Skip to content

Legal

Cookie Policy

The few cookies and browser storage items Waltz uses, why each is needed, and why there is no consent banner.

Draft · Last updated

Draft for counsel's review. Not yet in effect.

1. The short version

Waltz uses only cookies and browser storage that the Service needs to work: to keep you signed in, and to remember small things between pages. We use no analytics, advertising or tracking cookies, and no third-party cookies. That is why waltz.run shows no consent banner. If we ever add a cookie that isn't strictly necessary, we will ask first, and "Deny" will be as easy as "Accept".

2. Cookies

Name Set by Purpose Type Lasts
waltz_access api.waltz.run Keeps you signed in to the console. Holds a short-lived access token Strictly necessary. HttpOnly, Secure, SameSite=Strict, path / [The token is valid for 10 minutes; cookie lifetime to confirm]
waltz_refresh api.waltz.run Renews your session without signing in again. Sent only to the API's sign-in routes Strictly necessary. HttpOnly, Secure, SameSite=Strict, path /v1/auth Up to 30 days without use, and 90 days from sign-in at most
waltz_last_org waltz.run Remembers the last organization you opened, so the console opens there Functional. First-party [Duration to set]

HttpOnly cookies can't be read by scripts on the page. SameSite=Strict cookies aren't sent with requests from other sites. In addition, the API honours the session cookies only on requests that carry a header other sites can't send.

The Brief viewer (links in Brief emails) sets no cookies.

3. Browser storage

The console also keeps a few short-lived items in your browser's local or session storage. They never leave your browser except where noted, and each is removed as soon as it has been used.

Key Storage Purpose Lasts
waltz.next Local storage Where to take you after you sign in, across the email link round trip Until you sign in
waltz.brief-link Local storage A Brief link you opened from an email while your org requires sign-in, kept while you sign in (sign-in by email finishes in another tab). Sent to the API once, to open the Brief Until read, and 30 minutes at most
waltz.install.org Session storage Which org started connecting an integration, so you return to it Until read, or until the tab closes

4. Emails

Waltz's emails contain no tracking pixels, no remote images and no scripts. We don't track whether you opened an email or clicked a link in it.

5. Third parties

Waltz's website and console set no third-party cookies. Our hosting provider for waltz.run (Vercel) and our DNS provider (Cloudflare) receive your IP address and request details to serve the site, as described in our Privacy Policy. [Counsel to confirm that Vercel sets no cookies on the production domain.]

When you connect an integration, you are sent to that vendor's site (for example GitHub or Slack) to approve it. That site's own cookie policy applies there. When you pay, Stripe Checkout and the billing portal run on Stripe's site under Stripe's cookie policy.

6. Your choices

You can block or delete cookies in your browser's settings. If you block the strictly necessary cookies, you won't be able to sign in to the console. Blocking waltz_last_org or browser storage only means the console asks a little more often where to go.

7. Changes and contact

We will update this page when the cookies we use change. Questions go to [privacy@waltz.run].