Trading Securely 24 Hours a Day
028 123 4567

Cookies Policy

Legal & Policy

Cookies Policy | LIST SECURE

Cookies Policy

Document: Cookies Policy | Version: 2.0 | Effective date: [INSERT: effective date] | Owner: LIST SECURE (PTY) LTD


Contents


1. Introduction

1.1 This Cookies Policy explains how LIST SECURE (PTY) LTD ("List Secure", "we", "us", "our") uses cookies and similar technologies on the Platform, why we use them, which of them need your consent, and how you can control them.

1.2 Our details are:

Legal nameLIST SECURE (PTY) LTD
Registration number[INSERT: company registration number]
Registered and physical address16 Pelican Way, Zeekoevlei, Western Cape, 7942, South Africa
Websitehttps://listsecure.co.za
Support emailsupport@listsecure.co.za
Privacy / Information Officer emaildata@listsecure.co.za
Information Officer[INSERT: full name of the Information Officer]
Telephone[CONFIRM: +27 28 123 4567]

1.3 This Cookies Policy forms part of the Platform Terms. Read it with the Privacy Policy, which explains everything else we do with your Personal Information, and with the Terms & Conditions.

1.4 This Policy takes effect on [INSERT: effective date] and replaces the cookie section that appeared in the Privacy Policy dated 15 December 2025.


2. Definitions

In this Policy:

2.1 "Platform" means the List Secure website at listsecure.co.za, its subdomains, mobile applications and related services.

2.2 "User" means any person who accesses or uses the Platform.

2.3 "Buyer" means a User who purchases or offers to purchase an Item through the Platform.

2.4 "Vendor" means a User approved by List Secure to list Items for sale on the Platform.

2.5 "Item" means any product or goods listed for sale on the Platform.

2.6 "Listing" means a Vendor's offer of an Item, including all text, images and specifications.

2.7 "Order" means a Buyer's accepted offer to purchase an Item.

2.8 "Escrow Provider" means TradeSafe, or such other escrow provider as List Secure may appoint.

2.9 "Payment Provider" means PayFast, or such other payment service provider as we may appoint.

2.10 "Personal Information" has the meaning given to it in POPIA.

2.11 "Content" means any material a User uploads, posts or transmits through the Platform.

2.12 "POPIA" means the Protection of Personal Information Act 4 of 2013 and its Regulations.

2.13 "Consent Banner" means the cookie consent tool that appears when you first visit the Platform, and the preference centre it links to.



4. What cookies and similar technologies are

4.1 Cookies. A cookie is a small text file that a website asks your browser to store on your device. When you come back, the browser sends the cookie back, so the site can recognise your browser and remember things — that you are logged in, what is in your cart, what language you chose.

4.1.1 A first-party cookie is set by the site you are visiting — here, listsecure.co.za.

4.1.2 A third-party cookie is set by a different organisation whose content or service is loaded into the page — for example an analytics provider or an embedded map.

4.1.3 A session cookie is deleted when you close your browser.

4.1.4 A persistent cookie stays on your device until it expires or you delete it.

4.2 Pixels, web beacons and tags. A tiny, usually invisible image or piece of code loaded into a page or an email. It tells the sender that the page or email was opened, and can read or set cookies.

4.3 Local storage and session storage. Storage inside your browser that a website can write to. It works like a cookie but is not sent with every request and can hold more data. We use it for things like keeping your cart and interface preferences.

4.4 Software development kits (SDKs). Code built into a mobile application that can store identifiers on the device and report usage back. [CONFIRM: whether a List Secure mobile application exists or is planned, and which SDKs it embeds — if there is no application, delete this clause]

4.5 Server logs. Our servers automatically record technical information about each request: IP address, date and time, the page requested, the referring page, browser and operating system, and the response. Server logs are not cookies and are not set on your device, but they do involve Personal Information, so we describe them in the Privacy Policy and account for them here.

