Skip to main content
DigitalSpur
ServicesEventsHow it worksHelp
Track a transactionLog inCreate account

Menu

ServicesEventsHow it worksHelp
Track a transactionLog inCreate account

Legal and privacy

Cookie policy

The strictly necessary browser storage DigitalSpur uses for checkout, security, and account sessions.

DigitalSpur public policy setPrivacy policyTerms and conditionsRefunds and cancellationsData deletion instructionsAccount deletionCookie policyAccessibility statementAcceptable use
On this pageStrictly necessary storageCookie security and durationPreferences, analytics, and social providersManaging cookies
On this page
Strictly necessary storageCookie security and durationPreferences, analytics, and social providersManaging cookies
Plain-language summary

The customer web currently uses four server-managed cookie types for requested security and commerce features. It uses no analytics, advertising, or social-login cookies and stores no tokens in Web Storage.

Strictly necessary storage

DigitalSpur uses secure server-managed cookies for customer authentication, cross-site request forgery protection, active guest-checkout possession, and verified guest access. These support features the customer requested and are not optional analytics storage.

  • DSP-CUSTOMER-SESSION: an HttpOnly customer authentication session cookie.
  • DSP-XSRF-TOKEN: a CSRF protection cookie paired with the X-DSP-XSRF-TOKEN request header for state-changing requests.
  • DSP-GUEST-CHECKOUT: an HttpOnly possession cookie for an active guest checkout session.
  • DSP-GUEST-ACCESS: an HttpOnly cookie for a verified, scoped guest transaction-access grant.

Cookie security and duration

Session and guest-access cookies are Secure in production and use a SameSite policy. Sessions and guest access expire according to the security and transaction rules that apply to the journey.

The CSRF cookie must be readable by the web application so its unpredictable value can be sent in the required request header; session and guest-access secrets remain HttpOnly.

Preferences, analytics, and social providers

The inspected customer web uses no localStorage or sessionStorage, and loads no optional analytics, advertising, Google sign-in, Facebook Login, or social-widget scripts. It therefore shows no non-essential-cookie consent banner.

If optional storage or third-party scripts are introduced, they must remain blocked until any required consent is recorded and this inventory is updated with purpose, provider, duration, and control instructions.

Managing cookies

Browser settings can remove or block cookies. Blocking strictly necessary cookies can prevent checkout, sign-in, verification, secure status recovery, and access to receipts or service results from working correctly.

Signing out ends the current customer session. Guest checkout and access grants also expire automatically.

Questions about this policy?

Email support@digitalspur.co.zw. Do not include passwords, wallet PINs, card data, one-time codes, ticket codes, access tokens, or complete token values.

DigitalSpur

Everyday services, one clear route.

support@digitalspur.co.zw
ServicesAll servicesElectricityEvent ticketsTrack transaction
DigitalSpurAboutHow it worksPaymentsSecurityChannelsContactHelp and support
Legal and privacyPrivacyTermsRefundsData deletionAccount deletionCookiesAccessibilityAcceptable use

© 2026 DigitalSpur. Service availability can change.