Cookie Policy — Visual Sectors
Covers the Visual Sectors platform at visualsectors.com — the site, your account, and the product features on it — and our campaign pages at lp.visualsectors.com, which ask for your choice separately because each site keeps its own.
The Visual Sectors Data API at api.visualsectors.com is a separate product with its own cookie disclosure. Nothing described here applies there, and nothing there applies here.
The short version
One cookie keeps you signed in. Two more come from our security provider. The office-hours booking calendar sets Calendly's own, only if you open it. Nothing that measures or tracks you — including advertising tags — runs unless you turn it on. Visitor identification (RB2B) is a separate choice, off unless you tick it.
Measurement is off until you accept it — not off until you dismiss a banner, off until you say yes. If you never answer the banner, nothing non-essential ever loads. If you accept, the analytics, advertising and session-recording tags listed below run in your browser.
Strictly necessary — always on
These are needed for the site to work at all. There is no way to use an account without them, and the law does not require us to ask permission for them.
| Name | vs_wf_session |
|---|---|
| Purpose | Keeps you signed in |
| Contains | A random, signed token. It carries no personal data, and the matching value is stored in our database only as a hash |
| Lifetime | 30 days, or until you sign out |
| Flags | HttpOnly — no script can read it, so a scripting flaw cannot steal your session · Secure — never sent over an unencrypted connection · SameSite=Lax — not sent on cross-site form posts, which is the cross-site request forgery case that matters |
| Set by | Visual Sectors (first party) |
Signing out deletes it, both in your browser and in our database.
Why SameSite=Lax and not Strict: Strict withholds the cookie on any arrival from another site, including you clicking a link in your own email — you would land signed out and confused, with nothing on screen explaining why.
We also store your cookie choice in your browser's local storage, under vs.workflows.consent.v1, so we do not ask you again on every page. It is not a cookie, it is never sent to us, and clearing your browser storage clears it.
Set by our infrastructure — always on
The site runs behind Cloudflare, which sets its own cookies for security and bot management.
| Name | __cf_bm |
|---|---|
| Purpose | Cloudflare's bot management — telling automated traffic from people |
| Lifetime | 30 minutes |
| Flags | HttpOnly, Secure, SameSite=None |
| Set by | Cloudflare, acting for us |
Cloudflare may also set cf_clearance if you are shown a security challenge, to record that you passed it. If you are never challenged, it is never set.
Neither is used to profile you, to build an advertising audience, or to track you across other websites.
The office-hours booking calendar — only if you open it
Our weekly office hours are booked on Calendly, in a frame on the office-hours booking card. The frame loads only when you open it. Calendly then sets the cookies it needs to run the booking, and asks you itself about any it does not need. Those cookies are Calendly's, under Calendly's cookie notice; we do not read them. Nothing about you is passed to the frame: Calendly sees only what you type into it. You can also book in a new tab on calendly.com instead.
Measurement and advertising — off unless you accept it
If you accept measurement in the banner, we load Google Tag Manager, which loads the tags below. Each sets its own cookies or similar identifiers in your browser. Some of them are advertising tags: they tell the advertising platform that you visited us, so it can measure which of our ads bring visitors and show our ads to people who have visited before. Those platforms can recognise you on other websites that use them.
| Tag | What it is for |
|---|---|
| Google Analytics (Google) | How the site is used: pages viewed, clicks on buttons and links, how far a page is scrolled, which parts of a page were on screen and for how long, time on the page, and key actions such as signing up, starting a checkout and completing a purchase (the plan and the amount). No name, e-mail address, account id or anything you type is sent. Cookies such as _ga and _ga_<id>, lasting up to two years |
| Google Ads / DoubleClick (Google) | Measuring which Google ads bring visitors, and showing our ads to people who have visited |
| Meta pixel (Meta Platforms) | The same, for Facebook and Instagram ads |
| TikTok pixel (TikTok) | The same, for TikTok ads |
| LinkedIn Insight Tag (LinkedIn) | The same, for LinkedIn ads |
| X pixel (X Corp.) | The same, for ads on X |
| Yandex Metrica (Yandex) | How the site is used, including which searches and ads bring visitors |
| Hotjar (Hotjar) | Session recording and heatmaps: how pages are scrolled and clicked, so we can see where they confuse people |
| Metricool (Metricool) | Which of our social-media posts bring visitors |
| LinkMink (LinkMink) | Which referral or affiliate link a visitor arrived through, so a referrer can be credited |
This is the list as measured on 25 September 2026, by loading the site with measurement accepted and recording every third-party address it contacted.
