This policy explains what browser storage (cookies, localStorage) Cloop uses across the marketing site, dashboard, and embeddable chat widget.
1. Marketing Site (www.cloop.io)
The marketing site at www.cloop.io uses Google Tag Manager to load HubSpot (account hosted in HubSpot's EU region) for website analytics and the cookie consent banner, and Calendly for booking a meeting. Google Tag Manager sets no cookies itself. There are no advertising pixels and no other third-party trackers.
Consent comes first. On your first visit HubSpot's cookie banner asks whether you accept cookies ("Hyväksy") or decline them ("Hylkää"). HubSpot's analytics cookies are set only if you accept. Google consent signals start as denied. You can change your choice at any time from the cookie settings link (Evästeasetukset) in the site footer.
Before you choose, and if you decline, HubSpot still counts each page view anonymously: it receives the page address and the page you came from, and, as with any web request, your IP address and browser details. No cookie is set and nothing links one page view to the next.
| Cookie | Purpose | Set when |
|---|---|---|
__hs_cookie_cat_pref | Remembers your choice, whether you accepted or declined (kept for 6 months) | When you choose in the banner |
__hstc, hubspotutk | Recognise a returning browser for website analytics (kept for 6 months) | Only if you accept |
__hssc, __hssrc | Count visits within a session; expire within a day or when you close the browser | Only if you accept |
__cf_bm on HubSpot's domains | Bot protection by Cloudflare for HubSpot's servers; expires within a day | When the page loads HubSpot's banner and scripts |
__cf_bm, _cfuvid on calendly.com | Bot protection by Cloudflare for Calendly's servers; expire within a day or when you close the browser | When the page loads Calendly's booking button |
Without JavaScript the banner cannot ask for consent, so the site then loads none of these analytics tools.
However, the site embeds the Cloop chat widget. If you interact with the widget, it stores a visitor identifier in your browser's localStorage as described in Section 3 below, and the backend records your conversation data (messages, session metadata, conversation phase) as described in our Privacy Policy.
2. Dashboard (console.cloop.io)
The Cloop admin dashboard uses the following browser storage:
Authentication
| Storage | Purpose | Duration |
|---|---|---|
| localStorage | Access token (JWT) | Until logout or token expiry |
| localStorage | Refresh token | Until logout or token expiry |
Preferences
| Storage | Purpose | Duration |
|---|---|---|
| localStorage | Currently selected site | Until changed |
| localStorage | Theme (light/dark) | Until changed |
| localStorage | Language/locale | Until changed |
No third-party cookies are set by the dashboard. No analytics or tracking scripts are loaded.
Legal basis: Contract performance (Art. 6(1)(b) GDPR) — these tokens and preferences are necessary to authenticate you and provide the service you signed up for.
3. Chat Widget (Embedded on Customer Websites)
When a customer embeds the Cloop widget on their website, the widget uses the following browser storage on the visitor's device:
Session & Identity
| Storage | Purpose | Duration |
|---|---|---|
| localStorage | Random visitor UUID for returning-visitor recognition (cloop_vid) | Persistent until cleared by visitor |
| localStorage | Chat session ID (cloop_session_<site>) | Persistent until cleared or session expires |
| localStorage | Visitor email, if voluntarily provided during chat (cloop_visitor_email_<site>) | Persistent until cleared by visitor |
| localStorage | Campaign link token, only when you arrive via a personalized link in an email the website owner sent you (cloop_st) | Persistent until cleared by visitor |
| localStorage | Identification markers that prevent the same identification event from being sent twice | Persistent until cleared by visitor |
| localStorage | Chosen chat language (cloop_lang_<site>) | Until changed |
| localStorage | Live-chat handover state, so a conversation with a human survives a page reload (cloop_live_<scope>) | Until the live chat ends |
| sessionStorage | Widget open/closed state (cloop_open_<site>) | Current browser tab |
| sessionStorage | Page URL for navigation tracking within the chat | Current browser tab |
| sessionStorage | A page action the visitor asked for, held across the navigation that carries it out (cloop_pending_page_action) | Current browser tab |
| sessionStorage | Visitor Intelligence session marker (only on websites where the owner has enabled it; see below) | Current browser tab |
| sessionStorage | Proactive chat trigger state (which triggers have shown or been dismissed) | Current browser tab |
| sessionStorage | Campaign entry key, only when you arrive through a campaign link set up by the website owner (cloop_campaign_context_<site>) | Current browser tab |
| sessionStorage | Personal campaign link identifier, only when you arrive through a personal link the website owner sent you; it is removed from the address bar and used only if you send a chat message (cloop_campaign_recipient_<site>) | Current browser tab |
