COOKIES AND SIMILAR TECHNOLOGIES POLICY

Last updated: 20 June 2026
Effective from: 20 June 2026
Version: 1.0

1. About This Policy

This policy explains how Paul Hepple, a sole trader trading as DarkByte Creations, uses cookies and other technologies that store information on, or access information from, a user's device in connection with NibbleKit.

In this policy, DarkByte, NibbleKit, we, us and our refer to Paul Hepple trading as DarkByte Creations.

This policy applies to NibbleKit services that link to it, including, where applicable:

A NibbleKit-powered service may be branded for a participating Merchant. Section 9 explains how responsibility is divided where a Merchant or another provider selects additional technology.

This policy should be read with the NibbleKit Privacy Policy.

2. What Are Cookies and Similar Technologies?

A cookie is a small file that a website asks a browser to store on a device.

Cookies are only one type of storage or access technology. This policy also covers technologies such as:

These rules can apply to mobile apps and connected devices as well as conventional websites.

Device permissions, such as notification, location, camera or photo permissions, may also affect how an app accesses information or device functions. Permissions are explained at the point they are requested and can normally be managed in the device settings.

3. How We Classify These Technologies

We classify storage and access technologies according to their actual purpose.

3.1 Communication technologies

These are used solely to transmit a communication over a network.

3.2 Strictly necessary technologies

These are essential to provide an online service or function that the user has requested.

Depending on the relevant service, this may include technology needed to:

A technology is not treated as strictly necessary merely because it is useful to us, generates revenue or improves general marketing performance.

3.3 Statistical technologies

A technology may be used without prior consent under the applicable statistical-purpose exception only where all required conditions are met.

Where we rely on this exception:

If those conditions are not met, we will obtain consent before using the technology.

3.4 Appearance or functionality preference technologies

A technology may be used under an applicable appearance or functionality exception where its sole purpose is to adapt the appearance or operation of the service to a preference selected by the user.

Where we rely on this exception, we will provide clear information and a simple and free way to object.

Unless another lawful exception clearly applies, we will obtain consent before using technology for purposes such as:

We will not treat silence, inactivity, continued browsing, use of a pre-ticked box or acceptance of general Terms and Conditions as consent to an optional technology.

4. Current Technology Register

The exact storage keys and provider cookies can vary by device, browser, app version, environment and Merchant configuration. The current public register is:

Technology or providerWhere usedPurposeConsent positionTypical durationUser control
Firebase Authentication and NibbleKit session storageCustomer app, Merchant portal, admin tools and webviewsAuthenticate users and maintain secure signed-in sessionsStrictly necessary for signed-in useSession, logout or provider-configured token lifetimeSign out, delete account where applicable, or clear browser/app storage
Firebase email verification and password-reset action codesVerification and reset pagesComplete the user's requested security actionStrictly necessarySingle use or provider-configured expiryDo not use the link, or request a new link
Basket, checkout and order-state storageCustomer ordering and checkoutMaintain basket, checkout, payment and order-status workflowsStrictly necessary for orderingSession, local app storage or server-side order lifecycleClear basket, sign out, clear browser/app storage or delete account where applicable
Firebase, Google Cloud and hosting security logsPublic pages, apps, APIs and admin toolsTransmit requests, protect accounts, detect abuse and diagnose faultsCommunication/strictly necessary and legitimate security useProvider-configured operational retentionCannot be disabled without affecting service security
Flutter secure/local storageMobile and desktop appsStore authentication state, essential app settings and requested preferencesStrictly necessary or preference-based depending on featureUntil logout, app removal, account deletion or configured expiryApp settings, device settings, logout or app removal
Firebase Cloud Messaging and local notification tokensMobile apps and supported devicesDeliver account, order, security and service notifications where enabledDevice permission plus service needUntil token replacement, logout, app removal or provider expiryApp and device notification settings
Stripe PaymentSheet, PaymentIntent and wallet-provider technologiesCheckout/payment flowProcess payments, pre-authorisations, fraud checks, refunds and disputesNecessary for selected payment method; Stripe/provider terms also applyProvider-controlledChoose another enabled payment method where available
Google Places, Maps or postcode/address providers where enabledAddress lookup, delivery areas and route featuresProvide requested address, postcode, map or route functionalityNecessary for requested feature or subject to device/browser permission where applicableProvider-controlledEnter address manually where available or manage location permissions
StackEdit stylesheet and content-delivery resources for policy pagesPublic policy pagesRender the policy page stylingContent delivery, not advertisingBrowser/provider cache durationBrowser controls
Analytics, advertising or cross-service trackingNot part of the core NibbleKit demo unless separately enabledMeasurement, advertising or retargeting only if introducedPrior consent where PECR requires itProvider/configuration-specificConsent controls before use

5. Current Use of Advertising and Cross-Service Tracking

NibbleKit platform and demo services that link to this policy do not use storage or access technologies for behavioural advertising, retargeting, cross-site tracking or cross-app advertising measurement.

If advertising, retargeting or cross-service tracking technologies are introduced later, they must be identified in the register above, remain disabled unless and until the user gives valid consent, and be capable of rejection without preventing access to the core NibbleKit service.

