6membership6membershipA 6clement Joshua service™Legal & Trust Center
Cookies · Legal document

Cookie and Tracking Technologies Policy

Detailed terms governing applications, membership relationships, payment review, benefits, conduct, verification and status.

Version 0.9-draftUpdated 6 August 202615 sections69 detailed clauses
Statusdraft
Effective dateNot yet effective
Change typeinitial publication
ReacceptanceNot required yet
Before you continue

Understanding this document

This Cookie and Tracking Technologies Policy explains how 6membership may store information on, or access information from, a visitor’s browser, device or terminal equipment.

The word “cookie” is used broadly in parts of this Policy for convenience. The rules may also apply to local storage, session storage, pixels, software development kits, tags, scripts, identifiers and comparable storage or access technologies.

6membership is a membership service operated by 6clement Joshua under the laws of the Federal Republic of Nigeria, with mandatory local consumer and privacy rights preserved where they apply.

This Policy must be read with the Privacy and Data Protection Notice, Country-Specific Privacy Rights Addendum, Electronic Communications Consent and Third-Party Service Providers List.

This Cookie Policy is part of the application legal-disclosure framework, but acknowledging or accepting this Policy does not itself consent to optional analytics, advertising, profiling or other non-essential storage and access technologies. Any optional technology consent must be requested separately through the cookie-preference interface where consent is required.

The actual technologies used by the production website must remain consistent with the current cookie inventory and consent interface. This Policy does not authorise an undisclosed technology merely because a general category is described.

Optional technologies must not be activated silently

Where consent is legally required, optional analytics, advertising, profiling or comparable technologies must remain disabled until the visitor makes a valid choice. Accepting this Cookie Policy as an application disclosure is not that optional consent. Rejecting optional technologies must not disable the ordinary website unless the affected feature genuinely requires that technology.

Scope

Who these Terms apply to

01

Visitors using the 6membership website.

02

Visitors opening the Legal & Trust Center or standalone policy pages.

03

Applicants beginning, saving or submitting a membership application.

04

Applicants uploading photographs or supporting documents.

05

Persons using payment, email OTP, application-status or membership-verification functions.

06

Approved members accessing a future membership portal.

07

Parents, guardians and authorised representatives using the service.

08

Visitors interacting with embedded content or an authorised third-party service.

09

Persons managing cookie and tracking preferences.

Jump toDocument sections
1

Meaning and scope

The technologies covered by this Policy and the devices to which it may apply.

1.1

What a cookie is

A cookie is a small piece of information that a website may ask a browser to store and return during a current or later visit.

Cookies can support functions such as maintaining a session, remembering a preference, protecting a form, recording consent or measuring website performance.

A cookie may be temporary and expire when the browser closes, or persistent and remain until its stated expiry, deletion or replacement.

Plain-language meaning

A cookie is a small browser record. Some cookies make a website work; others may remember choices or measure how the website is used.

1.2

Similar technologies

This Policy also covers technologies that store information on, or access information from, a browser, phone, computer or other terminal equipment even where the technology is not technically called a cookie.

Examples may include local storage, session storage, pixels, tags, scripts, device identifiers, embedded resources, link identifiers and software development kits.

The legal treatment of a technology depends on what it does, not merely the name assigned to it.

1.3

First-party and third-party technologies

A first-party technology is ordinarily set or controlled through the 6membership website domain.

A third-party technology may be set, accessed or controlled by another provider whose service is integrated into the website.

A third-party technology may be governed both by this Policy and by the provider’s own privacy or cookie information.

1.4

This Policy is not permission to deploy every category

The categories described in this Policy establish rules for technologies that may be used.

They do not mean that every listed category is currently active.

6membership must maintain an accurate production inventory and update the consent interface when a technology is added, removed or materially changed.

Related documents
Privacy and Data Protection NoticeThird-Party Service Providers List
2

Technology-use principles

Standards that apply before a cookie or similar technology is introduced.

2.1

Necessity and proportionality

A technology should be introduced only where it supports a defined and legitimate operational purpose.

6membership should prefer a less intrusive method where it can reasonably achieve the same purpose.

A technology must not collect substantially more information, operate for substantially longer or reach more people than reasonably required for its purpose.

