What this page is
This page describes exactly what Arms and Legs stores on your device, why, and how to change it.
Our attorneys are reviewing a fuller Cookie Policy. Rather than publish a document that misdescribes what we do, or a page saying the policy is coming, this is an accurate account of our current behaviour, verified against the platform's own code on 6 August 2026. It will be replaced by the reviewed version when that lands, and nothing here will be quietly dropped in the process.
We use the word "cookies" loosely below, as most people do. Where it matters we say precisely which technology is involved, because most of what we store is not actually a cookie.
Cookies and similar technologies
Three different mechanisms store data on your device, and all three are covered by this policy and by your choices:
- Cookies — small files sent back to our servers with each request.
- Local storage — stays on your device until you clear it. Never sent to our servers automatically.
- Session storage — cleared when you close the browser tab. Never sent to our servers automatically.
1. Strictly necessary
These are required for the platform to work. They cannot be switched off, because without them you could not sign in or stay signed in. We do not ask consent for these, and they are never used to profile you.
| What | Type | Purpose | How long |
|---|---|---|---|
sb-<project>-auth-token (sometimes split across .0, .1 … when large) | Cookie | Keeps you signed in. Holds your session token, and is checked every time the platform decides what you are allowed to see | Up to 400 days, refreshed while you stay active. Signing out removes it |
sb-<project>-auth-token-code-verifier | Cookie | A one-time security value that ties a sign-up or password-reset link back to the browser that asked for it, so someone else cannot use your link | Deleted the moment the sign-up or reset completes |
site-access-token | Cookie | Grants access during our pre-launch phase, while the platform is closed to the public. Removed at public launch | 30 days |
cookie_consent | Cookie | Remembers the choices you make below, together with the date you made them and the version of this policy you saw. This is also our record that you were asked | 12 months |
orphan_booking_reported_v1 | Session storage | Set only if the platform detects a fault while displaying your bookings. Records which faults have already been reported so the same one is not sent repeatedly. Contains no information about you | Until you close the tab |
The <project> in the first two names is an identifier for our database. Your browser will show the full name.
A note on how long you stay signed in. The sign-in cookie can last up to 400 days. If you are using a shared or public computer, sign out when you finish rather than only closing the tab.
2. Functional
These remember your preferences. They are only set if you consent to functional storage, and the platform works without them — you will simply be asked or shown defaults more often.
| What | Type | Purpose | How long |
|---|---|---|---|
armsandlegs-ui-theme | Local storage | Remembers whether you chose light or dark mode | Until you clear site data |
armsandlegs_profile_notification_dismissed | Local storage | Remembers that you dismissed the prompt to complete your profile, so it stays hidden for seven days | Until you clear site data |
provider_profile_draft_<your account id> | Local storage | For providers only. Saves your in-progress profile form so a crash or accidental reload does not lose your work | Deleted when you save or cancel the form |
Please read this one if you are a provider. provider_profile_draft_… holds what you have typed into your profile form — business name, contact details, service areas and similar — in ordinary readable form on your own device, until you save or cancel. It is not sent anywhere. But if you share a computer, finish or cancel the form rather than leaving it open.
3. Analytics
We do not use any third-party analytics or advertising product. There is no Google Analytics, no Meta pixel, no Mixpanel, Hotjar, PostHog, Plausible or equivalent anywhere on this platform.
We do use Sentry, an error-monitoring service, and one part of it needs your consent:
| What | Type | Purpose | How long |
|---|---|---|---|
sentryReplaySession | Session storage | Session Replay. Records a reconstruction of your visit — what you clicked, scrolled and navigated to — so we can see what actually happened when something breaks | Until you close the tab |
Session Replay only runs if you consent to analytics. If you decline, it does not start, and if you withdraw consent it stops immediately. This is a change we made on 6 August 2026: before that, the analytics choice did not control it.
When Session Replay does run, all text and everything you type is masked before it leaves your browser, and recording is switched off entirely on sign-in, account, provider application, checkout and booking pages.
Error monitoring itself is not optional and continues regardless of your choice. When something goes wrong we record the fault, the page it happened on and the technical details needed to fix it. This carries no recording of your screen, does not include your IP address or email, and strips identifying details on the sensitive pages listed above. We consider this operationally necessary to run a service people pay money on.
4. Marketing
None. We set no advertising or marketing cookies, we do not track you across other websites, and we do not sell your data. If that ever changes we will update this policy, tell you, and ask before setting anything.
Third parties who receive data
| Who | What they receive | Where |
|---|---|---|
| Sentry | Error reports, and Session Replay recordings if you consented to analytics | Processed in Germany (European Union) |
| Paystack | Your payment details, entered on Paystack's own checkout page | South Africa |
| Supabase | Your account and booking data, as described in our Privacy Notice | — |
About paying. When you pay for a booking, we send you to Paystack's own checkout page to enter your card details — they are never typed into Arms and Legs and never reach our servers. While you are on Paystack's page, Paystack sets its own cookies under its own privacy notice, which we do not control. You return to Arms and Legs once the payment finishes.
Sending error data to Sentry in Germany is a cross-border transfer of personal information. We rely on Sentry's contractual data-protection commitments for this, as described in our Privacy Notice.
Your choices
You can change your mind at any time using the Cookie preferences link in the footer of every page. Changes take effect immediately — you do not need to reload.
Declining functional storage means preferences such as your theme are not remembered. Declining analytics means Session Replay does not run. Neither prevents you using the platform or making a booking.
You can also clear or block storage in your browser's settings. Blocking strictly necessary cookies will stop you being able to sign in.
Do Not Track. There is no agreed industry standard for how sites should respond to browser Do Not Track signals, and we do not currently treat that traffic differently. We may revisit this as standards settle.
Changes to this policy
When this policy changes materially — a new category of storage, or a new third party receiving your data — we bump its version, which re-opens the consent banner so you are asked again rather than carried over on a choice you made about something else.
Contact
Questions about anything on this page can go to our support team. Your rights over your personal information, and how to exercise them, are set out in our Privacy Notice.