Strictly Necessary
livex_cookie_consent
- Provider
- LiveX AI
- Technology
- Cookie
- Party
- First party
- Purpose
- Stores the visitor's cookie choice and makes it available during page requests.
- Data collected
- Selected categories, timestamp, policy version, and consent-region value.
- Duration or expiry
- Up to 12 months.
- EU/EEA transfer and safeguard
- Stored on the device and sent to LiveX-hosted pages; hosting-provider safeguards apply.
- User control
- Always active so the site can remember and respect your choice.
Strictly Necessary
livex.cookieConsent.v2
- Provider
- LiveX AI
- Technology
- Local storage
- Party
- First party
- Purpose
- Keeps the detailed consent record synchronized with the first-party consent cookie.
- Data collected
- Selected categories, timestamp, policy version, and consent-region value.
- Duration or expiry
- Up to 12 months; stale policy versions are rejected.
- EU/EEA transfer and safeguard
- Remains on the visitor's device unless included in a support diagnostic supplied by the visitor.
- User control
- Always active so the site can remember and respect your choice.
Strictly Necessary
livex-csp-monitor
- Technology
- Cookie
- Party
- First party
- Purpose
- Enables controlled security-policy monitoring without exposing report details to browser scripts.
- Data collected
- A value indicating that Content Security Policy reporting is enabled.
- Duration or expiry
- 3 days.
- EU/EEA transfer and safeguard
- United States and provider locations; Vercel's DPA incorporates EU Standard Contractual Clauses.
- User control
- Activated only by an authorized CSP-monitoring URL and removable by disabling that monitoring URL.
Strictly Necessary
LiveX website delivery
- Technology
- Network request
- Party
- First party
- Purpose
- Hosts and delivers the LiveX website securely.
- Data collected
- IP address, requested URL, browser headers, timestamps, and security/request metadata.
- Duration or expiry
- Request duration; infrastructure logs follow the provider's contractual retention terms.
- EU/EEA transfer and safeguard
- United States and provider locations; Vercel's DPA incorporates EU Standard Contractual Clauses.
- User control
- Required to deliver the page and its first-party application code.
Strictly Necessary
cdn.livex.ai asset delivery
- Technology
- Network request
- Party
- First party
- Purpose
- Delivers essential LiveX visual and media assets.
- Data collected
- IP address, requested asset, browser headers, timestamps, and network-reliability metadata.
- Duration or expiry
- Request duration; infrastructure logs follow the provider's contractual retention terms.
- EU/EEA transfer and safeguard
- Global network including the United States; Cloudflare relies on the EU-U.S. DPF and EU SCCs with supplementary safeguards.
- User control
- Required when a page contains LiveX-hosted images, fonts, or video.
Strictly Necessary
cdn.sanity.io content delivery
- Technology
- Network request
- Party
- Third party
- Purpose
- Delivers images that are part of published case studies, careers, and insights.
- Data collected
- IP address, requested asset, browser headers, and request metadata.
- Duration or expiry
- Request duration; infrastructure logs follow the provider's contractual retention terms.
- EU/EEA transfer and safeguard
- EEA, United States, and subprocessor locations; Sanity's DPA uses adequacy decisions or EU SCCs as applicable.
- User control
- Required when published CMS content contains a Sanity-hosted image.
Strictly Necessary
Legacy Webflow content delivery
- Technology
- Network request
- Party
- Third party
- Purpose
- Delivers preserved images that remain part of legacy published content.
- Data collected
- IP address, requested asset, browser headers, and request metadata.
- Duration or expiry
- Request duration; infrastructure logs follow the provider's contractual retention terms.
- EU/EEA transfer and safeguard
- Global provider locations including the United States; Webflow publishes international-transfer safeguards in its privacy and data-processing terms.
- User control
- Required only when preserved legacy content references a Webflow-hosted asset.
- Provider
- LiveX AI
- Technology
- Local storage
- Party
- First party
- Purpose
- Remembers an optional language preference.
- Data collected
- Selected site-language code.
- Duration or expiry
- Until cleared or Functional consent is withdrawn.
- EU/EEA transfer and safeguard
- Remains on the visitor's device.
- User control
- Available only when Functional is enabled; removed when Functional consent is withdrawn.
Functional
livex.website-loader.has-played
- Provider
- LiveX AI
- Technology
- Session storage
- Party
- First party
- Purpose
- Avoids replaying the optional opening loader during the same session.
- Data collected
- A true/false value showing whether the opening loader already played.
- Duration or expiry
- Current browser session.