4.6 Device and browser fingerprinting signals. Some fraud-prevention and security tools combine technical attributes of a browser or device to recognise it without storing anything. Where we or a security provider do this, we treat it in the same way as a cookie and, unless it is strictly necessary for security, we ask for consent. [CONFIRM: whether any fingerprinting-based fraud or bot-detection tool is in use, and which]

4.7 In this Policy, "cookies" means all of the technologies in clauses 4.1 to 4.4 unless we say otherwise.



6. The cookies we use

6.1 The table below is organised by category. It is subject to the audit required by clause 3. Where a cookie name, duration or party is not yet confirmed, the entry is marked for insertion. We have not invented cookie names or durations.

6.2 "Consent required?" means: do we set this cookie only after you have consented through the Consent Banner?

6.3 Strictly Necessary

Purpose. To let you log in and stay logged in, to keep your shopping cart and session, to route your request to the right server, to remember your cookie choices, to protect forms against cross-site request forgery, and to complete checkout, payment and escrow. Without these the Platform does not work.

Cookie / technologySet byPurposeFirst or third partyDurationConsent required?
wordpress_[hash]WordPress (Automattic)Authenticates a logged-in User during the sessionFirst party[INSERT: duration — confirm by cookie scan]No
wordpress_logged_in_[hash]WordPress (Automattic)Indicates that a User is logged in, and who they areFirst party[INSERT: duration — confirm by cookie scan]No
wordpress_sec_[hash]WordPress (Automattic)Secures access to the administration and account areasFirst party[INSERT: duration — confirm by cookie scan]No
wp-settings-[user id] and wp-settings-time-[user id]WordPress (Automattic)Remembers interface preferences in the account areaFirst party[INSERT: duration — confirm by cookie scan]No
wp_woocommerce_session_[hash]WooCommerceLinks your browser to your cart and session data on our serverFirst party[INSERT: duration — confirm by cookie scan]No
woocommerce_cart_hashWooCommerceTells the site when the cart contents have changedFirst party[INSERT: duration — confirm by cookie scan]No
woocommerce_items_in_cartWooCommerceTells the site whether the cart has anything in itFirst party[INSERT: duration — confirm by cookie scan]No
[INSERT: MultiVendorX cookie names — confirm by cookie scan]MultiVendorXVendor store selection, multi-vendor cart splitting, Vendor dashboard stateFirst party[INSERT: duration — confirm by cookie scan]No, where strictly necessary — [CONFIRM: whether any MultiVendorX cookie is analytics or preference related, in which case it moves to a consent category]
[INSERT: PayFast transaction/session cookie names — confirm by cookie scan and with PayFast]PayFastCarries the payment session between the Platform and the payment page, and prevents duplicate or replayed paymentsThird party[INSERT: duration — confirm with PayFast]No — necessary to complete a payment you have requested
[INSERT: TradeSafe transaction/session cookie names — confirm by cookie scan and with TradeSafe]TradeSafeCarries the escrow transaction session and links the Order to the Escrow AccountThird party[INSERT: duration — confirm with TradeSafe]No — necessary to complete an escrow transaction you have requested
[INSERT: consent tool cookie name — confirm by cookie scan][INSERT: name of the cookie consent tool or plugin in use]Records your cookie choices so we do not ask again on every pageFirst party[INSERT: duration — a period of 6 to 12 months is common practice; confirm]No — we must store your choice in order to honour it
Local storage and session storage keysList SecureCart contents, interface state, draft Listing data, form recoveryFirst partyUntil cleared by you or by the browserNo, where strictly necessary — [CONFIRM: the full list of storage keys, by cookie scan]

6.4 Security and Fraud Prevention

Purpose. To protect the Platform, your account and other Users against unauthorised access, credential stuffing, bots, scraping, denial-of-service attacks, payment fraud and account takeover. This supports the fraud and risk controls described in the Privacy Policy.

