Cookie and Tracking Technologies Policy
Effective 20 August 2026 · Version 1.0 · Document reference SAVO-PRIV-POL-001
This policy explains how Savo, Inc. uses cookies and similar technologies on our website, in our platform, and in Savo Session interview environments. It sits alongside the Savo Privacy Policy and replaces the cookie section of that policy.
1. Purpose and Scope
This policy tells you what cookies and similar technologies we place on your device, why we place them, how long they last, and what control you have over them. It applies to three surfaces:
- The Savo marketing website savo.ai and its subdomains.
- The Savo platform at prod.savo.ai, used by subscribers and their authorized users.
- Savo Session interview environments, used by participants who have been invited to a session by a subscriber.
It does not cover the websites of our subscribers or of any third party you reach by following a link from our surfaces. It does not cover cookies placed on employees' devices in the course of their employment.
It also does not cover the recording and analysis of interview content itself. Recording, transcription and AI analysis of a session are described in the Privacy Policy and in the notice presented at the start of each session. Those are separate processing activities and they are not carried out through cookies.
2. Who We Are
Savo, Inc. is a Delaware corporation with its principal place of business in Dallas, Texas. For personal data collected through our own marketing website, Savo is the controller. For personal data we process inside the platform on behalf of a subscriber, the subscriber is the controller and Savo acts as processor under the terms of its agreement with that subscriber.
- Controller: Savo, Inc.
- Data Protection Officer: Dennis Pedini, privacy@savo.ai
- Contact form: savo.ai/contact-us, selecting "Privacy Request"
3. What Cookies and Similar Technologies Are
A cookie is a small text file that a website asks your browser to store on your device. When you return, the browser sends the file back, which lets the site recognize your browser and remember information about your visit.
We also use technologies that behave like cookies without being cookies. Where this policy says "cookies" it covers all of the following:
- Local and session storage — browser storage that holds data such as interface state. It is not sent with every request the way a cookie is.
- Pixels and web beacons — small transparent images embedded in a page or an email that register when the content is loaded.
- Software development kits and embedded scripts — code we or a provider load into a page, which may in turn set cookies.
- Server logs — records our hosting and security providers keep of requests made to our servers, including IP address, user agent and timestamp. These are not stored on your device and are not controlled by your cookie choices, but we describe them here for completeness.
4. How We Categorize Cookies
We sort every cookie into one of three categories. The category determines whether we need your consent before setting it.
| Category | What it does | Consent required |
|---|---|---|
| Strictly necessary | Needed for the site or platform to work, to authenticate you, to route your requests, to keep your account secure, or to remember the cookie choices you have made. Turning these off would break the service. | No. Exempt under ePrivacy Directive Art. 5(3). |
| Functional | Remembers choices you make and enables features such as live chat and consistent page variants. Not required for the service to function, but switching them off reduces what the site can do. | Yes, where you are in the EEA, the UK, or another jurisdiction requiring prior consent. |
| Analytics | Tells us how visitors find and move through our website so we can see which pages are useful and where people get stuck. On our marketing site this data can also be associated with a contact record in our CRM. | Yes, where you are in the EEA, the UK, or another jurisdiction requiring prior consent. |
We do not operate an advertising or targeting category, because we do not run advertising or retargeting technology on any Savo surface. See Section 10.
5. Cookies on the Savo Marketing Website
Our marketing website is hosted on HubSpot and measured with Google Analytics 4 and PostHog. The following cookies may be set when you visit savo.ai. Durations are the values configured by the provider and are reviewed as part of the annual review of this policy. The two Google Analytics cookies at the end of the table are written only after you accept analytics cookies. Section 5.1 explains how that is enforced.
