What this means in plain language.
We use strictly-necessary cookies to run the platform and optional analytics cookies only with your consent. Change preferences any time via the cookie banner.
Change cookie preferences any time.
Strictly-necessary cookies always run — they keep the site secure and functional. Optional analytics, functional and marketing cookies only run with your consent.
Cookies are grouped into four categories below. Each row in the doc body is tagged with one of these badges:
- Essential
- Performance
- Functional
- Marketing
TL;DR — What this means in plain language.#
- Template — review with counsel before going live. The cookie list below reflects our intended setup and must be confirmed against the production deployment before publication.
- Strictly necessary cookies are on by default — you can't sign in, stay signed in, or be protected against cross-site request forgery without them.
- Analytics, functional, and marketing cookies are opt-in in jurisdictions where consent is required (India under DPDP, the EU/UK under GDPR-ePrivacy, and similar regions). Choose what you want from the banner.
- We never set marketing cookies inside the app. Marketing cookies appear only on
www.wendesk.com, never onapp.wendesk.com, branded subdomains, or the marketplace shopping experience. - Do Not Track and Global Privacy Control — honouring ships 2026 H2 alongside the consent banner; until then, only strictly-necessary cookies are set without explicit consent.
- Change your mind any time — re-open the banner from the footer link, change your browser settings, or write to [email protected].
1. What cookies are#
A cookie is a small text file that a website asks your browser to store on your device, which the browser sends back on subsequent requests. Cookies allow a site to remember things between visits — for example, that you are signed in, what language you prefer, or that you have already dismissed a banner. They cannot run code on your computer or read other files on your device.
Cookies come in two technical flavours: session cookies are deleted as soon as you close your browser tab, while persistent cookies remain on your device for a defined duration (anywhere from a few minutes to a few years) until they expire or you clear them. They are also classified by who set them: first-party cookies are set by the website you are visiting (in our case, Fourteen Cloud Pvt Ltd operating the Wendesk brand), while third-party cookies are set by other domains the page loads resources from (advertising networks, analytics vendors, social-media widgets).
For the purposes of this policy we use the word "cookies" loosely to also cover similar storage technologies that achieve the same effect — including localStorage, sessionStorage, IndexedDB, browser cache identifiers, server-set local files, and pixel tags ("web beacons") that work alongside cookies. Wherever we say "cookie" we mean any of these.
Some cookies are strictly necessary to deliver the service you have asked for — without them you cannot sign in, your session would not persist between page loads, billing forms would be vulnerable to cross-site request forgery, and we would not be able to remember your consent choices. Other cookies are optional: they help us understand which features are useful, remember your preferences, and (on the marketing site only) measure the effectiveness of campaigns. Optional cookies are set only with your consent where consent is legally required, and you can withdraw consent at any time.
2. Categories we use#
We group cookies into four categories that map to standard ePrivacy and DPDP guidance: Strictly necessary (cannot be disabled without breaking the service), Performance / analytics (anonymised aggregate measurement), Functional (preferences and convenience), and Marketing / advertising (campaign attribution on the public marketing site only). The table below names every cookie we currently set, what it does, who provides it, how long it lives, and the category it belongs to.
| Name | Purpose | Provider | Duration | Category |
|---|---|---|---|---|
__Host-wd_session | Authenticated session for platform admin (wd-admin.wendesk.com) | Wendesk (Fourteen Cloud) | Session | Strictly necessary |
__Host-wd_tenant_session | Authenticated session for tenant dashboard (app.wendesk.com) | Wendesk (Fourteen Cloud) | Session | Strictly necessary |
__Host-wd_customer_session | Authenticated session for marketplace shoppers | Wendesk (Fourteen Cloud) | Session | Strictly necessary |
wd_refresh | Encrypted refresh token (httpOnly, SameSite=strict) used to rotate the 15-minute access token | Wendesk (Fourteen Cloud) | 30 days | Strictly necessary |
wd_csrf | Cross-Site Request Forgery protection on state-changing forms and tRPC mutations | Wendesk (Fourteen Cloud) | Session | Strictly necessary |
wd_lb | Load-balancer affinity so your requests reach the same application server during a session | Wendesk (Fourteen Cloud) | Session | Strictly necessary |
wd_consent | Stores your cookie-banner choices so we don't ask again on every visit | Wendesk (Fourteen Cloud) | 12 months | Strictly necessary |
wd_locale | Remembers your chosen interface language (English or Hindi at launch). | Wendesk (Fourteen Cloud) | 12 months | Functional |
wd_theme | Remembers your light/dark mode and dashboard layout preference | Wendesk (Fourteen Cloud) | 12 months | Functional |
ph_* | Anonymised page-view and feature-usage analytics; aggregated, no cross-site tracking | PostHog (self-hosted on AWS Mumbai) | 12 months | Performance |
plausible_* | Privacy-friendly visitor counts on the marketing site (no personal identifiers) | Plausible Analytics | 24 hours | Performance |
sentry-* | Correlates client-side JavaScript errors so engineers can debug without seeing your data | Sentry | Session | Performance |
_li_* / li_sugr | LinkedIn Insight Tag — measures conversion of LinkedIn ad campaigns; marketing site only | LinkedIn (Microsoft) | 90 days | Marketing |
_gcl_au | Google Ads conversion attribution; server-side only via the Conversions API; marketing site only | 90 days | Marketing | |
_fbp | Meta conversion attribution; marketing site only | Meta Platforms | 90 days | Marketing |
Strictly necessary cookies are exempt from consent requirements under DPDP, GDPR-ePrivacy, and equivalent rules because the service literally cannot function without them. All other categories are off by default in jurisdictions that require explicit consent and are set only after you opt in via the banner. The list above is reviewed at every release; the canonical version is the one served at this URL.
