Overview
This Data Policy explains what cookies and browser storage mechanisms Listify uses, why we use them, and how you can control them.
A cookie is a small text file placed on your device by a website you visit. Cookies allow the website to recognise your device on subsequent visits and remember certain information about your session.
We use cookies and related technologies only to the extent necessary to operate the Platform effectively and to understand how it is used so we can improve it. We do not use cookies to build personal advertising profiles or to track you across unrelated websites without your consent.
For details on how we handle your personal data more broadly, see our Privacy Policy.
Plain English: Cookies are small files stored in your browser that help websites remember who you are and how you use them.
Essential Cookies
Essential cookies are strictly necessary for the Platform to operate. Without them, features such as sign-in and security protection are unavailable.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
| next-auth.session-token | Maintains your authenticated session after sign-in | Session / 30 days | Listify (NextAuth) |
| __Secure-next-auth.session-token | Secure variant of the session token (HTTPS only) | Session / 30 days | Listify (NextAuth) |
| next-auth.csrf-token | Prevents cross-site request forgery (CSRF) attacks | Session | Listify (NextAuth) |
| next-auth.callback-url | Stores the URL to redirect to after successful sign-in | Session | Listify (NextAuth) |
| cookieConsent | Records your cookie consent choice so we don't ask again | 1 year | Listify |
Plain English: These cookies are required for the Platform to work. You cannot opt out of them while using Listify.
Preference & Functionality Cookies
Preference cookies allow the Platform to remember choices you make to personalise your experience. They are not strictly necessary but significantly improve usability.
| Cookie / Storage Key | Purpose | Duration | Provider |
|---|---|---|---|
| theme | Stores your preferred colour scheme (light or dark mode) set via the theme toggle | 1 year | Listify (next-themes) |
You can opt out of preference cookies by clearing your browser cookies or by not setting a theme preference. The Platform defaults to light mode unless you choose dark mode or system mode.
Plain English: These cookies remember your choices (like dark mode) so you don't have to set them every time.
Analytics & Performance
We use analytics to understand how visitors interact with the Platform — which pages are viewed most, how users navigate and where they encounter issues. This helps us make the Platform better.
Vercel Analytics (provided by Vercel, our hosting provider) collects aggregated, anonymised page-view and performance metrics. Vercel Analytics is designed to be privacy-friendly:
- No personal identifiers (name, email, IP address) are stored;
- No cookies are set by Vercel Analytics;
- Data is aggregated before it reaches us — individual visitors are not tracked.
Because Vercel Analytics does not use cookies or collect personally identifiable information, it does not require consent under the CyberSecurity and Data Protection Act, 2021.
If we introduce additional analytics tools that use cookies or collect personal data, we will update this policy and present a consent prompt accordingly.
Plain English: We measure how pages are used to improve the Platform. Analytics data is aggregated — it never identifies you personally.
Advertising & Retargeting Pixels
As part of our growth strategy we intend to run paid advertising campaigns that may use retargeting pixels — snippets of code that allow advertising platforms to show you relevant Listify ads on other websites after you have visited ours.
Current status: advertising pixels are not active. No Meta Pixel, Google Ads remarketing tag or equivalent tracking pixel is currently loaded on the Platform.
When we enable advertising pixels we will:
- Update the cookie consent banner to include an "Advertising" category;
- Only load advertising pixels for users who have consented to the "Advertising" category; and
- Update this Data Policy with details of each pixel and what it collects.
When advertising pixels are active, they may collect the URLs of pages you visit on Listify and actions you take (e.g. viewing a listing, completing a purchase). This information is processed by the advertising platform (e.g. Meta, Google) under their respective privacy policies.
Plain English: Advertising pixels are not currently active on Listify. When we enable them in future, we will ask for your consent first.