2.2

Transparency

Visitors should receive clear and accessible information about the relevant technology categories, purposes, providers and available controls.

Important information must not be hidden only inside a difficult-to-find policy while the consent interface gives no meaningful explanation.

Short banner wording may link to this detailed Policy, but the banner must still communicate the essential choice.

2.3

Meaningful choice

Where consent is required, the visitor must have a genuine opportunity to accept, reject or customise optional technologies.

The design must not use misleading colours, repeated obstruction, confusing labels or unequal effort to pressure acceptance.

Acceptance of the Membership Terms, this Cookie Policy or another application disclosure must not be used as a substitute for a separate optional cookie or tracking choice.

Closing a banner, continuing to browse, inactivity or using a pre-selected optional category will not be treated as affirmative consent where affirmative consent is required.

2.4

Accountability

6membership may maintain records of consent versions, technology categories, visitor choices, timestamps and changes.

The website should be tested to confirm that optional technologies do not activate before the required choice.

Material provider or configuration changes should trigger review of this Policy and the consent mechanism.

3

Technology categories

How 6membership classifies technologies according to purpose.

3.1

Strictly necessary

Strictly necessary technologies support a function that is essential to provide the website, security or service expressly requested by the visitor.

Examples may include maintaining a secure session, routing a request, preventing cross-site request forgery, recording cookie choices, supporting load balancing or protecting an application form from abuse.

A technology is not strictly necessary merely because it is commercially useful, convenient for analytics or preferred by a provider.

Example

A technology that remembers that a visitor selected “necessary only” may be required to respect that preference and avoid repeatedly asking during every page load.

3.2

Preferences and functionality

Preference technologies remember optional choices such as interface settings, display preferences, language or an enhanced feature.

Some preference functions may be requested directly by the visitor and qualify for an applicable exception; others may require consent depending on the technology, jurisdiction and purpose.

6membership will not automatically classify every convenience feature as strictly necessary.

3.3

Analytics and performance

Analytics technologies may help measure page use, navigation paths, errors, performance, device categories or aggregated usage trends.

Analytics data may include an online identifier, approximate location, referring page, viewed page, event time, device information and interaction events.

Where applicable law requires consent for analytics storage or access, analytics technologies will remain disabled until consent is given.

No automatic analytics exception

Describing analytics as privacy-friendly or aggregated does not automatically make consent unnecessary. The actual technology, configuration and applicable law must be assessed.

3.4

Marketing, advertising and profiling

Marketing technologies may be used to measure campaigns, create audiences, personalise advertising, link activity across services or determine whether an advertisement led to an application.

These technologies can create a higher privacy risk because they may track behaviour over time or across websites and services.

Marketing, cross-site tracking and advertising profiling technologies will not be classified as strictly necessary.

They will be activated only where 6membership has intentionally approved them and the required consent or other legal conditions are satisfied.

3.5

Security and fraud prevention

Security technologies may help detect repeated malicious submissions, suspicious sessions, automated abuse, altered requests, compromised devices or attempts to evade restrictions.

A security purpose does not provide unlimited permission to track visitors.

The technology must remain proportionate to the identified threat and should avoid unrelated behavioural profiling.

3.6

Payment and checkout technologies

Flutterwave is the selected production payment integration for 6membership. When a visitor opens or completes the authorised Flutterwave checkout, Flutterwave may use session, fraud-prevention, authentication, transaction and security technologies within its own payment environment.

Flutterwave and participating financial institutions may independently determine some of their processing and technology choices under their own legal responsibilities.

6membership will identify Flutterwave accurately at checkout and through the Third-Party Service Providers List. 6membership will not represent technologies controlled solely within Flutterwave's environment as though they were first-party 6membership cookies.

Related documents
Payments, Taxes, Refunds, Chargebacks and Renewals PolicyThird-Party Service Providers List
4

Current and planned use

How the live production website must describe technologies accurately.

4.1

Production inventory

6membership will maintain an internal inventory of technologies used by the production website.

The inventory should record the name, provider, category, purpose, information handled, duration, first-party or third-party status and consent requirement.

The public cookie settings or inventory may use shorter descriptions while linking to this detailed Policy.

4.2

No fabricated inventory

6membership will not claim that a named cookie or provider is active unless the production website actually uses it.

