Cr8tivehub
Last updated: 14 September 2026

Cookie Policy

This policy explains the cookies and similar technologies we use on cr8tivehub.com, accounts.cr8tivehub.com, and agency.cr8tivehub.com. It also briefly covers the mobile-app equivalents. The full Privacy Policy is at cr8tivehub.com/privacy.

1. What This Policy Covers

This policy explains the cookies and similar technologies we use on:

  • cr8tivehub.com (public website)
  • accounts.cr8tivehub.com (account portal)
  • agency.cr8tivehub.com (agency portal)

2. What Cookies Are

A cookie is a small text file stored on your device when you visit a website. Cookies let a website remember things about your visit — for example, that you are signed in. Some cookies are set by us (first-party), and some by services we use (third-party).

We also use localStorage and sessionStorage, which work similarly but are stored differently on your device. For brevity, we refer to all of these as “cookies” in this policy.

In short: we use only strictly necessary cookies — to keep you signed in and to block bots. We do not use analytics, advertising or tracking cookies on our websites.

3. The Categories We Use

CategoryWhat it doesUsed?
Strictly necessarySign-in and bot protectionYes — cannot be turned off
FunctionalityRemember a display preferenceOne browser-storage item on agency.cr8tivehub.com only
AnalyticsMeasure how the site is usedNo
Marketing / advertisingTrack you for advertisingNo

Because we do not use analytics or marketing cookies, our websites do not show a cookie banner and have no cookie-preferences setting — there is nothing optional to switch on or off.

4. The Specific Cookies We Set

The table below lists everything we set ourselves (first-party), by website. Cookies set by our service providers are listed in section 5.

cr8tivehub.com (the public website) sets no cookies of its own.

NameWebsitePurposeDurationCategory
__sessionaccounts.cr8tivehub.comKeeps you signed in. HttpOnly (cannot be read by page scripts), set by the Firebase Auth session-cookie API.14 daysStrictly necessary
cr8t.dashboard.submissionsRange (localStorage)agency.cr8tivehub.comRemembers the date range you chose for the submissions chart on the agency dashboard.Until clearedFunctionality

5. Third-Party Services That Set Cookies

5.1 Google reCAPTCHA

Where: accounts.cr8tivehub.com and agency.cr8tivehub.com, where reCAPTCHA Enterprise runs through Firebase App Check; and the report and enquiry forms on cr8tivehub.com.

Cookies set: Google may set its reCAPTCHA cookies, such as _GRECAPTCHA. These are set by Google, not by us.

Purpose: Detects automated abuse and bot traffic on sign-in, our APIs and form submission. Strictly necessary for security.

Duration: Up to 6 months.

Privacy policy: policies.google.com/privacy

5.2 Google Firebase (browser storage, not cookies)

Where: accounts.cr8tivehub.com and agency.cr8tivehub.com.

Storage set:The Firebase SDK keeps your sign-in state and App Check token in your browser's indexedDB.

Purpose: Authentication and bot protection. Strictly necessary.

Duration: Until you sign out or clear your browser storage.

5.3 PayFast (only on checkout redirect)

PayFast may set its own cookies on its own domain when you are taken through the payment flow. We do not control or have access to those cookies. See payfast.co.za/legal/privacy-policy.

5.4 Didit (only on the identity-verification redirect)

Where:Didit's own hosted verification page. Starting identity verification in the Cr8tivehub app, or business verification in the agency portal, opens that page — in an in-app browser tab on mobile, or a redirect on the web.

Cookies set: Didit may set its own cookies and storage on its own domain while you are on that page, including what it needs to keep your verification session alive and to detect fraud and automated abuse. They are set by Didit, not by us, and we cannot read them.

Purpose: Running and securing the identity check you agreed to. You are told before you are taken there, and the check is optional.

Privacy policy: didit.me/terms/privacy-policy

We do not use analytics tools, Google Ads, Meta Pixel, TikTok Pixel, or any other advertising-network pixel on our websites. If we ever add one, we will update this policy and ask for your consent before it is used.

6. Mobile App Equivalents

The Cr8tivehub mobile app does not use HTTP cookies, but it uses similar technologies:

  • Firebase Instance ID — a unique identifier for your app install, used for push notifications.
  • Advertising ID (AAID on Android) — used only if you opt in, for Mobile Ads.
  • Crashlytics installation ID — used to group crash reports together.
  • App-local storage — settings and cache stored on your device by the app.

You can reset your Android advertising ID, opt out of personalised ads in your device settings, and revoke notification permissions from your device's app settings.

7. How to Control Cookies

Because every cookie we use is strictly necessary, there is no cookie banner or preferences setting on our websites. You can still block or delete cookies and browser storage through your browser's settings. Doing so may stop sign-in and form submission from working, because they rely on the strictly necessary cookies and storage described above.

8. Do Not Track and Global Privacy Control

We do not use analytics, advertising or tracking cookies on our websites, so a Do Not Track (DNT) or Global Privacy Control (GPC) signal from your browser does not change the cookies we set — we set only the strictly necessary ones either way.

9. Changes to This Policy

We may update this policy when we add or remove technologies, or to keep up with law. The “Last updated” date above will reflect any change. If we ever add a cookie that is not strictly necessary — such as analytics — we will ask for your consent before setting it.

10. Contact