Legal · Cookie Notice
Cookie Policy
What cookies and similar technologies we use on glacis.io and related sites — and how you can control them.
Contents
1. What are cookies
A “cookie” is a small text file that a website places on your device. Cookies let a site remember you across pages or visits. “Similar technologies” include local storage, session storage, IndexedDB, fingerprinting beacons, and tracking pixels. We use the term “cookies” in this policy to refer to all of them.
Cookies can be first-party (set by GLACIS on a domain we control) or third-party (set by a service provider whose code runs on our pages). They can be session cookies (deleted when you close your browser) or persistent (stored for a defined period).
2. Why we use them
We use cookies for four things: keeping the site secure, remembering your preferences, measuring how people find and use the site, and measuring the effectiveness of our B2B marketing. For marketing measurement, some of the cookies in Section 4 below transmit browsing signals to advertising platforms (LinkedIn, StackAdapt, Leadfeeder/Dealfront); under California’s CPRA this is a “share” of personal information. You can opt out at any time — via the consent banner on first visit, the “Do Not Sell or Share” link in the footer, or by sending a Global Privacy Control signal, which we honor automatically. We do not use cookies for profiling of the kind that would result in legally significant decisions about you.
3. Categories we use
- Strictly necessary. Required for core functionality: load balancing, security (bot-challenge tokens, CSRF protection), cookie-consent state. These cannot be disabled; they do not require consent under EU law.
- Performance & analytics. First-party, cookieless measurement helps us understand site usage and improve content. In consent-required regions it remains off until acceptance; it does not run on legal pages and is suppressed after a stored decline or when Global Privacy Control is active.
- Functional. Remember preferences (language, dark mode, cookie consent) to give you a more personal experience across visits.
- Marketing. Measure B2B campaigns and prospective-account activity using the providers listed below. In consent-required regions these technologies remain off until acceptance; elsewhere they remain subject to the site opt-out and GPC.
First-party funnel measurement
GLACIS runs cookieless, first-party measurement (/api/event). It uses no cookies or cross-site tracking; a per-tab session ID lives in sessionStorage and dies with the tab. It records page paths, referrer hostnames, and product events such as completing a record verification. It follows the same binary choice as the marketing technologies below and is disabled on legal pages, after a stored decline, and when Global Privacy Control is active.
4. Specific cookies we set
The list below reflects the cookies and storage items identified in the site implementation reviewed on 26 August 2026. Providers can change their own cookie names and durations; this table must be rechecked when integrations change.
| Name | Provider | Category | Purpose | Duration |
|---|---|---|---|---|
| __cf_bm | Cloudflare | Strictly necessary | Bot-management challenge token. | 30 min |
| cf_clearance | Cloudflare | Strictly necessary | Challenge-passed indicator used to allow page load. | 30 days |
| cf-turnstile-* | Cloudflare Turnstile | Strictly necessary | Invisible bot-protection on forms. | Session |
| glacis-consent | GLACIS (first-party) | Strictly necessary | Records your marketing-technology choice in browser local storage. | 12 months from the latest choice |
| _cfuvid | Cloudflare | Strictly necessary | Rate-limiting and DDoS protection. | Session |
| __hstc, hubspotutk, __hssrc, __hssc | HubSpot | Marketing | Associate form fills, page views, and demo requests with a contact record for sales follow-up. | Up to 13 months |
| apollo_visitor, apollo_session | Apollo.io | Marketing | Visitor identification for account-based marketing; measures reach to identified target accounts. | Up to 12 months |
| ahrefs-* | Ahrefs | Performance | SEO-analytics pixel measuring organic-search journey. | Up to 13 months |
| _lfa, lfeeder_* | Leadfeeder (Dealfront) | Marketing | Company-level identification of site visitors from their IP, used for account-based sales outreach. No individual identification. | Up to 24 months |
| bcookie, bscookie, li_gc, _lipt, AnalyticsSyncHistory, lms_analytics, UserMatchHistory | LinkedIn Insight | Marketing | Conversion tracking and audience measurement for LinkedIn-originated traffic; suppressed when Global Privacy Control is detected. | Up to 6 months (some session-only) |
| sa-user-id, sa-user-id-v2, _uid-* | StackAdapt | Marketing | Attribution and conversion measurement for display campaigns; aggregated, no profile building for ad targeting on this site. | Up to 13 months |
| Local storage: glacis-prefs | GLACIS (first-party) | Functional | UI preferences (theme, dismissed banners, video autoplay preference). | Until cleared |
If the cookie inventory changes, this page should be updated with the deployment. Any applicable provider and data-processing information should also be reconciled with the current Subprocessor list at trust.glacis.io.
5. Third-party cookies
Third-party cookies are placed by service providers running on our pages for the purposes described in Section 4. These providers have their own privacy notices:
- Cloudflare — cloudflare.com/privacypolicy
- HubSpot — legal.hubspot.com/privacy-policy
- Apollo.io — apollo.io/privacy-policy
- Ahrefs — ahrefs.com/legal/privacy-policy
- LinkedIn Insight — linkedin.com/legal/privacy-policy
- StackAdapt — stackadapt.com/privacy
- Leadfeeder / Dealfront — privacycockpit.leadfeeder.com
We do not load Google Ads or Meta (Facebook/Instagram) pixels in the audited implementation. LinkedIn Insight, StackAdapt, and the other listed B2B measurement technologies load only through the shared marketing gate; they remain disabled when GPC is detected or the user declines marketing.
6. How long cookies last
Session cookies are deleted when you close your browser. Persistent-cookie durations are listed in the table above. The glacis-consent local-storage choice expires 12 months after the latest choice; other local-storage items remain until the site or browser clears them.
7. How to control cookies
7.1 Site controls
The site presents a binary analytics-and-marketing choice in consent-required regions. The footer’s “Do Not Sell or Share” control records a decline. The buttons below let this browser replace that choice; the selection is stored in glacis-consent local storage for 12 months. The current implementation does not offer separate per-provider or per-category toggles.
7.2 Browser controls
Most browsers let you block or delete cookies through their settings. Instructions for common browsers:
Blocking strictly necessary cookies may prevent parts of the Services from working.
7.3 Analytics opt-out
The site controls govern first-party measurement and the shared marketing gate, including HubSpot, Ahrefs, Apollo, Leadfeeder/Dealfront, LinkedIn Insight, and StackAdapt where those integrations are present. Browser settings can also block or clear storage and third-party requests.
8. DNT and Global Privacy Control
We honor the Global Privacy Control (GPC) signal as an opt-out of the “sale” and “share” of personal information under the CCPA/CPRA and equivalent state laws. When we detect the GPC signal from your browser, marketing technologies and first-party analytics are suppressed, regardless of any prior consent stored in glacis-consent local storage.
We recognize but do not rely on the legacy Do Not Track (DNT) header, because it lacks a consistent specification. The shared marketing gate honors GPC and the site’s stored decline choice.
9. Changes to this policy
We may update this Cookie Policy when cookies, providers, or categories change. Material changes should be reflected in the effective or revision date after the revised notice is approved. The table is a maintained disclosure, not a live technical scan.
10. Contact
Questions about this Cookie Policy:
GLACIS Technologies, Inc.
Seattle, Washington, USA
[email protected]
Trust Center: trust.glacis.io
Effective 18 April 2026 · Revised 11 June 2026 · v1.1 · Published by GLACIS Technologies, Inc.