Account Settings

Account Management

Update your profile, change your password or email, manage sessions, enable 2FA, and review security alerts.

Your profile information includes your name, contact details, and preferences. It is separate from your agent data (agents are what get sent; profile is your account owner information). Here is how to update it.

1. Where To Update Profile

  • Sign in to your dashboard.
  • Go to Account Settings.
  • Click Profile.
  • Every editable field is on this page.

2. What Fields Are On The Profile

  • First name and last name. How ContactID addresses you in email.
  • Display name. Shown in the dashboard header.
  • Company name. Appears on invoices.
  • Time zone. Used for scheduled batches and email timing.
  • Language. Dashboard interface language.
  • Country. For tax and compliance purposes.
  • Marketing preferences. Toggle emails about product updates, tips, offers.

3. Editing And Saving

  • Change any field.
  • Click Save Changes at the bottom.
  • A confirmation toast appears.

Changes are effective immediately across all your devices and the extension.

4. Profile Vs Agent Data

Do not confuse profile with agent:

  • Profile is your ContactID account owner information.
  • Agent is the sender identity used on outbound forms.

They can differ. Your profile might say “Sarah Chen, Acme” while an agent says “Sarah, Acme Design Studio” with a slightly different pitch. That’s fine.

5. Time Zone Changes

Changing time zone affects:

  • Scheduled batch times. A batch scheduled for “9 AM” is now 9 AM in the new time zone.
  • Email timestamps. Report emails show times in your new zone.
  • Activity display. Sends are still stored in UTC but displayed in your zone.

6. Marketing Preferences

Four categories you can toggle:

  • Product updates. New features, extension releases.
  • Tips and best practices. Newsletter with outreach tips.
  • Special offers. Discounts and promotions.
  • Account notices. Not toggleable; always sent (billing, security, expiring cards).

7. Language Support

The dashboard supports:

  • English (default).
  • Spanish.
  • French.
  • German.
  • Portuguese.

Extension side panel is English only for now. Adding more languages over time.

Changing your password takes about a minute. Do it if you suspect compromise, or as a periodic security hygiene. Here is the flow.

1. From Account Settings

  • Sign in.
  • Go to Account Settings, then Security.
  • Click Change Password.
  • Enter your current password.
  • Enter your new password twice.
  • Click Update Password.

2. Password Requirements

  • Minimum 8 characters.
  • At least one letter and one number.
  • Cannot be one of your last 5 passwords.
  • Cannot be a common password (like “password123” or “12345678”).

Longer passwords are stronger. A 16-character phrase-based password is far more secure than an 8-character random one.

3. What Happens After Change

  • Every active session on every device is signed out. This includes the extension.
  • You must sign in again on each device with the new password.
  • Batches in progress are not affected; only the sessions.

4. When To Change Password

Change immediately if:

  • You get a security alert about unauthorized access.
  • Your account email address was compromised.
  • You suspect a shared computer had unauthorized access.
  • Your password appears in a data breach notification.

5. Password Manager Recommended

Store your ContactID password in a password manager (1Password, Bitwarden, LastPass, browser-integrated). Benefits:

  • No need to memorize a strong password.
  • Auto-fill on sign-in.
  • Sharing with team members via manager, not exposed.

6. Forgot Password

If you forgot your password:

  • On the sign-in page, click Forgot Password.
  • Enter your account email.
  • Check your inbox for a reset link (valid for 1 hour).
  • Click the link, set a new password.
  • Sign in with the new password.

The reset link works even if you cannot access your current password.

7. Google Sign-In Accounts

If you signed up with Google, you don’t have a ContactID password by default:

  • To add one (so you can sign in without Google later), go to Security > Set Password.
  • Follow the same flow as changing a password.

8. Two-Factor Authentication

For higher security, enable 2FA. See the article on 2FA.

Changing your account email takes a bit more than changing a password because we verify the new address. Here is the flow.

1. From Account Settings

  • Sign in.
  • Go to Account Settings, then Profile.
  • Click Change Email Address.
  • Enter the new email.
  • Click Send Verification.

2. Verification Flow

A verification code goes to the new email. Meanwhile:

  • Your current email keeps being used for account notices until verification completes.
  • The old email gets an email notification alerting you to the pending change (for security).
  • The new email has a 15-minute window to verify.

Enter the code on the verification screen. Once verified:

  • New email becomes your account email.
  • Future notices go to the new address.
  • Sign-in uses the new address.
  • Old email is no longer associated with the account.

3. Cancelling A Pending Change

If you started the change but did not verify, the pending change expires after 15 minutes. If you want to cancel before that:

  • Go back to Account Settings > Profile.
  • Click Cancel Email Change.
  • Confirmed.

4. If You Lose Access To The New Email

If you sent verification to an address you cannot access:

  • Contact support with your account details.
  • We can revert the change after confirming ownership of your account (typically via original email address, subscription history, or Stripe reference IDs).

