Version 1 · Effective 17 August 2026
ShopHex uses secure session cookies for authentication and CSRF protection; local or session storage for device, preference, draft and PWA state; service-worker caches for public application assets; and hashed, bounded first-party usage events for installs, stability and marketplace performance. Private API and media responses are excluded from the public PWA cache. Browser controls can clear local storage, but doing so may sign the user out or remove local preferences.