Storage & Tracking Transparency

Cookie Policy

This Cookie Policy explains how MtishbiScholars uses essential cookies, functional local storage, analytics, and error-monitoring technologies when you visit our website or use our student platform.

Last Updated: 25 August 2026Applicable Law: United Republic of Tanzania
1

Introduction

MtishbiScholars (“we”, “our”, or “us”) is an international education advisory and student placement platform based in Dar es Salaam, Tanzania. We are dedicated to maintaining complete transparency regarding how we store data in your browser, maintain secure user sessions, monitor software stability, and assess public website traffic.

This Cookie Policy outlines the specific cookies and local storage items used on our platform, their operational purposes, retention durations, and the mechanisms available to manage your preferences.

2

What Cookies and Browser Storage Are

Cookies are small text files placed on your computer or mobile device by websites you visit. Cookies are transmitted between your web browser and web servers to enable authentication, preserve user sessions, and maintain platform security.

Browser Local Storage (localStorage) is a browser-based storage technology that allows web applications to store functional key-value pairs locally on your device. Unlike HTTP cookies, local storage items are not automatically sent to web servers with every network request.

3

How MtishbiScholars Uses Storage Technologies

We utilize cookies and browser storage strictly for legitimate operational purposes, categorized as follows:

1. Strictly Necessary

Essential for user sign-in, session persistence, role access verification, and platform security.

2. Functional Storage

Stores user-chosen interface settings, such as dark/light theme preferences and notification UI filters.

3. Analytics

Measures public website traffic and aggregate navigation trends without collecting sensitive personal data.

4

Strictly Necessary Authentication Cookies

Strictly necessary cookies are essential for our platform to operate securely. They enable student login, secure session validation across page loads, and role-based route protection in our middleware.

sb-<project-ref>-auth-token (including .0, .1 chunked variants)

Provider: Supabase Authentication (`@supabase/ssr`).

Purpose: Stores encrypted JSON Web Tokens (JWT) and refresh tokens required to authenticate students, admission officers, and finance staff securely across server requests.

Lifespan: Session-based or duration-limited by token expiration.

5

Google OAuth & PKCE Verification

When you authenticate using Google OAuth, our authentication provider utilizes the standard Proof Key for Code Exchange (PKCE) security protocol to prevent authorization code interception.

sb-<project-ref>-auth-token-code-verifier

Purpose: Transient cryptographic verifier cookie used temporarily during OAuth callback processing to ensure that the entity completing authentication is the same entity that initiated it.

Lifespan: Short-lived; automatically removed upon completion of authentication.

6

Functional Browser Storage (localStorage)

We use browser local storage to save your UI preferences directly in your browser. These items are strictly functional and do not track you across external websites:

mtb_themeStores student portal and public UI display mode preference (“light”, “dark”, or “system”).
mtishbi_admin_themeStores administrative theme preference for staff dashboards.
mtb_ui_notif_prefsStores student notification UI filter and alert preferences.
mtishbi_admin_notif_prefsStores administrative notification filter preferences.
mtishbi_remember_emailOptional: Stores student email address on login form only when user selects “Remember email”.
mtishbi_admin_remember_emailOptional: Stores staff email on admin login form when selected.

Note: sessionStorage is not used anywhere on the platform.

7

Google Analytics (GA4)

We use Google Analytics 4 to evaluate public website traffic, page navigation patterns, popular destination searches, and public call-to-action interactions.

Configuration & Data Protection:

  • Google Analytics operates in consent mode and respects user consent choices.
  • IP anonymization is enforced on analytics requests.
  • No Sensitive Personal Information Collected: We strictly prohibit sending student passwords, passport numbers, national identification numbers, payment documents, academic transcripts, or private application details to Google Analytics.
  • Analytics scripts are loaded asynchronously (after interactive) to ensure that website performance, speed, and Largest Contentful Paint (LCP) are preserved.
8

Sentry Error Monitoring

We use Sentry for production error monitoring, crash detection, unhandled exception diagnosis, and application reliability tracking.

Purpose: Sentry is purely a technical stability and diagnostic tool, not an advertising or marketing service. It captures software stack traces, browser environment context, and error messages to help developers fix bugs promptly.

Data Scrubbing: Sentry is configured with automated data-scrubbing filters that remove sensitive headers, authentication tokens, passwords, passport numbers, and identification records before error payloads are transmitted.

9

Google Search Console

MtishbiScholars uses Google Search Console as an administrative webmaster service to monitor website search indexing, submit XML sitemaps, verify search crawl health, and identify technical search visibility issues.

Google Search Console operates via server-level metadata verification and does not inject advertising tracking scripts or behavioral cookies into your browser.

10

Analytics & Tracking Technologies Not Used

To protect applicant privacy, MtishbiScholars explicitly does not install, use, or integrate any of the following third-party tracking services:

  • Meta / Facebook Pixel
  • Microsoft Clarity
  • Hotjar
  • Vercel Analytics
  • PostHog / Mixpanel / Segment
  • TikTok Pixel / LinkedIn Insight Tag
11

Advertising & Marketing Technologies

MtishbiScholars does NOT use advertising cookies, marketing pixels, cross-site trackers, or behavioral profiling tools.

We do not monetize your browsing activity, display third-party advertisements on our platform, or share student browsing profiles with commercial ad networks.

12

Third-Party Services Summary

SupabaseProvides database hosting, encrypted session authentication cookies, and secure document storage.
Google OAuthProvides optional federated login using standard PKCE token exchange.
Google Maps EmbedDisplays our physical office location map in Dar es Salaam on the contact section with standard no-referrer policies.
13

Cookie & Storage Lifespan

  • Session Cookies: Temporary cookies that remain active only while your browser is open and are deleted upon closing the browser.
  • Persistent Cookies & Local Storage: Stored locally until their expiration date or until manually cleared via your browser settings or dashboard preferences.
14

Managing Cookies & Browser Storage

You have full control over cookie storage through multiple methods:

1. Cookie Consent Banner: You may accept or decline optional analytics storage via our on-page cookie preferences banner on public pages.

2. Web Browser Controls: Most web browsers allow you to view, manage, delete, or block cookies and local storage through their settings menu (Chrome, Safari, Firefox, Edge). Consult your browser's help documentation for instructions.

15

Impact of Disabling Essential Storage

If you configure your browser to block all cookies, strictly necessary authentication cookies will be blocked, preventing you from logging into your student dashboard, uploading application documents, or submitting university files. Public pages (universities, scholarships, services) will remain readable.

16

Privacy & Personal Data Protection

For detailed information regarding how personal information is collected, processed, retained, and protected in accordance with the Tanzania Personal Data Protection Act, 2022, please review our Privacy Policy.

17

Changes to This Cookie Policy

We may periodically update this Cookie Policy to reflect changes in our operational technologies or applicable statutory standards. Any modifications will be posted on this page with an updated “Last Updated” date.

18

Contact Information

If you have inquiries or questions regarding our Cookie Policy or storage technologies, please contact us:

General & Data Inquiries
info@mtishbischolar.com

Admissions guidance and privacy inquiries.

Technical & Account Support
support@mtishbischolar.com

Technical assistance and storage questions.

Telephone Consultation
+255 764 488 687

Mon–Fri 8:00 AM – 5:00 PM, Sat 8:00 AM – 1:00 PM (EAT).

Headquarters

Dar es Salaam, Tanzania

In-person advisory sessions available by appointment.