Skip to main content

Pay on delivery in Lagos · Verified vendors · Nationwide delivery

Legal

Cookie policy

Four cookies, all of them either the sign-in itself or a preference you set. What each one does, and what breaks if you block it.

Written in British English. Your rights over your data are in the privacy policy

Pre-launch draft — not yet reviewed by a lawyer

This page describes the cookies the marketplace actually sets, checked against the code that sets them. It has not been settled by a Nigerian data protection lawyer, and it carries no effective date until that review has happened. Treat it as an accurate technical description rather than as approved legal text.

The short version

Three cookies keep you signed in and one remembers your language. Nothing here advertises to you, measures you, or follows you to another site — which is why this marketplace has no cookie banner. The privacy policy covers everything beyond cookies.

1.What a cookie is here

A cookie is a small piece of text your browser stores for a site and sends back on the next request. It is how a website recognises that two page loads came from the same person.

BuildLink uses them for two things and no others: keeping you signed in, and remembering the language you chose. There is no advertising cookie on this site, no analytics cookie, no third-party tracker, and no pixel belonging to a social network or an ad exchange.

That is why you are not asked to accept anything. A consent banner exists to gather permission for tracking; there is no tracking here to permit, and a banner that appeared anyway would be theatre.

2.The cookies that sign you in

Three cookies carry your session. They are strictly necessary: they are not an accessory to signing in, they are the mechanism, and the marketplace has no way to keep you signed in without them.

mkt_at
Your access token, and the credential every request is authorised with. HTTP-only, so no script running on the page can read it. It expires after about fifteen minutes and is renewed silently.
mkt_rt
The refresh token that renews the one above, so a session survives longer than fifteen minutes without your password being held anywhere. HTTP-only, and sent only to the sign-in routes rather than to every page.
mkt_session
A marker whose entire value is the character "1". It says that a session exists, so a page can render the signed-in header without asking the server. It carries no token and grants no access — the API verifies the real credential on every request regardless.

Signing out clears all three. Blocking them leaves the catalogue fully browsable and makes signing in impossible, because they are the sign-in.

3.The cookie that remembers a choice you made

One cookie stores a preference, and only because you set it yourself using the language switcher in the header.

buildlink_locale
The language you picked. It holds a language code and nothing else — no identifier, no history, nothing that could be tied back to you. It lasts a year, so a returning visitor is not asked twice.

The same value is also written to your browser’s local storage as a fallback, under the same name. That is browser storage rather than a cookie: it is never sent to a server, and clearing site data removes it.

Blocking it costs you nothing except the setting — the site opens in British English each time instead of the language you chose.

4.What we do not set

Stated positively so it can be checked against the site rather than taken on trust. This marketplace does not set:

  • analytics or measurement cookies, of our own or anybody else’s
  • advertising, retargeting or audience cookies
  • social network pixels or share-button trackers
  • cross-site identifiers, fingerprinting scripts, or anything that follows you to another site
  • a consent-management cookie, since there is no consent to manage

The four cookies above are the complete list. If that ever changes, this page changes with it, and anything that profiles a visitor would need your consent before it was set at all.

5.Third parties, and where their cookies live

Paying for an order hands you to a payment provider to enter your card details. That provider is a separate company on its own domain, and it sets its own cookies under its own policy while you are there — which is also why your card details never reach this marketplace.

A cookie set on another company’s domain cannot be read by this one, and vice versa. What that provider stores is governed by their cookie policy, not this one.

Nothing else on the marketplace embeds a third party that could set a cookie: no video player, no map, no comment widget, no advertising slot.

6.Refusing or deleting them

Every browser can block cookies, delete them for one site, or clear them all, usually under Settings, then Privacy. Private or incognito browsing discards them when the window closes.

The trade-off is worth being plain about, because "block all cookies" is easy to click and its consequence is not obvious:

  • Blocking the three session cookies: you can browse the catalogue and open any listing, but you cannot sign in, place an order, or see your orders.
  • Blocking the language cookie: everything works and the site opens in British English every time.
  • Deleting them after signing in: you are signed out, and nothing else is lost — your account and your orders live on the server, not in the cookie.

None of these cookies can be cleared by us on your behalf. They sit on your device and are yours to remove.

7.Questions about this page

Write to support@buildlink.ng and put "Cookie policy" in the subject line.

For anything wider than cookies — what personal data is held, who receives it, and how to have it corrected or deleted — the privacy policy sets out the routes and the regulator you can escalate to.

Want the rest of the picture?

The privacy policy covers what personal data is held and who receives it. The terms cover the agreement itself.