Skip to content
Legal

Cookie & Local-Storage Policy

Which cookies and browser storage Propel uses, why, for how long, and how you accept, refuse or change your choice.

Last updated: 28 September 2026 · Version 2.1

This Cookie & Local-Storage Policy explains how Propel (the “Service”, available at propeltech.io) and its provider, Clovr Labs, S.L., a company incorporated in Spain, registered office at Avenida Generalitat 24, 08840 Viladecans, Barcelona, Spain, tax ID B67306894, use cookies and equivalent browser-storage technologies (local storage, session storage, IndexedDB, the service-worker cache and similar).

It is published under the Spanish Ley 34/2002 de Servicios de la Sociedad de la Información y de Comercio Electrónico (LSSI-CE), in particular its Article 22.2, the EU ePrivacy Directive (as transposed), the EU GDPR (Reg. 2016/679) and the Spanish LOPDGDD (Ley Orgánica 3/2018), and it follows the Agencia Española de Protección de Datos (AEPD) guide on the use of cookies. Read it together with our Privacy Policy and the Legal Notice.

1. What are cookies and local storage?

A cookie is a small text file that a website asks your browser to store on your device. On each later request to the same site, the browser sends it back, which lets the site keep you signed in, remember preferences and, in some cases, measure how it is used.

Browsers also offer related storage technologies, which this policy treats the same way:

  • Local storage and session storage: key/value data kept in the browser. Local storage persists until cleared; session storage is cleared when the tab closes. Unlike cookies, it is not sent with every request.
  • IndexedDB: a client-side database, which Propel uses only to hold large email drafts.
  • Service worker and Cache Storage: a small script the browser keeps for the site, which Propel uses to show an offline page and to display notifications you have turned on.

References to “cookies” include these technologies, because the LSSI-CE / ePrivacy rules apply to any storage of, or access to, information on a user’s device, whatever the mechanism.

2. Who sets cookies: first-party vs third-party

  • First-party: everything in section 4 is set by Propel itself, on its own domain. The application and its API are served from the same origin, so even the sign-in cookie, which comes from the authentication software running behind that origin, is ours and not a provider’s.
  • Third-party: no advertising, analytics or other provider script is loaded on Propel’s pages, so no third party sets a cookie here, with one exception once online payment is enabled: SumUp’s payment widget, loaded in Settings → Billing only when you open the card form (section 7). Section 7 lists the providers your browser does contact, and the flows that take you to a provider’s own site, where it sets its own cookies.

3. Categories of cookies and storage we use

Propel is a business productivity tool, not an advertising product. We use the minimum needed to run it securely, and one optional category that you decide on.

3.1 Strictly necessary, always on. Required to provide a service you asked for: keeping you signed in, knowing which organization’s data to load, applying the interface settings you chose, and remembering your cookie choice itself. Under Article 22.2 LSSI-CE these are exempt from consent; switching them off would break the Service.

3.2 Functional, set by using a feature. These remember choices you make while working: your language, saved views, list columns and sorting, board settings, open panels, snoozed items, email drafts and onboarding progress. They stay on your device, hold no identifier used to follow you elsewhere, and each one appears only because you used the feature it belongs to. They are also exempt from consent, as storage you requested.

3.3 Product analytics, only with your consent. If you accept, Propel records which screens are opened and which actions are used (for example, “opened the deals board”, “searched the inbox”), queues them in your browser and sends them to Propel’s own servers. Screens are recorded by their route (/deals/:id), never by the record you opened. No third party receives them, they are not used for advertising, and Propel keeps them for 180 days. This is off by default and stays off until you choose otherwise.

3.4 Advertising and cross-site tracking, not used. Propel sets no advertising, retargeting or cross-site tracking cookies and does not sell personal data. Adding any would require updating this policy and asking for your consent first.

4. Cookie & local-storage table

The <project> part of the session cookie is derived from the address Propel is served from. We keep this table in line with each release.

NamePurposeDurationTypeParty
sb-<project>-auth-token[.0, .1, …]Your signed-in session (access and refresh token), split into numbered chunks when it is too large for one cookie. Readable by the page’s own script, which manages it; SameSite=LaxCookie lifetime 400 days; the session itself ends on sign-out or when the server revokes it, and the access token inside is renewed every hourCookie (strictly necessary)First-party
sb-<project>-auth-token-code-verifierTemporary PKCE value used while signing in, confirming an email or resetting a passwordUntil that step completesCookie (strictly necessary)First-party
propel_consent_v1Your cookie choice (whether product analytics is allowed) and when you made it12 months, then you are asked againLocal storage (strictly necessary)First-party
crm_authThe signed-in user and organization, so the app can render before the session is re-checked. Holds no password or tokenUntil sign-outLocal storage (strictly necessary)First-party
crm_settingsTheme, colour palette, density and your organization’s display settings, applied before the page paintsPersistentLocal storage (strictly necessary)First-party
crm_languageYour language (en / es / pt / fr / de / it), on the public site and in the appPersistentLocal storage (functional)First-party
crm_views, crm_list_columns, crm_list_sort, crm_list_paging, crm_list_layout, crm_board_settings, crm_calendar_view, crm_inbox_details_open, crm_inbox_rail_expanded, crm_thread_snooze, crm_snoozed_actions, crm_distribution_lists, crm_onboarding_v1, propel:recents:v1, propel:sidebarCollapsedSaved views, list columns, sorting, page size and layout, board and calendar settings, open panels, snoozed items, distribution lists, onboarding progress, recently viewed records and the sidebar statePersistent (session items cleared on sign-out, see section 6)Local storage (functional)First-party
crm_emails_v2, crm_email_draft:v3:<scope>, IndexedDB propel-composer-draftsYour connected mailbox address and local email drafts, including recipients and body; large drafts go to IndexedDBUntil sent, discarded or sign-outLocal storage / IndexedDB (functional)First-party
crm_ai_chatYour conversation with the AI assistant on this deviceUntil sign-outLocal storage (functional)First-party
crm_doc_seq:<type>:<period>, crm_lead_decay_checkpoint_<org>Fallback numbering for quotes and invoices when the server cannot be reached, and when lead scores were last recalculatedPersistentLocal storage (functional)First-party
propel.intendedPlanThe plan you picked on the pricing page, carried into sign-upUntil sign-up completesLocal storage (functional)First-party
propel_announce_dismissed_v1That you dismissed the announcement bar on the public sitePersistentLocal storage (functional)First-party
propel_company_logos_v1, propel:org-claim-reloadA cache of company logo addresses, and a one-time marker used to recover a sign-in that needs a reloadUntil the tab closesSession storage (functional)First-party
Service worker sw.js, Cache Storage propel-offline-v1Shows an offline page when the connection drops, and displays the notifications you turned onUntil you clear site dataService worker / cache (functional)First-party
crm_ux_metrics_v1Queue of product-analytics events (screens and actions, by route) waiting to be sent to PropelUntil sent, at most a few minutes; kept by Propel for 180 days; deleted at once if you refuseLocal storage (analytics, consent required)First-party