5. Email And Google Sign-In

If you signed up with Google:

  • Your ContactID email is tied to your Google account.
  • Changing the email requires either signing in with a different Google account or converting to email/password sign-in first.

To decouple:

  • Go to Security > Set Password.
  • Set a ContactID password.
  • Then change email through the normal flow.

6. Email Changes And Sessions

An email change:

  • Invalidates every session on every device.
  • Requires you to sign in again with the new email.
  • Does not affect batches in progress.

7. Emails To The Old Address

Once change is complete:

  • No more notices go to the old address.
  • Historical emails already sent to it stay in that inbox.
  • Invoices generated before the change still show the old address; they are historical records.

8. Billing Email Vs Account Email

Some users have a separate billing email (for a bookkeeper or company). Set separately:

  • Account Settings > Billing Details > Billing Email.
  • Invoices go there.
  • Account notices still go to your main account email.

ContactID uses a sliding session model that extends your sign-in each time you use the app, so active users never get logged out. Inactive users get logged out for security. Here is how it works.

1. The Sliding Window

Your session is a token stored in your browser (dashboard) or extension storage (extension). Its lifetime works like this:

  • Sessions are valid for 30 days from creation.
  • Each active use extends the session by another 30 days.
  • After 30 days of no use, the session expires and you have to sign in again.

Active use includes:

  • Opening the dashboard or extension.
  • Starting or watching a batch.
  • Any API call (browsing, editing, exporting).

2. Why This Design

The sliding window balances two concerns:

  • Convenience. Regular users never see a login screen. Sign in once and you’re set.
  • Security. Inactive accounts eventually log out, reducing risk of unauthorized access on old devices.

3. Extension Sessions

The extension has its own session, separate from the dashboard. The rules are the same (30-day sliding), but:

  • Extension sessions are per-browser. Signing in on Chrome does not sign in on Brave.
  • Multiple sessions per account are allowed. You can be signed in on many browsers and devices at once.

4. Session Extension Frequency

For efficiency, the session-extension write is throttled: it fires at most once per 60 minutes of active use. If you use ContactID heavily throughout a day, you may see the last-use timestamp update once, not on every click.

Doesn’t affect functionality; just an internal optimization.

5. Manually Extending A Session

There’s no way to “extend” a session manually. Any use extends it automatically. If you know you’ll be away for over 30 days, no action needed; when you return, you sign in again.

6. Manually Ending A Session

To sign out early:

  • From the dashboard: Account menu > Sign Out.
  • From the extension: Side panel profile icon > Sign Out.
  • All devices at once: Account Settings > Sessions > Sign Out Everywhere.

7. What Ends A Session Immediately

Beyond the 30-day timeout:

  • Explicit sign out.
  • Password change.
  • Email change.
  • Signing out from another device via Sign Out Everywhere.
  • Account suspension by ContactID (rare).

8. Session Security

Sessions are protected by:

  • HTTP-only cookies (dashboard) or Chrome extension storage (extension).
  • Cross-site request forgery (CSRF) tokens on every state-changing action.
  • Encrypted transmission (HTTPS everywhere).
  • Server-side revocation on password/email change.

The Sessions page shows every active sign-in across every device and gives you tools to review or revoke them. Here is what it shows and how to use it for security.

1. Where To See Sessions

  • Sign in to your dashboard.
  • Go to Account Settings, then Sessions.
  • The table lists every active session.

2. What Each Row Shows

  • Device. Chrome on Windows, Safari on Mac, etc.
  • IP address. The IP where the session is used (may change if IP updates).
  • Approximate location. City/region from IP geolocation.
  • First sign-in. When this session started.
  • Last activity. When this session was last used.
  • Type. Dashboard or Extension.

3. Reviewing For Anomalies

Check the list periodically for:

  • Devices you don’t recognize. Sign-in from a device you’ve never used.
  • Locations that don’t match. Sign-in from a country you’ve never visited.
  • IPs you don’t recognize. Corporate network IPs, VPN IPs.

Anomalies could indicate compromise; act quickly.

4. Revoking A Session

  • Find the session row to revoke.
  • Click Revoke.
  • Confirm.

The device is immediately signed out. Its next request to ContactID gets a 401 and prompts sign-in.

5. Sign Out Everywhere

For a “reset” of all sessions:

  • On Sessions page, click Sign Out Everywhere.
  • Confirm.
  • Every session (including the one you’re using) is signed out.

You’ll be redirected to the sign-in page immediately.

6. Automatic Session Cleanup

Sessions inactive for 30 days are automatically revoked. You don’t need to manually clean up.

7. Multiple Extension Sessions

The extension can have multiple simultaneous sessions if you use ContactID on multiple browsers or devices. Each is listed separately with its device info.

