Last updated: 20 June 2026
Effective from: 20 June 2026
Version: 1.0
This policy explains how Paul Hepple, a sole trader trading as DarkByte Creations, uses cookies and other technologies that store information on, or access information from, a user's device in connection with NibbleKit.
In this policy, DarkByte, NibbleKit, we, us and our refer to Paul Hepple trading as DarkByte Creations.
This policy applies to NibbleKit services that link to it, including, where applicable:
A NibbleKit-powered service may be branded for a participating Merchant. Section 9 explains how responsibility is divided where a Merchant or another provider selects additional technology.
This policy should be read with the NibbleKit Privacy Policy.
A cookie is a small file that a website asks a browser to store on a device.
Cookies are only one type of storage or access technology. This policy also covers technologies such as:
These rules can apply to mobile apps and connected devices as well as conventional websites.
Device permissions, such as notification, location, camera or photo permissions, may also affect how an app accesses information or device functions. Permissions are explained at the point they are requested and can normally be managed in the device settings.
We classify storage and access technologies according to their actual purpose.
These are used solely to transmit a communication over a network.
These are essential to provide an online service or function that the user has requested.
Depending on the relevant service, this may include technology needed to:
A technology is not treated as strictly necessary merely because it is useful to us, generates revenue or improves general marketing performance.
A technology may be used without prior consent under the applicable statistical-purpose exception only where all required conditions are met.
Where we rely on this exception:
If those conditions are not met, we will obtain consent before using the technology.
A technology may be used under an applicable appearance or functionality exception where its sole purpose is to adapt the appearance or operation of the service to a preference selected by the user.
Where we rely on this exception, we will provide clear information and a simple and free way to object.
Unless another lawful exception clearly applies, we will obtain consent before using technology for purposes such as:
We will not treat silence, inactivity, continued browsing, use of a pre-ticked box or acceptance of general Terms and Conditions as consent to an optional technology.
The exact storage keys and provider cookies can vary by device, browser, app version, environment and Merchant configuration. The current public register is:
| Technology or provider | Where used | Purpose | Consent position | Typical duration | User control |
|---|---|---|---|---|---|
| Firebase Authentication and NibbleKit session storage | Customer app, Merchant portal, admin tools and webviews | Authenticate users and maintain secure signed-in sessions | Strictly necessary for signed-in use | Session, logout or provider-configured token lifetime | Sign out, delete account where applicable, or clear browser/app storage |
| Firebase email verification and password-reset action codes | Verification and reset pages | Complete the user's requested security action | Strictly necessary | Single use or provider-configured expiry | Do not use the link, or request a new link |
| Basket, checkout and order-state storage | Customer ordering and checkout | Maintain basket, checkout, payment and order-status workflows | Strictly necessary for ordering | Session, local app storage or server-side order lifecycle | Clear basket, sign out, clear browser/app storage or delete account where applicable |
| Firebase, Google Cloud and hosting security logs | Public pages, apps, APIs and admin tools | Transmit requests, protect accounts, detect abuse and diagnose faults | Communication/strictly necessary and legitimate security use | Provider-configured operational retention | Cannot be disabled without affecting service security |
| Flutter secure/local storage | Mobile and desktop apps | Store authentication state, essential app settings and requested preferences | Strictly necessary or preference-based depending on feature | Until logout, app removal, account deletion or configured expiry | App settings, device settings, logout or app removal |
| Firebase Cloud Messaging and local notification tokens | Mobile apps and supported devices | Deliver account, order, security and service notifications where enabled | Device permission plus service need | Until token replacement, logout, app removal or provider expiry | App and device notification settings |
| Stripe PaymentSheet, PaymentIntent and wallet-provider technologies | Checkout/payment flow | Process payments, pre-authorisations, fraud checks, refunds and disputes | Necessary for selected payment method; Stripe/provider terms also apply | Provider-controlled | Choose another enabled payment method where available |
| Google Places, Maps or postcode/address providers where enabled | Address lookup, delivery areas and route features | Provide requested address, postcode, map or route functionality | Necessary for requested feature or subject to device/browser permission where applicable | Provider-controlled | Enter address manually where available or manage location permissions |
| StackEdit stylesheet and content-delivery resources for policy pages | Public policy pages | Render the policy page styling | Content delivery, not advertising | Browser/provider cache duration | Browser controls |
| Analytics, advertising or cross-service tracking | Not part of the core NibbleKit demo unless separately enabled | Measurement, advertising or retargeting only if introduced | Prior consent where PECR requires it | Provider/configuration-specific | Consent controls before use |
NibbleKit platform and demo services that link to this policy do not use storage or access technologies for behavioural advertising, retargeting, cross-site tracking or cross-app advertising measurement.
If advertising, retargeting or cross-service tracking technologies are introduced later, they must be identified in the register above, remain disabled unless and until the user gives valid consent, and be capable of rejection without preventing access to the core NibbleKit service.
