Cookie Policy
Last updated: June 20, 2026
1. Overview
This policy lists every cookie and similar browser-storage technology (sessionStorage, localStorage, IndexedDB) used in connection with Attributely. There are two distinct contexts:
- Customers' websites — the tracking script our customers embed sets first-party storage on their domain to attribute visits, leads, purchases, and calls. The website owner is the data controller for this data; Attributely is their processor.
- The Attributely app (app.attributely.io) — the dashboard our customers sign in to.
This policy is effective as of June 12, 2026.
2. Storage set by the tracking script on customers' websites
Everything below is first-party on the customer's own domain. Which items are used depends on the tracking mode the site owner chose (Standard or Advanced) and whether the site runs in ecommerce mode. The script bails entirely for known crawlers and sets nothing for them.
| Name | Type | Mode | Lifetime | Purpose |
|---|---|---|---|---|
la_vid | Cookie (first-party) | Standard + Advanced | 90 days | Anonymous visitor ID for attribution |
la_vsid | sessionStorage | Both | Tab session | Current visit + pageview IDs; 30-minute inactivity rollover |
la_mode | sessionStorage | Both | Tab session | Cached tracking-mode configuration |
la_btype | sessionStorage | Both | Tab session | Cached business-type configuration (lead-gen vs ecommerce) |
la_dsig | sessionStorage | Advanced | Tab session | Cached device signals so they're collected once |
la_porders | sessionStorage | Ecommerce | Tab session | Order-ID dedupe so a thank-you-page refresh doesn't double-count |
la_buyer | sessionStorage | Ecommerce | Tab session | Buyer contact stash bridging multi-step checkouts |
la_vid_local | localStorage | Advanced only | Persistent | Mirror of la_vid for cookie-wipe recovery |
la_tracking.kv | IndexedDB | Advanced only | Persistent | Second mirror of the visitor ID |
3. Storage set by the Attributely app itself
When you sign in to the Attributely dashboard, the following is stored in your browser:
| Name | Type | Lifetime | Purpose |
|---|---|---|---|
Supabase auth token (sb-*-auth-token) | localStorage | Session (7 days of inactivity / 30 days max) | Keeps you signed in |
| Date-range preference | localStorage | Persistent | Remembers your last-used dashboard date range |
| Stripe cookies | Set by Stripe on checkout/portal pages | Per Stripe's policy | Payment processing and fraud prevention |
The Attributely marketing site itself runs no analytics and sets no cookies or browser storage of its own.
4. No third-party cookies
Neither the tracking script nor the Attributely app ever sets third-party cookies. The tracking script sets storage only as first-party on the customer's own domain, never sells or shares data for advertising, and never follows you across unrelated websites.
5. Consent and legal basis
Standard mode is designed to operate as first-party analytics, falling under the strictly-necessary / first-party-analytics reading of GDPR and the ePrivacy rules: a 90-day first-party cookie, tab-scoped session keys, and no device fingerprinting or persistent ID mirroring.
Advanced mode adds device fingerprinting and persistent storage (la_vid_local,
la_tracking.kv), which under GDPR/ePrivacy typically requires explicit visitor consent. The website
owner, as the controller for their site, is responsible for capturing that consent — for example via a cookie
banner — before Advanced mode runs for a visitor in jurisdictions where consent is required.
6. Managing cookies and storage
You can block or delete cookies, localStorage, and IndexedDB data through your browser settings at any time. Clearing this storage on a customer's website resets your visitor ID (in Standard mode, attribution starts fresh); clearing it on the Attributely app signs you out. Disabling cookies may reduce attribution accuracy on sites that use Attributely.
7. Changes and contact
We will update this page when the cookie or storage inventory changes and revise the "Last updated" date above. Questions: support@attributely.io.
This document is provided for the operation of the Attributely service. If you embed Attributely on your own website, you are the controller for the first-party storage listed in section 2 and should seek your own legal advice about consent and disclosure obligations in your jurisdiction.