8. Session Data Retention

Session records (for security auditing) are retained for 12 months. This lets you look back at sign-in history to spot anomalies retrospectively.

Two-factor authentication (2FA) adds a second verification step to sign-in, using a code from an authenticator app on your phone. Here is how to enable it and use it.

1. What 2FA Does

When 2FA is on:

  • Sign-in requires: Email + password + a 6-digit code from your authenticator app.
  • The 6-digit code changes every 30 seconds.
  • Even if someone steals your password, they still need physical access to your phone.

Significantly harder to hack. Recommended for any account with financial data.

2. Enabling 2FA

  • Go to Account Settings, then Security.
  • Click Enable 2FA.
  • ContactID displays a QR code and a text-based key.
  • Open your authenticator app (Google Authenticator, Authy, 1Password, etc.).
  • Add a new entry and scan the QR code (or type the key).
  • The authenticator now shows a 6-digit code for ContactID.
  • Enter the current code on the ContactID screen.
  • Click Confirm.
  • 2FA is now enabled.

3. Backup Codes

Immediately after enabling 2FA, ContactID shows 10 backup codes. Save these:

  • Print them and store in a safe place.
  • Or save in your password manager.

Each code is single-use and lets you sign in without your authenticator app (in case you lose your phone).

4. Signing In With 2FA

  • Enter email and password as usual.
  • ContactID prompts for the 2FA code.
  • Open your authenticator app, find ContactID, and type the current code.
  • Click Sign In.

The extension prompts for 2FA on first sign-in after enabling; you don’t need to enter it again unless the session ends.

5. Losing Your Authenticator App

If your phone is lost or the authenticator app is uninstalled:

  • Use a backup code to sign in.
  • Go to Security > 2FA > Regenerate.
  • Disable 2FA and re-enable with a fresh QR code on your new device.

If you don’t have backup codes, contact support with proof of account ownership (subscription details, past invoices).

6. Disabling 2FA

  • Go to Security > 2FA.
  • Click Disable.
  • Enter your password to confirm.
  • Enter a 2FA code to confirm.
  • 2FA is off; sign-in returns to password-only.

7. Recommended Authenticator Apps

  • Google Authenticator. Free, simple, single device.
  • Authy. Syncs across devices with encrypted backup.
  • 1Password. Built into 1Password password manager.
  • Bitwarden. Built into Bitwarden password manager.

Any TOTP-compatible app works.

8. 2FA On The Extension

The extension respects your 2FA setting:

  • Enabled on your account: extension prompts for 2FA on sign-in.
  • Disabled: extension only asks for password.

ContactID watches for patterns that might indicate account compromise. When something looks unusual, you get an alert. Here is what triggers alerts and how to respond.

1. What Triggers An Alert

Alerts fire when:

  • New device sign-in. Sign-in from a device or browser not seen before.
  • Impossible-geography sign-in. Sign-in from US, then within an hour, sign-in from Europe (physical travel is impossible).
  • Multiple failed sign-in attempts. More than 5 failed passwords in an hour.
  • Password change. Confirmation email even for legitimate changes.
  • Email change. Confirmation to old email address.
  • Sensitive setting change. Adding/removing payment method, enabling auto-recharge with high amount.
  • Bulk credit refund or reversal.

2. Delivery

Alerts arrive via:

  • Email to your account email address.
  • In-app banner on the dashboard.
  • Extension notification (if the extension is running).

Alerts are hard to miss.

3. What Each Alert Includes

  • What happened. The specific event.
  • When. Timestamp.
  • Device and location. Best-effort estimate.
  • What to do next. Instructions if the activity is legitimate or not.

4. When To Take Action

If the alert describes activity that was you:

  • No action needed; you can ignore.
  • Alerts help you verify your own activity later.

If the alert is NOT you:

  • Sign out everywhere immediately (Sessions > Sign Out Everywhere).
  • Change your password (Security > Change Password).
  • Enable 2FA if not already on (Security > 2FA).
  • Contact support with the alert details.

5. Preventing Alerts For Legitimate Activity

Some alerts are unavoidable for security:

  • New device sign-in always alerts.
  • Impossible-geography always alerts.
  • Password/email changes always alert.

Others can be tuned:

  • Bulk actions (like auto-recharge amount changes) can be pre-authorized in Settings.

6. Alert Frequency

  • New device: Once per new device per 30 days.
  • Impossible geography: Every occurrence.
  • Failed sign-in: Every occurrence above threshold.
  • Password/email: Every occurrence.

7. Turning Off Alerts

Most alerts are considered security-critical and cannot be disabled entirely. You can toggle:

  • New-device alerts (in Notifications settings).
  • Marketing-style alerts (not security).

Security alerts (impossible geography, password change) stay always-on.

Still stuck? We’re happy to help.

Install the extension, sign up, or reach out to support directly.

Back to Help Center