| Cookie | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
__cf_bm |
Cloudflare, as HubSpot's CDN | Distinguishes human visitors from automated traffic and supports bot mitigation. Set by the content delivery network HubSpot uses to serve our site. | Strictly necessary | 30 minutes |
_cfuvid |
Cloudflare, as HubSpot's CDN | Supports per-visitor rate limiting and abuse prevention. Not used for analytics or profiling. | Strictly necessary | Session |
__hs_cookie_cat_pref |
HubSpot | Records which cookie categories you have accepted or declined. | Strictly necessary | 6 months |
__hs_opt_out |
HubSpot | Records your decision to decline cookies so the banner is not shown again. | Strictly necessary | 6 months |
__hs_initial_opt_in |
HubSpot | Prevents the consent banner from redisplaying if you have not yet responded. | Strictly necessary | 7 days |
__hs_do_not_track |
HubSpot | Suppresses HubSpot tracking if you have opted out. | Strictly necessary | 6 months |
hs_ab_test |
HubSpot | Keeps you on the same variant of an A/B tested page for the session. | Functional | Session |
messagesUtk |
HubSpot Conversations | Identifies you across chat conversations so chat history persists between visits. | Functional | 6 months |
hs-messages-is-open |
HubSpot Conversations | Stores whether the chat widget is open or closed. | Functional | 30 minutes |
hs-messages-hide-welcome-message |
HubSpot Conversations | Records that you dismissed the chat welcome message. | Functional | 1 day |
__hstc |
HubSpot | Primary analytics cookie. Stores the first visit, previous visit and current visit timestamps and a visit counter. | Analytics | 6 months |
hubspotutk |
HubSpot | Assigns a unique visitor token used to link page views and form submissions to a contact record in our CRM. | Analytics | 6 months |
__hssc |
HubSpot | Counts page views within the current session. | Analytics | 30 minutes |
__hssrc |
HubSpot | Records whether you restarted the browser, used to identify the start of a new session. | Analytics | Session |
_ga |
Distinguishes one visitor from another so page views can be grouped into a visit. Written only after you grant analytics consent. | Analytics | 2 years | |
_ga_3CKKWYRW1H |
Holds session state for our specific Google Analytics data stream. Written only after you grant analytics consent. | Analytics | 2 years | |
__ph_opt_in_out_… |
PostHog | Records whether you have opted in to or out of PostHog capture, so your choice persists between visits. Set whichever way you decide. | Strictly necessary | 12 months |
ph_…_posthog |
PostHog | Stores a randomly generated device identifier and session information so page views can be grouped into a single visit. Written only after you grant analytics consent. | Analytics | 12 months |
Our website also loads a JavaScript library from the jsDelivr content delivery network. That request does not set a cookie, but it discloses your IP address and browser details to the network operator. We are reviewing whether to serve this library from our own domain instead.
HubSpot pop-ups, banners and embedded calls to action may store a short-lived record that you have already seen a given item, so it is not shown to you repeatedly. Where that record is stored in a cookie it falls into the functional category.
5.1 Google Analytics and Google Consent Mode v2
Our website uses Google Analytics 4, property measurement ID G-3CKKWYRW1H, installed through HubSpot's Google Analytics integration. It is governed by Google Consent Mode v2, which is a signalling layer that sits between our consent banner and Google's tags and tells those tags what they are permitted to do.
Before you make any choice, all four Google consent signals on our site are set to denied:
| Signal | Default | What the default prevents |
|---|---|---|
ad_storage |
Denied | Google may not store or read advertising cookies or identifiers on your device. |
analytics_storage |
Denied | Google Analytics may not write or read the _ga cookies. No persistent analytics identifier is created for you. |
ad_user_data |
Denied | No user data may be sent to Google for advertising purposes. |
ad_personalization |
Denied | No data may be used for personalized advertising or remarketing. |
The page waits up to one second for your consent decision before Google's tags act. If you accept analytics cookies, analytics_storage is updated to granted and the two Google Analytics cookies described in the table above are then written. If you decline, or if no decision is recorded, the denied default stands and no Google Analytics cookie is written to your device at any point.
We want to be precise about one thing here. When analytics_storage is denied, Google's tag still loads and still sends a request to Google that contains your IP address, user agent, page address and referring page. That request stores nothing on your device and carries no identifier that could be used to recognize you on a later visit. Google uses it only to produce aggregate, modeled traffic estimates. So it is accurate to say that no Google Analytics cookie is placed before consent. It would not be accurate to say that no data reaches Google before consent, and we would rather tell you the difference than leave you to assume the stronger version.
Google Analytics on our site does not use Google Signals, is not linked to a Google Ads account, and is not used for remarketing or audience building. Google derives an approximate location from your IP address and does not store the address itself in our Analytics property.
5.2 PostHog
We also use PostHog for product analytics on our marketing website, to understand which pages people find useful and where they get stuck. Our PostHog project identifier is phc_m9727oHLmZNSsCUTYXXHDyJo9EwBVJC7qNkoZXjAhNVg and the data is held in PostHog's United States cloud region. The two PostHog cookies in the table above carry that project identifier in their names.