- EU/EEA transfer and safeguard
- Remains on the visitor's device.
- User control
- Available only when Functional is enabled; removed when Functional consent is withdrawn.
Functional
livex:stable-scroll:<path>
- Provider
- LiveX AI
- Technology
- Session storage
- Party
- First party
- Purpose
- Restores the visitor's position during requested page navigation.
- Data collected
- Page path and previous vertical scroll position.
- Duration or expiry
- Current browser session.
- EU/EEA transfer and safeguard
- Remains on the visitor's device.
- User control
- Available only when Functional is enabled; removed when Functional consent is withdrawn.
Functional
YouTube privacy-enhanced embed
- Technology
- Network request
- Party
- Third party
- Purpose
- Plays an embedded case-study video requested by the visitor.
- Data collected
- IP address, browser/device data, media interactions, and provider identifiers or cookies such as YSC and VISITOR_INFO1_LIVE.
- Duration or expiry
- Provider-managed storage ranges from the session to approximately 180 days.
- EU/EEA transfer and safeguard
- Global provider locations including the United States; Google relies on the EU-U.S. DPF and SCCs where required.
- User control
- The iframe remains absent until Functional is enabled; withdrawal unloads it immediately.
- Technology
- Network request
- Party
- Third party
- Purpose
- Plays an embedded event or case-study video requested by the visitor.
- Data collected
- IP address, browser/device data, media interactions, and provider security or player identifiers such as __cf_bm.
- Duration or expiry
- __cf_bm is approximately 30 minutes; other provider-managed storage varies by Vimeo policy.
- EU/EEA transfer and safeguard
- Global provider locations including the United States; Vimeo relies on the EU-U.S. DPF and SCCs where required.
- User control
- The iframe remains absent until Functional is enabled; withdrawal unloads it immediately.
Strictly Necessary
HubSpot contact and demo forms
- Technology
- Network request
- Party
- Third party
- Purpose
- Processes a contact or demo request explicitly submitted by the visitor without loading a tracking SDK.
- Data collected
- Submitted contact fields, page URL/name, and submission time. No tracking-account cookie is sent to the separate forms account.
- Duration or expiry
- Not browser storage; submitted records follow LiveX and HubSpot account-retention rules.
- EU/EEA transfer and safeguard
- Global provider locations including the United States; HubSpot relies on the EU-U.S. DPF and SCCs where required.
- User control
- No request is sent until the visitor submits the form. Reject All blocks tracking but does not block this user-requested submission.
Strictly Necessary
HubSpot newsletter submission
- Technology
- Network request
- Party
- Third party
- Purpose
- Processes an explicitly requested LiveX newsletter subscription without loading a tracking SDK.
- Data collected
- Email address, consent wording, page URL/name, and submission timestamp. No tracking-account cookie is sent to the separate forms account.
- Duration or expiry
- Not browser storage; retained until unsubscribed/deleted under LiveX and HubSpot account-retention rules.
- EU/EEA transfer and safeguard
- Global provider locations including the United States; HubSpot relies on the EU-U.S. DPF and SCCs where required.
- User control
- No request is sent until the visitor checks the separate marketing-consent box and submits the form. Reject All blocks tracking but does not block this explicit subscription request.
Analytics
Google Analytics 4 measurement
- Technology
- Network request
- Party
- Third party
- Purpose
- Measures page views and site usage so LiveX can understand and improve the public website.
- Data collected
- IP address, page URL and title, referrer, browser and device information, timestamps, consent state, and session or interaction metadata.
- Duration or expiry
- Request duration; Google Analytics account records follow the retention settings configured by LiveX.
- EU/EEA transfer and safeguard
- Global provider locations including the United States; Google relies on the EU-U.S. DPF and SCCs where required.
- User control
- The Google tag remains unloaded until Analytics is enabled; withdrawal disables future measurement activity.
Analytics
_ga and _ga_<container-id>
- Technology
- Cookie
- Party
- First party
- Purpose
- Distinguishes visitors and preserves Google Analytics session state after Analytics consent is enabled.
- Data collected
- Pseudonymous browser, client, and session identifiers used to distinguish visits and maintain session state.
- Duration or expiry
- Up to 2 years by default, subject to browser limits and the Google Analytics settings configured by LiveX.
- EU/EEA transfer and safeguard
- Stored on the visitor's device and included in consented Google Analytics requests; Google applies its published international-transfer safeguards.
- User control
- Created only after Analytics is enabled; removed when that consent is withdrawn.
Analytics
HubSpot website analytics
- Technology
- Network request
- Party
- Third party
- Purpose
- Measures page views and visitor sources in tracking account 44252774; website forms remain in account 246760225.
