COOKIE & CONSENT GUIDANCE

Collect only after
permission.

ConvertClarity defaults to consent-gated collection. Customers control the consent banner and remain responsible for regional legal requirements and their own privacy notice.

Browser storage

After analytics consent, the collector creates an anonymous session identifier in first-party session storage and a random first-party visitor identifier in local storage. The visitor identifier links return visits only on that site; ConvertClarity stores a site-scoped hash rather than the browser value. The collector does not set an advertising cookie or use cross-site identity.

When consent is withdrawn, the site should dispatch conversion-lens:consent-denied. Collection stops immediately and the persistent visitor identifier is removed.

Dashboard session

The customer dashboard uses a secure, HTTP-only, SameSite=Lax authentication cookie. It is necessary for signed-in account access and is not used for advertising.

Implementation checklist

01

Classify

Classify behavior analytics correctly for each jurisdiction and document the lawful basis with counsel.

02

Gate

Keep the WordPress plugin in “Wait for consent event” mode and dispatch conversion-lens:consent-granted only after analytics consent.

03

Honor choice

Do not initialize after denial or withdrawal. Update the site notice with purposes, retention and deletion instructions.