Skip to main content

Cookie & Tag Database: Field Descriptions

Use this guide to understand the fields ObservePoint adds to its cookie and tag definitions—what each field means, why it matters, and how to interpret the values you see.

Written by Product Enablement

Overview

When ObservePoint defines a cookie or tag, we add a standard set of fields that explain what the item is, who provides it, and how sensitive it may be. In the app, you’ll see a short description next to each field. This article gives you the fuller explanation behind those “learn more” links.

The fields are grouped by where they apply: fields used for both cookies and tags, cookie-only fields, and tag-only fields. Each field has its own section so you can link directly to it. If you’re new to the Cookie & Tag Database, start with Using the Cookie & Tag Database. If you want to add your own context, see Creating & Managing Definitions.


Fields on Cookies and Tags

Vendor

The company or organization behind the cookie or tag. Think of this as the answer to, “Whose technology is this?” For example, Google is the vendor for _ga, and Meta is the vendor for _fbp.

Sometimes the same cookie name is used by more than one vendor. Because cookie names are not guaranteed to be unique across the internet, ObservePoint uses Unknown instead of guessing. When that happens, the definition may include possible vendors and examples in other fields.

Vendor URL

A link to the vendor’s website, so you can quickly learn more about the company behind the cookie or tag.

Privacy Policy URL

A link to the vendor’s privacy policy. This is helpful when you’re reviewing how the vendor handles data or documenting a privacy or compliance decision.

Summary

A short, plain-language explanation of what the cookie or tag does—the quick answer to, “What is this for?”

Description

A more detailed explanation of how the cookie or tag works. Use this when the summary does not provide enough context.

Risk Level

A general rating of how sensitive a cookie may be, based on the type of data it can hold and how broadly that data may be shared.

Risk Level

Definition

Examples

High

May help share Personally Identifiable Information (PII), such as email, SSN, or health data, with third parties.

Social media tracking pixels, third-party CRM integrations.

Medium

Collects pseudonymous data or behavioral patterns. It may not identify a person directly, but vendors can still use it for profiling or cross-site tracking.

Analytics cookies, behavioral advertising IDs, functional third-party tools.

Low

Supports site functionality or aggregate reporting. It usually does not contain unique user identifiers and is typically first-party only.

Session IDs, load balancing, language preferences, security or CSRF tokens.

Risk is a general guide based on ObservePoint’s analysis, not a compliance ruling. How you use a cookie can raise or lower the actual risk on your site.

Risk Reasoning

The explanation behind the assigned risk level. Read this with Risk Level to understand why an item was rated High, Medium, or Low instead of relying on the label alone.

Category

The functional category for the technology, such as Analytics, Advertising Tracker, or Social Media. Categories help group similar technologies so you can evaluate them together.

Category Name

Definition

Examples

Digital Measurement & Attribution

General-purpose event collection pipelines that capture user events and feed other platforms, plus attribution tools that track which marketing channels (ads, email, social) deserve credit for a conversion.

Segment, Mixpanel, Amplitude, Rockerbox, Northbeam, Triple Whale, AppsFlyer

Advertising & Paid Media

Ad serving, programmatic buying, and paid campaign tools. Excludes retargeting-only.

Google Ads, The Trade Desk, Xandr

A/B Testing & Optimization

Experimentation, personalization testing, and conversion optimization.

Optimizely, VWO, Adobe Target

Personalization

Real-time content and experience customization.

Monetate, Evergage, Dynamic Yield

Tag Management

Systems for managing tags and script loaders.

Google Tag Manager, Tealium iQ, Adobe Launch

Ecommerce

Shopping carts, checkouts, and platform tools.

Shopify, Magento, PayPal, Stripe

Audience Research & Feedback

Market research panels, audience intelligence, and on-site surveys and feedback tools.

Nielsen, comScore, Kantar, Qualtrics, SurveyMonkey, Medallia, Pendo

Social Media

Pixels, share buttons, and social login tools.

