Effective date: 27 September 2026.
1.What this covers
This policy covers cookies and equivalent browser storage (localStorage and sessionStorage) set on worldwatch.market and on the dealer application. Read it alongside the Privacy Policy, which explains what we do with the data these technologies produce.
A cookie is a small file a site stores in your browser. Some are strictly necessary, meaning the service cannot work without them. Everything else needs your consent under Article 5(3) of the ePrivacy Directive and its Dutch implementation in the Telecommunicatiewet.
2.The public marketing site
The pages you can read without signing in are deliberately close to cookie-free. The public tier loads no authentication SDK, and the HTML served is identical for every visitor. It does load Google Analytics, here and in the dealer application, in Google's consent mode: until you accept analytics, Google Analytics sets no cookies and sends only cookieless signals that carry no identifier.
| Name | Purpose | Type | Duration |
|---|---|---|---|
NEXT_LOCALE | Remembers the language you chose, so the site does not keep guessing from your browser settings | Preference | 1 year |
wwmlang | Records that you dismissed the "this page is also available in your language" banner, so it is not shown again | Preference | 1 year |
wwm-consent (in localStorage) | Records your cookie choice, so the consent card is not shown again. It stays on your device and is never sent to us | Strictly necessary | Until you change your choice or clear your browser data |
_ga, _ga_8CT0EWLCH6 | Set by Google Analytics to tell visits and sessions apart, so we can see how the site and the dealer application are used. Set only after you accept analytics, and deleted if you withdraw that consent | Analytics (consent) | 2 years |
__client_uat (and __client_uat_<suffix> on preview deployments) | Read, not written, on public pages: it is how the page decides whether to show "Sign in" or "Go to dashboard" before anything renders. Set by our identity provider when you sign in | Strictly necessary | Session, managed by the identity provider |
If you also accept marketing, Google Analytics may use your visit for Google's advertising measurement and personalisation. We do not load a separate advertising tag.
Page analytics and performance measurement on the public site are also provided by Vercel Web Analytics and Vercel Speed Insights, which are cookieless and do not identify individual visitors.
3.The dealer application
| Name | Purpose | Type | Duration |
|---|---|---|---|
__session | The signed session token that authenticates each request | Strictly necessary | Short-lived, refreshed continuously while you are signed in |
__client_uat | Signed-in state, used by our routing layer to decide whether a page needs authentication | Strictly necessary | Session |
__clerk_db_jwt | Development and preview environments only, where third-party cookie restrictions require it | Strictly necessary | Session |
NEXT_LOCALE | Language preference, shared with the public site | Preference | 1 year |
wwm-onboarding-just-completed | Prevents the onboarding flow from bouncing you backwards in the seconds after you finish it | Strictly necessary | 30 seconds |
ph_<project key>_posthog | Set by PostHog, our product analytics provider, only once you use the dealer application. It measures how the application is used, such as which pages dealers spend time on, and links that to your account so we can improve the tools you work in | Necessary (product analytics) | 1 year |
__stripe_mid, __stripe_sid | Set by Stripe on billing and checkout pages to detect payment fraud | Strictly necessary | 1 year and 30 minutes respectively |
We also use browser storage for a few things that never leave your device: theme records whether you chose light, dark or system appearance; wwm.auth-machine.v2 and wwm.auth-machine.v1.idempotency-key keep your place in onboarding if you close the tab, and stop a repeated submission creating two accounts; wwm.get-started.register-dealer in sessionStorage holds a one-off reference for a single attempt at creating a dealer profile, so that a resubmitted form does not register a second business, and is discarded once the profile has been created; wwm.activeCatalogImportId and wwm.acknowledgedCatalogImportId track a catalogue import in progress; and agent_session_id in sessionStorage keeps one assistant conversation together for the length of a tab.
4.Diagnostics
Our error monitoring provider, Sentry, sets no cookies. It records error reports, performance traces, and a replay of interface interactions for a sampled share of sessions plus every session in which an error occurs, so that a fault can be reproduced. Authentication tokens, credentials and request bodies are stripped before an event is sent.
5.Marketing attribution
The sign-up and onboarding flow loads a script from Cometly, which attributes a new dealer account to the campaign that produced it. It is not loaded on the public marketing pages or anywhere else in the application.
6.Consent
Strictly necessary cookies do not require consent. Everything else does, before it is set.
On your first visit a card asks for your choice. Accept all and Reject all are always one click away, and Customize lets you decide on Analytics and Marketing separately. Nothing optional is set until you press one of those buttons.
You can change your mind at any time with Cookie settings in the footer of every page. Withdrawing analytics consent deletes the Google Analytics cookies from your browser. We record which choice was made, without identifying you on the public site, so we can see how the card is used.
The two preference cookies in section 2 are set only as a direct result of an action you take, such as choosing a language or dismissing a banner, which is why they are treated as necessary to deliver a service you asked for.
7.Controlling cookies yourself
Every major browser lets you see, block and delete cookies from its settings. Blocking strictly necessary cookies will stop you signing in and will break parts of the dealer application. Clearing NEXT_LOCALE or wwmlang simply means the site asks about your language again, and clearing wwm-consent means the consent card asks again.
8.Changes
We may change this policy as the software changes. The date at the top of the page changes with it.
9.Governing language
This policy is published in English, and any translation is offered for convenience only. If a translated version conflicts with the English version, the English version governs.