Cookie Policy
Last updated: 15 September 2026 · This version is still under legal review. The final version will replace it without any change to functionality or rights.
This policy explains which cookies and comparable storage techniques (local storage, session storage) doWallet uses on dowallet.de, in the app and on public pass pages. It supplements our Privacy Policy.
1. In short
- We only use strictly necessary cookies and preference storage.
- There is no tracking, no analytics cookies and no marketing cookies.
- No cookie is set by a third party. Every entry is set by doWallet itself.
- A cookie banner only appears if optional purposes are configured. That is currently not the case.
- The settings are always reachable via the "Cookie-Einstellungen" link.
2. What we do not use
doWallet uses no web analytics services, no advertising or retargeting pixels, no social media plugins and no fingerprinting. Fonts and scripts are served from our own servers. The login page runs a bot check (doCaptcha, a product of Applox GmbH) that loads a script from widget.docaptcha.com but sets no cookies.
3. Full inventory
The table below lists every cookie and storage entry, grouped by category. It is generated from the same source that feeds the cookie settings in the product.
Necessary
| Name | Type | Purpose | Duration | Set by |
|---|---|---|---|---|
| dwlt_session | Cookie | Keeps you signed in (httpOnly, readable by the server only). | Session | Backend |
| dwlt_csrf | Cookie | Protects forms and API calls against cross-site request forgery. | Session | Backend |
| dwlt_impersonation | Cookie | Marks a support session in which a doWallet admin views an account for troubleshooting. | Session | Backend |
| dwlt_wa_chal | Cookie | Short-lived challenge for passkey sign-in (WebAuthn). | 5 minutes | Backend |
| dwlt_consent | Cookie | Stores your cookie decision so we do not ask again. | 180 days | doWallet |
| dw_attr_<slug> | Cookie | Random per-offer device key so reopening the page returns the same pass instead of issuing a second one. No person, no tracking. | 180 days | doWallet |
| dwlt:consent:v1 | Local storage | Your cookie decision with timestamp and version. | Until you clear your browser storage | doWallet |
| dowallet:attr:<slug> | Local storage | Copy of the dw_attr_<slug> device key in case the cookie is missing. | 180 days | doWallet |
| dwlt:chunk-reloaded | Session storage | Prevents a reload loop when an old file is missing after a deployment. | Until the tab is closed | doWallet |
Preferences
| Name | Type | Purpose | Duration | Set by |
|---|---|---|---|---|
| dwlt_lang | Cookie | Remembers the language you picked so pages are served in it directly. Only set when you actively switch languages. | 1 year | doWallet |
| dwlt:lang | Local storage | Chosen interface language. | Until you clear your browser storage | doWallet |
| dwlt.nav | Local storage | Sidebar state (expanded or collapsed). | Until you clear your browser storage | doWallet |
| dwlt:template-draft:<id> | Local storage | Unsaved draft in the pass editor so a reload loses nothing. | Until you clear your browser storage | doWallet |
| dowallet:wizard-draft:<id> | Local storage | Draft in the campaign wizard. | Until you clear your browser storage | doWallet |
| dowallet:flow-wizard | Local storage | Draft in the flow wizard. | Until you clear your browser storage | doWallet |
| dwlt:demo-* | Local storage | Progress of the demo tour in the workspace. | Until you clear your browser storage | doWallet |
| dwlt:welcome-seen | Local storage | Remembers that the welcome tour was shown. | Until you clear your browser storage | doWallet |
| dwlt:journey-dismissed | Local storage | Dismissed setup strip. | Until you clear your browser storage | doWallet |
| dwlt:hide-tap-hint | Local storage | Tap hint hidden in the pass preview. | Until you clear your browser storage | doWallet |
| dwlt:device-dark | Local storage | Dark device frame in the pass preview. | Until you clear your browser storage | doWallet |
| dwlt:osm-ok | Local storage | Remembers your choice to load the OpenStreetMap map in the location editor without asking again. | Until you clear your browser storage | doWallet |
| dwlt:search-recent | Local storage | The last eight items you opened from search, for the “Recent” section. | Until you clear your browser storage | doWallet |
| dwlt:pitch:presenter:<token> | Session storage | Presenter mode of a pitch deck for this tab. | Until the tab is closed | doWallet |
| dwlt:payreminder:<org> | Session storage | Payment reminder dismissed for this tab. | Until the tab is closed | doWallet |
| dwlt:overdue:<org> | Session storage | Overdue invoice notice dismissed for this tab. | Until the tab is closed | doWallet |
4. Legal basis
Strictly necessary entries are stored under § 25(2) no. 2 of the German TDDDG and Art. 6(1)(b) and (f) GDPR. Preference storage (for example your language choice or the state of the sidebar) only keeps a setting you chose yourself. Should we ever introduce optional purposes, they will only become active after explicit consent (Art. 6(1)(a) GDPR).
5. Changing your settings
You can open and change your selection at any time. The link is in the footer of every page and here:
On public pass pages (/p/<slug>) a device key ensures that only one pass is issued per phone. This entry is strictly necessary and therefore cannot be opted out of, but it can be deleted via your browser controls.
6. Browser controls
Every browser lets you view, delete or block cookies and site data, usually under "Privacy and security" or "Site data". If you block strictly necessary cookies you can no longer sign in and public pass pages only work in a limited way.
- Chrome: Settings → Privacy and security → Third-party cookies / Site data
- Safari: Settings → Privacy → Manage Website Data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Edge: Settings → Cookies and site permissions
7. Changes
When the entries change we update this page and the table above. For new optional purposes we ask for your consent again.
8. Contact
Our data protection officer answers questions about cookies and privacy at dsb@dowallet.de. The controller is Applox GmbH, see Imprint.