Cookie / technologySet byPurposeFirst or third partyDurationConsent required?
__cf_bmCloudflareDistinguishes human visitors from bots, to protect the siteThird party[INSERT: duration — confirm by cookie scan]No, where used only for bot management — [CONFIRM: whether Cloudflare or another WAF/CDN is in front of the Platform; if not, delete this row]
cf_clearanceCloudflareRecords that a challenge has been passed, so you are not challenged repeatedlyThird party[INSERT: duration — confirm by cookie scan]No — [CONFIRM: as above]
[INSERT: security plugin cookie names — confirm by cookie scan][INSERT: name of the WordPress security or firewall plugin in use, if any]Login protection, brute-force detection, IP reputationFirst party[INSERT: duration — confirm by cookie scan]No
Anti-CSRF tokens and noncesList Secure / WordPressPrevents a third-party site from submitting a form or action as youFirst partySessionNo
Fraud and risk signals collected in-sessionList SecureDevice and behaviour signals used in the risk scoring described in the Privacy PolicyFirst party[INSERT: retention period for in-session risk signals]No, where strictly necessary for security — [CONFIRM: whether any third-party fraud or fingerprinting service is used; if it is, consent is likely to be required and it must be listed here]

6.5 Performance and Analytics

Purpose. To understand how the Platform is used — which pages and Listings are visited, how people move through search and checkout, where errors and drop-offs occur — so that we can fix problems and improve the service. We use this at an aggregated level. We do not use analytics to make decisions about you as an individual.

These cookies are set only after you consent.

Cookie / technologySet byPurposeFirst or third partyDurationConsent required?
_gaGoogle AnalyticsDistinguishes one browser from another so that visits can be countedThird party2 years [CONFIRM by cookie scan — Google may change this]Yes
_ga_[INSERT: GA4 measurement/container ID suffix]Google Analytics (GA4)Keeps session state for GA4Third party2 years [CONFIRM by cookie scan]Yes
_gidGoogle AnalyticsDistinguishes one browser from another; used for short-term reportingThird party24 hours [CONFIRM by cookie scan]Yes
_gat or _gat_gtag_[INSERT: property ID]Google AnalyticsLimits the rate at which requests are sent to GoogleThird party1 minute [CONFIRM by cookie scan]Yes
[INSERT: any other analytics or heatmap cookie names — confirm by cookie scan][INSERT: name of any other analytics, session-recording or heatmap tool in use, if any][INSERT: purpose][INSERT: first or third party][INSERT: duration]Yes

Google Analytics settings. [CONFIRM: whether IP anonymisation / IP truncation is enabled, whether Google Signals is enabled, whether data sharing with Google is switched off, and what the data retention setting is — these settings materially affect the POPIA and GDPR analysis and must be recorded here]

6.6 Functional

Purpose. To remember choices you make so that the Platform behaves the way you expect — your saved preferences, recently viewed Items, saved searches, chat and support widgets, and embedded content such as maps and videos.

These cookies are set only after you consent, except where the feature is one you have specifically asked for in that moment.

Cookie / technologySet byPurposeFirst or third partyDurationConsent required?
[INSERT: preference cookie names — confirm by cookie scan]List SecureRemembers display, currency, sort order and similar preferencesFirst party[INSERT: duration]Yes
[INSERT: cookie names set by Elementor — confirm by cookie scan]ElementorPage-builder features, pop-up and form behaviour, view countsFirst party, and third party [CONFIRM][INSERT: duration]Yes, unless the scan shows the cookie is strictly necessary to render a page [CONFIRM]
[INSERT: cookie names set by Google Business Profile / Google Maps embeds — confirm by cookie scan]GoogleRenders our business listing, reviews and any embedded mapThird party[INSERT: duration]Yes — the embed is blocked until you consent
[INSERT: cookie names set by any embedded video player — confirm by cookie scan][INSERT: video platform, if any]Plays embedded video and remembers playback preferencesThird party[INSERT: duration]Yes
[INSERT: chat or support widget cookie names — confirm by cookie scan][INSERT: name of the chat or helpdesk widget in use, if any]Keeps a support conversation open across pagesThird party[INSERT: duration]Yes

6.7 Targeting and Advertising

Purpose. To measure the performance of our marketing, to show you our advertisements on other websites, and to avoid showing you the same advertisement repeatedly.

