1. What this notice covers
A cookie is a small value a website can ask a browser to store and return. Web applications can also use local or session storage for similar purposes. This notice describes the technology Wazzl intentionally uses and the support provider technology that can load when you visit the support page.
No advertising or cross-site profiling: Wazzl does not use advertising cookies or third-party audience analytics. Optional acquisition measurement is first-party, finite, unlinked to account or lead content, and off until the visitor grants permission.
2. Wazzl cookies and browser preference
| Technology | Purpose | When used | Duration and controls |
|---|---|---|---|
wazzl_refresh | Maintains and securely rotates a signed-in session after the short-lived access token expires. | Set by the API after successful sign-in or registration; scoped to Wazzl’s authentication API path. | HTTP-only, SameSite=Lax, Secure in production, and expires according to the configured session period or earlier on logout or revocation. |
wazzl_measurement_session | Provides a random, unlinked first-party session for a finite set of client-observed acquisition stages. Only a SHA-256 hash of the token is stored by Wazzl. | Set only after optional measurement permission on an eligible Wazzl acquisition page. It is host-only, HTTP-only, SameSite=Lax, Secure in production, and scoped to the exact /api/acquisition path. | Expires after 24 hours or is cleared after confirmed revocation. Global Privacy Control, Do Not Track 1, an explicit denial, or a missing/invalid preference withholds collection and requests revocation. |
wazzl_measurement_preference_v1 local storage | Remembers only the versioned granted or denied choice and its expiry. The preference is scoped to the current website or app origin and is not transferred between them. | Written when a visitor uses “Privacy choices”. It never contains the measurement token, event identifiers, campaign values, form values, or an event queue. | Up to 90 days, or earlier when cleared by the browser. If it cannot be read and durably saved, measurement stays off and Wazzl requests server revocation. |
The essential refresh cookie is required for the signed-in application to resume and rotate a session. The access token used by the application is kept in memory rather than deliberately persisted in browser storage. Optional measurement records contain only allowlisted event, page, step, sanitized campaign code, and timestamps. Each event and content-free retry receipt expires 90 days after server receipt. A no-event session expires 90 days after consent; its parent row can remain only until its latest child expires, at most about 91 days from consent, while collection still ends after 24 hours.
3. Tawk.to support technology
The support page embeds Tawk.to. When that page opens, the browser connects directly to Tawk.to. Tawk.to may use cookies or local storage to provide chat, remember a chat session, prevent abuse, and operate its service. It may also receive network, browser, device, and chat information.
Tawk.to controls the exact names and lifetimes of its own storage and can change them independently. If you do not want the embedded service to load, do not open the support page; email [email protected] instead.
4. Infrastructure and browser behaviour
The workflow-review form keeps its retry key only in the open page’s memory and sends the request with cookie credentials omitted. No workflow-review field, retry key, signup value, session JWT, or workspace identifier is sent to acquisition measurement. Raw UTM and supported click identifiers are removed from the visible URL before error diagnostics initialize and are never accepted by the measurement API. Cloudflare or other infrastructure providers may use strictly necessary security or network mechanisms when protecting and delivering a page. Browsers, extensions, password managers, and linked third-party websites can also store information independently of Wazzl.
Some marketing, authentication, and signed-in application pages make direct Google Fonts resource requests; the signed-in application can also request fixed fictional PRavatar images. These are disclosed network-resource requests, not Wazzl browser storage or acquisition measurement. Their provider boundaries are described in the privacy policy and subprocessor list.
5. Your controls
Use “Privacy choices” on an eligible acquisition page to allow or deny optional first-party measurement. Denial stops browser collection immediately and requests durable server revocation. A Global Privacy Control signal or Do Not Track value of 1 also withholds measurement and overrides a saved grant. If server confirmation is temporarily unavailable, the browser keeps measurement locally off and retries the content-free revocation without copying the HTTP-only token into browser storage. Most browsers also let you inspect, block, or clear cookies and site storage. Blocking Wazzl’s essential refresh cookie can prevent sign-in persistence and session refresh; clearing support-provider storage can end or reset a chat.
6. Changes and contact
Wazzl will update this notice when its intentional use of browser storage changes. Questions can be sent to [email protected].