Simpplr uses cookies to help you sign in securely, keep your data safe, improve app performance, and understand usage through analytics. On this page, you’ll find details about the cookies we use, why we use them, how long they stay, and whether they come from Simpplr or a trusted third party.
Cookies used in Simpplr fall into the following categories:
Strictly necessary cookies – Required for core functionality such as login, authentication, and security.
Preferences Cookies – Store user settings such as language or display options.
Statistics Cookies – Collect analytics on usage patterns to improve the platform.
Analytics/performance cookies (via RudderStack) – Tracks page activity, user identity, session details, search behavior, and browser/device context.
Each cookie can be either:
Persistent – Remains stored until expiry or manual deletion.
Session – Deleted when the browser session ends.
Cookies may also be:
First-party – Set directly by Simpplr.
Third-party – Set by partner services integrated into Simpplr.
Cookie name | Category | Duration | Provenance | Domain | Notes |
|---|---|---|---|---|---|
token | Strictly necessary | Persistent (can be session) | First party | — | Can be made session-based via Security > Session Settings |
ftoken | Strictly necessary | Persistent (can be session) | First party | — | Can be made session-based via Security > Session Settings |
csrfid | Strictly necessary | Persistent (can be session) | First party | — | Protects against CSRF attacks. Follows session setting if enabled |
ym_xid | Strictly necessary | 8 hrs (agent) / 24 hrs (mobile) | Third party | Set by Yellow.ai. Mandatory for virtual assistant sessions | |
hjSession, hjSessionUser, ph_phc*, cfuvid, GENABLED_IDPS | Statistics | Session / Persistent (varies) | Third party | Set by Yellow.ai for analytics and personalization | |
rl_anonymous_id, rl_page_init_referrer, rl_session, rl_user_id, rl_trait | Statistics | Persistent | First party | App analytics. Set by RudderStack integration | |
cfbm | Strictly necessary | Persistent | Third party | Cloudflare bot management. Not related to analytics |
Note: Yellow.ai does not provide end-user cookie choice only if the integration is enabled for the tenant . Documentation is limited as these are internal to Yellow.ai.
Google analytics 4 (GA4) – Cookies set only if enabled by the customer. See GA4 Help.
Aisera – Cookies set only if enabled by the customer.
Q: What are cookies and why does Simpplr use them?
Ans: Cookies are small files stored in your browser. Simpplr uses them to sign you in securely, keep your data safe, protect against common web threats, support app performance, and understand usage through analytics.
Q: What types of cookies does Simpplr use?
Ans: They fall into a few categories: strictly necessary cookies (login, authentication, and security), preferences cookies (settings such as language or display options), statistics cookies (usage analytics to improve the platform), and analytics/performance cookies via RudderStack (page activity, user identity, session details, search behavior, and browser/device context).
Q: What's the difference between session and persistent cookies?
Ans: A session cookie is deleted when your browser session ends. A persistent cookie remains stored until it expires or you delete it manually.
Q: What's the difference between first-party and third-party cookies?
Ans: First-party cookies are set directly by Simpplr. Third-party cookies are set by partner services integrated into Simpplr, such as Yellow.ai or Cloudflare.
Q: Which cookies are essential for Simpplr to work?
Ans: The strictly necessary ones. These include token and ftoken (authentication), csrfid (protection against CSRF attacks), cfbm (Cloudflare bot management), and, if the virtual assistant is enabled, ym_xid for Yellow.ai sessions.
Q: Can I turn off strictly necessary cookies?
Ans: No. These are required for core functionality like login, authentication, and security, so the platform cannot function properly without them.
Q: What are the RudderStack cookies for?
Ans: The rl_anonymous_id, rl_page_init_referrer, rl_session, rl_user_id, and rl_trait cookies are first-party statistics cookies used for app analytics through the RudderStack integration.
Q: Why do I see Yellow.ai cookies?
Ans: These appear only if the Yellow.ai virtual assistant integration is enabled for your tenant. ym_xid is mandatory for virtual assistant sessions, and additional cookies (_hjSession, hjSessionUser, phphc*, cfuvid, GENABLED_IDPS) support analytics and personalization. Yellow.ai does not provide end-user cookie choice for these, as they are internal to Yellow.ai.
Q: Can I control whether authentication cookies persist after I close my browser?
Ans: Yes. The token, ftoken, and csrfid cookies can be made session-based through Security > Session Settings, so they expire when the browser closes.
Q: Are Google Analytics 4 or Aisera cookies always present?
Ans: No. GA4 and Aisera cookies are set only if your organization chooses to enable those integrations.