These cookies are set only after you consent.

Cookie / technologySet byPurposeFirst or third partyDurationConsent required?
[INSERT: advertising and remarketing cookie or pixel names — confirm by cookie scan][INSERT: name of each advertising platform in use, for example a Google Ads or Meta pixel — if none is in use, state that plainly and delete this table]Conversion measurement, audience building, remarketingThird party[INSERT: duration]Yes
[INSERT: email marketing tracking pixel — confirm with the email platform][INSERT: email/marketing platform]Records whether a marketing email was opened and which links were clickedThird partyNot stored on your device; recorded by the sending platformYes, and only where you have consented to marketing under the Privacy Policy

6.7.1 [CONFIRM: whether any advertising, remarketing or social media pixel is currently installed on listsecure.co.za. If none is installed, this clause 6.7 must say so plainly rather than describing advertising cookies that do not exist.]

6.7.2 We do not sell your Personal Information, and we do not allow an advertising partner to use data collected on the Platform to build a profile of you for its own unrelated purposes.



8. How to control cookies in your browser

8.1 Your browser also lets you block or delete cookies. Browser menus change, so treat the paths below as a guide.

8.2 Google Chrome. Settings > Privacy and security > Third-party cookies (and > Delete browsing data to remove cookies already stored). Chrome also has a per-site control in Settings > Privacy and security > Site settings.

8.3 Apple Safari.

8.3.1 On macOS: Safari > Settings (or Preferences) > Privacy — "Prevent cross-site tracking" and "Manage Website Data".

8.3.2 On iOS and iPadOS: Settings > Apps > Safari > Privacy & Security — "Block All Cookies", and "Clear History and Website Data".

8.4 Mozilla Firefox. Settings > Privacy & Security > Enhanced Tracking Protection, and > Cookies and Site Data to clear or manage stored cookies.

8.5 Microsoft Edge. Settings > Cookies and site permissions > Manage and delete cookies and site data, and Settings > Privacy, search, and services > Tracking prevention.

8.6 Google Analytics opt-out. You can install Google's browser add-on, which stops Google Analytics collecting data about your visit across all websites, at https://tools.google.com/dlpage/gaoptout. The add-on is not available on every browser or mobile platform.

8.7 Mobile devices. On Android and iOS you can reset or limit the advertising identifier in the device's privacy settings.

8.8 A warning about "block all cookies". Setting your browser to block all cookies will block the strictly necessary cookies too. See clause 9.


9. What happens if you refuse cookies

9.1 Refusing non-essential cookies is fine. If you reject analytics, functional and advertising cookies, you can still browse the Platform, view Listings, register, buy and sell. You will lose some conveniences: preferences may not be remembered, embedded maps and videos may not load until you allow them, and our reporting on how the site is used will be less accurate.

9.2 Blocking strictly necessary cookies breaks the Platform. If you block all cookies in your browser, or block first-party cookies for listsecure.co.za, then:

9.2.1 you will not be able to log in, or you will be logged out on every page;

9.2.2 your cart will empty between pages;

9.2.3 checkout will fail — the payment session with the Payment Provider cannot be maintained;

9.2.4 the escrow flow will fail — the transaction session with the Escrow Provider cannot be maintained, which means funds cannot be placed into or released from the Escrow Account through the Platform;

9.2.5 Vendor dashboard functions, including Listing management and Order fulfilment, will not work;

9.2.6 security protections such as anti-forgery tokens will fail, and forms will be rejected; and

9.2.7 the Consent Banner will reappear on every page, because we cannot store your choice.

9.3 We cannot provide the Platform without the strictly necessary cookies. If you are not willing to accept them, please do not transact on the Platform.

9.4 Refusing non-essential cookies has no effect on your rights, your prices, the service you receive, or how a Dispute is decided. We do not penalise you for saying no.