| sessionStorage | Markers that stop the same chat event being reported twice to the website's own analytics, only where the website owner has turned this on and your consent has been given on that website (cloop_analytics_<event>_<session>) | Current browser tab |
Preferences
| Storage | Purpose | Duration |
|---|---|---|
| localStorage | Font scale setting | Persistent until changed |
| localStorage | Sidebar width setting | Persistent until changed |
| localStorage | Chat language choice | Persistent until changed |
| localStorage | Voice playback mute setting | Persistent until changed |
What This Means
- All values are stored per site — they are not shared across different websites that use Cloop
- The visitor UUID is a random identifier (e.g.,
a1b2c3d4-e5f6-...) — it contains no personal information by itself - These are not cookies — they are not sent with HTTP requests and cannot be read by other domains
- sessionStorage items are automatically cleared when the browser tab is closed
- Preference items (font scale, sidebar width) contain no personal data — they store the visitor's chosen display settings
Visitor Activity Tracking (optional, controlled by the website owner)
The website owner can enable a Visitor Intelligence feature for their site. When it is enabled, the widget additionally records how you use that website: which pages you view (path only, never the full address with query parameters), how long you stay on a page, how far you scroll, and how you interact with the chat surfaces. These events are sent in batches to Cloop's EU servers, linked to the visitor identifier described above, and deleted after 90 days.
This tracking is off by default. It runs only if the website owner has switched it on, and it never starts before the website's consent mechanism (where one is configured) has signaled approval. It uses no additional browser storage beyond the existing visitor identifier and the session marker listed above.
If you arrived at the website through a personalized link in an email the website owner sent you, the widget stores that link's token so your visit and chat can be connected to the conversation you already have with them. This applies only to recipients of such links, never to ordinary visitors.
Cookie Consent Considerations
Whether this localStorage usage requires cookie consent depends on your jurisdiction and interpretation of the ePrivacy Directive:
- Strictly necessary exception may apply, as the storage enables the chat service the visitor initiates. Several EU DPAs have indicated that storage strictly necessary for a service explicitly requested by the user is exempt from consent.
- Conservative approach: If your compliance policy requires consent for all browser storage, you can configure the widget to delay initialization until consent is signaled.
We recommend that customers mention the Cloop chat widget in their cookie/privacy policy regardless. See our End-User Privacy Notice template for suggested text.
4. What We Do NOT Use, and What We Do
We do not use:
- Advertising cookies or pixels
- Cross-site tracking: nothing Cloop stores is shared between different websites
- Fingerprinting techniques
- Third-party analytics services (Google Analytics, etc.) in the dashboard or the Widget. The marketing website's analytics, which runs only with your consent, is described in Section 1.
- Social media cookies or pixels
- Session cookies (we use tokens in localStorage instead)
We do offer first-party visitor activity tracking as an optional feature that each website owner decides to enable or not, as described in Section 3. It is limited to the single website you are visiting, it is consent-gated, and it is never used for advertising.
The website owner can also let the Widget report three chat events (conversation started, contact requested, meeting booked) with campaign labels to their own website analytics, such as Google Tag Manager. This is off by default, runs only after the website's own consent tool has recorded your consent, and sends no personal data. Cloop receives nothing from it.
5. How to Clear Cloop Storage
Dashboard
Log out of the Cloop dashboard (clears tokens), or clear localStorage for console.cloop.io in your browser settings to remove all dashboard storage.
Widget
Clear localStorage for the website where the widget is embedded. The visitor ID and session will be regenerated on next visit (a new anonymous session will start). Preferences (font scale, sidebar width) will reset to defaults.
6. Changes
We update this policy whenever a feature changes what is stored or tracked. In June 2026 we added the optional Visitor Intelligence feature described in Section 3 and are notifying all customers who embed the Widget before any site can enable it. We will do the same for any future change of this kind. In September 2026 we added consent-based analytics to our own marketing website (Section 1); it does not run in the Widget or the dashboard, so it changes nothing on customer websites.
Contact
Questions: privacy@cloop.io