Cookie notice

Cookie and local storage notice.

This site writes three things to your browser. Two are ours and one belongs to Cloudflare. There is no analytics cookie, no advertising pixel and no cross-site tracker, and this page lists what exists rather than what a template assumed would exist.

Version 1.0 · Effective 18 August 2026

Three items, none of them advertising

cx-theme remembers your colour scheme, cx-consent remembers your answer to the banner, and __cf_bm belongs to Cloudflare and tells a person from a script. Nothing else is written to your browser by this site.

1. The complete list

Every key below is written by code in this site's single script file or by Cloudflare's edge. If a key is ever added, this table is updated in the same change.

NameTypeSet byCategoryWhat it doesHow long it lasts
cx-theme Local storage First party (this site) Functional Remembers whether you chose the light or the dark colour scheme, so the site does not flash the wrong one on your next visit. Persistent — stays until you clear it or change the setting
cx-consent Local storage First party (this site) Strictly necessary Records the choice you made in the cookie banner, and the moment you made it, so the banner is not shown again and so the desk can evidence what you consented to. Stores a small JSON object: whether analytics was accepted, a timestamp, and a version number. Persistent — stays until you clear it or change your choice
__cf_bm Cookie Third party (Cloudflare, Inc.) Strictly necessary Cloudflare bot management. Distinguishes a person from an automated script so that the forms and the rate endpoint are not abused. Set by Cloudflare at the edge, if present on the plan serving this site — the desk does not set it, cannot read its contents and cannot use it to identify you. 30 minutes

Local storage is not a cookie. It is a browser store that is never sent to a server with a request, which is why the two items the desk sets cannot be used to follow you anywhere. Clearing site data removes both.

2. What each item holds, in detail

cx-theme

Remembers whether you chose the light or the dark colour scheme, so the site does not flash the wrong one on your next visit.

Personal information: No personal information. A single value: "light" or "dark".

cx-consent

Records the choice you made in the cookie banner, and the moment you made it, so the banner is not shown again and so the desk can evidence what you consented to. Stores a small JSON object: whether analytics was accepted, a timestamp, and a version number.

Personal information: No name, email or identifier. The timestamp is a record of your consent, which POPIA requires the desk to be able to demonstrate.

__cf_bm

Cloudflare bot management. Distinguishes a person from an automated script so that the forms and the rate endpoint are not abused. Set by Cloudflare at the edge, if present on the plan serving this site — the desk does not set it, cannot read its contents and cannot use it to identify you.

Personal information: Cloudflare processes the request metadata needed for bot detection. It is not used for advertising or cross-site profiling.

3. What this site does not set

No analytics cookie. No advertising or remarketing pixel. No social media tracking tag. No cross-site identifier, fingerprinting script, session replay or heatmap tool. No third-party font, script or image loaded from another company's domain, other than the bot mitigation described below.

No analytics or marketing script loads before consent. At the date of this notice the site loads no analytics beacon at all. If privacy-friendly, cookieless analytics is added later, the script will be loaded only after a positive choice is recorded in cx-consent, and this notice will be updated with its name and behaviour before it goes live.

The site's rate data is fetched from the desk's own endpoint on its own domain. Nothing about that request is shared with the venues the data originates from.

4. Cloudflare Turnstile on pages with a form

Pages that carry a form load Cloudflare Turnstile, which distinguishes a person from a script without asking you to identify traffic lights. It is loaded only on those pages; the rest of the site makes no third-party request at all.

Turnstile is a security control rather than an analytics tool, and it falls under strictly necessary processing. Cloudflare may set short-lived security values in the course of serving the challenge. Any such value is Cloudflare's, is used only to decide whether a request is automated, and is not read by the desk. The only Cloudflare cookie the desk is aware of on this site is the one listed in the table above.

5. Server logs, which are not cookies

Serving a page produces a log line at the edge: the IP address the request came from, the user agent string, the URL requested, the time and the response status. That is how every web server on the internet works, and it happens whether or not you accept anything in the banner.

Those logs are held by the hosting provider for a short operational period, are used for security and diagnostics, and are not linked to a client record. They are described here because a cookie notice that ignores server logs is telling you only half of what happens when you load a page.

6. The law that applies

South Africa has no dedicated cookie statute. Where a cookie or storage key contains personal information, the Protection of Personal Information Act 4 of 2013 applies to it, and the desk relies on section 11(1)(f) — legitimate interests — for strictly necessary items and on section 11(1)(a) — consent — for anything optional. Section 45 of the Electronic Communications and Transactions Act 25 of 2002 governs unsolicited commercial communication and is not engaged by anything on this list.

The practical result is that strictly necessary items are set without asking, because the site cannot work correctly without them, and nothing else is set at all until you say so.

From this site. Scroll to the bottom of any page and use the Cookie preferences link in the footer. The banner reopens with your current choice shown; change it and it is saved immediately to cx-consent.

By clearing site data. Deleting this site's data in your browser removes cx-theme and cx-consent. The banner will appear again on your next visit, because the record of your previous answer is the thing you deleted.

From your browser. Every major browser lets you block or delete cookies and site data for a specific site: in Chrome and Edge under Settings → Privacy and security → Cookies and site data; in Firefox under Settings → Privacy & Security → Cookies and Site Data; in Safari under Settings → Privacy → Manage Website Data. Blocking storage for this site entirely is supported — the theme toggle will simply forget your choice between visits, and the consent banner will appear on every page load, because both need somewhere to write their answer.

Withdrawing consent has no effect on your ability to use the site, to request a quote or to trade. Nothing here is a condition of service.

8. Do Not Track and Global Privacy Control

The site sets no tracking storage, so a Do Not Track header or a Global Privacy Control signal changes nothing about how it behaves — there is nothing to switch off. This is stated plainly rather than claimed as a feature.

9. Questions, complaints, and version

Questions about this notice go to the Information Officer at support@conexus-crypto.com. How your personal information is handled more broadly is set out in the privacy notice, and you may complain to the Information Regulator at any time: Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 · PO Box 31533, Braamfontein, 2017 · telephone 010 023 5200 · general enquiries enquiries@inforegulator.org.za · POPIA complaints POPIAComplaints@inforegulator.org.za · PAIA complaints PAIAComplaints@inforegulator.org.za · inforegulator.org.za

Version 1.0. Effective 18 August 2026. Last reviewed 18 August 2026. Next scheduled review 18 August 2027, or immediately if a new key is added to the site.

Change your mind whenever you like.

The consent control sits in the footer of every page on this site, and clearing cx-consent in your browser resets the answer entirely. Nothing on this site tracks you across other sites either way.

Investing in crypto assets may result in the loss of capital, as the value is variable and can go up as well as down. A crypto asset is not legal tender and does not fall within the National Payment System Act. Conexus Crypto provides an exchange service only and does not provide financial, investment, legal or tax advice.
WhatsApp Request a quote