Cr8tivehub
Last updated: 21 May 2026

Cookie Policy

This policy explains the cookies and similar technologies we use on cr8tivehub.com, accounts.cr8tivehub.com, and agency.cr8tivehub.com. It also briefly covers the mobile-app equivalents. The full Privacy Policy is at cr8tivehub.com/privacy.

1. What This Policy Covers

This policy explains the cookies and similar technologies we use on:

  • cr8tivehub.com (public website)
  • accounts.cr8tivehub.com (account portal)
  • agency.cr8tivehub.com (agency portal)

2. What Cookies Are

A cookie is a small text file stored on your device when you visit a website. Cookies let a website remember things about your visit — for example, that you are signed in. Some cookies are set by us (first-party), and some by services we use (third-party).

We also use localStorage and sessionStorage, which work similarly but are stored differently on your device. For brevity, we refer to all of these as “cookies” in this policy.

3. The Four Categories We Use

CategoryWhat it doesDefaultCan you turn it off?
Strictly necessarySign-in, security, fraud preventionOnNo
FunctionalityRemember preferences such as themeOnYes
AnalyticsHelp us understand usage so we can improveOff — opt inYes
Marketing & personalisationTailor recommendations and (if applicable) adsOff — opt inYes

You set your choices in the cookie banner that appears on your first visit, and you can change them at any time in Cookie preferences (in the website footer) or Settings → Privacy once you are signed in.

4. The Specific Cookies We Set

The table below lists each cookie we set ourselves (first-party). Third-party cookies set by our service providers are listed in section 5.

NamePurposeDurationCategory
__sessionKeeps you signed in. HTTP-only, set by the Firebase Auth session-cookie API.14 daysStrictly necessary
c8h_consent_v1Stores your cookie-preference choices. The version number changes when we update the categories.12 monthsStrictly necessary
c8h_csrfCSRF token used by API routes to prevent cross-site request forgery.SessionStrictly necessary
c8h_theme (localStorage)Remembers light/dark theme preference.Until clearedFunctionality
c8h_last_section (localStorage)Remembers the last settings section you visited.Until clearedFunctionality

5. Third-Party Services That Set Cookies

5.1 Google reCAPTCHA Enterprise

Cookies set: _GRECAPTCHA, plus internal Google bot-protection identifiers.

Purpose: Detects automated abuse and bot traffic on login and form submission. Strictly necessary for security.

Duration: Up to 6 months.

Privacy policy: policies.google.com/privacy

5.2 Google Firebase

Cookies / storage set: Firebase Auth identifier persistence in indexedDB, plus a small number of internal Firebase technical cookies.

Purpose: Authentication and platform operation.

Duration: Until you sign out or clear your browser storage.

5.3 Firebase Analytics (only set if you opt in to Analytics)

Cookies set: _ga, _ga_<container>.

Purpose: Aggregate usage measurement.

Duration: Up to 24 months.

5.4 Cloudflare (if used at the CDN layer)

Cookies set: __cf_bm, cf_clearance.

Purpose: Bot management and security challenge state.

Duration: Up to 30 minutes (__cf_bm), up to 1 year (cf_clearance).

5.5 PayFast (only on checkout redirect)

PayFast may set its own cookies on its own domain when you are taken through the payment flow. We do not control or have access to those cookies. See payfast.co.za/legal/privacy-policy.

We do not currently use Google Ads, Meta Pixel, TikTok Pixel, or any other advertising-network pixel. If we add one in the future, this policy will be updated and your consent will be re-prompted.

6. Mobile App Equivalents

The Cr8tivehub mobile app does not use HTTP cookies, but it uses similar technologies:

  • Firebase Instance ID — a unique identifier for your app install, used for push notifications.
  • Advertising ID (AAID on Android) — used only if you opt in, for Mobile Ads.
  • Crashlytics installation ID — used to group crash reports together.
  • App-local storage — settings and cache stored on your device by the app.

You can reset your Android advertising ID, opt out of personalised ads in your device settings, and revoke notification permissions from your device's app settings.

7. How to Change Your Choices

  • In the cookie banner when you first visit.
  • Via the Cookie preferences link in the footer of every page.
  • In Settings → Privacy when you are signed in.
  • In your browser — you can also block or delete cookies through your browser's settings. Doing so may break parts of the site that rely on strictly necessary cookies.

Withdrawing consent does not affect anything we did before you withdrew it.

8. Do Not Track and Global Privacy Control

If your browser sends a Do Not Track (DNT) signal or a Global Privacy Control (GPC) signal, we treat that as an opt-out of analytics and marketing categories by default. You can still override this in your cookie preferences if you want to opt in.

9. Changes to This Policy

We may update this policy when we add or remove technologies, or to keep up with law. The “Last updated” date above will reflect any change. Material changes — such as adding a new category of tracking — will trigger a new banner prompt.

10. Contact