5. Legal basis: necessity vs consent

  • Strictly necessary items (section 3.1) are used without consent, because they are indispensable to a service you requested. The related processing relies on the performance of our contract with you and our legitimate interest in running and securing the Service (GDPR Art. 6(1)(b) and 6(1)(f)).
  • Functional items (section 3.2) are written only because you used the feature they belong to, and store your own choice on your own device.
  • Product analytics (section 3.3) is used only with your prior consent (Art. 22.2 LSSI-CE; GDPR Art. 6(1)(a)). Continuing to browse, scrolling or closing the banner is not consent: until you press Accept or switch the category on, nothing is recorded.

6. Your controls

The banner. On your first visit a banner offers Accept, Reject and Configure, with the same prominence, and links to this page. It does not block the page, and nothing optional is switched on in advance. Configure shows each category and lets you turn product analytics on or off. Your choice is kept for 12 months.

Changing your mind. Use Cookie settings in the footer of the public site, or Settings → Data → Cookie settings in the app. Withdrawing consent is as easy as giving it and takes effect at once: the analytics queue on your device is deleted and nothing more is sent.

Signing out clears the items that belong to your session: crm_auth, your mailbox and drafts, the assistant conversation, saved views, distribution lists, snoozed items, board settings, onboarding progress and recently viewed records. It keeps per-browser preferences (language, interface settings and your cookie choice), which are not tied to an account.

Browser controls. You can inspect and delete everything above from your browser:

  • Google Chrome, Settings → Privacy and security → Third-party cookies / Site data.
  • Mozilla Firefox, Settings → Privacy & Security → Cookies and Site Data.
  • Apple Safari, Settings → Privacy → Manage Website Data.
  • Microsoft Edge, Settings → Cookies and site permissions.

Deleting the strictly necessary items (the session cookie or crm_auth) signs you out. Deleting the functional items loses your saved views, drafts and preferences.

7. Third parties your browser contacts

Apart from SumUp’s payment widget once online payment is enabled (below), no third-party script runs on Propel’s pages. Your browser does, however, request some content directly from other providers, which lets them see your IP address and browser details, and some flows take you to a provider’s own site:

  • Company logos: to show a company’s logo, your browser requests it from Google’s favicon service and from that company’s own website. No cookie of ours is involved.
  • Contact photos: when a Google account is connected, contact photos may load from Google’s image servers.
  • Sign-in and connections: connecting Google (Gmail, Calendar, Contacts) or Microsoft (Outlook) takes you to their sign-in pages, which set their own cookies under their own policies.
  • Payment: once online payment is enabled (it is not yet), entering a card in Settings → Billing loads SumUp’s payment widget from SumUp’s own servers (gateway.sumup.com). The card form is SumUp’s: your browser sends the card details directly to SumUp, never to Propel, and SumUp may set or read its own cookies or browser storage for that payment, under SumUp’s policies. If your bank asks you to confirm the payment (3-D Secure), that step is shown by SumUp and your bank. The widget is loaded nowhere else, and only when you open the card form.
  • Notifications: if you turn on browser notifications, they are delivered through your browser vendor’s push service (for example Google, Mozilla or Apple).

Where one of these providers sets a cookie, it does so on its own domain as an independent controller. Email open and click tracking applies to messages Propel users send, not to visitors of this site; it is described in the Privacy Policy.

8. International transfers

The items in section 4 stay on your device or go to Propel’s own servers. Where a provider in section 7 processes data outside the EEA, the safeguards for that transfer (such as the EU Standard Contractual Clauses or an adequacy decision) are described in the Privacy Policy.

9. Changes to this Cookie Policy

We update this policy when the cookies or storage we use change, or when the law does. A new optional category is never switched on by an earlier choice: the banner asks again before it is used, and the date above changes.

10. Contact

  • Privacy and data-protection requests: hello@clovrlabs.com
  • Provider: Clovr Labs, S.L., Avenida Generalitat 24, 08840 Viladecans, Barcelona, Spain, B67306894
  • Or use the contact page on propeltech.io

You also have the right to lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD), www.aepd.es. See also our Privacy Policy and the Legal Notice.

Published and in force as of the date above. It describes the cookies and browser storage the Service actually sets, checked against the software for this version. It has not been reviewed by external counsel.

Propel

The AI-native CRM for outbound teams.

AboutBlogContactStatusLegal noticePrivacy policyTerms of serviceCookie policy© 2026 Clovr Labs, S.L.