Cookie Policy

Effective date: March 11, 2026. Last updated: March 11, 2026.

This Cookie Policy explains how Bwiser uses cookies and similar technologies on our website and web application (“Web”). It also explains your choices. For information about how we process personal information more broadly, please read our Privacy Policy and POPIA Notice.

1. What Are Cookies?

Cookies are small text files stored on your device by your browser when you visit a website. Cookies help a site remember information about your session (such as being logged in) and can also support security and performance features. Similar technologies include local storage, session storage, device identifiers, and tracking pixels. In this policy, we refer to all of these collectively as “cookies”, unless otherwise stated.

2. Why Bwiser Uses Cookies

We use cookies for a limited set of operational purposes, including:

  • Security: protecting sessions, preventing unauthorised requests, and detecting abuse.
  • Authentication: keeping you signed in as you navigate between pages.
  • Preferences: storing consent preferences and basic UI settings.
  • Operational continuity: ensuring key workflows work reliably (for example, voucher redemptions and repayments in the web interface).
  • Analytics (optional): measuring performance and improving usability where we have an appropriate lawful basis and, where required, your consent.

3. Cookie Categories

We group cookies into categories. Not all categories are necessarily used at all times. If we introduce new cookies, we may update this policy and/or the consent tool.

3.1 Strictly Necessary Cookies

These cookies are essential for the Web to function and cannot be switched off without impacting core functionality. They are generally used for session management, CSRF protection, and security.

3.2 Functional Cookies

These cookies enable improved functionality and personalisation, such as remembering consent preferences and certain UI settings. They may be set by us or by services we use.

3.3 Analytics / Performance Cookies (Where Enabled)

These cookies help us understand how visitors use the Web so we can improve performance and user experience. Where required, we will ask for your consent before enabling these cookies.

3.4 Third-Party Cookies (Where Applicable)

Some embedded features (for example, external payment pages, mapping providers, or identity providers) may set cookies on their own domains. Those cookies are governed by the third party’s policy, not ours.

4. Cookies We Commonly Use

The exact cookies may vary by environment (local, staging, production) and browser. The list below reflects cookies commonly used in a Laravel-based web application and the Bwiser Web experience.

Session cookie

Purpose: Maintains your authenticated session and keeps you signed in while you use the Web. Example name: fuellevy-session (name may change by environment). Type: strictly necessary.

CSRF protection cookie

Purpose: Helps protect against cross-site request forgery by pairing with a server-side token. Example name: XSRF-TOKEN. Type: strictly necessary.

Remember-me cookie (if you choose “Remember me”)

Purpose: Enables persistent login across browser sessions when you select “Remember me” on sign-in. Example name: remember_web_*. Type: functional/strictly necessary for the remember-me feature.

Cookie consent preference

Purpose: Records whether you have accepted or declined optional cookies (where we provide a consent tool). Example name: bwiser_cookie_consent. Type: functional.

We avoid storing sensitive information such as passwords in cookies. Passwords are stored as secure hashes server-side. Where a cookie contains an identifier, it is generally a random value used to look up session state securely on the server.

5. Retention and Expiry

Some cookies (session cookies) expire when you close your browser. Others (like remember-me cookies) may persist longer so you remain signed in. We aim to keep cookie lifetimes proportionate to the purpose and to rotate or invalidate cookies where security requires it (for example, after password changes, suspicious activity, or logout).

6. Managing Cookies and Your Choices

You can manage cookies in several ways:

  • Using the cookie consent prompt (where available) to accept or decline optional categories.
  • Using your browser settings to block or delete cookies.
  • Using private browsing mode (note this may still allow some cookies for the duration of your session).

If you block strictly necessary cookies, the Web may not function correctly. This can affect sign-in, voucher creation, voucher redemption, repayment actions, and account security features.

7. Third-Party Services

Depending on your use of the Platform and which features are enabled, you may be directed to or embedded with third-party services such as payment gateways, mapping providers, or identity providers. When you interact with those services, the third party may set cookies under their own policies. We encourage you to review the third party’s privacy and cookie policies when you leave our domain.

8. Updates to This Policy

We may update this Cookie Policy from time to time to reflect operational changes, new features, or legal requirements. We will update the “Last updated” date above. Material changes may also be communicated through the Platform.

9. Legal Basis and Consent (South Africa)

In South Africa, cookies can constitute personal information when they relate to an identifiable person or can be linked to an identifiable person. Where required, we rely on consent for optional cookies (for example, analytics), and we rely on contractual necessity and legitimate interests for strictly necessary cookies that support security and core platform operations.

You can change your mind about optional cookies at any time by clearing cookies in your browser and revisiting the Web, or by using any consent controls made available. Please note that withdrawing consent does not affect the lawfulness of processing based on consent before it was withdrawn.

