Legal Center

Dafluma legal

Controlled draft

Cookie Policy

How browser cookies and local storage support sign-in, security, preferences, and attribution.

Version
1.0
Effective
2026-08-06
Applies to
Website and application visitors

Controlled draft

This document is versioned but is not a current published policy. Refer to its publication status in the Legal Center.

Essential technologies

Dafluma uses realm-specific session and CSRF cookies to authenticate requests and protect against cross-site request forgery. These are necessary for the service to operate and should be Secure and HttpOnly where applicable. The CSRF token must remain readable by the browser client so it can be returned in protected requests.

Preferences and continuity

We may store limited preferences and short-lived attribution data so a referral or campaign can survive a normal sign-in or checkout journey. These values must not contain passwords, payment PINs, or production secrets.

Optional analytics and advertising

Optional analytics, advertising, or personalization technologies should be activated only when configured, disclosed, and supported by the consent or other lawful basis required for the user and jurisdiction. The absence of an integration means no such provider cookie should be claimed or presented as active.

Your controls

You can control cookies through browser settings. Blocking essential session or CSRF cookies may prevent login, checkout, uploads, or other protected actions from working. Consent choices should be available before non-essential cookies are enabled.

Operator: IWEBZ KENYA LTD

Platform: Dafluma

Contact: legal@dafluma.com

Address: Westlands, Nairobi, Kenya