Scope
This Cookie Policy explains how dashboardWISE uses cookies, local storage and similar browser technologies on its public website and application. It should be read with our Privacy Policy.
This policy describes our current implementation. A customer-selected external service may use its own storage when you visit or authorise that service, subject to its own policy.
Browser Storage Technologies
Cookies are small text records stored by a browser and, where applicable, sent with later requests. Local storage is a browser feature that can remember information without sending it with every request. We use both to authenticate users, protect transactions, remember choices and, with permission, understand product usage.
Cookie names can receive a secure prefix in production and may differ slightly between development and production environments. Storage durations below describe the intended maximum or typical lifecycle; browser settings, sign-out, account changes and technical cleanup can cause earlier removal.
Necessary and Functional Storage
These records support security, a service you request or a choice you ask us to remember. They are not used for advertising.
- dw_cookie_consent records whether browser analytics was accepted or rejected. Cookie, up to one year.
- better-auth.session_token, normally with a secure prefix in production, authenticates a signed-in user. HttpOnly cookie, for the session period configured by the authentication service.
- dw_onboarding preserves a protected onboarding step after email verification. HttpOnly cookie, up to one day.
- dashboardwise_2fa_pending completes a two-factor authentication challenge. HttpOnly cookie, up to ten minutes.
- dw_firm_id and dw_pms_data_source_id remember the authorised firm and practice management source selected by a signed-in user. HttpOnly cookies, up to one year.
- dw_smokeball_pkce_* protects a temporary Smokeball authorisation exchange. HttpOnly cookie, up to ten minutes.
- theme remembers the application appearance selected by the user. Local storage, until removed.
- dashboardwise.practice-area-visibility.* remembers chart categories hidden by the signed-in user for a selected data source. Local storage, until removed.
- dashboardwise:first-visit-offer-dismissed:v1 remembers that a visitor closed the website welcome offer. Local storage, until removed.
Analytics Storage
If you accept analytics, dashboardWISE uses PostHog to record limited product analytics. Depending on the page and whether you are signed in, this can include page navigation, account and firm identifiers, feature events and device or browser information. PostHog profiles are configured for identified users, and automatic interaction capture is disabled in the current browser implementation.
PostHog may create first-party cookies or local storage beginning with ph_ to maintain an analytics identifier and related preference state. dashboardWISE does not initialise browser analytics until analytics permission has been recorded. We do not use analytics storage for third-party advertising.
Separately, dashboardWISE creates server-side operational events and logs needed for billing, integrations, synchronisation, diagnostics and security. These records do not place or read browser storage and are therefore not controlled by the browser analytics toggle. Our Privacy Policy explains how personal data in those records is used.
How Consent Works
When no preference has been recorded, the website offers choices to accept analytics, reject analytics or manage settings. Choosing analytics stores v1:analytics; rejecting it stores v1:necessary. If analytics was active and you later reject it, browser event capture is opted out for later activity.
Necessary storage remains active because it supports authentication, security, saved settings and features you request. Refusing analytics does not prevent access to core product functions.
Legal Basis
Where EU rules apply, we ask for consent before using non-essential browser storage. UK law permits limited exceptions for certain necessary, security, preference and statistical purposes, but our current website still asks for permission before initialising PostHog browser analytics. We use necessary storage to deliver a service you request, protect the service and remember choices, as permitted by applicable law.
Consent can be withdrawn at any time for future browser analytics. Withdrawing consent does not affect the lawfulness of earlier processing or storage that remains necessary for a requested service.
Your Choices
You can change your preference at any time using Cookie settings in the website footer. You can also delete cookies and local storage or restrict them in your browser. Removing necessary records may sign you out, interrupt an authorisation flow or reset saved preferences.
We will treat legally recognised browser-based opt-out preference signals, including Global Privacy Control, as required by applicable law. A signal does not grant analytics consent. Because dashboardWISE does not currently sell personal data or use it for targeted advertising, it does not change those practices.
Providers and Retention
PostHog provides browser analytics. Authentication, hosting and customer-selected integrations can also set or receive storage where needed for their function. Our Subprocessors page identifies material providers and current processing locations.
We retain browser storage for the periods stated above or until you remove it. Information generated from that storage may be retained separately for the period reasonably necessary for analytics, security, support, legal or operational purposes, as described in our Privacy Policy and provider settings.
Changes and Contact
We may update this policy when storage names, purposes, providers, consent controls or retention periods change. We will publish the revised policy and its updated date. Where required, we will ask for consent before a newly introduced non-essential technology is used.
Questions can be sent to support@dashboardwise.com.