Legal

Cookie Policy

Last updated

Clientwharf keeps cookies to the minimum needed to sign you in.

1. What cookies are

Cookies are small text files a website stores in your browser. Similar technologies, such as local storage, work in a comparable way. This policy explains which ones Clientwharf, operated by Goohoost Ltd, uses and why.

2. Essential cookies we set

We only set cookies that are strictly necessary to provide the Service you ask for, mainly to keep you signed in securely. They are not used for advertising or tracking, and they are not shared with third parties. Because they are essential, they do not require consent, and we do not show a cookie banner.

Essential cookies set by Clientwharf
CookiePurposeDuration
cw.session_tokenKeeps you signed in to the app or a client portal and protects your session.Up to 30 days, renewed while you use the Service; removed when you sign out.
cw.session_dataShort-lived cache of your session so pages load faster without weakening security.5 minutes
cw.dont_rememberSet if you sign in without staying signed in, so your session ends when you close the browser.Browser session
cw.two_factorLinks the two steps of sign-in when two-factor authentication is turned on.A few minutes, during sign-in only
cw.trust_deviceSet only if you choose to trust a device during two-factor sign-in, so you are not asked for a code on that device again.Up to 30 days
cw_wsRemembers which workspace you last opened if you belong to more than one.Until you sign out or clear it

In production, session cookies carry the __Secure- prefix, which means browsers only send them over encrypted (HTTPS) connections. Session cookies are also marked HttpOnly so scripts on the page cannot read them.

3. Analytics without cookies

We use Vercel Web Analytics to count page views in aggregate, for example which pages are visited and which countries and browsers visitors use. It does not use cookies or local storage, does not identify individual visitors, and does not track you across other websites. Vercel derives a temporary visitor value from each request and discards it after 24 hours. See our Privacy Policy for details.

4. Paddle checkout

Payments are handled by Paddle, our reseller and Merchant of Record. Paddle’s checkout is loaded only on the billing page inside the app. When that page is open, and when you open the checkout, Paddle may set its own cookies and similar technologies, for example to process the payment securely and prevent fraud. Paddle sets these under its own Privacy Notice (opens in a new tab), which links to Paddle’s cookie notice. We do not control or have access to Paddle’s cookies.

5. No advertising or social media cookies

We do not use advertising cookies, retargeting pixels, social media tracking or third-party embeds that set cookies on our website. If we ever want to add non-essential cookies, we will update this policy first and ask for your consent where the law requires it.

6. How to control cookies

You can view and delete cookies, and block them, in your browser settings. Most browsers explain how in their help pages, for example under “Privacy” or “Cookies and site data”.

If you block or delete our essential cookies, you will be signed out and will not be able to sign in to Clientwharf until you allow them again. Blocking Paddle’s cookies may prevent checkout from working. The public website, including this page, works without cookies.

7. Changes and contact

We update this policy when the cookies we use change. The “Last updated” date at the top shows when it last changed. Questions can be sent to privacy@clientwharf.com.