Cutz Legal
Cookie & Local Storage Policy
The short version
Cutz does not use advertising cookies, tracking pixels, or third-party analytics. There is no Google Analytics, no Meta Pixel, no advertising identifier, and nothing that follows you to other websites.
What we do use is a handful of strictly necessary items: a cookie that keeps you signed in, a cookie that protects you from a specific kind of attack, and some browser storage that remembers your settings and lets the app work when your connection drops.
That is why you will not see a cookie banner on Cutz. Under the Nigeria Data Protection Act 2023 we do not need consent for storage that is strictly necessary to deliver a service you asked for — but you should still know it is there, which is what this page is for.
This policy forms part of the Privacy Policy.
1. What these technologies are
Cookies are small text files a website stores in your browser and sends back with each request.
Local storage and session storage are browser stores a web app can read and write. They are not sent to the server automatically.
A service worker cache is a store the browser keeps so a web app can load and show data when you are offline or on a poor connection.
Secure storage on a native app is the device keychain (iOS) or keystore (Android), used to hold a sign-in token safely.
We refer to all of these together as "storage" in this policy.
2. What we use, and why
2.1 Strictly necessary cookies
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
cutz-session | Cutz | Keeps you signed in on the web apps. Without it you would be signed out on every page load. | Until the session expires or you sign out |
XSRF-TOKEN | Cutz | Protects against cross-site request forgery — stops another site from making requests as you. | Session |
These are essential. If you block them, you cannot sign in or perform any action that changes data.
2.2 Browser storage
| What we store | Purpose | Lifetime |
|---|---|---|
| Appearance preference (Light / Dark / Same as device) | Remembers how you like the app to look | Until you clear it |
| Sign-in token (in the browser's secure store, on installed apps) | Keeps you signed in without re-entering a code | Until sign-out or expiry |
| The sign-in method you last used | Offers you a one-tap "Continue with…" shortcut. Stored in the browser's encrypted store, not plain storage, so a hint of your phone number or email is not casually readable. | Until sign-out |
| Install prompt state | Stops us re-asking you to install the app after you have dismissed or installed it | Until you clear it |
| Notification prompt state | Stops us re-asking for notification permission too often | Until you clear it |
| A referral code from a link you followed | Applies the code when you create your account | Until used or cleared |
| Cached queue, salon, and profile data | Lets the app show your last known queue position when your connection drops | Refreshed on reconnect; cleared on sign-out |
2.3 Service worker cache
Our progressive web apps register a service worker that caches the app shell and recent data so the app opens fast and keeps working offline. The cache is stored on your device, not on our servers, and is cleared when you uninstall the app or clear site data.
Cached queue data can be out of date. Always let the app refresh before relying on a position or wait time.
2.4 What we do not use
- Advertising or retargeting cookies
- Third-party analytics or product-telemetry SDKs
- Social media tracking pixels
- Cross-site or cross-device tracking
- Fingerprinting for advertising purposes
- Advertising identifiers (IDFA, GAID)
If this ever changes we will update this policy first, and where the law requires consent we will ask for it before setting anything.
3. Third-party requests
Even though we do not set third-party cookies, some pages make requests to third parties. Those parties can see your IP address and basic request information as a result.
| Third party | Where | What happens | Their policy |
|---|---|---|---|
| Cutz-hosted fonts | cutz.ng website | Fonts are served from Cutz's own static hosting. No third-party font request is made. | — |
| Cloudflare | Websites, CDN, DNS, and stored media | Serves our content and media. May set a cookie strictly necessary for security and bot mitigation. | cloudflare.com/privacypolicy |
| Google Cloud | API and database (server-side) | Does not set cookies in your browser; processes account and queue data on our servers. | cloud.google.com/terms/cloud-privacy-notice |
| Google Maps Platform | Address search in the Cutz Salon app | Address lookups are sent from our servers, not your browser, so Google does not see your IP address for this. | policies.google.com/privacy |
| Paystack | Subscription checkout | If you pay, you interact with Paystack's checkout, which sets its own cookies under its own policy. | paystack.com/terms |
| Google Sign-In | Sign-in screen, where offered | If you choose to sign in with Google, Google's own cookies and policy apply to that interaction. | policies.google.com/privacy |
| Zoho | Transactional email | Email delivery; no browser cookie on cutz.ng from Zoho for ordinary browsing. | zoho.com/privacy |
We are working towards self-hosting our fonts so that no request leaves for a third party on a simple page view.
4. How to control storage
4.1 Browser settings. Every major browser lets you view, block, and delete cookies and site data. Look under Settings → Privacy. Blocking our strictly necessary cookies will prevent you from signing in.
4.2 Clearing site data signs you out, clears your appearance preference, resets prompt states, and empties the offline cache. Your account and data on our servers are unaffected.
4.3 Uninstalling the app (progressive web app or native) removes its local storage and cache from your device.
4.4 Notifications are controlled separately, in your browser or device settings. Turning them off removes your push subscription; see the Privacy Policy.
4.5 Location is also a device permission, not a cookie. Revoke it in browser or device settings at any time.
4.6 Do Not Track. Browsers can send a "Do Not Track" signal. There is no agreed standard for responding to it, and we do not track you across sites in any case, so we take no action on it.
5. Changes to this policy
We will update this policy if we add or remove any storage described here. The current version is always at cutz.ng/legal/cookies.
6. Contact
Questions about this policy: hello@cutz.ng
Cutz Cookie & Local Storage Policy · Version 1.0 · Drafted 31 July 2026 · Effective 2 August 2026