No advertising or cross-service tracking technology may be introduced merely by changing a third-party tag manager or provider configuration without first updating the register, carrying out the required assessment and implementing the necessary consent control.
Where consent is required:
Users can manage their choices through the privacy controls, cookie banner, app permission settings or device/browser settings provided in the relevant service; if no optional technologies are enabled, no separate preference control may be shown.
Where we rely on the statistical-purpose or appearance exception, users can object free of charge through the privacy controls, cookie banner, app permission settings or device/browser settings provided in the relevant service; if no optional technologies are enabled, no separate objection control may be shown.
Declining or objecting to optional technologies will not prevent access to the core Services. A particular optional feature may not work where it genuinely depends on the technology that the user has declined.
Deleting the technology used to remember a privacy choice may result in the choice being requested again.
Most browsers allow users to:
Mobile operating systems and device settings may allow users to:
Browser and device controls are supplementary. They do not replace a consent, rejection or objection mechanism that DarkByte is required to provide.
Blocking strictly necessary technologies may prevent account authentication, verification, basket, checkout, security or other requested functions from working correctly.
The fact that a mobile application does not use conventional browser cookies does not mean that no storage or access technology is used.
A NibbleKit mobile application may use:
Every active technology must be assessed according to its actual purpose and listed in the register where appropriate.
Where a web page is displayed inside an app webview, the technologies used by that page remain subject to this policy and the applicable privacy choices.
The app will request operating-system permissions at an appropriate point and explain their purpose. A permission may be refused or withdrawn through the app or device settings, although the related feature may then be unavailable.
NibbleKit is a white-label platform. A service may display a Merchant's brand while using technology selected or operated by DarkByte, the Merchant or both.
Responsibility depends on who decides to deploy and configure the technology and for what purpose.
DarkByte is responsible for providing accurate information and appropriate controls for storage or access technologies that DarkByte selects, configures or controls on a service linking to this policy.
A Merchant is responsible for technologies that it independently selects or instructs DarkByte to deploy for the Merchant's own purposes, such as Merchant-controlled:
Where both DarkByte and a Merchant influence a technology's purposes or configuration, the parties must assess and document their respective responsibilities. The user-facing notice must identify the relevant parties and must not simply refer vaguely to unnamed "partners".
A Merchant may not introduce optional tracking into a NibbleKit-powered service without first:
DarkByte remains responsible for technologies that DarkByte itself selects or configures. A contractual allocation to a Merchant does not remove obligations that apply directly to DarkByte.
A NibbleKit service may embed or interact with a payment, mapping, video, support or other third-party service.
Where a third-party component is embedded into a NibbleKit service, it may store or access information on the user's device. The relevant provider, purpose, duration and choice must be identified in the technology register.
A simple link to an external website does not by itself mean that the external website's technologies are used before the user follows the link. Once a user follows an external link, the destination service's own privacy and technology notices apply.
Payment providers, app stores and device operating-system providers may independently use technologies under their own terms. Their independent activities should be explained at the point they become relevant.
We do not accept responsibility for a third party's independent website merely because NibbleKit provides a link to it. This does not remove any responsibility DarkByte has for choosing, embedding, configuring or disclosing a third-party component within the Services.
Some storage and access technologies involve processing personal data, such as:
Where personal data is involved, the NibbleKit Privacy Policy explains:
A PECR exception does not remove obligations under data-protection law. Where consent is required under PECR and personal data is processed, we will also ensure that the associated processing has an appropriate UK GDPR basis.
Consent to one purpose does not amount to consent to a materially different purpose.
The duration of each technology is stated in the register.
We determine an appropriate duration by considering:
We do not keep a persistent technology active merely because its provider uses that duration by default.
We review persistent technologies and their configured durations periodically.
We will review the Services periodically to identify:
Before deploying a new technology, we will determine:
A provider's automatic classification of a technology will not be accepted without reasonable review.
Questions or requests concerning personal data used through these technologies may be submitted through the NibbleKit Privacy Rights and Data Protection Complaints page or sent to support@nibblekit.com.
Where DarkByte is the relevant controller, we will:
Where a complaint concerns a technology independently controlled by a Merchant, we may forward the complaint to the Merchant or direct the complainant to the appropriate Merchant contact. We will explain the action taken where reasonably possible.
This does not affect the right to complain to the Information Commissioner's Office.
We may update this policy where:
The last-updated date and version number will be shown at the top of the page.
Where a change introduces a new consent-based purpose, we will not treat an earlier choice as consent to that new purpose. We will request a new choice where required.
Previous material versions are available on reasonable request from support@nibblekit.com.
NibbleKit is operated by:
Paul Hepple, a sole trader trading as DarkByte Creations 152 Lindhurst Road, Barnsley, S71 3DG Email: support@nibblekit.com