Cookie Policy
Last updated: August 2026
This Cookie Policy explains which cookies and similar technologies are used on crm.whowsell.com, what each of them does and how long it stays on your device. It forms an integral part of our Privacy Policy and should be read together with it.
1. What Cookies Are
A cookie is a small text file that a website stores in your browser and reads again on your next visit. Cookies cannot run programs on your device and cannot read the files on your computer. They simply carry a short piece of information, such as a session reference or a preference you have chosen.
Some cookies are deleted the moment you close the browser, while others stay for a set period. Some are placed by the site you are visiting, and others by a service the site works with, such as a payment provider.
Alongside cookies, websites can also use the local storage built into your browser. That is a closely related technology with one important difference, which we explain in section 3.
2. Cookies We Use
We use three cookies, and all three are technically required for the service to work. The first is the session cookie, which appears in your browser under a name that begins with sb- and ends with -auth-token. Because its value is long, the browser may split it into parts such as sb-...-auth-token.0 and sb-...-auth-token.1.
This is the cookie that verifies your identity after you sign in and keeps your session alive as you move between pages. Without it you cannot enter your account at all. It is valid for the duration of your session and becomes invalid when you sign out or when the session is renewed.
The second cookie is crm_locale, which holds your interface language preference. It is stored for one year and is set with SameSite=Lax. It does not track your identity and does nothing beyond remembering the language you selected.
The third cookie is wsmfa, which appears only if you use two-step verification and, at the sign-in screen, choose “Trust this device for 30 days”. It is set with HttpOnly, so no script on the page can read or write it, and it carries nothing but a random token; the record it points to (the device, the connection it was granted from and the expiry) is held on our servers. The 30 days run from the moment you granted trust and are never extended by later sign-ins. You can see and remove your trusted devices at any time under Settings, Security.
3. Browser Local Storage
Local storage, known technically as localStorage, is an area inside your browser where a site can keep small values on your own device. Unlike a cookie, its content is not attached to requests and is not sent to our servers; it stays on the device until you clear it.
In local storage we keep the following: whowsell-auth for the session token; whowsell-language and language for your language preference; themeMode for your dark or light theme choice; and whowsell_remember_me for your remember me selection. These entries are what allow the panel to open with the language, theme and session state you last chose.
We also keep panel interface preferences there, such as sidebar-collapsed for the state of the sidebar, tab and column layout preferences stored under names beginning with col_order_, and read markers. Clearing your browser data removes all of these, after which the panel simply returns to its default appearance.
4. Payment Provider Cookies
When you reach a card payment screen, Stripe may place its own cookies for fraud prevention. Stripe carries out the card transaction on its own infrastructure, and those cookies help it tell a genuine payment attempt from a fraudulent one.
These cookies come into play only during the payment flow and are required for the security of the payment. Their lifetimes are determined by the relevant provider, not by us.
We do not read the contents of these cookies and do not use them for any purpose of our own. For details you can consult the cookie notice published by Stripe.
5. Cookies We Do Not Use
We use no analytics cookies. There is no Google Analytics, no Meta Pixel, no advertising network, no heat map tool and no third-party tracking script anywhere on crm.whowsell.com.
There are no advertising or profiling cookies either. Cookie data is never sold and is never shared for advertising purposes, under any circumstances.
The WhowSell browser extension uses no cookies at all; it only keeps a session token and your preferences in the browser's own local storage. That storage never leaves your device, and the extension carries no tracking script and no advertising pixel.
6. How to Manage Your Cookie Preferences
Because every cookie we use is technically required for the service to function, applicable law does not call for separate consent for them. If a non-essential cookie is ever added, we will inform you in advance and obtain your consent before it is placed.
You can delete or block cookies from your browser settings at any time. In Chrome, Safari, Firefox and Edge this setting sits in the privacy or site data section of the settings menu, where you can also review the cookies stored for a single site.
Please note that if you block the session cookie you will not be able to sign in to your account, because nothing will be left to carry your session. Blocking crm_locale only means that the panel will not remember your language choice.
7. Changes and Contact
We may update this policy when the cookies or storage we use change, or when the law requires it. The current version is always published on this page, and the date at the top shows when it was last revised.
If a change is significant, such as the addition of a cookie that is not strictly necessary, we will tell you before it takes effect through the panel or by email. Until such a change takes effect, the version published on this page remains the one in force.
For any question about this policy you can reach WhowSell LLC at support@whowsell.com or at 1209 Mountain Road Pl NE #7495, Albuquerque, NM 87110, United States. Questions about cookies and questions about your personal data are answered from the same address.