No advertising or cross-service tracking technology may be introduced merely by changing a third-party tag manager or provider configuration without first updating the register, carrying out the required assessment and implementing the necessary consent control.

Where consent is required:

Users can manage their choices through the privacy controls, cookie banner, app permission settings or device/browser settings provided in the relevant service; if no optional technologies are enabled, no separate preference control may be shown.

Where we rely on the statistical-purpose or appearance exception, users can object free of charge through the privacy controls, cookie banner, app permission settings or device/browser settings provided in the relevant service; if no optional technologies are enabled, no separate objection control may be shown.

Declining or objecting to optional technologies will not prevent access to the core Services. A particular optional feature may not work where it genuinely depends on the technology that the user has declined.

Deleting the technology used to remember a privacy choice may result in the choice being requested again.

7. Browser and Device Controls

Most browsers allow users to:

Mobile operating systems and device settings may allow users to:

Browser and device controls are supplementary. They do not replace a consent, rejection or objection mechanism that DarkByte is required to provide.

Blocking strictly necessary technologies may prevent account authentication, verification, basket, checkout, security or other requested functions from working correctly.

8. Mobile Applications and Webviews

The fact that a mobile application does not use conventional browser cookies does not mean that no storage or access technology is used.

A NibbleKit mobile application may use:

Every active technology must be assessed according to its actual purpose and listed in the register where appropriate.

Where a web page is displayed inside an app webview, the technologies used by that page remain subject to this policy and the applicable privacy choices.

The app will request operating-system permissions at an appropriate point and explain their purpose. A permission may be refused or withdrawn through the app or device settings, although the related feature may then be unavailable.

9. Merchant-Branded and Merchant-Controlled Services

NibbleKit is a white-label platform. A service may display a Merchant's brand while using technology selected or operated by DarkByte, the Merchant or both.

Responsibility depends on who decides to deploy and configure the technology and for what purpose.

DarkByte is responsible for providing accurate information and appropriate controls for storage or access technologies that DarkByte selects, configures or controls on a service linking to this policy.

A Merchant is responsible for technologies that it independently selects or instructs DarkByte to deploy for the Merchant's own purposes, such as Merchant-controlled:

Where both DarkByte and a Merchant influence a technology's purposes or configuration, the parties must assess and document their respective responsibilities. The user-facing notice must identify the relevant parties and must not simply refer vaguely to unnamed "partners".

A Merchant may not introduce optional tracking into a NibbleKit-powered service without first:

DarkByte remains responsible for technologies that DarkByte itself selects or configures. A contractual allocation to a Merchant does not remove obligations that apply directly to DarkByte.

A NibbleKit service may embed or interact with a payment, mapping, video, support or other third-party service.

Where a third-party component is embedded into a NibbleKit service, it may store or access information on the user's device. The relevant provider, purpose, duration and choice must be identified in the technology register.

A simple link to an external website does not by itself mean that the external website's technologies are used before the user follows the link. Once a user follows an external link, the destination service's own privacy and technology notices apply.

Payment providers, app stores and device operating-system providers may independently use technologies under their own terms. Their independent activities should be explained at the point they become relevant.

We do not accept responsibility for a third party's independent website merely because NibbleKit provides a link to it. This does not remove any responsibility DarkByte has for choosing, embedding, configuring or disclosing a third-party component within the Services.

11. Personal Data and the Privacy Policy

Some storage and access technologies involve processing personal data, such as:

Where personal data is involved, the NibbleKit Privacy Policy explains:

A PECR exception does not remove obligations under data-protection law. Where consent is required under PECR and personal data is processed, we will also ensure that the associated processing has an appropriate UK GDPR basis.

Consent to one purpose does not amount to consent to a materially different purpose.

12. How Long Technologies Remain Active

The duration of each technology is stated in the register.

We determine an appropriate duration by considering:

We do not keep a persistent technology active merely because its provider uses that duration by default.

We review persistent technologies and their configured durations periodically.

13. Audits and New Technologies

We will review the Services periodically to identify:

Before deploying a new technology, we will determine:

A provider's automatic classification of a technology will not be accepted without reasonable review.

14. Privacy Rights and Data-Protection Complaints

Questions or requests concerning personal data used through these technologies may be submitted through the NibbleKit Privacy Rights and Data Protection Complaints page or sent to support@nibblekit.com.

Where DarkByte is the relevant controller, we will:

Where a complaint concerns a technology independently controlled by a Merchant, we may forward the complaint to the Merchant or direct the complainant to the appropriate Merchant contact. We will explain the action taken where reasonably possible.

This does not affect the right to complain to the Information Commissioner's Office.

15. Changes to This Policy

We may update this policy where:

The last-updated date and version number will be shown at the top of the page.

Where a change introduces a new consent-based purpose, we will not treat an earlier choice as consent to that new purpose. We will request a new choice where required.

Previous material versions are available on reasonable request from support@nibblekit.com.

16. Contact Details

NibbleKit is operated by:

Paul Hepple, a sole trader trading as DarkByte Creations 152 Lindhurst Road, Barnsley, S71 3DG Email: support@nibblekit.com