1. What this policy covers
This policy explains cookies and similar technologies on CompanyProof, including local storage, session storage and measurement scripts. It supplements our Privacy notice. Global Data Intelligence Limited is responsible for the CompanyProof choices described here.
A cookie is a small value stored by your browser and sent to the relevant website. Local storage normally remains until it expires under an application rule or is cleared; session storage normally ends when a tab or browser session closes. A storage lifetime is different from how long related information is kept on a server.
2. Essential cookies and browser storage
We use the following storage to deliver a service you request, secure access, prevent abuse or remember your privacy choice. These functions are enabled without optional analytics consent. Blocking them may prevent login, checkout completion or recovery of a verification request.
Identity and payment providers may set additional security, session or fraud-prevention cookies within their own login and payment pages. The exact names and lifetimes can depend on the sign-in method, deployment and provider configuration. Their notices apply to their own pages; optional marketing cookies are not made essential simply because a provider offers them.
| Storage / provider | Purpose | Lifetime or expiry rule |
|---|---|---|
| CompanyProof consent choice and consent record · local storage | Remembers your accepted or essential-only choice, policy version and decision time. | A choice is valid for 180 days. The site asks again after expiry or a material consent-version change. You can clear it sooner. |
| WorkOS / AuthKit session cookies | Authenticate users, maintain the selected account and protect sign-in redirects. | Session or provider-controlled expiry; sign out to end access from the current session. |
| __Host-companyproof_guest_questions · cookie | Enforces the anonymous daily question allowance and prevents abuse. | Up to 24 hours; the question allowance resets by UTC day. |
| __Host-companyproof_guest_session and __Host-companyproof_pending_save · cookies | Associate a guest verification with a subsequent account save. | Up to 7 days. |
| companyproof_pending_text_check · session storage | Recovers an interrupted text-verification request in the same tab. | Removed after completion; recovery is accepted for up to 24 hours, or until the browser session ends. |
| companyproof_checkout_pending · local storage | Maintains a payment request identifier so a retry can safely continue the same purchase. | Reused for up to 24 hours. The stored value remains until completed, abandoned, replaced or cleared; it does not authorise payment by itself. |
| __hs_do_not_track · HubSpot preference cookie | Remembers withdrawal if HubSpot was previously loaded. | Provider preference lifetime; removed when you actively allow analytics again. |
| companyproof-asset-reload · session storage | Prevents repeated automatic reloads after a failed application asset. | Browser session. |
| Stripe on hosted checkout and billing pages | Payment session, fraud prevention and secure payment completion. | Set by Stripe according to the payment flow; see Stripe’s cookie policy. |
3. Optional analytics
If you choose Accept analytics, CompanyProof can collect first-party journey events and load Google Analytics and the configured HubSpot website tracker on public pages. These scripts are not loaded before a valid choice. Account, authentication and payment routes are excluded from our optional journey measurement.
First-party events use a random session identifier, page path, referring hostname, campaign labels and limited event properties. We do not put the content of your verification requests, account secrets or payment details into these events. Google and HubSpot also receive network and browser information when their scripts run; their notices describe their own processing.
Our Google configuration disables advertising consent, Google signals and advertising personalisation. We set the Google Analytics cookie lifetime to 180 days. HubSpot’s tracker is optional even if HubSpot separately receives a contact enquiry to help us answer you. Consent to analytics is not consent to receive marketing emails.
| Optional storage / provider | Purpose | Typical lifetime |
|---|---|---|
| _ga and _ga_* · Google Analytics | Distinguish browsers and measure website sessions. | 180 days under our configuration; later permitted visits may refresh expiry. |
| hubspotutk and __hstc · HubSpot | Identify a consenting browser and record visits. | Up to 6 months under HubSpot’s published defaults. |
| __hssc · HubSpot | Track a website session. | 30 minutes. |
| __hssrc · HubSpot | Detect a new browser session. | Browser session. |
| companyproof_analytics_session and companyproof_session_attribution · session storage | Associate our first-party events with a session and limited campaign context. | Browser session, or earlier on withdrawal. |
4. Set or withdraw your choice
Essential only and Accept analytics are available in the banner. Use the controls below at any time to change your choice. Withdrawal stops our future optional event collection, removes accessible optional cookies and session identifiers, and reloads the page so previously loaded trackers stop running. It does not invalidate processing that occurred before withdrawal.
A choice applies to this browser and origin. Set it separately on another browser, device or CompanyProof domain. If storage is unavailable, we keep optional analytics off. A previously accepted choice without the current version and expiry record is not treated as fresh consent.
Browser settings can remove cookies and block storage. We cannot delete cookies held by another domain or remove data already sent to a provider from your browser; use the Privacy notice to request deletion where the right applies. Necessary login and payment controls remain available when you reject analytics.
Current choice: Not selected
5. Changes and questions
We update this inventory when our use of storage changes. A material change to optional purposes or providers requires a new choice before the changed processing starts. Published provider defaults can change, so enterprise reviews should also consider the configuration used for their chosen workflow.
For questions or a complaint about tracking, email privacy@globaldatabase.com. For other data rights, retention and international-transfer information, read the Privacy notice.
Artisans’ House, 7 Queensbridge, Northampton, Northamptonshire, United Kingdom, NN4 7BF
Privacy: privacy@globaldatabase.com
Contracts and support: office@globaldatabase.com
