Cookie Policy
Last updated: September 2026
This Cookie Policy explains how Nova Rides Limited ("Nova Rides", "we", "us") uses cookies and similar technologies on novarides.ng and related apps. It should be read with our Privacy Policy.
Manage your choices
You can review or change optional cookie categories at any time. Strictly necessary cookies remain enabled so sign-in, security, and bookings keep working.
1. What are cookies?
Cookies are small text files stored on your device. We also use related storage such as localStorage and sessionStorage where needed for the same purposes described below.
2. How we use them
We group technologies into four categories. Optional categories only run after you allow them in the consent banner or preferences panel.
Strictly necessary
Required for Nova Rides to work securely. This includes sign-in, session protection, fraud prevention, and core booking features. These cannot be turned off.
Functional
Remembers language and the country marketplace you are browsing, plus non-essential preferences such as theme (light, dark, or system).
Analytics
Helps us understand how people use Nova Rides (page views, journeys, and product usage) so we can improve the service. Nova Rides does not currently load analytics tools in the browser. If we add them later, they will not run until you allow this category.
Marketing
Supports first-party share attribution so we can understand how listings are discovered. No advertising pixels or third-party marketing trackers are loaded today. Marketing cookies only run when you allow this.
3. Cookies and storage we use
The list below reflects technologies currently implemented in Nova Rides. Retention and names may change as we ship product updates; material changes to consent categories will prompt a new choice.
Strictly necessary
| Name | Type | Purpose |
|---|---|---|
| nova_token | cookie | Authenticated session (HttpOnly JWT).HttpOnly, SameSite=Lax, Secure in production, 7-day max age. |
| Supabase Auth cookies (OAuth PKCE) | cookie | Google OAuth / PKCE flow via @supabase/ssr.Set only during OAuth; required to complete sign-in. |
| nova_waitlist_dash | cookie | Waitlist dashboard session.HttpOnly, SameSite=Lax, Secure in production. Cleared on waitlist dashboard sign-out, marketplace logout, and account deletion. |
| nova_active_business_id | cookie | Active business context for multi-business hosts.HttpOnly via auth cookie options. |
| nova_consent | cookie | Stores your cookie preference decision (versioned).Readable by the browser so preferences apply on every page. SameSite=Lax, Secure in production. |
| nova_consent | localStorage | Mirror of consent decision for reliable client reads. |
| Supabase Auth storage | localStorage | OAuth / PKCE session bridge for Google sign-in. |
| nova_oauth_next | sessionStorage | Post-OAuth return path within the app. |
| nova-intro-seen | sessionStorage | Skips the intro splash for the rest of the browser tab session.Session-only UI state (not cross-session). Cleared when the tab/session ends. Not used for tracking. |
| nova_rental_auth_* | sessionStorage | Offline cache of guest rental authorization for police-stop verification.Expires after rental end (+48h buffer) or 7 days from write; cleared on logout and when the rental is inactive. |
Functional
| Name | Type | Purpose |
|---|---|---|
| nova-theme-preference | localStorage | Remembers light / dark / system theme.Persisted only when functional consent is granted. |
| nova_locale | cookie | Remembers your language for site chrome (header and footer).Kept if you turn off other functional cookies, so the language you chose stays available. |
| nova_locale | localStorage | Mirror of language preference for reliable client reads.Not cleared when functional consent is withdrawn. |
| nova_market | cookie | Remembers the country marketplace you are browsing (Nigeria today).Kept if you turn off other functional cookies. Independent from language. |
| nova_market | localStorage | Mirror of marketplace preference for reliable client reads.Not cleared when functional consent is withdrawn. |
Analytics
No analytics cookies or browser analytics SDKs are active in Nova Rides today. This category is reserved for future tools and will stay off until you opt in.
Marketing
| Name | Type | Purpose |
|---|---|---|
| nova_share | cookie | First-party share / listing attribution token.Only set when marketing consent is granted. Max age 30 days. |
| nova_share_token | localStorage | Share attribution mirror (local). |
| nova_share_token | sessionStorage | Share attribution mirror (session). |
4. Related third-party services
Some features rely on third parties. Where those parties set their own cookies on their domains (for example after you are redirected to pay), their policies also apply.
Paystack / Flutterwave
Payment checkout via redirect to the payment provider. No in-app payment SDK cookies. Cookies may be set on the provider domain after redirect. Treated as necessary for the feature it supports.
Google OAuth
Optional Google sign-in. Uses Google frames allowed by CSP during OAuth. Treated as necessary for the feature it supports.
YouVerify
Identity and licence verification (server-side API). No client tracking script. Separate KYC consent is collected in-product. Treated as necessary for the feature it supports.
Sentry (server envelope)
Server-side error reporting when a DSN is configured. No browser Sentry SDK today. A future client SDK should be registered under analytics or necessary ops policy. Treated as necessary for the feature it supports.
OpenStreetMap links
External map links for trip location (no Mapbox/Google Maps JS SDK). Treated as necessary for the feature it supports.
Nova Rides does not currently load third-party analytics or advertising pixels in the browser. If we add them later, they will be registered under Analytics or Marketing and will not run until you consent to that category.
5. Your choices
Use to accept all, reject optional cookies, or set categories individually. You can also control cookies through your browser settings. Blocking strictly necessary cookies may prevent sign-in, payments, or bookings from working.
6. Contact
Questions about cookies or privacy: use Help & support or email support@novarides.ng.