Skip to content
DataVisitors
Menu

Document details

Last revised: 8 September 2026. Status: policy review copy. Legal review: not yet recorded. This version has no effective date.

This disclosure describes the implemented application. The final operator must confirm its legal details and the production provider inventory before approval. Contact [[email protected]](mailto:[email protected]) with questions about storage or consent.

The marketing website

The public marketing pages add no analytics tracker, advertising tracker, or non-essential cookie. Reading a feature, pricing, or policy page does not require a new account session.

Your browser can still send a first-party cookie that an earlier sign-in page created. Normal browser caching can also retain public assets. Network providers or future added services require their own accurate disclosure; this page does not certify an unverified deployment.

Account access and security cookies

The application uses these first-party cookies for requested account and security functions:

  • sg_auth: keeps an authenticated account signed in. Its configured lifetime is 30 days, subject to earlier logout or revocation.
  • gr_session: binds interactive forms and security checks to the same browser. It is a session cookie with no persistent expiry set by the application. Browser session-restoration settings can affect how long it remains.
  • gr_sso or __Host-gr_sso: binds an organization single sign-on attempt to the browser that started it. It expires after 10 minutes and is cleared when the flow completes.
  • gr_social or __Host-gr_social: binds a supported external sign-in attempt to the initiating browser. It expires after 10 minutes and is cleared when the flow completes.

The secure deployment setting selects the host-prefixed names for external sign-in cookies. These cookies support authentication; they do not measure advertising audiences. A chosen external sign-in provider can use its own cookies under its own notice.

App installation, offline storage, and notifications

When the application registers its service worker, the browser can store versioned public assets and an offline fallback page. This uses the browser's Cache Storage, not an analytics cookie.

The current product configuration does not make the private analytics dashboard an offline database. The service worker excludes API, engine-action, and development-profile paths from its cache handling. Future offline features need a corresponding disclosure update.

If you enable browser notifications, the browser creates a push subscription. The service stores the destination and delivery keys needed to send authorized notifications. You can remove notification permission through your browser and use the application's notification controls.

Browser-managed storage can remain until the application updates or clears it, the browser evicts it, or you clear site data. It has no universal fixed lifetime set by a cookie expiry field.

The tracker installed on a customer's site

A customer can install the DataVisitors tracker on its own website. That website's operator is responsible for its notices, legal basis, and consent controls.

The tracker starts without a persistent device identifier. The project's selected privacy regime and consent state determine whether it can use device storage. It also observes supported Global Privacy Control and Do Not Track signals.

Stateless counting still processes a request and can use a rotating server-side identifier. The absence of a cookie does not automatically remove every data protection or storage-access obligation.

Tracker storage names and purposes

When the selected settings permit storage, the browser tracker can use localStorage entries on the customer's website:

  • sg_aid: a random identifier used for permitted visitor continuity.
  • sg_sid: the current analytics session identifier.
  • sg_last: the last-activity time used for session handling.
  • sg_idt: a digest used to avoid resending unchanged identity and trait values.
  • sg_regime: a stored indication of the permitted Opt-out regime.
  • sg_optout: the choice to stop collection when the visitor opts out.

The analytics session changes after 30 minutes of inactivity. That session rule does not automatically delete every localStorage entry. LocalStorage has no built-in expiry. Entries can remain until consent handling, application code, browser controls, or browser eviction removes them.

Mobile and desktop SDKs can use application storage for identifiers, consent state, or queued events. Their storage rules depend on the platform and the customer's integration. See the SDK guide.

Consent and privacy modes

Automatic mode selects behavior using the supported country and signal rules. Strict mode avoids the optional stored-identifier path. Opt-out mode allows its configured storage behavior unless the visitor opts out or a supported signal stops it.

These are technical controls. The website operator must still check the law that applies to its visitors. Optional storage requires consent unless a valid legal exception applies. A configuration name is not proof that an exception applies.

Where consent is required, it must be informed and based on an affirmative choice. An applicable exception can have its own information and objection requirements. Read the ICO storage guidance for the UK framework.

Change or remove your choices

Use the relevant website's consent controls to change future collection. The DataVisitors tracker supports consent and opt-out operations that the website owner can connect to those controls.

You can block cookies, clear site data, or change notification permissions through your browser. Removing account cookies can sign you out. Removing an opt-out entry can also remove the remembered choice, so set the preference again when needed.

Clearing browser storage does not erase events already held by the customer's analytics project. Request deletion from the responsible website or application operator. For your DataVisitors account, follow the Privacy Policy.

Changes and further information

A material change to scripts, providers, storage purposes, or expiry rules requires a review of this disclosure. New non-exempt storage must not begin before the required consent.

Read the tracker guide, Privacy Policy, and subprocessor disclosure. The final production inventory must include any additional provider cookies or storage used by the deployed service.