Cookie Policy
This policy explains the cookies and browser storage used across Darwa’s website, accounts, dashboard, admin panel, webmail, checkout, and browser-based tools.
- Essential technologies support security, sign-in, checkout, service setup, preferences, and the features you request.
- Darwa’s Google Analytics, Mixpanel, and Microsoft Clarity integrations stay off until you allow analytics.
- Reditus records affiliate attribution only when a visitor follows a Darwa partner link; it does not build an advertising profile.
- We do not use advertising cookies or sell data collected through cookies.
- Customer-hosted websites and applications may use their own cookies under the customer’s notice, not this policy.
1. Scope
This policy covers technologies set or read by Darwa on darwa.co and Darwa-operated subdomains, including the API, dashboard, admin panel, and webmail. A cookie is a small value stored by a browser and sent with matching requests. Local storage and session storage remain in the browser and are not automatically attached to every request.
Some names are environment-dependent and secure production cookies may use a browser security prefix. Durations below are typical maximums: a cookie or stored value may disappear sooner when a flow ends, you sign out, settings change, or the browser clears or limits storage.
2. Essential cookies
These cookies provide a feature you request, remember a setting, or protect Darwa and its users. They are not used for advertising and do not depend on analytics consent.
| Name or category | Purpose | Typical duration |
|---|---|---|
darwa_session and darwa_csrf | Keep an account signed in and protect state-changing API requests from cross-site request forgery | Session or the configured sign-in period, currently up to 30 days of inactivity |
darwa_device | Recognise a security device and help prevent abuse or banned-account evasion | Up to one year |
| MFA, password-reset, OAuth, account-type, source-connection, and project-deletion challenge cookies | Carry signed, short-lived state through the security or provider flow you start and prevent request substitution | Usually minutes and removed when the flow finishes |
darwa_admin_session, darwa_admin_csrf, and darwa_admin_challenge | Authenticate and protect authorised administration on the separate admin panel | Challenge duration or the configured admin session, no longer than 24 hours |
darwa_webmail_session | Authenticate the webmail session selected by the mailbox user | Session or the selected webmail sign-in period |
darwa_cookie_consent | Remember whether you allowed optional analytics | One year |
darwa_theme and darwa_currency | Remember the display theme and preferred pricing currency | Up to one year |
Cloudflare security cookies, which may include cf_clearance, __cf_bm, or _cfuvid | Complete an anti-abuse challenge, distinguish legitimate requests, apply rate limits, and protect the network when the relevant Cloudflare feature is active | Feature-dependent; challenge clearance is commonly about 30 minutes but may be configured differently |
| Stripe payment and fraud-prevention technologies | Securely render payment components, prevent fraud, and complete checkout or payment-method verification when requested | Set by Stripe according to the payment and security feature used |
_gr_id (Reditus) | Attribute a referral when you follow a Darwa affiliate link; Reditus states that this identifier is not used to build a visitor or advertising profile | Only for affiliate-link visitors; duration follows Darwa’s configured referral window |
3. Essential browser storage
| Category | Examples and purpose | Typical duration |
|---|---|---|
| Display and navigation preferences | Theme, collapsed navigation, recent command-palette items, splash-screen state, and webmail preferences | Until replaced or cleared |
| Account and workspace flows | Pending signup email, invitation and referral details, first-workspace draft, selected plan, and AI Agent onboarding choices | The browser tab, the flow, or until cleared |
| Affiliate conversion guard | A Reditus conversion marker keyed by the Darwa user ID prevents a verified signup from being reported more than once | Until browser storage is cleared |
| Billing verification | A short-lived verification reference used to resume Stripe payment-method setup after returning from the provider | Until verification finishes, fails, or the tab storage is cleared |
| Browser tools and consoles | Database-canvas layout, visual preferences, webmail message state, and deployment-specific UI recovery markers | The tab or until the saved preference or marker is replaced or cleared |
4. Optional analytics
Darwa does not initialise Google Analytics, Mixpanel, or Microsoft Clarity until you select “Allow analytics.” They help us understand navigation, feature use, device class, referrer, approximate location, and performance. When you are signed in, product analytics may be associated with your Darwa user ID and basic account attributes. We do not use these technologies for third-party advertising.
| Provider | Technology and purpose | Typical duration and control |
|---|---|---|
| Google Analytics | _ga distinguishes browsers and _ga_<container-id> preserves session state for measurement | Google’s default is two years, subject to our configuration and browser limits; consent is required and matching identifiers are cleared from the current host when withdrawn |
| Mixpanel | mp_* local-storage identifiers measure product interactions and navigation; session recording is disabled | Until cleared or replaced; consent is required, tracking is opted out, and Mixpanel local identifiers are removed when consent is withdrawn |
| Microsoft Clarity | _clck and _clsk support consent-based interaction analytics and session insights | Only after consent; Clarity is stopped and matching first-party identifiers are removed when consent is withdrawn |
5. Third-party and integration technologies
Stripe and Cloudflare may process device, network, or browser information under their own notices when you use a protected or payment feature. GitHub, GitLab, Bitbucket, identity providers, and other sites may set cookies on their own domains when you choose to sign in, authorise a connection, or visit them. Darwa does not control storage set solely on another provider’s domain.
6. Your choices
Select “Essential only” or “Allow analytics” in the banner. To change your selection later, use “Cookie settings” in the footer. Rejecting optional analytics does not prevent access to Darwa. Browser controls can also delete stored data, but blocking essential technologies may stop sign-in, checkout, or other requested features from working.
Withdrawing analytics consent stops future Darwa analytics collection from that browser and clears the analytics identifiers our code can access on the current hostname. Browser settings can be used to clear data across other Darwa subdomains. Withdrawal does not affect processing that lawfully occurred before the change.
7. Customer-hosted services
A website, WordPress installation, AI Agent, web service, or other application hosted through Darwa may set its own cookies on a Darwa-provided hostname or custom domain. The customer operating that service chooses those technologies and is responsible for its notice and consent mechanism. Darwa’s website cookie banner does not manage cookies inside a customer-operated application or the Darwa Analytics script a customer elects to install on its own site.
8. Changes
We update this page when a cookie, browser-storage purpose, provider, or material retention practice changes. The version and updated date identify the current policy.
Contact
Darwa is a product and brand of Zevello, Inc., a C corporation headquartered in Newark, Delaware, United States. Written notice may be sent to legal@darwa.co. Finance, billing, and technical questions go to support@darwa.co. Security reports go to security@darwa.co. Privacy requests go to privacy@darwa.co.