The consent banner
The first time you visit most pages on this site, a banner appears at the bottom of the screen with three options: Accept all, Analytics only, or Reject. Your choice is recorded as a localStorage entry called dh-consent and respected on every subsequent visit. To change it, use Cookie preferences in the footer or clear the site's data in your browser settings and reload. Our single-form enquiry page shows no banner, so no analytics or advertising cookies are set there unless you already accepted them on another page of this site.
Until you explicitly choose, Google Analytics storage is denied and no analytics or advertising cookies are set by us. Because the Google tag uses advanced Consent Mode, Google may still receive limited cookieless consent or measurement signals. Microsoft Clarity is not loaded until analytics consent, and OpenAI Ads measurement is not loaded until Accept all. We do not use scroll-based, dwell-based, or implicit-consent triggers; nothing about visiting or scrolling counts as consent. A browser Global Privacy Control signal forces the rejected state.
Strictly necessary (no consent required)
These entries are exempt from the consent requirement under Article 5(3) of the EU ePrivacy Directive (2002/58/EC) and Regulation 6 of the UK PECR because they are strictly necessary to deliver the service you are actively requesting.
| Name | Type | Purpose | Persists |
|---|---|---|---|
dh-consent | localStorage | Records your choice from the consent banner so we don't ask again on every page. | Until you clear browser data |
dh-theme | localStorage | Remembers whether you selected dark or light mode for the site. | Until you clear browser data |
dh-webchat-* and related chat keys | localStorage | Caches the chat token and thread, recent messages, contact identity, source/referrer/campaign context, navigation trail, and interface state so an enquiry can resume. | Until you clear browser data |
Booking and application form submissions also cache a one-time payload in sessionStorage (named dhBooking) so that the confirmation page can display your meeting summary without needing to re-fetch from the server. SessionStorage is automatically cleared when you close the browser tab; we do not retain or read it from anywhere else.
Functional (set with consent, browser-only)
Some of the free tools at /tools/ remember your last-used inputs locally so you do not have to re-enter them every visit. Each entry is stored in localStorage with a dh- prefix, scoped to the originating tool, and never leaves your browser. If you reject all non-essential cookies, the tools still work, they just do not remember your previous values.
Examples of tool-scoped functional keys you might see: dh-shop:t, dh-software:t, dh-web:t, dh_schema_type. The list is not exhaustive and grows as we ship new tools.
Analytics (cookies only after consent)
If you accept all cookies or analytics-only, Google Analytics 4 may set its analytics cookies and Microsoft Clarity is loaded for behavioural metrics, heatmaps, and session replay. Google IP anonymisation is enabled. On the analytics-only tier, Google ad storage, Google ad personalisation, and Clarity advertising storage remain denied.
| Name | Set by | Purpose | Persists |
|---|---|---|---|
_ga | Google Analytics 4 | Distinguishes unique users with a randomized client ID. IP is anonymized in transit before storage. | Up to 400 days in current Chrome |
_ga_TBH7EF1WRV | Google Analytics 4 | Persists session state for the GA4 property associated with this site. | Up to 400 days in current Chrome |
_clck | Microsoft Clarity | Persists a pseudonymous Clarity user ID and preferences for this site. | Up to 1 year |
_clsk | Microsoft Clarity | Connects page views into one Clarity session recording. | About 1 day |
_cltk | Microsoft Clarity sessionStorage | Holds a provider session token while Clarity is enabled. | Browser session |
CLID, ANONCHK, MR, MUID, SM | Microsoft domains | Provider-controlled identifiers and synchronization or operational flags used by Clarity after consent. | Varies by Microsoft cookie |
If you change your mind after accepting, use Cookie preferences in the footer. You can also clear the entries above in your browser's site-data settings and refresh the page.
Advertising measurement (Accept all only)
OpenAI Ads measurement initializes only after Accept all. It measures whether a Digital Heroes ad led to a website visit, lead, or registration. The browser Pixel may automatically detect supported contact fields, normalize and SHA-256 hash email addresses or phone numbers in the browser, and send only those hashes with a conversion. Our server-side Conversions API payload contains no raw or hashed email address or phone number.
| Name | Type / set by | Purpose | Persists |
|---|---|---|---|
__obref | OpenAI cookie | Pseudonymous browser reference used for ad attribution. | Up to about 1 year (provider controlled) |
__oppref | OpenAI cookie | Eligible ad-click reference associated with later conversion events. | Provider controlled |
__oaiq_consent | OpenAI cookie | Records the OpenAI Pixel's advertising-measurement consent state. | Up to about 30 days (provider controlled) |
oaiq_consent | OpenAI localStorage | Records the SDK's advertising-measurement consent state. | Until site data is cleared |
dh-ads-fired | localStorage | Keeps the most recent 50 opaque conversion IDs so the browser does not report the same conversion twice. | Until site data is cleared |
Choosing analytics-only or reject keeps this measurement disabled. Changing from a consented state to reject revokes the provider signals, cancels undelivered server events for that session, and reloads the page without Microsoft Clarity or OpenAI Ads. Loading OpenAI's SDK CDN can also create short-lived Cloudflare security cookies on the CDN domain, such as __cf_bm and _cfuvid.
What we do not set
This site does not use Meta Pixel, Google Ads remarketing, LinkedIn Insight Tag, TikTok Pixel, Pinterest Tag, X Pixel, Reddit Pixel, or Snap Pixel. It does not use a fingerprinting library or embed tracking social-share widgets. Microsoft Clarity and OpenAI Ads are the disclosed exceptions: both are gated by the consent choices above.
Before introducing another non-essential analytics or advertising technology, we will update this page and the Privacy Policy and apply the appropriate consent control.
Browser controls
Most modern browsers let you block all cookies, block third-party cookies only, clear cookies on close, or send a Do Not Track or Global Privacy Control signal. We respect Global Privacy Control: when your browser exposes GPC, the site forces the rejected state, denies Google Analytics storage, and does not load Microsoft Clarity or OpenAI Ads. The Google tag may still send limited cookieless Consent Mode signals.
Browser-specific cookie management documentation: Chrome, Firefox, Safari, Edge.
Legal basis
This cookie policy is designed around the consent and opt-out requirements that can apply under the EU ePrivacy Directive, UK PECR, GDPR, India's Digital Personal Data Protection Act, and US state privacy laws. We do not sell personal information. OpenAI advertising measurement may be treated as sharing or targeted advertising in some US states; reject, analytics-only, and Global Privacy Control keep it disabled.
Contact
Questions about cookies or browser storage on this site: privacy@digitalheroes.co.in. We reply within five business days.