Cookies and storage used by CookieHub
The cookie and local storage items CookieHub sets in a visitor's browser, and the structure of the consent cookie.
Depending on configuration, CookieHub may use up to three cookies or local storage items in the visitor's browser:
| Name | Type | Purpose |
|---|---|---|
| cookiehub | Cookie | Stores the visitor's consent state and configuration metadata |
| cookiehub-ac | Local storage | Stores the Additional Consent string when Google Additional Consent Mode is enabled |
| euconsent-v2 | Cookie | Stores the IAB Transparency and Consent string when TCF is enabled |
cookiehub
So that the consent dialog does not appear again on every page for the same visitor, their choices are stored in a first-party cookie in the browser. The cookie expires after one year by default. Its lifetime, its name and whether the Secure attribute is added are set in the Consent storage section of your domain settings, which is the recommended place. They can also be set in the CookieHub tag in Google Tag Manager, or in the cpm variable of the inline HTML code; a value set in cpm overrides the Dashboard setting. The Secure attribute is not added by default.
CookieHub aims to store only necessary information and to be transparent about what is collected. The value is base64 encoded, to avoid characters that are not permitted in cookies, and resembles:
eyJhbnN3ZXJlZCI6dHJ1ZSwicmV2aXNpb24iOjMsImRudCI6ZmFsc2UsImFsbG93U2FsZSI6dHJ1ZSwicmVnaW9uIjoiRzAiLCJ0b2tlbiI6IkVqN2FEb0dna2xLbVpUSEVZTWxQTE1Sc1pnOFVGY0hNZkNxblA4N1U3SWhKZnZhY25kTkYxMFlLUHRYcXIxclciLCJ0aW1lc3RhbXAiOiIyMDIyLTEyLTE3VDIzOjE3OjA1LjMxOFoiLCJhbGxBbGxvd2VkIjp0cnVlLCJjYXRlZ29yaWVzIjpbXSwidmVuZG9ycyI6W10sInNlcnZpY2VzIjpbXSwiaW1wbGljaXQiOmZhbHNlfQ==Decoded, it is a JSON object:
{
"answered":true,
"revision":3,
"dnt":false,
"allowSale":true,
"region":"G0",
"token":"Ej7aDoGgklKmZTHEYMlPLMRsZg8UFcHMfCqnP87U7IhJfvacndNF10YKPtXqr1rW",
"timestamp":"2022-12-17T23:17:05.318Z",
"allAllowed":true,
"categories":[],
"vendors":[],
"services":[],
"implicit":false
}| Property | Details |
|---|---|
| answered | Whether the visitor has made any choice in the consent dialog: allowing all categories, denying all, or allowing some. |
| revision | 1 by default. Each time Reset consents is clicked in the Dashboard, the domain's revision increases by 1. A visitor whose cookie holds a lower revision than the domain's current one is asked to make their choices again. |
| dnt | True if the visitor's browser sends the do-not-track (DNT) flag. CookieHub respects the flag and does not automatically load cookie categories used for tracking when it is sent. |
| allowSale | Used only when the CCPA policy framework or IAB GPP is active. False if the visitor has opted out of the sale of personal information. |
| region | The region code detected from the visitor's IP address. See Anonymization of IP addresses. |
| token | A unique token created for each visitor, used to look up their consent in the consent log. |
| timestamp | The date and time of the last change to the visitor's consent. |
| categories | The categories the visitor allowed. Empty when allAllowed is true. |
| vendors | The vendors the visitor allowed. Empty when allAllowed is true. |
| services | The services the visitor allowed. Empty when allAllowed is true. |
| implicit | True if the implied consent type was active, so cookies were set before the visitor answered. |
cookiehub-ac
Stores the AC string of Google Additional Consent Mode, which lists the Google Ad Tech Providers (ATPs) the visitor has consented to that are not registered with the IAB. An AC string has three parts:
- a specification version number, such as
1 - the separator
~ - a dot-separated list of the consented ATP IDs, such as
1.35.41.101
The AC string 1~1.35.41.101 means the visitor consented to the ATPs with IDs 1, 35, 41 and 101, in the format of the v1.0 specification. See Google's Additional Consent Mode technical specification and Google Additional Consent Mode v2.
euconsent-v2
Stores the TC string, which holds the transparency and consent established for the vendors on IAB's Global Vendor List (GVL). See IAB TCF and the Transparency and Consent String format.
Related pages
- Consent storage: the cookie's name, lifetime and
Secureattribute. - Security and data protection practices: what CookieHub holds about visitors and where.