A planned analytics, advertising or preference technology must not be presented as currently active before implementation.

Similarly, a removed technology should be removed from the public inventory within a reasonable operational period.

4.3

Launch position

The production launch baseline is necessary-only operation: the website should use only the minimum technologies reasonably required for security, website delivery, application processing, consent management and an expressly requested transaction unless the production inventory records an approved optional technology and the required user controls are active.

Optional analytics or marketing technologies must not be introduced merely because a standard template, framework, hosting service or third-party script includes them.

Before an optional technology is introduced, 6membership will assess its purpose, provider, configuration, retention, jurisdictional treatment and consent or objection requirements.

4.4

Periodic review

The production website may be periodically scanned and manually reviewed for unexpected technologies.

A provider update, embedded service or code deployment may introduce a technology unintentionally.

Unexpected optional technologies should be disabled or brought into the approved consent and disclosure framework promptly.

5

Consent and available choices

How visitors accept, reject, customise and later change optional technologies.

5.1

Valid consent

Where consent is required, it must be freely given, specific, informed and indicated through an unambiguous affirmative action.

The visitor must understand the relevant category or purpose before making the choice.

Consent for one purpose does not automatically authorise an unrelated purpose.

5.2

Accept and reject options

The initial consent interface should provide a clear way to accept all optional categories and a comparably clear way to reject optional categories.

A visitor should not be required to open multiple hidden screens merely to reject optional technologies when acceptance is offered immediately.

Necessary technologies may remain enabled and should be clearly identified as unavailable for optional withdrawal where they are genuinely necessary.

5.3

Customised choices

Visitors may be allowed to enable or disable preference, analytics and marketing categories separately.

A category should not combine unrelated purposes where separating them is reasonably practical and legally required.

The consent interface should explain the effect of each choice in clear language.

5.4

No pre-selected optional consent

Optional consent controls will not be selected in advance where an affirmative opt-in is required.

A visitor’s silence, inactivity, page scrolling or continued browsing will not by itself constitute affirmative consent.

5.5

Withdrawal and preference updates

A visitor may reopen cookie settings and withdraw or change optional consent.

Withdrawal should be as reasonably accessible as the original consent process.

After withdrawal, optional technologies controlled by 6membership should stop activating for future activity.

Withdrawal does not automatically remove information already processed lawfully, but retention and deletion rules will continue to apply.

5.6

Consent duration and renewal

A stored preference may expire after an appropriate period or be requested again where the purposes, providers, technology categories or applicable rules materially change.

6membership will avoid asking for consent unnecessarily on every page where a valid preference can be remembered lawfully.

5.7

Consent evidence

A consent event may record a visitor identifier, consent version, categories selected, action taken, timestamp, source page, country information and limited device or network information.

Consent records support accountability, dispute resolution and proof that a visitor’s choice was applied.

Related documents
Electronic Communications ConsentPrivacy and Data Protection Notice
5.8

Cookie Policy acknowledgement is not optional-cookie consent

The Cookie and Tracking Technologies Policy may be included among the legal documents presented during an application, checkout or policy-acceptance step.

Acknowledging that this Policy was presented, reviewed or accepted records the applicable legal disclosure. It does not switch on analytics, marketing, advertising, profiling or another optional technology.

Where optional consent is required, the cookie-preference interface must capture the relevant category or purpose separately and preserve that choice independently from the general application-policy acceptance record.

A later update to this Policy does not silently change an existing optional-cookie preference. A new consent or objection choice must be requested where the changed purpose, provider or technology requires it.

6

Strictly necessary technologies and exceptions

The limited circumstances in which consent may not be required.

6.1

Service expressly requested

An applicable exception may permit storage or access where it is strictly necessary to provide a service expressly requested by the visitor.

The exception must be interpreted narrowly.

A technology does not qualify merely because disabling it would reduce business insight, marketing performance or general convenience.

6.2

Communication transmission

An applicable exception may permit a technology whose sole purpose is carrying out or facilitating communication over an electronic communications network.

The technology must remain limited to that transmission purpose.

6.3

Security technologies

Certain security technologies may be necessary to protect a requested form, session, payment flow or verification function.

Security must not be used as a broad label for optional tracking that is not genuinely required for the protected function.

