Anonymization of IP addresses
What CookieHub does with a visitor's IP address: region detection, and an anonymized address in the consent log.
CookieHub uses a visitor's IP address for two things, and keeps it for neither in full.
Region detection
When the consent dialog loads, CookieHub's servers detect the visitor's region from the IP address of the request, so that the right region settings apply: which consent type the dialog uses, which framework is active and which texts are shown. The detection happens server-side, and the address is discarded as soon as the region is resolved. Only the detected region code reaches the browser, where it is stored in the consent cookie as the region property; see Cookies and storage used by CookieHub.
The consent log
If the consent log is enabled for your domain, each entry records the visitor's choice together with the technical data needed to demonstrate it. The IP address in an entry is anonymized before it is stored, and the entry's country is derived from the anonymized address, not from the full one.
| Address | Anonymized how | Example |
|---|---|---|
| IPv4 | The last segment is removed | 203.0.113.42 becomes 203.0.113 |
| IPv6 | The last two groups are set to zero | 2001:db8:85a3:8d3:1319:8a2e:370:7348 becomes 2001:db8:85a3:8d3:1319:8a2e:0:0 |
Anonymized before anything is logged
Anonymization happens before an address is written anywhere. CookieHub's own request logs hold only anonymized addresses, so neither the consent log nor any log entry contains a visitor's full IP address.
This is why CookieHub describes visitor data as pseudonymous: a consent log entry can be matched to a visitor who presents their consent token, but not traced back to a person from the stored address. See Personal data processed and Data retention.