PostHog is configured conservatively, and the settings below are visible to anyone who reads our page source:
| Setting | What it means for you |
|---|---|
| Capture off by default | PostHog captures nothing at all until analytics consent is granted. This is the starting state for every visitor, in every country. |
| Cookieless on reject | If you decline analytics cookies, PostHog does not stop working but it stops persisting anything. No cookie is written and no identifier survives beyond the page you are on. |
| Session recording disabled | PostHog is capable of recording your screen, mouse movement and typing. We have that switched off. It has never been switched on. |
| Profiles for identified people only | No person profile is created for an anonymous visitor. A profile exists only where someone has identified themselves to us, for example by submitting a form. |
| Do Not Track respected | If your browser sends a Do Not Track signal, PostHog captures nothing regardless of your cookie choices. |
When capture is switched on by your consent, PostHog records page views and interactions such as which links and buttons you clicked. It records that an element was clicked and what that element was. It does not record what you type into a form field. Anything you deliberately submit to us through a form is covered by the Privacy Policy rather than by this one.
6. Cookies in the Savo Platform
When a subscriber or an authorized user signs in to prod.savo.ai, we set cookies that keep the session working and keep it secure. We do not run marketing analytics inside the authenticated platform.
| Cookie | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| Authentication session token | Savo | Maintains an authenticated session so you are not asked to re-authenticate on every page. | Strictly necessary | Session or until sign-out |
| Anti-forgery (CSRF) token | Savo | Protects authenticated actions against cross-site request forgery. | Strictly necessary | Session |
| Request routing / load balancing | Savo infrastructure | Directs your requests consistently within our hosting environment. | Strictly necessary | Session |
| Interface preferences | Savo | Retains display and interface settings you have chosen. | Functional | Until cleared |
7. Cookies in Savo Session Interview Environments
If a subscriber has invited you to take part in a session, the environment you join sets only what is needed to run that session.
| Cookie | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| Interview session token | Savo | Authorizes your access to the specific session you were invited to and maintains that session. | Strictly necessary | Duration of the session |
| Real-time media session state | Savo real-time media provider | Maintains the audio and real-time connection for the duration of the session. | Strictly necessary | Duration of the session |
| Consent and notice record | Savo | Records that you were shown and acknowledged the in-session notice, including notice that you are speaking with an AI system. | Strictly necessary | Duration of the session; the record itself is retained as described in the Privacy Policy |
We do not place analytics or marketing cookies in interview environments. What is recorded during the session, how long it is kept, and who it is shared with are covered in the Privacy Policy and in the notice you are shown before the session begins.
8. Legal Bases
For visitors in the European Economic Area and the United Kingdom, two separate rules apply. The first governs whether we may place or read anything on your device at all. The second governs what we may then do with any personal data that results.
| Category | Basis for placing the cookie | Basis for the resulting processing |
|---|---|---|
| Strictly necessary | Exempt from consent under Art. 5(3) ePrivacy Directive and Reg. 6(4) UK PECR, because the cookie is required to provide a service you have requested. | Performance of a contract, GDPR Art. 6(1)(b), and our legitimate interests in operating and securing our services, GDPR Art. 6(1)(f). |
| Functional | Your consent, obtained through our cookie banner. | Your consent, GDPR Art. 6(1)(a). |
| Analytics | Your consent, obtained through our cookie banner. | Your consent, GDPR Art. 6(1)(a). |
Outside the EEA and the UK, including in the United States, we operate on an opt-out basis consistent with applicable state privacy law. Cookies are set on arrival and a notice banner tells you so. You can exercise the opt-out at any time using the controls in Section 9.
9. Your Choices
9.1 If you are in the European Economic Area or the United Kingdom
You are shown a cookie banner before any non-essential cookie is set. The banner lets you accept or decline functional and analytics cookies separately, and declining is presented as plainly as accepting. Nothing in the functional or analytics categories is set until you choose, and if you never choose, nothing in those categories is ever set. Strictly necessary cookies are set regardless, because without them the site cannot work.
Your choice drives every tool on the site at once. Accepting analytics turns on HubSpot analytics, releases Google's analytics storage, and switches PostHog capture on. Declining leaves all three off, with Google and PostHog continuing in a mode that writes nothing to your device.
9.2 If you are outside the European Economic Area and the United Kingdom
You are shown a different banner, and it behaves differently. It tells you that we use cookies and asks you to acknowledge that notice. It does not ask your permission and it does not offer a decline button. Cookies in all three categories, including analytics, are set when you arrive rather than after you respond.
