Not one. There is no document.cookie anywhere in this site, the portals or the API. No advertising pixel, no tag manager, no session cookie, nothing from a third party. This page lists every single thing we do store on your device instead, what each item is for, and how to remove it.
Most cookie pages are long because there is a lot to disclose. This one is short for the opposite reason. It is still worth reading, because "no cookies" is not the same as "nothing stored" — and the difference is the honest part.
All of it is browser localStorage on this domain, not cookies, which means it is never attached to a network request automatically and is never visible to any other site.
| Name | Why | Kept Until |
|---|---|---|
tf_session Essential | Your signed-in portal session, issued after two-factor authentication. This is what keeps you signed in between pages. | Sign out, or the session expires |
tf_key | Your account's API key, so the portal can call the API on your behalf. | Sign out |
tf_role, tf_user, tf_email, tf_status | Who you are signed in as and what your role permits, so the portal can show you the right things without asking the server on every click. | Sign out |
tf_admin_session, tf_admin_role, tf_admin_name | The equivalent for an administrator session. Only ever set on a SESPI Africa administrator's browser. | Sign out |
tf_serial, tf_device_id, tf_plan_name, tf_plan_price | Your device serial and plan, so the portal opens on the right account state. | Sign out |
tf_ref | If you arrived from a reseller's link, the reseller code, so the right partner is credited when you sign up. | Until you sign up |
tf_tickets | References for support tickets you raised without an account, so "Track a ticket" works without you typing anything. Nobody but you can read it. | Until you clear it |
tf_consent | Your answer to the question below. We have to store the fact that you answered, or we would have to ask again on every page. | 12 months |
| Name | Why | Kept Until |
|---|---|---|
tf_v Analytics | A random identifier — not derived from anything about you — so we can count how many people read a page rather than how many times it was loaded. It goes to our own server. Nobody else sees it. | Until you withdraw consent |
That is the entire list. If you decline, tf_v is never created; if you had already allowed it and change your mind, it is deleted the moment you withdraw.
You can change your answer at any time — no need to email anyone or find a form.
We also honour Global Privacy Control and Do Not Track automatically. If your browser sends either signal, page counting is off before you are asked, and we do not ask.
Separate from anything stored on your device: when you request a call back, raise a support ticket or open an account, we keep what you typed — your name, company, email, phone, and the details of the request. We use it to answer you and to run your account, and for nothing else. Your fiscal data (invoices, devices, receipts) is held for your account only and is never visible to another customer.
To see, correct or delete what we hold about you, email support@thatfiscal.com from the address on the account, or send us a message. Where records must be retained for tax purposes we will say so and tell you for how long.
If ThatFiscal ever does set a cookie, or ever loads a third-party script, this page changes first and the banner asks again. A claim like "we use no cookies" is only worth making if it stays checkable — so it is stated narrowly, on a page with a date on it.
Last reviewed August 2026 · SESPI Africa (Private) Limited, 3 Yates Road, Hillside, Harare.