You really shouldn't be sending anything in a cookie except a serial number uniquely identifying the browser, and then provide a login mechanism to temporarily associate this particular browser for a limited time with a server-side storage of the data. Of course,
I wrote a column on that.
-- Randal L. Schwartz, Perl hacker