Third-Party Service Integrations
The following third-party services are integrated into the Platform. Each processes data only as necessary to provide their service to us, under contractual data protection obligations.
| Service | Provider | Purpose | Data processed | Privacy policy |
|---|---|---|---|---|
| AWS Cognito | Amazon Web Services | User authentication and account management | Email address, hashed password, phone number | aws.amazon.com/privacy |
| AWS S3 | Amazon Web Services | Storage for listing images uploaded by users | Listing photographs (no personal identifiers in files) | aws.amazon.com/privacy |
| Stripe | Stripe, Inc. | Payment processing for subscriptions and credits | Billing name, card details (PCI-DSS compliant; not stored by Listify) | stripe.com/privacy |
| Vercel | Vercel, Inc. | Website hosting and performance analytics | Aggregated page-view data; server access logs (90-day retention) | vercel.com/legal/privacy-policy |
Plain English: We use a small number of trusted third-party services to operate Listify. Each is bound by a data processing agreement.
Browser Local & Session Storage
In addition to cookies, we use your browser's built-in localStorage and sessionStorage APIs to store lightweight preference and state data. Browser storage itself is not sent with every request like a cookie. A feature may, however, read a stored selection and send the relevant values to our servers when you choose to continue that workflow, as described below.
| Key | Storage type | Purpose | Persists after window close? |
|---|---|---|---|
| theme | localStorage | Stores your light/dark mode preference | Yes — until cleared |
| listify_recent_views | localStorage | Stores IDs of recently viewed listings so we can show a "Recently Viewed" section | Yes — until cleared or 30 days |
| listify.finance.estimate.v1 | sessionStorage | Temporarily stores the selected listing, product version and calculator choices; it contains no applicant identity or affordability data | No — cleared with the browser session |
| listify.finance.draft-key.* | sessionStorage | Prevents accidental duplicate draft creation when a finance request is retried | No — cleared with the browser session |
You can clear localStorage data at any time through your browser's developer tools or via the "Clear site data" option in browser settings.
Plain English: We use your browser's storage to remember preferences and temporary workflow state. Finance inputs are sent to our servers only when you start or update a draft.
Finance Draft Storage
Before sign-in, the finance calculator stores only the listing ID, lender product version, deposit, term and fee-treatment choices in sessionStorage. It does not place your name, identity number, income, guarantors or documents in browser storage.
When you choose to start an application, those calculator choices are sent to Listify to create a server-backed draft. Applicant and affordability changes are then autosaved to that authenticated draft so you can resume on another device. Draft information is not shared with the lender until you explicitly submit.
Consent records are stored as versioned evidence, including the notice version, a cryptographic hash of the displayed text, your choice, timestamp and limited request evidence. This supports auditability and does not replace your right to withdraw an optional consent.
Plain English: Only calculator choices are held temporarily in the browser. Once started, your private application draft is stored securely against your Listify account.
Consent Management
On your first visit to the Platform, a consent banner will appear allowing you to choose which categories of cookies you accept:
- Essential: always active — required for the Platform to function.
- Preferences: opt in/out of functionality cookies (e.g. theme preference).
- Analytics: opt in/out of performance measurement (currently cookie-free via Vercel Analytics; consent collected for future tools).
- Advertising: opt in/out of retargeting pixels (currently inactive; consent will be required before activation).
Your consent choice is stored in the cookieConsent cookie for one year. You may update your preferences at any time by clicking "Cookie Settings" in the footer.
Plain English: On your first visit we ask for your consent to non-essential cookies. You can change your mind at any time.
Managing Your Cookie Preferences
Most browsers allow you to view, manage and delete cookies and local storage:
- Google Chrome: Settings → Privacy and security → Cookies and other site data
- Mozilla Firefox:Settings → Privacy & Security → Cookies and Site Data
- Apple Safari: Preferences → Privacy → Manage Website Data
- Microsoft Edge: Settings → Cookies and site permissions → Cookies and site data
Important: blocking or deleting essential cookies (particularly the session token) will prevent you from signing in to Listify.
Advertising opt-outs (for future advertising pixels):
- Google Ads: visit adssettings.google.com
- Meta / Facebook: facebook.com/settings?tab=ads
- General opt-out: youronlinechoices.com
Plain English: You can block or delete cookies through your browser settings. Blocking essential cookies will prevent sign-in.
Contact
Questions about our use of cookies or this Data Policy? Visit our Contact page to reach us by email or WhatsApp.
For broader privacy concerns, see our Privacy Policy.

