaning of section 49(1)(d) of the Consumer Protection Act 68 of 2008 (the “CPA”), that: (i) the Supplier deploys no third-party advertising, profiling, behavioural-targeting or cross-site tracking mechanism in the Services, and that the aggregate product measurement described at clause 5A is neither directed at, nor capable of, the identification of an individual data subject by the Supplier; (ii) the mechanisms described in clauses 2 and 3 above are, respectively, strictly necessary for the operation of the Services and functional preferences the Customer sets by its own use of them; and (iii) any cookie set by a third-party sign-in provider or upon the payment gateway provider’s own hosted payment page is set by that provider, upon that provider’s systems, and governed exclusively by that provider’s own published policies.
- (b) Limitation of liability. Subject in every respect to sub-clause (d) below, and without derogating from clause 9 of our Terms of Service, which applies of its own force, no Indemnified Person (as that term is defined in sub-clause 9.4 thereof) shall be liable to the Customer or to any Authorized User for any loss arising out of or in connection with: any cookie or similar mechanism set by a third party as described in sub-clause (a)(iii) above; any act, omission, change of policy, or failure on the part of such a third party; or the consequences of the Customer clearing, blocking, or restricting browser storage as described in clause 8 above.
- (c) Assumption of risk as to browser configuration. The Customer assumes the risk of, and is solely responsible for, its own browser, device, and extension configuration, including any consequence of blocking or clearing the storage described in this policy — being, at minimum, that the Customer is signed out, that its appearance preferences revert to their default values, and that the browser is treated as a new device upon the next sign-in, with the consequences described in our Privacy Policy and, where a plan limit upon active devices applies, in clause 5 of our Pricing Policy.
- (d) Savings: rights that cannot lawfully be excluded. Nothing in sub-clauses (a) to (c) above, or anywhere else in this policy, excludes, limits, waives, deprives any person of, or purports to do any of those things in respect of: (i) any right of a data subject under POPIA, including the rights conferred by Chapter 3 thereof and the right to institute a civil action under section 99 thereof; (ii) any right conferred upon the Customer by the CPA, or any obligation or duty imposed upon the Supplier thereby, in a case to which that Act applies, such a provision being prohibited by section 51(1)(b)(i) and (ii) thereof; (iii) any liability of the Supplier, or of any person acting for or controlled by the Supplier, for loss directly or indirectly attributable to gross negligence, such a provision being prohibited by section 51(1)(c)(i) and (ii) of the CPA; (iv) any liability for fraud or wilful misconduct; or (v) any other right, remedy, or protection conferred by South African law which cannot lawfully be excluded, limited, or waived by agreement, including at common law. To the extent that any such provision contravenes section 51 of the CPA, it is void to that extent, and to that extent only, in terms of section 51(3) thereof, and shall be severed, the remainder of this policy continuing in full force and effect.
The Supplier records that the fact, nature, and effect of sub-clauses (a) to (c) above are, by the conspicuous form and manner in which they are here presented, by the plain-language summary with which this panel opens, and by the publication of this policy at a stable public address at which it is continuously accessible, drawn to the attention of the Customer in a manner and form intended to satisfy sections 49(3), 49(4), and 49(5) of the CPA, read with section 22 thereof, in every case to which that Act applies.
9. Changes to this policy
The Supplier reserves the right to vary the storage mechanisms described herein as the Services evolve, and will update this page accordingly. Material changes are flagged in the manner described in clause 13 of our Terms of Service. The “Last updated” date above reflects the version currently in force, which applies to the exclusion of any prior version. As clause 6 above records, where the Supplier introduces a mechanism requiring consent under applicable law, that consent will be obtained before the mechanism is deployed and this policy updated beforehand.
10. Contact us
Questions: email support@htmledgr.com or use our contact page.
Questions about any of this? Reach us here: