How consent works on this site, and where it does not apply
If you are visiting from the European Economic Area, the United Kingdom or Gibraltar, none of the third-party tags described below is in the page you receive until you agree to them. The decision is made on our server, before the page is built, so an unanswered visit is not a case of a script being loaded and then held back: the tag is not in the HTML at all. You will see a banner offering Accept all, Reject all and a per-category choice.
There are three categories, because they are three different intrusions:
- Analytics: Google Analytics 4.
- Advertising: Google Ads conversion tracking and the PromoteKit affiliate script, both of which follow a person as far as signup.
- Session recording: Microsoft Clarity, which records how you move through the page.
You can change your mind at any time using the Cookie preferences control at the bottom of every page.
Outside those countries the banner is not shown and all four tags load as before. We are telling you that rather than describing the gate as though it covered everybody. A refusal you have recorded is honoured everywhere, in every region, but if you have never been asked and you are outside the gated region, you have not been asked.
How we decide which visitors are in the gated region, and why it is imperfect. Two signals. The first is the domain you are on: siteqwality.de and siteqwality.it are aimed at Germany and Italy, so every visit to them is gated, and that signal cannot be altered by your browser. The second, used on siteqwality.com, is your browser’s own time zone, which we store for one day in a cookie. A time zone is not a location: a VPN, a traveller or a reset clock will all get it wrong. We deliberately treat every Europe/… time zone as gated, which sweeps in several countries the GDPR does not cover, because over-gating costs a visitor a banner and under-gating costs them a choice. When neither signal resolves, we load nothing and let the browser decide, because that is the direction that cannot leak.
We do not keep a server-side record of your consent. This is a static site with no database. Your choice lives in a first-party cookie in your own browser and nowhere else, which means you can delete it and we cannot produce it. We would rather say so than imply we hold a consent ledger we do not have.
Do Not Track and Global Privacy Control
On our marketing websites we honour both. If your browser sends DNT: 1 or Sec-GPC: 1, or exposes navigator.globalPrivacyControl or navigator.doNotTrack, we treat it as a refusal in every region, including outside the EEA and the UK, and we do not show you a banner, because asking again after you have already said no is not respecting the answer. The request-header check runs on our server before the page is built; the browser-property check runs in the page.
We do not act on either signal in our dashboard or in our SDK. Nothing in the authenticated dashboard at app.siteqwality.com, and nothing in the Site Qwality SDK that a customer installs on their own website, reads navigator.doNotTrack, Sec-GPC or navigator.globalPrivacyControl. That half is unchanged and we are not going to let a true statement about the marketing site imply it.
Cookies we set ourselves
Four, all first-party, none used to identify or track you across sites. Two of them exist only because of the consent gate described above.
| Name | What it holds | Purpose | Lifetime and attributes |
|---|---|---|---|
sq_consent |
A small JSON record: your yes or no for each of the three categories, the version of this policy you were shown, and the time you chose. | Records your consent choice so we can act on it on our server, before any third-party tag is written into the page. It is the only record of your choice that exists. | 180 days (max-age=15552000), path=/, SameSite=Lax, and Secure over HTTPS. If we change the categories or the vendors behind them, the stored version no longer matches and we ask you again rather than resting on a choice you made about a different set of vendors. |
sq_region |
The value eu or row, nothing else. |
Records whether your browser’s time zone places you in the region where we show the banner, so the server can make that decision on your next page view. It holds no location beyond those two values and no identifier. | 1 day (max-age=86400), path=/, SameSite=Lax, and Secure over HTTPS. Deliberately short, so that travelling is picked up quickly. |
resolution |
Your screen width in pixels. | Lets the server pick an appropriately sized image rather than sending a desktop-sized image to a phone. | Set by an inline script in the page head with path=/, SameSite=Lax, and Secure over HTTPS. It carries no expiry, so it is a session cookie and your browser discards it when you close it. |
sq_locale_dismissed |
The value 1, nothing else. |
Written only if you dismiss the bar suggesting you view the site in another language. It stops us showing it again. | 1 year (max-age=31536000), path=/, SameSite=Lax. |
The first three are set without asking you, and we think that is right: sq_consent is the record of your own choice, sq_region exists to decide whether to ask you, and resolution sizes an image. None of them is used for analytics, advertising or recording, and refusing every category leaves all four in place.
