Cookie Statement for Salesforce Applications

This statement was last updated on 14 Feb 2024 and relates to the use by persons other than PwC personnel (including, where appropriate, ex-personnel and PwC client users) of the following application:

● PwC Alumni

Cookies are small text files placed on your computer by the websites that you visit. They are used in order to make websites work, or work more efficiently, as well as to provide information to the owners of the website/application.

The use of cookies is now standard for most websites. If you are uncomfortable with the use of cookies, you can normally manage and control them through your browser settings, including removing cookies by deleting them from your ‘browser history’ (cache) when you leave the website/application.

Types of cookies

‘Session’ cookies remain in your browser during your browser session only, i.e. until you leave the website/application.

‘Persistent’ cookies remain in your browser after the session (unless deleted by you).

Categories of cookies

‘Strictly necessary’ cookies are essential to enable you to use the service provided to you by the website/application

‘Performance’ cookies collect information about your use of the website/application, such as pages visited and any error messages that occurred; they do not collect personal information, and the information collected is aggregated such that it is anonymous. Performance cookies are used to improve how a website/application functions.

‘Functionality’ cookies allow the website/application to remember any choices you make (such as changes to text size, customised pages, language)

We only use ‘Strictly necessary’ cookies on our application. These cookies are necessary for our application to operate. Our application cannot function without these cookies so they are always set on.

The table below provides details about the actual cookies we use of each type. We’ve included information on the duration of each cookie and its purpose and if its use involves the transfer of information to our third party business partner Salesforce.
 

Provider

Name

First or third party Cookie?

Description

Type

Required / Not Required

SF

apex__EmailAddress

First

Caches contact ids associated with email addresses.

1 Year

Required

SF

BrowserId

First

Used for security protections.

1 Year

Required

SF

BrowserId-sec

First

Used to log secure browser sessions/visits for internal-only security use cases.

1 Year

Required

SF

communityId

First

Cookie set to tie the ideas to a specific Experience Cloud site.

Session

Required

SF

CookieConsent

First

Used to apply end-user cookie consent preferences set by our client-side utility.

1 Year

Required

SF

CookieConsentPolicy

First

Used to apply end-user cookie consent preferences set by our client-side utility.

1 Year

Required

SF

cookieSettingVerified

First

Used to create popup message telling users cookies are required.

Session

Required

SF

csssid

First

Used to establish a request context in the correct tenant org.

Session

Required

SF

csssid_Client

First

Enables user switching.

Session

Required

SF

devOverrideCsrfToken

First

CSRF Token.

Session

Required

SF

disco

First

Tracks the last user login and active session for bypassing login (ex: oauth immediate flow).

Session

Required

SF

force-proxy-stream

First

Ensure client requests hit the same proxy hosts and are more likely to retrieve content from cache.

3 hours

Required

SF

force-stream

First

Used to redirect server requests for sticky sessions.

Long

Required

SF

FedAuth

First

The Federation Authentication (FedAuth) cookie is used to authenticate to the top-level site in SharePoint (such as the root site).

Session

Required

SF

idccsrf

First

Tracks CrossSiteRequestForgery validation for certain SSO flows.

3 Months

Required

SF

inst

First

Used to redirect requests to an instance when bookmarks and hardcoded URLs send requests to a different instance. This can happen after an org migration, a split, or after any URL update

Session

Required

SF

lastlist

First

Used to store the cookie name for the last list URL.

Session

Required

SF

lloopch_loid

First

Determine whether to send the user to a specific portal login or an app login.

2 Years

Required

SF

oid

First

Stores the last logged in org for redirecting requests. Used for logging whether the cookie is present in site and community guest-user requests.

2 Years

Required

SF

pctrk

First

Used to track unique page visitors in Experiences.

Session

Required

SF

promptTestMod

First

Stores whether test mode is in effect. This cookie read-only.

30 Days

Required

SF

QCQQ

First

Determine forced login type.

Session

Required

SF

QCQQI

First

ForcedLoginUserList represents the list of users for which the browser or device continues or cancels the Forced Login interstitial page.

Session

Required

SF

QCQQR3

First

Class contains operations related to Forced Login protection, such as detection, interception, logging, and so on.

Session

Required

SF

QCQQS

First

Class contains operations related to Forced Login protection, such as detection, interception, logging, and so on.

Session

Required

SF

renderCtx

First

Used to store site parameters in the session for reuse across requests by a single client for functionality and performance reasons.

Session

Required

SF

RSID

First

Session ID and login-as session ID. In this case the cookies are copied to the response and in a proxy situation cause the target URL to rebuild appropriately. The cookies aren't created, examined, or modified.

Session

Required

SF

sfdc-stream

First

Used to properly route server requests within Salesforce infrastructure for sticky sessions.

3 hours

Required

SF

sid

First

SessionID.

Session

Required

SF

sid_Client

First

Used to detect and prevent session tampering.

Session

Required

SF

ssostartpage

First

Identifies the IdP location for SSO; certain service provider initiated SSO requests can fail without this cookie.

1 Year

Required

SF

52609e00b7ee307e

First

Browser Fingerprint cookie. Used to detect session security problems.

Session

Required

SF

79eb100099b9a8bf

First

Browser Fingerprint trigger cookie. Used to detect session security problems.

Session

Required

Follow us