Core concepts

Privacy and consent

What the tracker stores, what it does when a visitor has asked not to be tracked, and how to make it wait for your cookie banner. This page describes the product. It is not legal advice, and you decide what your own site needs.

What the tracker stores in the visitor's browser

ItemWhat it is
visitor_idA random id for the browser, kept until the visitor clears their data. It is not a name or an email.
jh_sessionThe current visit and when it was last active.
jh_active, jh_sc, jh_hrSmall helper values: which window is active, and when a page was last reported.

It does not set cookies. It stores these in the browser's local storage and sends the events described in Installation and setup to Jellyhook. The visitor's IP address is never stored as such: only a salted one-way hash is kept, and the visitor's country comes from the hosting platform's own header or a one-time lookup that deletes the address afterwards. The privacy policy has the full list.

Visitors who have asked not to be tracked

When the visitor's browser sends Global Privacy Control or Do Not Track, the tracker does nothing at all. It does not read or write storage and sends nothing, so that visitor never appears in your data. This is automatic and cannot be turned off.

Waiting for your cookie banner (consent mode)

If your visitors need to give consent first, add data-require-consent to the script tag. The tracker then stays completely off: nothing is stored and nothing is sent. When your banner records a yes, call:

<script src="https://jellyhook.com/tracker.js" data-key="YOUR_KEY" data-require-consent></script>

// in your cookie banner's code, when the visitor accepts:
window.jellyhook.consent(true);

// when they decline, or later withdraw:
window.jellyhook.consent(false);
  • consent(true) starts the tracker straight away, and remembers the choice, so the visitor is not asked on later visits.
  • consent(false) erases the ids the tracker stored in that browser and stops it. The page reloads once to make sure nothing keeps running.
  • Call window.jellyhook.consent only after the tracker script has loaded. A banner that runs earlier should wait for the script's load event.
What this does not do

Jellyhook does not ship a banner, and it does not decide whether your visitors need consent. If your site has visitors in the EU, the UK or elsewhere with consent rules, getting that consent and describing the tracking in your own privacy notice is your responsibility. Consider asking a lawyer before onboarding those visitors.