Third-party tags we load on the marketing site
Four, on siteqwality.com, siteqwality.de and siteqwality.it. Whether any of them is in the page depends on the consent gate described above: in the gated region none is present until you accept the category it belongs to, and outside it they load in the page head as they always have. Each sets its own cookies or storage under its own names, which the vendor controls and can change without telling us. We name the vendor, the account identifier we configure, and what it does.
On every page of these three sites, whatever region you are in and whether or not you have been asked, we declare Google’s consent settings before anything that could load a Google tag. That is the only ordering in which those settings mean anything. The declaration is never skipped. Only its value changes, and the value is the truth about that particular page load.
We declare granted in one case, and only one: you are outside the gated region, you have not recorded a choice, and your browser sent no refusal signal. The four tags genuinely do load for you, so telling Google otherwise would be a declaration we contradict in the next line of the page.
We declare denied if any of the following is true, so that a tag loading afterwards reads the refusal before it does anything. There are four, they overlap, and any one of them is enough:
- your browser sent
DNT: 1orSec-GPC: 1, in any region, whether or not you have also recorded a choice; - you have recorded a choice, in any region, whatever that choice was. Accepting everything still produces a denied declaration, followed by the update described below;
- you are in the gated region and have not recorded a choice, which is the state in which you are being shown the banner;
- we could not work out which region you are in and you have not recorded a choice.
That last case is not an edge case, and we would rather name it than let it hide inside the word “or”. It is the first page load of every new visitor to siteqwality.com. The region is read from the first-party sq_region cookie described above, which our own script writes from your browser’s time zone; on your very first request that cookie does not exist yet, so the region is unknown and we declare denied. The granted declaration can only appear from your second page load onward. On siteqwality.de and siteqwality.it the question never arises, because the domain itself puts you in the gated region.
An update follows the declaration only where a choice has been recorded: when you answer the banner, when you change your answer through the preferences control, or when your browser’s refusal signal is stored as a refusal. It carries that recorded choice and nothing else. If you were never asked, you get the declaration and no update, in the page and in our script alike, because an update is a report of a decision somebody made and we will not send Google one on behalf of a person we never put the question to.
| Vendor and tag | What it does | What it receives |
|---|---|---|
Google Analytics 4 (measurement id G-3TNM429V9M) |
Marketing analytics: which pages are viewed, in what order, from where. | Visitor and device identifiers, IP address, page URL, referrer. |
Google Ads (conversion id AW-16514481998) |
Advertising conversion measurement. A conversion event fires on every “Start free” call to action. | Visitor and device identifiers, IP address, the conversion event. |
Microsoft Clarity (project tbv6fv0o2l) |
Session recording and heatmaps. It records how you move through and interact with our marketing pages. | A recording of your interaction with the page, plus the usual visitor identifiers and IP address. It runs on marketing pages only; it is not loaded inside the authenticated dashboard. |
| PromoteKit | Affiliate and referral attribution. It loads on the marketing site and also on the authenticated dashboard, and the referral identifier is mirrored into our payment processor’s customer record when you sign up. | A referral identifier tied to your visit and, if you become a customer, to your customer record. It does not receive monitoring, log, real user monitoring or replay data. |
[[VERIFY: capture the exact cookie names, values and lifetimes each of these four vendors sets, from a live browser session against siteqwality.com, and list them here. We can name the tags from our own source with certainty; we cannot name the vendor’s cookies from our source, and this page will not guess at them.]]
[[VERIFY: confirm the removal of LogRocket from the authenticated dashboard has shipped to production before this page is deployed. This page does not list it.]]
Browser storage in the dashboard
Our dashboard uses your browser’s storage for two different things, and the first of them is not a preference.
Strictly necessary. Your authentication session is held in local storage as stytch_session_jwt and stytch_session_token. These are sent to us on every request as your credential, and clearing them signs you out, so “clearing site data resets your preferences and nothing else” would be wrong. A staff impersonation session, when one is active, is held separately in session storage as sq_impersonation and is discarded when you close the tab. Two short-lived keys, github_oauth_action and google_oauth_action, are written to session storage while a social sign-in is in flight.
Convenience. Interface state in local storage: sq_theme, sidebar-collapsed, per-page view modes under sq_view_, logs_pinned_facets, logs_dismissed_insights and sq_staff_preview, plus sq_verify_banner_dismissed in session storage. Alongside them, nine keys beginning persist:, written by the state library the dashboard is built on. They are worth describing accurately, because their names suggest more than they hold. Seven of the nine (persist:monitorsReducer, persist:integrationsReducer, persist:notificationsReducer, persist:statusPageReducer, persist:siteReducer, persist:jobsReducer and persist:eCommerce) are configured to persist nothing, and contain only the library’s own version marker. So despite the names, your monitors, integrations, notification settings and status pages are not cached in your browser. The two that do hold something are persist:userReducer, which holds your own member profile and the accounts you belong to, and persist:uiReducer, which holds the filters you last set on a list view. None of these is sent back to us, everything in them came from us in the first place, and clearing them costs you nothing but a refetch.
One key in this group is sent to us. If you are a partner managing client accounts, sq_partner_client in session storage records which client account that browser tab is currently viewing, and its account identifier is attached to every request the tab makes so that we return that client’s data rather than your own. It is scoped to the tab and discarded when you close it.
Browser storage set by our SDK on a customer’s site
If you are visiting a website that has installed Site Qwality real user monitoring, our SDK writes one key:
| Name | Where | What it holds | Lifetime |
|---|---|---|---|
sq_rum_session |
sessionStorage on the site you are visiting, not a cookie |
A randomly generated session identifier, the time the session started, and the time of the last activity. It contains no name, no email address and no identifier we assign to you personally. | Session storage: your browser discards it when you close the tab. |
The SDK is installed and configured by the operator of that website, not by us. It writes this key as soon as it initialises. There is no end-user opt-out in the SDK today: no consent option, no sampling switch and no reading of Do Not Track or Global Privacy Control. If you want it to stop, the operator of that site is the only party who can stop it, because they control whether the SDK runs at all. Our Privacy Policy explains why that is their decision rather than ours.
Third-party content embedded in our pages
The contact form on our contact page is not our form. It is served by a third party, theemaildelivery.com. It does not load until you ask for it. What the page gives you instead is a placeholder of ours that names the vendor and says what loading it would mean. That vendor’s address is held in a data attribute and is never a src, an href or a preconnect, so nothing is requested from that company and it does not see your IP address until you press the button.
When you do press it, the form is placed in a frame served from that vendor’s own origin. From that moment it sees your IP address, it can set its own cookies, and its fields, submission endpoint, storage and retention are under its control, not ours. We send it no referrer.
Two consequences of doing it this way, both deliberate and neither hidden. We do not record that you pressed it, anywhere, so the placeholder returns on your next visit: writing a consent cookie off an embed click would be recording a choice you were never offered. And if you have JavaScript turned off there is no contact form on the page at all, because the frame only exists once the click handler runs. The email addresses on that page reach us either way. Do not use the form for anything involving your personal data rights; write to privacy@siteqwality.com instead.
What you can do about it
- Cookie preferences. The control at the bottom of every page reopens the choice and lets you change or withdraw it for each category. Withdrawing is exactly as easy as giving it.
- Do Not Track or Global Privacy Control. Turn either on in your browser and our marketing sites will treat it as a refusal, in any country, without asking you.
- Browser settings. Every major browser lets you block or delete cookies for a site. Blocking them for siteqwality.com will not break anything except image sizing and the language-suggestion bar, though deleting
sq_consentalso deletes the record of your choice, so we will ask again. - Vendor opt-outs. Google and Microsoft each publish their own opt-out mechanisms for the products listed above.
- Ask us. Write to privacy@siteqwality.com and we will tell you what we hold and, if you ask, delete it.
Changes to this policy
This page carries a date. If the set of tags on our site changes, this page changes with it. It is maintained alongside the code that loads them, so a new tag and this page move together.
Related documents
- Privacy Policy: what we collect, why, and your rights.
- Subprocessors: every third party that processes data, and where.
- Data Retention: how long each category is kept.