6.4

Remembering consent choices

A technology that stores a visitor’s cookie preference may be necessary to respect that choice and avoid activating rejected technologies.

The preference record should contain only information reasonably required for consent management and should use an appropriate duration.

6.5

Exception review

Every technology treated as exempt from consent should have a documented purpose and justification.

If its purpose or configuration changes, the exception must be reviewed again.

7

Local storage, session storage and browser memory

How browser storage methods other than conventional cookies are treated.

7.1

Possible uses

Local or session storage may support form progress, interface preferences, temporary state, security controls or consent choices.

Session storage ordinarily remains available for the current browser session, while local storage may persist until expiry, replacement or deletion.

7.2

Sensitive information restrictions

Highly sensitive application answers, complete identity documents, payment credentials and privileged server secrets must not be placed in ordinary browser storage merely for convenience.

Client-side storage may be viewed, altered or extracted by someone with access to the device or by malicious code.

No secret keys in browser storage

Supabase secret keys, Resend API keys, Flutterwave secret keys or access tokens, webhook-signature secrets, encryption keys and administrative credentials must remain server-only and must never be placed in browser cookies or local storage.

7.3

Application progress

Where form progress is stored locally, the visitor should be informed and the stored information should be limited.

Sensitive uploaded documents should be transferred through the approved private-storage process rather than embedded into ordinary local storage.

A visitor using a shared device should clear saved progress where appropriate.

7.4

Browser controls

Visitors may remove local and session storage through browser or device controls.

Removing necessary stored state may sign the visitor out, reset preferences or remove incomplete application progress.

8

Embedded content and third-party technologies

Technologies introduced by payment, media, security or other integrated providers.

8.1

Payment providers

Opening the authorised production payment checkout may load technologies controlled by Flutterwave.

These technologies may support authentication, fraud prevention, transaction processing, security, payment-method operation and provider compliance.

Flutterwave may act independently for part of its processing and provides its own privacy or technology information for activity within its environment.

6membership must not load a different payment provider into production without first updating the provider, payment and privacy disclosures and reviewing the technologies introduced by that integration.

8.2

Embedded media

Embedded video, maps, social content or comparable media may allow the external provider to receive device, network or interaction information.

Where the embedded content is optional and may set non-essential technologies, 6membership may delay loading it until the visitor chooses to activate it.

8.3

Security and anti-abuse services

A security provider may use limited device, network or request information to distinguish normal activity from bots, fraud or malicious traffic.

The provider and configuration must remain proportionate to the security purpose.

8.4

Provider changes

When a third-party integration is introduced or materially changed, its technologies must be reviewed before production deployment.

The provider should be added to the Third-Party Service Providers List where relevant.

Related documents
Third-Party Service Providers ListSecurity, Account Access and Incident Response Policy
9

Analytics and performance measurement

Requirements applying before optional measurement tools are enabled.

9.1

Permitted measurement purposes

Approved analytics may be used to understand website reliability, page performance, navigation problems, conversion steps and aggregated usage patterns.

Analytics must not be used to create secret eligibility, creditworthiness or membership-worthiness profiles.

9.2

Privacy-focused configuration

Where reasonably available, analytics should use data minimisation, shortened retention, restricted access, limited event collection and reduced cross-service linking.

Unnecessary capture of application answers, document names, email addresses, payment references or Membership IDs in analytics URLs or event labels must be prevented.

9.3

Consent where required

Where applicable storage, access or data-protection rules require consent, analytics will not activate until the visitor opts in.

The analytics category must stop loading after consent is withdrawn, subject to technical processing already completed.

9.4

Operational logs versus analytics

Short-lived server logs used to secure, diagnose and deliver a requested service are not automatically treated as optional analytics.

However, operational logs must still be limited, protected and retained according to their purpose.

Related documents
Data Retention, Deletion and Records Policy
10

Marketing and advertising technologies

Restrictions on promotional tracking, audiences and campaign measurement.

10.1

No default marketing tracking

Marketing technologies will not be enabled by default merely because the website is publicly available.

A marketing provider must be assessed and deliberately approved before its code is added to production.

10.2

Possible purposes

Where implemented, marketing technologies may measure campaigns, prevent repeated advertisements, attribute applications or create advertising audiences.

