Legal

Cookie Policy

This policy explains the cookies and browser storage used across Darwa’s website, accounts, dashboard, admin panel, webmail, checkout, and browser-based tools.

Version 2.1Effective 9 September 2026Updated 16 September 2026
In short
  • Essential technologies support security, sign-in, checkout, service setup, preferences, and the features you request.
  • Darwa’s Google Analytics, Mixpanel, and Microsoft Clarity integrations stay off until you allow analytics.
  • Reditus records affiliate attribution only when a visitor follows a Darwa partner link; it does not build an advertising profile.
  • We do not use advertising cookies or sell data collected through cookies.
  • Customer-hosted websites and applications may use their own cookies under the customer’s notice, not this policy.

1. Scope

This policy covers technologies set or read by Darwa on darwa.co and Darwa-operated subdomains, including the API, dashboard, admin panel, and webmail. A cookie is a small value stored by a browser and sent with matching requests. Local storage and session storage remain in the browser and are not automatically attached to every request.

Some names are environment-dependent and secure production cookies may use a browser security prefix. Durations below are typical maximums: a cookie or stored value may disappear sooner when a flow ends, you sign out, settings change, or the browser clears or limits storage.

2. Essential cookies

These cookies provide a feature you request, remember a setting, or protect Darwa and its users. They are not used for advertising and do not depend on analytics consent.

Name or categoryPurposeTypical duration
darwa_session and darwa_csrfKeep an account signed in and protect state-changing API requests from cross-site request forgerySession or the configured sign-in period, currently up to 30 days of inactivity
darwa_deviceRecognise a security device and help prevent abuse or banned-account evasionUp to one year
MFA, password-reset, OAuth, account-type, source-connection, and project-deletion challenge cookiesCarry signed, short-lived state through the security or provider flow you start and prevent request substitutionUsually minutes and removed when the flow finishes
darwa_admin_session, darwa_admin_csrf, and darwa_admin_challengeAuthenticate and protect authorised administration on the separate admin panelChallenge duration or the configured admin session, no longer than 24 hours
darwa_webmail_sessionAuthenticate the webmail session selected by the mailbox userSession or the selected webmail sign-in period
darwa_cookie_consentRemember whether you allowed optional analyticsOne year
darwa_theme and darwa_currencyRemember the display theme and preferred pricing currencyUp to one year
Cloudflare security cookies, which may include cf_clearance, __cf_bm, or _cfuvidComplete an anti-abuse challenge, distinguish legitimate requests, apply rate limits, and protect the network when the relevant Cloudflare feature is activeFeature-dependent; challenge clearance is commonly about 30 minutes but may be configured differently
Stripe payment and fraud-prevention technologiesSecurely render payment components, prevent fraud, and complete checkout or payment-method verification when requestedSet by Stripe according to the payment and security feature used
_gr_id (Reditus)Attribute a referral when you follow a Darwa affiliate link; Reditus states that this identifier is not used to build a visitor or advertising profileOnly for affiliate-link visitors; duration follows Darwa’s configured referral window

3. Essential browser storage

CategoryExamples and purposeTypical duration
Display and navigation preferencesTheme, collapsed navigation, recent command-palette items, splash-screen state, and webmail preferencesUntil replaced or cleared
Account and workspace flowsPending signup email, invitation and referral details, first-workspace draft, selected plan, and AI Agent onboarding choicesThe browser tab, the flow, or until cleared
Affiliate conversion guardA Reditus conversion marker keyed by the Darwa user ID prevents a verified signup from being reported more than onceUntil browser storage is cleared
Billing verificationA short-lived verification reference used to resume Stripe payment-method setup after returning from the providerUntil verification finishes, fails, or the tab storage is cleared
Browser tools and consolesDatabase-canvas layout, visual preferences, webmail message state, and deployment-specific UI recovery markersThe tab or until the saved preference or marker is replaced or cleared

4. Optional analytics

Darwa does not initialise Google Analytics, Mixpanel, or Microsoft Clarity until you select “Allow analytics.” They help us understand navigation, feature use, device class, referrer, approximate location, and performance. When you are signed in, product analytics may be associated with your Darwa user ID and basic account attributes. We do not use these technologies for third-party advertising.

ProviderTechnology and purposeTypical duration and control
Google Analytics_ga distinguishes browsers and _ga_<container-id> preserves session state for measurementGoogle’s default is two years, subject to our configuration and browser limits; consent is required and matching identifiers are cleared from the current host when withdrawn
Mixpanelmp_* local-storage identifiers measure product interactions and navigation; session recording is disabledUntil cleared or replaced; consent is required, tracking is opted out, and Mixpanel local identifiers are removed when consent is withdrawn
Microsoft Clarity_clck and _clsk support consent-based interaction analytics and session insightsOnly after consent; Clarity is stopped and matching first-party identifiers are removed when consent is withdrawn

5. Third-party and integration technologies

Stripe and Cloudflare may process device, network, or browser information under their own notices when you use a protected or payment feature. GitHub, GitLab, Bitbucket, identity providers, and other sites may set cookies on their own domains when you choose to sign in, authorise a connection, or visit them. Darwa does not control storage set solely on another provider’s domain.

6. Your choices

Select “Essential only” or “Allow analytics” in the banner. To change your selection later, use “Cookie settings” in the footer. Rejecting optional analytics does not prevent access to Darwa. Browser controls can also delete stored data, but blocking essential technologies may stop sign-in, checkout, or other requested features from working.

Withdrawing analytics consent stops future Darwa analytics collection from that browser and clears the analytics identifiers our code can access on the current hostname. Browser settings can be used to clear data across other Darwa subdomains. Withdrawal does not affect processing that lawfully occurred before the change.

7. Customer-hosted services

A website, WordPress installation, AI Agent, web service, or other application hosted through Darwa may set its own cookies on a Darwa-provided hostname or custom domain. The customer operating that service chooses those technologies and is responsible for its notice and consent mechanism. Darwa’s website cookie banner does not manage cookies inside a customer-operated application or the Darwa Analytics script a customer elects to install on its own site.

8. Changes

We update this page when a cookie, browser-storage purpose, provider, or material retention practice changes. The version and updated date identify the current policy.

Contact

Darwa is a product and brand of Zevello, Inc., a C corporation headquartered in Newark, Delaware, United States. Written notice may be sent to legal@darwa.co. Finance, billing, and technical questions go to support@darwa.co. Security reports go to security@darwa.co. Privacy requests go to privacy@darwa.co.