Cookie Policy
Dime Legacy Partners · RC. 1927994
Applies to: dimelegacy.com, herohr.dimelegacy.com, partners.dimelegacy.com, careers.dimelegacy.com, admin.dimelegacy.com.
Effective date: 26 August 2026
This document is an initial legal framework generated from a technical audit of the DLP platform's cookie and storage usage as it exists at the time of the audit. It must be reviewed by qualified legal counsel, and re-audited whenever a new tracking, analytics, or advertising tool is added to the platform, before publication or reliance.
1. What this Policy covers
This Policy explains the cookies and similar technologies (such as browser local storage) used across the DLP platform, and why.
2. Audit finding: no advertising or analytics cookies in use
As at the date of this audit, the platform does not load any third-party advertising, analytics, or behavioural tracking script (no analytics tag, no advertising pixel, no session-replay or heatmap tool was found in any app's codebase). The cookies in use are strictly necessary ones, described below.
If this changes (for example, if a web analytics or advertising tool is added), a cookie consent banner offering accept/reject choices for non-essential cookies will become a legal requirement in most of DLP's operating jurisdictions, and this Policy, along with the relevant technical implementation, must be updated before that tool goes live. This finding should be re-checked at every platform audit.
3. Cookies we use
Cookie | Purpose | Type | Duration |
|---|---|---|---|
Refresh token (client, partner, and admin sessions) | Keeps you signed in without repeatedly re-entering your password | Strictly necessary | Up to 7 days (client and partner), shorter for admin sessions |
Supabase session cookies | Support authentication and, where used, real-time updates (for example, live pipeline status) | Strictly necessary | Session-based |
These cookies are set as httpOnly, Secure, and SameSite=Strict (or an equivalent restrictive setting), meaning they cannot be read by JavaScript running on the page and are not sent to any other website. They exist solely to let the platform recognise you as signed in and to protect your session; we do not use them to track you across other websites, build an advertising profile, or share data with advertisers.
4. Local browser storage
The access token used during an active session is held in your browser's memory (React application state) for the duration of your visit, not in local storage or session storage, and is cleared when you close the tab or sign out.
5. Your choices
Because the platform currently uses only strictly necessary cookies, a consent banner is not a legal requirement under the Nigeria Data Protection Act 2023 (NDPA), the Ghana Data Protection Act 2012, or the Kenya Data Protection Act 2019, all of which exempt strictly necessary cookies from prior opt-in consent. We show a brief notice on your first visit regardless, as a transparency courtesy linking to this Policy. Dismissing it does not change what cookies are set, since only strictly necessary ones are ever used; it simply acknowledges you have seen the notice. You can still control or delete cookies through your browser settings at any time; doing so may sign you out of the platform or prevent you from staying signed in.
6. Changes to this Policy
We will update this Policy, and put a consent mechanism in place, before introducing any cookie or similar technology that is not strictly necessary to operate the platform.
7. Contact
Dime Legacy Partners Email: partners@dimelegacy.com
8. Governing law
This Policy is governed by the laws of the Federal Republic of Nigeria, without prejudice to any mandatory right available to you under the law of Ghana or Kenya where the platform is used from those jurisdictions.