3. Third-party cookies#
The third parties that may set cookies through our pages — only with your consent and only on the surfaces noted — are listed below with links to their own privacy notices, so you can read how each one handles your data independently of us.
- LinkedIn (Microsoft Corporation) — Insight Tag for B2B campaign attribution. Set on
www.wendesk.commarketing pages only. LinkedIn Privacy Policy. - Google LLC — Google Ads conversion API and (where you have opted in) Google Analytics 4 with IP anonymisation. Marketing site only. Google Privacy Policy.
- Meta Platforms Ireland Limited — conversion attribution for Facebook and Instagram ad campaigns; marketing site only. Meta Privacy Policy.
- Plausible Analytics — privacy-friendly aggregate visitor counts on the marketing site, with no cross-site tracking and no personal identifiers. Plausible Privacy.
- Sentry — error monitoring used inside the application; logs error context but not personal Customer Data. Sentry Privacy.
- PostHog — product analytics on a self-hosted instance running on our AWS Mumbai infrastructure; data does not leave our control. PostHog Privacy.
Marketing cookies are never set inside app.wendesk.com, branded tenant subdomains, custom-domain tenant deployments, or the customer-facing marketplace storefronts. They are restricted to the public marketing site so we can measure ad performance without tracking signed-in customers across our product surfaces.
Performance and functional cookies on the marketing site are aggregated and anonymised. Inside the application we use the self-hosted PostHog instance described above; your interaction data does not leave our infrastructure for analytics purposes.
4. Manage your preferences#
You stay in control of every category beyond strictly necessary. The mechanisms below all change the same underlying record — the wd_consent cookie — so picking the most convenient one for you is fine; you do not need to update each surface separately.
- Cookie banner. The first time you visit our marketing site we show a banner with a category-by-category toggle. Choose what you want and submit. The banner is also reachable from the "Cookie preferences" link in the footer of every page, so you can revisit the choice at any time.
- In-app privacy console. Once signed in, visit Account Settings → Privacy & Tracking to view current consent state, withdraw any optional category, and download a JSON copy of your consent history.
- Do Not Track and Global Privacy Control (planned 2026 H2). Once the consent banner ships, browsers sending a DNT or GPC header will be treated as having declined non-strictly-necessary cookies, regardless of any previous interaction. Until then, the platform sets only strictly-necessary cookies in the absence of explicit opt-in — functionally equivalent for cookie purposes, but the GPC signal is not yet machine-honoured.
- Browser-level controls. See §5 for the per-browser instructions; clearing site data or blocking cookies for our domain achieves the same effect on a single device.
- Email request. Write to [email protected] if any of the channels above is unavailable to you (for example, an accessibility-tooling conflict). We will record the change against your account and confirm by reply.
Under DPDP and GDPR, withdrawing consent is as easy as giving it. Withdrawing consent does not affect the lawfulness of processing performed before the withdrawal, and it does not retroactively delete cookies already stored on your device — clear them via your browser if you want them removed entirely. Where you withdraw consent for analytics, the next page load will stop sending events; existing aggregated metrics that no longer identify you continue to be retained for historical reporting.
5. Browser controls#
Every major browser includes settings for blocking, allowing, or deleting cookies on a site-by-site basis. The instructions below cover the most common browsers; vendors update menus from time to time, so the exact path may differ slightly on your version. Blocking strictly necessary cookies will prevent you from signing in to Wendesk.
- Google Chrome (desktop) — open Settings → Privacy and security → Cookies and other site data, where you can block third-party cookies, clear cookies on exit, or remove cookies stored for
wendesk.comspecifically through "See all cookies and site data". - Mozilla Firefox — open Settings → Privacy & Security → Cookies and Site Data, choose between Standard, Strict, and Custom protection levels, or manage data per site through "Manage Data".
- Apple Safari (macOS) — open Safari → Settings → Privacy, then "Manage Website Data" to view and remove cookies stored for
wendesk.com; on iOS use Settings → Safari → Advanced → Website Data. - Microsoft Edge — open Settings → Cookies and site permissions → Manage and delete cookies and site data.
- Brave — open Settings → Shields → Cookies, where third-party cookies are blocked by default and per-site exceptions can be configured through the lion icon in the address bar.
- Mobile browsers — most mobile browsers expose a similar menu under Settings → Privacy or Settings → Site Data. On iOS, system-wide tracking prevention also applies.
For broader controls, the EU and US online-advertising self-regulatory programmes operate consent-management portals at youronlinechoices.eu and aboutads.info respectively; these allow you to opt out of behavioural advertising across many participating networks at once.
6. Changes#
We update this Cookie Policy whenever we add, remove, or materially change a cookie — for example, when we introduce a new analytics vendor, retire one, or change the duration of an existing cookie. Material changes trigger the cookie banner to re-ask for your consent so your prior choice does not silently roll over to a new use.
Non-material changes (clarification of wording, fixed typos, restructuring without substantive effect) are published immediately and noted in the version footer. Every change is reflected in the version number and "Reviewed" date at the top of this page, and previous versions are archived at /policies so you can compare. We also flag the most recent change in the cookie banner for 30 days after publication.
If a regulatory authority (the Data Protection Board of India, an EU supervisory authority, or equivalent) issues guidance that affects our cookie practices, we update this document promptly and notify workspace administrators by email so they can adjust their own privacy notices for their end-customers as needed.
Preferences
Manage cookie preferences
Review and update your cookie consent preferences below. Changes take effect immediately.
Strictly necessary
Essential for the website to function. Cannot be disabled.
Functional
Remembers your preferences and settings (e.g. locale, theme).
Marketing & analytics
Helps us understand how visitors use the site and enables relevant advertising.