We would rather explain that plainly than let you discover it. United States privacy law works on an opt-out basis rather than an opt-in one, so a website is entitled to set analytics cookies and let you turn them off afterwards. We have applied a consent banner where the law requires consent and a notice banner where it does not. That is a deliberate choice about where to apply a control, not an oversight, and this section exists so that you can disagree with it knowingly.
Turning it off is straightforward. The browser controls in Section 9.4 stop all of it. The Global Privacy Control signal described in Section 9.5 is respected. A Do Not Track signal stops PostHog specifically. You can also write to privacy@savo.ai and we will apply and confirm your opt-out. We do not sell your personal information or share it for targeted advertising in any case, so less turns on this than the difference between the two banners might suggest.
9.3 Changing your mind
If you are in the European Economic Area or the United Kingdom, you can withdraw consent at any time, and withdrawing is as straightforward as giving it. Use the Cookie Settings link in the footer of any page on savo.ai to reopen your preferences and change them. Withdrawal takes effect from the moment you make it and does not affect the lawfulness of anything we did before then.
If you are elsewhere, the notice banner you were shown has no preferences to reopen, so the Cookie Settings link will not give you anything to change. Your routes are the browser controls in Section 9.4, the signals in Section 9.5, or an email to privacy@savo.ai. We treat an emailed request exactly as we would treat a choice made in a banner, and we will confirm when it has been applied.
9.4 Browser and device controls
Every major browser lets you block cookies, delete cookies already stored, or be prompted before a new cookie is set. These settings are usually found under Preferences, Settings or Privacy. Blocking all cookies will stop parts of our platform from working, including staying signed in.
Clearing cookies also clears the record of your consent choices, so you will be asked again on your next visit.
9.5 Do Not Track and Global Privacy Control
Do Not Track is a browser setting that asks websites not to track you. It was never adopted as a standard and support for it across the industry is inconsistent, including on our own site. PostHog is configured to respect it and captures nothing at all from a browser sending the signal. The HubSpot and Google tags do not respond to it. We would rather tell you exactly which of our tools honors the signal than give you one answer that is only true of some of them.
Global Privacy Control is a more recent browser signal that several US state privacy laws, including the Texas Data Privacy and Security Act, treat as a valid opt-out request. Where a state law requires us to honor it, we do. Because we do not sell personal information and do not share it for targeted advertising, the practical effect on Savo surfaces is limited, but the signal is still respected where the law attaches consequences to it.
10. What We Do Not Do
Some of what follows is unusual enough in our sector to be worth stating plainly.
- We do not sell personal information, in the sense of disclosing it to a third party for money or other valuable consideration.
- We do not share personal information for cross-context behavioral advertising or targeted advertising. As at the date of this policy we run no advertising, retargeting or conversion pixels on any Savo surface. There is no Google Ads tag, no Meta pixel, no LinkedIn Insight Tag and no third-party advertising network on savo.ai. We do use Google Analytics, and Google's tag carries advertising consent signals as part of its standard configuration. Those signals start denied for every visitor. More to the point, nothing is connected that could act on them: Google Signals is switched off, no Google Ads account is linked to the property, and no advertising or remarketing product is attached to it. Analytics data from this site is not used to build advertising audiences.
- We do not use cookie or website analytics data to train, fine-tune or evaluate AI models. Data collected through the technologies described in this policy is used to operate, secure and improve our websites and services. It is excluded from every training, tuning and evaluation dataset. This exclusion is a controlled requirement in our AI management system.
- We do not run session replay or keystroke capture on our marketing website. Our product analytics tool, PostHog, is capable of session recording. We have it disabled, and Section 5.2 sets out the configuration. Recording within a Savo Session interview is a separate, disclosed activity governed by the Privacy Policy and the in-session notice, and has nothing to do with our website.
- We do not make automated decisions about you that produce legal or similarly significant effects, and cookie data is not used for any such decision.
One thing we do want to be precise about. If you accept analytics cookies and later submit a form on our website, the visitor token set by hubspotutk allows your earlier page views to be associated with your contact record in our CRM. That record can contribute to an internal score indicating how closely a contact matches our customer profile and how actively they have engaged with us. This is profiling for marketing purposes within the meaning of GDPR Art. 4(4). No automated decision follows from it, a person reviews any commercial follow-up, and you can object to it at any time under Art. 21 or by declining analytics cookies.
