Legal

Cookies & Local Storage

We keep you signed in using your browser's local storage rather than tracking cookies, and we run no advertising trackers. Here is exactly what is stored and why.

Last updated 5 August 2026

1. The short version

verified_user

No advertising or tracking cookies

The OhShip platform does not set advertising cookies, does not run third-party ad networks, and does not sell or share browsing data for advertising. The storage we use is strictly necessary to keep you signed in and to make the application work.

Because that storage is strictly necessary for a service you have asked for, we do not present a consent banner for it. If we later add optional analytics or marketing storage, we will ask for consent first and update this page.

2. What we store in your browser

We use the browser's local storage and session storage rather than cookies. Local storage persists until you sign out or clear it; session storage is discarded when you close the tab.

ItemPurposeTypeLifetime
Access tokenKeeps you signed in and authorises requests to our API.Strictly necessaryUntil sign-out, token expiry, or you clear storage
Refresh tokenObtains a new access token so you are not signed out mid-session.Strictly necessaryUntil sign-out or you clear storage
User profileCaches your name, role and permissions so the interface renders correctly without an extra request.Strictly necessaryUntil sign-out or you clear storage
Tenant identifierRecords which branded workspace you are signed in to, so data and theming resolve to the right provider.Strictly necessaryUntil sign-out or you clear storage
Preview overridesUsed during setup and preview to render a specific brand configuration.FunctionalSession only — cleared when the tab closes

Our servers also write ordinary request logs containing your IP address, browser type and the pages or endpoints accessed. That is covered in our Privacy Policy.

3. Third-party requests

Some pages load resources from, or hand you over to, third parties. Those parties may set their own cookies under their own policies.

  • Payment provider — when you pay, you are handed to a CBN-licensed payment provider's secure checkout, which sets cookies necessary for the transaction and fraud prevention. Card details are entered there; full card numbers and CVVs never reach our systems.
  • Google Fonts — our pages load typefaces from Google's font servers, which receive the request and your IP address as part of serving the file.
  • Notification service — the in-app notification inbox connects to our notification provider to fetch and stream your messages.
  • Error monitoring — when something breaks, diagnostic information about the error is sent to our monitoring provider so we can fix it.

These providers are listed with their purposes and locations in our Privacy Policy.

4. How to control it

  • Sign out — this clears the tokens and cached profile from your browser.
  • Clear site data — every major browser lets you clear cookies and site storage for a specific site, usually under Privacy and Security settings.
  • Block storage — you may block cookies and site storage entirely, but the platform will not be able to keep you signed in and will largely stop working.

5. Changes

If we introduce new storage, particularly anything analytical or non-essential, we will update this page and, where consent is required, ask for it before setting it.

6. Contact

Questions about this policy can be sent to support@ohship.africa.