The banner and detailed settings must identify the relevant purpose sufficiently clearly.

10.3

Sensitive membership events

Application answers, identity-document activity, payment review, guardian status, compliance review and private membership consideration must not be transmitted to an advertising provider as marketing events.

URLs, page names and event labels should be designed to avoid exposing sensitive application details.

10.4

Withdrawal and audience removal

Withdrawing marketing consent should prevent future activation of controlled marketing technologies.

Where technically and contractually available, 6membership may request deletion or suppression of related provider identifiers.

A provider may retain limited records where independently required for security, fraud prevention or legal compliance.

10.5

Email marketing is separately governed

Cookie consent does not automatically constitute consent to receive promotional email.

Similarly, opting out of marketing email does not automatically change browser cookie preferences.

Necessary application, payment, security and policy emails may continue even where optional marketing is declined.

Related documents
Electronic Communications Consent
11

Browser settings and privacy signals

How browser controls, Global Privacy Control and comparable signals may affect processing.

11.1

Browser cookie controls

Most browsers allow visitors to view, block, limit or delete cookies and other site data.

Blocking all technologies may affect sign-in, application progress, consent memory, payment or security functions.

Browser instructions vary by provider and device.

11.2

Private or incognito browsing

Private-browsing modes may reduce or delete stored information when the private session closes.

They do not necessarily prevent the website, network provider or integrated service from processing current request information.

11.3

Do Not Track

Browser Do Not Track signals do not have one uniform legal or technical meaning across all jurisdictions and services.

6membership may honour supported signals where technically appropriate but will not describe them as replacing the required consent interface unless applicable law permits that treatment.

11.4

Global Privacy Control and recognised opt-out signals

Where applicable law requires recognition of Global Privacy Control or another valid universal opt-out mechanism, 6membership will process the signal for the activities covered by that law.

A universal opt-out signal may affect sale, sharing, targeted advertising or comparable processing without disabling strictly necessary website functions.

Related documents
Country-Specific Privacy Rights Addendum
12

Younger visitors and guardian-managed use

Additional caution where a permitted younger applicant uses the website.

12.1

Children under 13

A child under 13 must not independently submit a membership application.

The website is not designed to use advertising or behavioural-profiling technologies to target children under 13.

12.2

Optional tracking involving younger applicants

Optional analytics, marketing or profiling involving a known younger applicant requires heightened assessment and any guardian involvement required by applicable law.

6membership should avoid optional behavioural advertising within guardian-consent and younger-applicant flows.

12.3

Shared devices

A parent, guardian and younger applicant may use the same device.

Cookie choices ordinarily apply to the browser or device identifier rather than automatically identifying which household member made every visit.

A user may reopen settings where a different preference is required.

Related documents
Eligibility, Age and Guardian Consent Policy
13

Retention and security

How technology identifiers, consent records and related logs are protected and retained.

13.1

Technology duration

Each cookie or similar technology should use a duration proportionate to its purpose.

Session technologies should expire when no longer required for the session.

Persistent consent or preference technologies may remain for a reasonable period to remember the visitor’s choice.

13.2

Consent records

Consent records may be retained for the period reasonably necessary to demonstrate the choice, resolve disputes and apply updated preferences.

A new consent event may supersede an earlier event without erasing the historical evidence needed for accountability.

13.3

Security controls

Technology identifiers and related records should be protected against unauthorised access, alteration, disclosure and misuse.

Administrative access to consent configuration and tag deployment should be limited to authorised personnel.

Production secrets and privileged credentials must remain outside client-side technology records.

13.4

Deletion and expiry

Expired or unnecessary technologies should be removed or allowed to expire.

A visitor may also delete browser-stored information directly.

Server-side records linked to a technology may remain where another lawful retention purpose applies.

Related documents
Data Retention, Deletion and Records PolicySecurity, Account Access and Incident Response Policy
14

International processing and jurisdiction-specific rights

How cookie rules may differ according to the visitor’s location.

14.1

Different legal requirements

Cookie, storage, privacy and advertising rules differ between jurisdictions.

A technology permitted without consent in one location may require consent, disclosure or an opt-out in another.

6membership may adapt its consent interface according to applicable law while maintaining a clear baseline choice.

