Cookies and storage on your device

A small number of cookies, all our own, each needed for something you asked for.

The short version

CREWWIZE sets a small number of cookies, all of them our own and all of them needed for something you asked for: staying signed in, protecting forms against forgery, completing a passkey or second-factor sign-in, showing you an access code once, and remembering whether you folded the sidebar and which language you chose.

There are no analytics cookies, no advertising cookies, no tracking pixels and no third-party scripts on any CREWWIZE page. No other company's code runs on our pages, so no other company can set a cookie through them. For that reason we do not show a cookie banner.

Cookies set by cloud.crewwize.com

Every cookie is sent only over HTTPS, only to our own origin, and with SameSite=Lax, which means a browser does not send it with a form posted from another site.

  • crewwize_session — keeps you signed in. Holds your account's identifier, the time you signed in and our signature over both; no other personal data. Kept 30 days, or until you sign out; ended earlier on every device if your password is reset. Not readable by script.
  • crewwize_csrf — a random token that proves a form was sent from our own page and not forged by another site. Kept 30 days; removed when you sign out. The sign-in page's own script reads it to send it back with a passkey request.
  • cw_wa — holds the state of a passkey ceremony (sign-up, sign-in or adding a device) between its two steps: the challenge, signed by us. Kept 5 minutes; removed when the ceremony ends. Not readable by script.
  • crewwize_2fa — marks a sign-in that has passed its first step and is waiting for the second (a passkey, an emailed code or a recovery code). It is not a session and grants nothing. Kept 10 minutes; removed when the sign-in completes. Not readable by script.
  • crewwize_apptoken — carries a newly issued app access code through one redirect, so it is shown to you exactly once on your Security page and not stored in the browser's history. Kept 60 seconds; removed as soon as it is read. Not readable by script.
  • crewwize_side — remembers whether you folded the sidebar on the fleet pages. Set only when you press the fold control, and holds the word open or folded and nothing else. Kept 1 year. Not readable by script.
  • crewwize_lang — remembers the language you picked from a language link (English, French, German …). Set only when you follow such a link, and holds the language code and nothing else. Kept 1 year. Not readable by script.

Storage in the app

The CREWWIZE app is a web app, served by each vessel from her own address and also from app.crewwize.com. It keeps a small amount of data in your browser's local storage and in a service-worker cache so that it works with no internet connection, at sea. Nothing in it is used to track you, and nothing is sent to anybody but the vessel you are using and, if you connect the app to your account, cloud.crewwize.com.

  • Signing in aboard: the vessel session, this handset's boarding passes, and who this handset belongs to.
  • Reaching the vessels you know: the list of vessels this app has connected to, most recent first, at most twenty.
  • Your account ashore, if you connect it: the access code you pasted in Settings and a dated copy of your fleet, so it can be read when the boat is out of reach — deleted when you check out.
  • The crew's emergency information, on a skipper's or mate's phone: a dated copy taken from the vessel, so it can be read in a power outage; dropped when the voyage closes, when the phone is released or signs out, and at checkout.
  • Settings you chose: night or day display, phone or tablet layout, microphone and speaker, push-to-talk mode, and whether you dismissed the install hint.
  • Something waiting to be sent: an invitation you opened, or a star rating not yet delivered.
  • The app itself: the app's own files, cached so it starts without a network, and a note of an update in progress.

The chat page on cloud.crewwize.com keeps a per-browser device identifier for the chat server and, briefly, a message you wrote that has not yet been sent.

Stripe's pages

Paying, managing a subscription, your card and your invoices happen on Stripe's own pages — Stripe Checkout and the Stripe Customer Portal — which you reach by leaving our site. Those are not our pages. Stripe sets its own cookies there, for its own purposes including fraud prevention, under its own notices: Stripe's cookie policy (stripe.com/legal/cookies-policy), Stripe's privacy policy (stripe.com/privacy) and Link's privacy policy (link.com/privacy). Where Stripe, through Link, acts as the seller of record, Link's own terms also apply on that page.

No Stripe script is ever loaded on a CREWWIZE page.

Questions

Write to service@crewwize.com, or use the contact form; a person answers.