Legal

Cookie Policy

This policy lists the browser storage used by the dashboardWISE website and application and explains how to control it.

Last updated 2 September 2026

On this page

Scope

This Cookie Policy explains how dashboardWISE uses cookies, local storage and similar browser technologies on its public website and application. It should be read with our Privacy Policy.

This policy describes our current implementation. A customer-selected external service may use its own storage when you visit or authorise that service, subject to its own policy.

Browser Storage Technologies

Cookies are small text records stored by a browser and, where applicable, sent with later requests. Local storage is a browser feature that can remember information without sending it with every request. We use both to authenticate users, protect transactions, remember choices and, with permission, understand product usage.

Cookie names can receive a secure prefix in production and may differ slightly between development and production environments. Storage durations below describe the intended maximum or typical lifecycle; browser settings, sign-out, account changes and technical cleanup can cause earlier removal.

Necessary and Functional Storage

These records support security, a service you request or a choice you ask us to remember. They are not used for advertising.

  • dw_cookie_consent records whether browser analytics was accepted or rejected. Cookie, up to one year.
  • better-auth.session_token, normally with a secure prefix in production, authenticates a signed-in user. HttpOnly cookie, for the session period configured by the authentication service.
  • dw_onboarding preserves a protected onboarding step after email verification. HttpOnly cookie, up to one day.
  • dashboardwise_2fa_pending completes a two-factor authentication challenge. HttpOnly cookie, up to ten minutes.
  • dw_firm_id and dw_pms_data_source_id remember the authorised firm and practice management source selected by a signed-in user. HttpOnly cookies, up to one year.
  • dw_smokeball_pkce_* protects a temporary Smokeball authorisation exchange. HttpOnly cookie, up to ten minutes.
  • theme remembers the application appearance selected by the user. Local storage, until removed.
  • dashboardwise.practice-area-visibility.* remembers chart categories hidden by the signed-in user for a selected data source. Local storage, until removed.
  • dashboardwise:first-visit-offer-dismissed:v1 remembers that a visitor closed the website welcome offer. Local storage, until removed.

Analytics Storage

If you accept analytics, the public dashboardWISE website uses Google Analytics 4 to measure page visits and selected interactions. This can include the page address and title, referrer, approximate location, browser and device information, and events such as selecting a trial, walkthrough or contact link. A successful contact form is recorded as a lead event, but the form contents, name and email address are not sent to Google Analytics.

Google Analytics may create first-party cookies named _ga and _ga_* to distinguish visits and maintain session state. Their default maximum duration is two years. Advertising storage, Google signals and ad personalisation are disabled in the website implementation.

The authenticated dashboard application separately uses PostHog for product analytics. This can include page navigation, account and firm identifiers, feature events and device or browser information. PostHog may create first-party cookies or local storage beginning with ph_ to maintain an analytics identifier and related preference state. Automatic interaction capture is disabled in the current application implementation.

dashboardWISE does not initialise Google Analytics or PostHog browser analytics until analytics permission has been recorded. We do not use analytics storage for third-party advertising.

Separately, dashboardWISE creates server-side operational events and logs needed for billing, integrations, synchronisation, diagnostics and security. These records do not place or read browser storage and are therefore not controlled by the browser analytics toggle. Our Privacy Policy explains how personal data in those records is used.

Your Choices

You can change your preference at any time using Cookie settings in the website footer. You can also delete cookies and local storage or restrict them in your browser. Removing necessary records may sign you out, interrupt an authorisation flow or reset saved preferences.

We will treat legally recognised browser-based opt-out preference signals, including Global Privacy Control, as required by applicable law. A signal does not grant analytics consent. Because dashboardWISE does not currently sell personal data or use it for targeted advertising, it does not change those practices.

Providers and Retention

Google Analytics provides public website analytics. PostHog provides product analytics in the authenticated application. Authentication, hosting and customer-selected integrations can also set or receive storage where needed for their function. Our Subprocessors page identifies material providers and current processing locations.

We retain browser storage for the periods stated above or until you remove it. Information generated from that storage may be retained separately for the period reasonably necessary for analytics, security, support, legal or operational purposes, as described in our Privacy Policy and provider settings.

Changes and Contact

We may update this policy when storage names, purposes, providers, consent controls or retention periods change. We will publish the revised policy and its updated date. Where required, we will ask for consent before a newly introduced non-essential technology is used.

Questions can be sent to support@dashboardwise.com.

Contracting entity

dashboardWISE LLC

Registered address

8 The Green STE ADover, Kent County, DE 19901United States

Legal contact

support@dashboardwise.com

State of Delaware, United States