11. Third Parties and International Transfers
The providers below can receive personal data through the technologies described in this policy. Savo holds a written data processing agreement with each provider it engages directly, and each is recorded in our vendor register. Where a provider is engaged by one of our own providers rather than by us, the table says so, and that relationship is governed by the agreement we hold with the provider that engaged them.
| Provider | Role | Privacy information |
|---|---|---|
| HubSpot, Inc. | Website hosting, CRM, website analytics, live chat and consent banner. | legal.hubspot.com/privacy-policy |
| Google LLC | Website analytics through Google Analytics 4, operating under Google's Ads Data Processing Terms. Cookies are set only after analytics consent is granted. | policies.google.com/privacy |
| PostHog, Inc. | Product analytics for our marketing website, held in PostHog's United States cloud region. Captures nothing until analytics consent is granted. | posthog.com/privacy |
| Cloudflare, Inc. | Content delivery, bot mitigation and denial-of-service protection for the HubSpot platform that hosts our site. Engaged by HubSpot as its subprocessor, not contracted by Savo, and covered by HubSpot's data processing agreement. | cloudflare.com/privacypolicy |
| jsDelivr | Public content delivery network serving one open-source JavaScript library. Receives IP address only; sets no cookie. | jsdelivr.com/terms/privacy-policy |
| Stripe, Inc. | Payment processing for subscribers. Stripe sets its own cookies on its hosted payment pages. | stripe.com/privacy |
Savo operates from the United States and personal data collected through these technologies is stored and processed there. Where we transfer personal data of individuals in the EEA or the UK to the United States, we rely on the transfer mechanisms recorded in our vendor register for each provider, which include the European Commission's Standard Contractual Clauses with the UK International Data Transfer Addendum where applicable, and the EU-U.S. Data Privacy Framework where the provider is certified. You may request details of the mechanism relied on for a particular provider by writing to privacy@savo.ai.
12. Retention
Each cookie expires after the period given in the tables above, or when you delete it, whichever comes first. Session cookies are removed when you close your browser.
Data derived from cookies is kept separately from the cookie itself. Event-level data in our Google Analytics property is retained for fourteen months, after which Google deletes it. Event data in our PostHog project is retained for twelve months. Website analytics data held in HubSpot is retained for as long as the associated contact record is active, and is deleted when that record is deleted. Server and security logs are retained for the period set in our logging and monitoring procedures. Retention of interview content is governed by the Privacy Policy and by our agreement with the relevant subscriber.
13. Your Rights
Where personal data is collected through cookies and we are the controller, you have the rights set out in full in Section 3 of the Privacy Policy. In summary you may ask us to confirm what we hold and give you access to it, correct it, delete it, give you a portable copy, restrict how we use it, or stop using it. Where our basis is consent you may withdraw that consent. Where our basis is legitimate interests you may object.
To exercise any of these rights, contact us through savo.ai/contact-us and select "Privacy Request", or write to privacy@savo.ai. We will respond within the period required by the law that applies to you. We do not charge for a request unless it is excessive or repetitive, and we will tell you before applying any charge. We will not treat you differently for exercising a right.
Where Savo processes personal data as a processor on behalf of a subscriber, please direct your request to that subscriber. We will support them in responding.
14. Complaints
If you are not satisfied with how we have handled a request or a concern, you may complain to a supervisory authority.
- EEA residents: the data protection authority in your country, listed at edpb.europa.eu
- UK residents: the Information Commissioner's Office, ico.org.uk/make-a-complaint
- Texas residents: the Office of the Attorney General, consumerprotection.texasattorneygeneral.gov
We would rather hear from you first, and we will always tell you the outcome and the reasons for it.
15. Security
Cookies we set on our own domains are transmitted over HTTPS only. Session and authentication cookies carry the HttpOnly and Secure attributes, which stop them from being read by scripts running in the page and stop them from being sent over an unencrypted connection. SameSite attributes are set to limit when a cookie is sent with cross-site requests.
Access to the systems that store data derived from cookies is restricted and reviewed under the Savo Access Control Policy.
16. Changes to This Policy
We review this policy at least once a year and whenever we add, remove or materially change a tracking technology. When we change it we update the version and the effective date at the top of this page. If a change means we need your consent for something new, we will ask for it before making the change effective.
17. Contact
Questions, concerns and complaints about this policy can be sent to Dennis Pedini, Chief Information Security Officer and Data Protection Officer, at privacy@savo.ai, or submitted through savo.ai/contact-us.
Savo, Inc., Dallas, Texas, United States.
Savo™, Signal Science™, Signal Event™, Savo Event Studio™, Savo Session™, Savo Insights™, and the Savo logo are trademarks of Savo, Inc. in the United States and other countries. All other trademarks, service marks, and trade names referenced in this material are the property of their respective owners.