Cookie policy

Almost no cookies. By design.

Most websites set dozens of marketing and tracking cookies. Ours sets none for ordinary visitors. The handful we do use exist only to keep our admin team signed in and to remember which hero video you'd already seen — that's it. This page documents every cookie we set, why, and how to switch them off.

Last updated · 26 May 2026

1 · TL;DR

  • No marketing cookies, ever. No Google Analytics, no Facebook Pixel, no LinkedIn Insight Tag, no ad-network beacons.
  • No third-party cookies.Anything we set is first-party (the cookie's domain matches octava.co.za).
  • You don't need to consentto read the marketing site — there's nothing to consent to.
  • We honour the Global Privacy Control and Do Not Track browser flags.

2 · What a cookie is

A cookie is a tiny text file your browser stores on your device when you visit a website. The website can read that file again on your next visit, which lets it remember things like "you're still signed in" or "you prefer dark mode."

Cookies can also be used invasively — chained across dozens of websites to build behavioural profiles for ad targeting. We don't do that.

3 · What we actually use

The exhaustive list of cookies the Octava Solutions website may set is below. Cookies are only set after the interaction described in the "set when" column — they are not set on first visit.

CookiePurposeSet whenExpires
next-auth.session-tokenKeeps a member of the studio signed into the admin panel between requests.Only after a successful sign-in to /admin. Never set for ordinary visitors.30 days, rolling
next-auth.csrf-tokenCSRF protection for the admin sign-in form.Only on the admin sign-in page.Session
next-auth.callback-urlRemembers which admin page you were trying to reach so we can return you there after sign-in.Only on the admin sign-in page.Session

All three cookies are strictly necessary under the POPIA and GDPR definitions — they exist solely to deliver the admin experience you actively requested by signing in. They do not require consent.

4 · What we don't use

We deliberately don't load any of these on the public marketing site:

  • Google Analytics, Google Tag Manager, GA4.
  • Facebook Pixel, Meta CAPI, TikTok Pixel.
  • LinkedIn Insight Tag, Twitter / X Pixel.
  • Hotjar, FullStory, Microsoft Clarity, or any session-replay vendor.
  • HubSpot, Marketo, Pardot, Segment, RudderStack, or other CRM/event-pipeline trackers.
  • Re-targeting, A/B-testing, or affiliate-tracking cookies.

When we need to understand traffic at an aggregate level (e.g. "how many people read the projects page last month?"), we use a small first-party page-view counter that records the page path and a timestamp on our own server — no cookie, no fingerprint, no IP retention beyond the request.

5 · Local & session storage

The marketing site may use your browser's localStoragefor one purpose only: remembering which hero video index has been displayed so we don't replay the same clip if multiple are configured. The key is non-identifying (just a small integer) and is automatically scoped to octava.co.za.

You can clear it any time from your browser's DevTools or the "Clear browsing data" option.

6 · Controlling cookies

You can block, delete or restrict cookies at any time. Standard instructions:

  • Chrome: Settings → Privacy and security → Cookies and other site data.
  • Safari: Settings → Privacy → Manage Website Data.
  • Firefox:Settings → Privacy & Security → Cookies and Site Data.
  • Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data.

Blocking the three admin cookies we set will stop a studio member from signing into the admin panel — but it has no effect at all on the public marketing site you probably came here to read.

7 · Do Not Track & Global Privacy Control

If your browser sends the legacy DNT: 1 header or the modern Sec-GPC: 1 header, we suppress the page-view counter entirely for that visit. We have nothing else to switch off.

8 · Changes to this policy

If we ever add a new cookie or analytics tool, we'll update the table in section 3, bump the "last updated" date, and email anyone with an active engagement at least 14 days before the change takes effect.

9 · Contact

Cookie or tracking question? Email support@octava.co.zawith "cookies" in the subject and we'll come back inside one business day.

Questions about this document? We answer them ourselves. Reach out and a real person will reply within one business day.