Where analytics are enabled, we aim to use them to improve performance and reliability rather than to build advertising profiles. We prefer privacy-preserving configurations (for example, limiting retention, limiting access, and avoiding unnecessary sharing) and we avoid enabling optional categories unless they are genuinely useful to improve the Platform.

10. Browser Controls (How to Block/Delete Cookies)

Most browsers allow you to manage cookies through settings. The exact steps differ by browser version, but typically you can:

  • View which cookies are stored by a site.
  • Delete cookies for a specific site (for example, bwiser.co.za).
  • Block third-party cookies.
  • Block all cookies (not recommended for the Bwiser Web experience).

Common examples:

  • Chrome: Settings → Privacy and security → Third-party cookies / Site settings.
  • Safari (macOS/iOS): Settings/Preferences → Privacy → Manage Website Data.
  • Firefox: Settings → Privacy & Security → Cookies and Site Data.
  • Edge: Settings → Cookies and site permissions.

If you delete or block cookies, you may be signed out and may need to sign in again. Certain actions may fail if CSRF/session cookies are blocked.

11. Do Not Track Signals

Some browsers offer a “Do Not Track” (DNT) preference. There is no universal standard for DNT responses. Bwiser’s response to DNT may depend on which analytics tools are enabled and how they are configured. Where we require consent for optional cookies, we prefer using explicit consent rather than relying on DNT.

12. Cookie Glossary (Plain Language)

Below are common cookie and web storage concepts that can help you understand what you may see in browser developer tools:

  • First-party cookie: a cookie set by the site you are visiting (for example, bwiser.co.za).
  • Third-party cookie: a cookie set by a different domain (often used by embedded services).
  • Session cookie: a cookie that expires when the browser session ends.
  • Persistent cookie: a cookie that remains until it expires or you delete it.
  • Local storage: a browser storage area that persists until cleared (not sent with every request like cookies).
  • SameSite: a cookie attribute that reduces cross-site request risks.
  • Secure: a cookie attribute that ensures a cookie is only sent over HTTPS.
  • HttpOnly: a cookie attribute that prevents JavaScript from reading the cookie (helps reduce XSS risk).

Bwiser configures security-sensitive cookies with protective attributes where supported by the browser and consistent with platform requirements. For example, session cookies are intended to be used only for authenticated sessions and are protected from being transmitted over insecure channels in production.

In some cases, cookies may be scoped to a domain (for example, a parent domain like .bwiser.co.za) so that sessions work consistently across subdomains (for example, www vs other subdomains). This is a security-sensitive configuration: it must be done carefully to avoid sending cookies to unintended hosts. Bwiser aims to scope cookies narrowly and securely, and to use Secure and SameSite attributes in production to reduce cross-site risks.

If your browser blocks third-party cookies or enforces strict tracking protection, some embedded content may not work as expected. Common symptoms include being repeatedly logged out, forms failing to submit, or security prompts appearing. When this occurs, it typically indicates that the browser is preventing a necessary cookie (session or CSRF) from being stored or sent back to the server.

If you use shared computers or devices, cookies can keep you signed in. Always sign out after using the Platform on a shared device, and consider disabling “Remember me” in those circumstances.

13. Cookies in Mobile Webviews and External Pages

Some users access Bwiser links through a mobile app webview or an in-app browser. Webviews typically support cookies, but they may behave differently from full browsers (for example, cookie sharing between apps, stricter privacy defaults, or limited settings). If you experience sign-in loops, missing sessions, or “Page expired”/CSRF-type errors, the cause is often related to blocked cookies or privacy settings in the embedded browser. Where possible, open the link in a full browser and ensure cookies are enabled for the site.

If you are using VPNs, content blockers, or strict privacy extensions, those tools can also interfere with cookies and with third-party scripts required for specific pages. For troubleshooting, temporarily disable blockers for bwiser.co.za and try again, or use a different browser profile.

When you are redirected to third-party pages (for example, payment gateway pages), those pages may set cookies under their own policies. This is common for authentication and payment flows. Bwiser does not control third-party cookie behaviour on external domains.

14. Contact

If you have questions about cookies or consent, contact [email protected].

If you are reporting a cookie-related problem, include your browser name/version and whether you are using private browsing, a content blocker, or an in-app browser. This makes it easier to diagnose session and login issues.

For most cookie issues, clearing site data for bwiser.co.za and signing in again resolves the problem.

If the issue persists, try a different browser, disable strict tracking protection for the site, and confirm that your device clock is correct (time skew can break secure sessions). These steps often resolve persistent authentication issues.

Note: This Cookie Policy is provided for transparency and operational readiness and does not constitute legal advice.