Flisters legal

Cookie

A practical guide to Flisters’ sign-in cookies, saved browser preferences, and how to control them.

Last updated:

1. Cookies and similar storage

This policy explains browser storage used by Flisters.com, operated by Inventivelabs LTD (RC 9758742). Cookies are small values a website stores in your browser and sends with relevant requests. Local storage keeps preferences in your browser without automatically sending them with every request.

Flisters uses cookies for authentication and security and browser storage for interface choices. We currently do not load advertising pixels or audience-analytics trackers such as Google Analytics or Meta Pixel. If we introduce optional tracking, we will explain it and request consent before activation where required by law.

2. Sign-in and security cookies

Flisters uses Auth.js for authentication. Cookie names can have a __Secure- or __Host- prefix on HTTPS and a numbered suffix when a value is split into several cookies.

  • authjs.session-token keeps you signed in. The configured authentication default is a session lifetime of up to 30 days, renewed by session activity. Signing out clears the session cookie.
  • authjs.csrf-token helps protect authentication requests from forgery. authjs.callback-url remembers the destination for a sign-in flow. These are session cookies; browser session-restore settings may preserve them.
  • When required by a sign-in flow, authjs.pkce.code_verifier and authjs.state validate the response and have a maximum age of 15 minutes. A flow may also use a session-based authjs.nonce. Flow-specific cookies are cleared when consumed.

These cookies enable the sign-in and security functions you request. Blocking them can prevent registration, sign-in, or authenticated features from working. They are not advertising cookies.

3. Preferences stored in your browser

The following local-storage entries support the interface. They have no automatic expiry in the application and remain until you change the relevant choice, clear site data, or your browser removes them.

  • theme: your light, dark, or system appearance preference.
  • sidebar-collapsed: whether the manager sidebar is collapsed.
  • tenant-statement-range: the selected date range for tenant statements.
  • flisters:manager-tour:v1:<userId>: whether a particular user has already been offered the manager tour in this browser. The tour can still be started from the dashboard.
  • flisters:cookie-notice:v1: whether you dismissed the cookie information notice in this browser.

Dismissing the notice only remembers that it has been shown. It does not grant consent to advertising, analytics, or a new use of personal information. Preferences are browser-specific and may need to be chosen again on another device.

4. Payment and sign-in providers

Using Stripe or OPay payment interfaces or choosing Google sign-in may involve provider cookies and similar technologies for their authentication, transaction, and fraud-prevention functions. Provider storage can be set on their pages or through an embedded interface and is governed by the relevant provider’s information.

See Stripe’s Cookie Policy and Google’s cookie information. For OPay, also review the privacy and storage information linked from its checkout. These services have separate cookie lifetimes and controls. We do not describe provider cookies as Flisters advertising trackers or claim that a Flisters preference setting controls another website.

5. Your controls

You can inspect, remove, or block cookies and local storage in your browser’s privacy or site-data settings. Search for Flisters.com in the stored-site-data list to remove its data. Your browser’s help pages explain controls for third-party cookies and automatic deletion.

Clearing site data may sign you out, reset your theme and sidebar, remove the saved statement range, and show the tour offer and cookie notice again. Blocking authentication cookies can make the portals unavailable. Signing out clears the authentication session but does not necessarily remove saved interface preferences.

There is currently no Flisters advertising or analytics consent category to enable or disable. The notice is informational. The Privacy Policy explains separate rights over personal data stored on our systems; deleting browser data does not delete an account or tenancy record.

6. Updates and questions

We update this inventory when our use of storage changes. The date above identifies this version. Contact privacy@flisters.com or use our contact form if you have a question about a cookie or privacy choice.

Who operates Flisters

Flisters.com is a brand owned and operated by Inventivelabs LTD (RC 9758742), a company registered in Nigeria and the parent company of Flisters, NaijaProperty, and NaijaPlace.

legal@flisters.comprivacy@flisters.com

Contact us about legal or privacy matters