- Data collected
- Page URLs, campaign parameters, referrer, IP address, browser/device information, timestamps, and pseudonymous visitor identifiers.
- Duration or expiry
- Requests follow the retention settings of the separate HubSpot tracking account.
- EU/EEA transfer and safeguard
- Global provider locations including the United States; HubSpot relies on the EU-U.S. DPF and SCCs where required.
- User control
- HubSpot loads only after Analytics consent. Withdrawal stops tracking and removes analytics cookies.
Analytics
hubspotutk, __hstc, __hssc, __hssrc
- Technology
- Cookie
- Party
- First party
- Purpose
- Distinguishes consented visitors and sessions for HubSpot website analytics.
- Data collected
- Pseudonymous visitor identity, session counts, page-view counts, and visit timestamps.
- Duration or expiry
- hubspotutk and __hstc: up to 6 months; __hssc: 30 minutes; __hssrc: the browser session.
- EU/EEA transfer and safeguard
- Stored on the device and included in consented HubSpot analytics requests.
- User control
- Created only after Analytics is enabled; removed when that consent is withdrawn.
Strictly Necessary
__hs_do_not_track
- Provider
- HubSpot
- Technology
- Cookie
- Party
- First party
- Purpose
- Remembers the visitor's decision to stop HubSpot tracking.
- Data collected
- An opt-out flag; no visitor identifier.
- Duration or expiry
- Up to 6 months.
- EU/EEA transfer and safeguard
- Stored on the visitor's device.
- User control
- Set after withdrawal to prevent further HubSpot tracking; removed when Analytics is re-enabled.
Advertising / Targeting
OpenAI Ads Measurement Pixel
- Technology
- Network request
- Party
- Third party
- Purpose
- Attributes visits from ChatGPT ads and measures the custom hubspot_demo_clicked event when a visitor opens the existing HubSpot meeting link.
- Data collected
- OpenAI click reference, browser reference, page origin, referrer, event name and timestamp, and browser/request metadata. If automatic advanced matching is enabled in OpenAI Ads, supported form values may be hashed in the browser before an event is sent.
- Duration or expiry
- Request duration; attribution identifiers are stored separately below and OpenAI account records follow the contracted retention terms.
- EU/EEA transfer and safeguard
- United States and provider locations; OpenAI's Ad Tools DPA provides applicable international-transfer safeguards.
- User control
- The SDK remains unloaded until Advertising / Targeting is enabled; withdrawal stops future measurement activity.
Advertising / Targeting
__oppref and __obref
- Technology
- Cookie
- Party
- First party
- Purpose
- Preserves ChatGPT ad attribution across pages and distinguishes the browser for conversion measurement.
- Data collected
- The OpenAI click reference from the oppref landing-page parameter and a randomly generated browser reference.
- Duration or expiry
- __oppref up to 30 days; __obref up to 12 months.
- EU/EEA transfer and safeguard
- United States and provider locations; OpenAI's Ad Tools DPA provides applicable international-transfer safeguards.
- User control
- Created only after Advertising / Targeting is enabled; removed when that consent is withdrawn.
Advertising / Targeting
__oaiq_consent and oaiq_consent
- Technology
- Cookie and local storage
- Party
- First party
- Purpose
- Allows the OpenAI pixel to respect the visitor's Advertising / Targeting choice.
- Data collected
- A true/false value recording whether OpenAI measurement consent is enabled.
- Duration or expiry
- Cookie up to 30 days; local storage until cleared or consent is withdrawn.
- EU/EEA transfer and safeguard
- Remains on the visitor's device until the SDK reads the value; event processing uses the safeguards described for the OpenAI pixel.
- User control
- Created only after Advertising / Targeting is enabled; removed when that consent is withdrawn.
Advertising / Targeting
OpenAI Ads SDK delivery security cookies
- Technology
- Cookie
- Party
- Third party
- Purpose
- Delivers and protects the OpenAI Ads Measurement Pixel SDK from abusive traffic.
- Data collected
- IP address, browser headers, request and security metadata, and provider security identifiers.
- Duration or expiry
- __cf_bm approximately 30 minutes; _cfuvid may last for the browser session or another provider-managed period.
- EU/EEA transfer and safeguard
- Global delivery network including the United States; OpenAI's Ad Tools DPA provides applicable international-transfer safeguards.
- User control
- The SDK delivery request occurs only after Advertising / Targeting is enabled; withdrawal prevents future requests and provider security cookies expire under provider controls.