Complete inventory maintained for GDPR Article 5(3) and POPIA compliance. Strictly necessary cookies cannot be disabled. Analytics require consent.
Below is a complete inventory of all cookies and similar technologies we use. This list is maintained to comply with GDPR Article 5(3) and POPIA openness requirements.
Strictly Necessary Cookies (First-Party & Essential Third-Party)
These cookies are essential for the platform to function securely. They manage user authentication, platform state, and financial fraud prevention. They cannot be disabled.
| Cookie Name | Purpose | Provider | Duration |
|---|
| sb-access-token | Core Supabase authentication and secure session state. | Registra / Supabase | Session |
| sb-refresh-token | Core Supabase authentication and secure session state. | Registra / Supabase | Session |
| payment_session | Transaction state management and secure checkout routing. | Payment Gateway (Peach Payments / PayFast) | Session |
| fraud_prevention | Device fingerprinting to prevent payment fraud and tampering. | Payment Gateway (Peach Payments / PayFast) | 1 year |
| registra_consent | Stores your explicit cookie consent choice. | Registra | 1 year |
(Note: Exact payment cookie names may vary slightly depending on our final integration with Peach Payments or PayFast, but their purpose and strict necessity remain identical).
Analytics Cookies (Third-Party)
These cookies require your explicit consent. They are only set after you click "Accept All" on the cookie banner. They are never set on authenticated breeder dashboard pages or the client portal.
Note: To ensure strict POPIA compliance, Registra forces a 12-month expiration limit on all analytics tracking, overriding default third-party limits.
| Cookie Name | Purpose | Provider | Duration |
|---|
| _ga | Google Analytics 4 client ID. | Google LLC | 12 months |
| _ga_* | GA4 session state. | Google LLC | 12 months |
| _gid | GA4 daily user identifier. | Google LLC | 24 hours |
| _gat | GA4 request throttling. | Google LLC | 1 minute |