Three things are worth saying plainly.
- Nothing loads before you accept. The page ships with no tracker markup at all, so there is nothing that can fire while the banner is on screen. This is built into the code rather than promised in prose: a single function is allowed to load a measurement script, and it refuses unless your stored choice says yes. Pages still served by our older site hold their own trackers back the same way until you accept.
- The tags live in a Google Tag Manager container, not in our code. A container can be changed without a release of this site, so this page is where the list is kept: if a tag is added or removed, this page changes first.
- You can change your mind. See below.
Visitor identification (RB2B) — a separate choice, off unless you tick it
The banner and the cookie settings offer visitor identification as its own tick box, naming RB2B. It is off until you tick it. Accepting measurement does not turn it on, and it counts only together with measurement, because RB2B loads through the same Tag Manager.
| Tag | What it is for |
|---|---|
| RB2B (GetEmails, LLC) | For visitors in the United States: matching the visit to the person making it, from RB2B's own database, and telling us their name, job title, company, LinkedIn profile and, where RB2B has one, an e-mail address, with the pages viewed, so we can get in touch |
RB2B's script sets RB2B's own cookies and similar identifiers, under RB2B's privacy policy. RB2B says it identifies people only in the United States. Some US state laws count this as a sale: the "Do not sell or share my personal information" link in the footer turns it off, together with measurement and ads, and a browser that sends Global Privacy Control keeps it off. The Privacy Policy (§3.7a, §9a) says what we do with it.
What this site does not do
| Advertising, retargeting or session-recording tags before you accept | ❌ never |
|---|---|
| Selling your data | ❌ never, except visitor identification (RB2B), which some US states count as a sale and which is off unless you tick it |
| Email open or click tracking | ❌ switched off on our sending domain |
The last one is deliberate: a password-reset link rewritten through a third-party tracking domain reads as phishing to filters and to people, and an invisible pixel is behavioural tracking without consent.
Campaign tags in links — not cookies, but worth explaining
A link to us from an email or an advertisement often carries tags in the URL — utm_source, utm_campaign, a Google or Facebook click identifier. They are part of the address, not a cookie, and they are visible to you in the address bar.
We read them once, when your account is created, so we can tell which channels bring people who find the Service useful. They are never updated afterwards, so a later visit cannot rewrite how you were originally acquired. See Privacy Policy §3.
Only if you accept measurement, we also keep them in your browser's session storage until you sign up or close the tab, so a sign-up later in the same visit is still credited to the link you arrived through. If you have not accepted, nothing is kept, and a sign-up after you leave the page you landed on is not credited to it.
Managing cookies
Change your answer here: use the cookie settings link in the site footer, or the "Do not sell or share my personal information" link beside it. Turning measurement or visitor identification off stops it from then on; cookies a tag has already set are removed by your browser's own controls.
In your browser: every browser lets you see and delete cookies, and block them by site. Blocking the strictly necessary ones will sign you out and keep you out — that is what they are for.
If this changes
If we add a tag, or a new kind of tracking, this page changes before it runs, and anything that runs only does so after you have accepted measurement, or ticked visitor identification. A banner that asks permission for something already running is not consent.
Contact
privacy@visualsectors.com
Visual Sectors, Inc., Suite 305, 131 Continental Drive, Newark, Delaware 19713, United States.