10. Do Not Track and Global Privacy Control

10.1 Do Not Track (DNT). Some browsers can send a "Do Not Track" signal. There is no agreed standard for what a website must do with it, and it is now deprecated in most browsers. We do not currently change our behaviour in response to a DNT signal, and we say so plainly rather than claiming a compliance we do not deliver. Use the Consent Banner instead — it works.

10.2 Global Privacy Control (GPC). GPC is a signal that a browser or extension can send to tell a website that you are exercising your privacy rights, including an objection to the sale or sharing of your personal information.

10.2.1 We do not sell or share your Personal Information for cross-context behavioural advertising, so the core of the GPC signal is already satisfied.

10.2.2 [CONFIRM: whether the consent management platform in use detects a GPC signal and automatically applies a "reject non-essential" preference. If it does, say so here. If it does not, this clause must say so honestly, and the business should consider enabling it.]

10.3 Section 11(3) objection. Separately from any browser signal, you may object at any time to our processing of your Personal Information on the grounds in section 11(3) of POPIA, using Form 1 of the POPIA Regulations. The Privacy Policy explains how.


11. Cookies and your rights

11.1 Cookie data that identifies you is Personal Information. All of the rights in the Privacy Policy apply to it — the right to be told what we hold, to ask for a copy, to ask for correction or deletion, to object, and to complain.

11.2 To exercise a right, write to the Information Officer at data@listsecure.co.za. Objections and correction or deletion requests are free of charge, and we accept them by email, SMS or WhatsApp as well as in writing. We respond within 30 days.

11.3 You may complain to the Information Regulator at any time:

Physical addressJD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Postal addressPO Box 31533, Braamfontein, Johannesburg, 2017
Telephone010 023 5200
General enquiriesenquiries@inforegulator.org.za
POPIA complaintsPOPIAComplaints@inforegulator.org.za
OnlineComplaints may also be lodged on the Regulator's online complaints portal, using Form 5

11.4 [CONFIRM: verify the Regulator's current address and complaint channel at inforegulator.org.za before publication]


12. Third parties and cross-border transfers

12.1 Some of the cookies described in clause 6 are set by third parties, and some of those third parties process data outside South Africa.

12.2 The Privacy Policy sets out the full position on transborder flows under section 72 of POPIA and the safeguards we rely on. In summary, and as it relates to cookies:

12.2.1 Google Analytics and Google Business Profile process in the United States and in other countries in which Google operates. We rely on your consent to the relevant cookie category and on Google's data processing terms and Standard Contractual Clauses.

12.2.2 Elementor processes in Israel, the European Union and the United States.

12.2.3 MultiVendorX is associated with processing in India. [CONFIRM: whether MultiVendorX is self-hosted software only, or whether the vendor accesses or supports the installation from India]

12.2.4 PayFast and TradeSafe are understood to process in South Africa. [CONFIRM: their processing and hosting locations]

12.2.5 [CONFIRM: whether Cloudflare or another WAF/CDN is in front of the Platform; if it is, its processing is global and must be reflected here]

12.3 We do not control the cookies that a third party sets through its own service, beyond deciding whether to load that service at all and blocking it until you consent. Read that third party's own cookie notice for the detail.


13. Changes to this Policy

13.1 We will update this Policy when we add, remove or change a cookie, a plugin, an embed or a tracking tool, when the audit in clause 3 is completed or repeated, or when the law changes.

13.2 The current version, with its version number and effective date, is always on the Platform.

13.3 Where a change means we want to set a new category of non-essential cookie, or use an existing one for a new purpose, we will ask for your consent again through the Consent Banner before we do it.

13.4 We keep previous versions and will provide one on request.


14. Contact Us

14.1 About cookies and privacy, the Information Officer: data@listsecure.co.za.

14.2 About anything else: support@listsecure.co.za.

14.3 By post: The Information Officer, LIST SECURE (PTY) LTD, 16 Pelican Way, Zeekoevlei, Western Cape, 7942, South Africa.


×

Login

Register

A link to set a new password will be sent to your email address.

Your personal data will be used to support your experience throughout this website, to manage access to your account, and for other purposes described in our privacy policy.