14.2

Nigeria

For Nigerian processing, the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Act General Application and Implementation Directive 2025 apply according to their scope.

The Nigerian implementation framework requires cookies and other tracking tools to comply with the data-protection principles and, except where an applicable exception applies, requires consent that is freely given, informed and specific.

The production website should present a conspicuous cookie notice or preference interface where required. A necessary technology must not be treated as exempt merely because it is operationally useful; its purpose and the information it processes must satisfy the applicable Nigerian conditions.

Where consent is required, the visitor must receive a clear and explicit way to accept or decline.

14.3

European Union and European Economic Area

Where EU or EEA storage and access rules apply, storing information on or accessing information from terminal equipment ordinarily requires clear information and valid consent unless a specific applicable exception permits the activity.

Related personal-data processing must also satisfy the applicable data-protection requirements.

14.4

United Kingdom

Where United Kingdom PECR rules apply, non-exempt storage and access technologies require the legally required consent.

Following the Data (Use and Access) Act 2025 changes, UK law recognises additional narrowly defined exceptions including qualifying statistical-purpose and appearance or functionality uses, alongside communication, strictly necessary and emergency-assistance exceptions.

Where a UK statistical-purpose or appearance exception is relied upon, 6membership must provide the required clear information and a simple, free means of objecting, and the technology must stay within the scope of that exception.

Online advertising, cross-site tracking and profiling must not be placed within an exception merely because they also provide analytics or fraud-related information.

14.5

Other jurisdictions

Some jurisdictions provide rights to opt out of sale, sharing, targeted advertising or profiling and may recognise browser-based preference signals.

Applicable rights and request methods are explained in the Country-Specific Privacy Rights Addendum.

Related documents
Country-Specific Privacy Rights Addendum
15

Updates, complaints and contact

How the Policy changes and how cookie concerns may be reported.

15.1

Policy versioning

Each published version will display a version number, last-updated date and effective date.

Material changes may include adding a new technology category, introducing behavioural advertising, changing providers or expanding the purpose of an existing technology.

15.2

Renewed consent

6membership will request a new choice where the existing consent does not reasonably cover a material change and applicable law requires renewed consent.

A change to the Cookie Policy alone must not silently expand an earlier optional-cookie consent.

A minor wording correction that does not change the purpose, provider, technology behaviour or visitor choice may not require renewed consent.

15.3

Questions and complaints

Questions about cookies, consent records or unexpected technologies may be sent to the privacy contact address.

A report should identify the page, approximate time, browser or device and the unexpected technology where known.

The visitor should not include passwords, payment credentials or unnecessary identity documents.

15.4

Regulatory rights

A visitor may contact an applicable privacy or communications regulator where the relevant law provides that right.

Using the internal contact channel first may help investigate the issue but does not remove a mandatory external right.

15.5

Policy-update framework

Publication, effective-date, notification and change-log rules are explained in the Policy Updates, Effective Dates and Change Log.

Related documents
Policy Updates, Effective Dates and Change Log
Cross-reference

Related policies

Privacy and Data Protection Notice

Explains the broader processing of personal information.

Country-Specific Privacy Rights Addendum

Describes rights that apply in particular jurisdictions.

Third-Party Service Providers List

Identifies providers that may place or support technologies.

Electronic Communications Consent

Separates website technology consent from electronic notice delivery.

Security, Account Access and Incident Response Policy

Explains security monitoring and incident procedures.

Data Retention, Deletion and Records Policy

Explains retention of consent, technical and security records.

Eligibility, Age and Guardian Consent Policy

Explains protections for permitted younger applicants.

Policy Updates, Effective Dates and Change Log

Explains material changes and renewed consent.

Official channels

Contact points

Cookie and privacy questionsprivacy@6membership.com

Cookie choices, consent records, browser-storage questions and privacy requests.

Security reportssecurity@6membership.com

Unexpected scripts, suspicious redirects, compromised sessions or malicious website activity.

General website and membership administrationadmin@6membership.com

General website and approved-membership assistance that does not require a formal privacy or security request.

Legal and regulatory correspondencelegal@6membership.com

Formal notices from authorised representatives and regulators.

6membershipA 6clement Joshua service™

© 2026 6clement Joshua. All rights reserved.