Cookie Policy
This Cookie Policy explains how Holovast Ltd uses cookies and similar technologies on this website.
Last updated: August 5, 20261) What cookies are
Cookies are small text files stored on your browser or device. They help websites remember preferences, keep services secure, and understand how pages are used.
2) Cookie categories we use
- Essential cookies: Required for core site operation and security. These cannot be switched off in our consent flow.
- Analytics cookies: Help us understand page usage and improve content quality and performance.
- Marketing cookies: Reserved for separately disclosed marketing features. The first-party website journey service does not activate a marketing or advertising provider.
3) How to manage preferences
You can accept all, reject all, or configure categories in the cookie banner and cookie preferences modal. Refusing and withdrawing analytics consent are available through the same controls used to grant it.
You can also control cookies from your browser settings, including blocking or deleting existing cookies. Disabling some categories may affect certain features.
4) First-party journey analytics
When you grant analytics consent, our same-origin acquisition service sets a signed, HttpOnly visitor cookie. Website JavaScript cannot read or transmit its value. The service uses it to delimit sessions and de-duplicate journey events.
The journey service records bounded events for page and named-section views, pricing-builder engagement, application progress, submission attempts, and video playback. Video playback events cover starts, stops, completion milestones, completed playback, and playback failures for explicitly listed website videos. They do not contain signed playback cookies or media URLs. The service may also record the allowlisted campaign fields UTM source, medium, campaign, term, and content. Arbitrary query parameters and URL fragments are not retained. A successful enquiry is recorded by the server, not by the browser.
No journey identifier, event, or analytics data is stored before consent. We do not load Google Tag Manager, Google Analytics, Amazon Pinpoint, Amplify Analytics, or another third-party analytics provider.
Pseudonymous raw journey events and the visitor cookie expire after 13 months. Anonymous daily aggregates are stored separately and may be retained for long-term comparison.
AWS hosts the service and our existing anti-abuse provider verifies public forms. They remain processors or subprocessors under our processing records, but neither is introduced as an additional analytics provider.
5) Withdrawal and erasure
Withdrawing analytics consent stops capture immediately, clears queued browser events, deletes the visitor cookie, starts deletion of raw journey events, and severs any link to an existing lead. Anonymous aggregates already produced are unaffected.
An essential, non-identifying withdrawal delivery record preserves a pending deletion across reloads and becomes the completion receipt when accepted. It contains the consent notice version and withdrawal time, not a visitor identifier.
Holovast workforce members working outside known office networks can set a first-party staff exclusion at /privacy/staff-analytics-exclusion. It marks consented traffic as internal for aggregate exclusion and does not grant analytics consent.
You can also ask us to erase journey data through the privacy contact in our Privacy Policy.
6) Updates to this policy
We may update this policy to reflect legal, operational, or technical changes. Material updates will be reflected on this page with a revised date.
7) Contact
If you have questions about our use of cookies, contact hello@holovast.com.