Facebook Pixel, Twitter/X, LinkedIn Insight

Data Management (DMP)

Audience data collection and segmentation. Excludes CDPs.

Oracle BlueKai, Adobe Audience Manager, Lotame

Privacy & Consent

Cookie consent and privacy compliance platforms (CMPs).

OneTrust, TrustArc, Cookiebot, Sourcepoint

Marketing Automation & Email

Platforms for automated marketing campaigns, lead nurturing, and email sending.

HubSpot, Marketo, Pardot, Eloqua, Mailchimp, SendGrid, Klaviyo, Braze

Customer Support & Chat

Live chat, helpdesks, and support tools.

Intercom, Zendesk, Drift, LivePerson

Identity & Authorization

User identity, SSO, and authentication tools.

Auth0, Okta, ForgeRock

Web Analytics

Tools whose primary deliverable is a self-contained traffic/session reporting dashboard — pageviews, sessions, bounce rate, user flows. Excludes event pipelines that feed other tools and attribution platforms.

Google Analytics, Adobe Analytics, Matomo, Heap

JavaScript Libraries

General-purpose JS libraries and utilities loaded on the page. Not analytics, ads, or martech.

MomentJS, jQuery, Bootstrap Loader, Polyfill, ESRI Leaflet, Bootstrap Icons

Heatmap & Recording

Session recording and click/scroll visualization.

Hotjar, FullStory, Mouseflow, Contentsquare

Site Infrastructure & Security

CDN, performance monitoring, bot detection, fraud prevention, and web security.

Akamai, Cloudflare, Amazon CloudFront, Fastly, New Relic, PerimeterX, reCAPTCHA, Sift

Video

Hosting, streaming, and player analytics.

YouTube, Brightcove, Wistia, JW Player

Customer Data Platform (CDP)

Platforms that unify first-party data from multiple sources to create a persistent, single customer view for identity resolution and activation across owned channels.

mParticle, Tealium AudienceStream, Treasure Data, Lytics, ActionIQ

Affiliate & Partner

Affiliate network tracking and referral tools.

Impact, CJ Affiliate, ShareASale, Rakuten

Content & Asset Management

Platforms for creating, managing, and publishing web content.

WordPress, Drupal, Contentful, Sitecore, Adobe Experience Manager

Retargeting

Specifically focused on re-engaging past visitors.

AdRoll, Criteo, Rtbhouse

CRM

Customer relationship management. Excludes marketing automation.

Salesforce, Microsoft Dynamics

SEO

Search optimization and structured data/schema loaders.

SEMrush, Moz, http://Schema.org

Most Common Consent Category

The consent category this cookie or tag most often falls under across the sites ObservePoint scans. Because sites and consent tools use different labels, ObservePoint normalizes them into four standard categories:

Consent Category

Examples Included

Strictly Necessary

Strictly Necessary, Essential, Required, GDPR Essential

Performance & Analytics

Performance, Analytics, Adobe Analytics, Statistics

Functional

Functional, Functionality, Personalization, Personalisation

Targeting & Advertising

Targeting, Advertising, Marketing, Sale of Personal Data, Social Media Cookies

This field shows how the item is typically categorized. It is not a compliance decision for your site. Use it as a starting point when deciding how the item should fit into your own consent setup.

Prevalence

How often ObservePoint sees this cookie across scanned websites. Prevalence helps you tell whether an item is widely used and well understood, or uncommon enough that it may deserve a closer look.

Quantile

Description

Very Common (>2%)

Found on more than 2% of websites scanned by ObservePoint.

Common (0.5% – 2%)

Found on 0.5% – 2% of websites scanned by ObservePoint.

Rare (0.1% – 0.5%)

Found on 0.1% – 0.5% of websites scanned by ObservePoint.

Very Rare (<0.1%)

Found on less than 0.1% of websites scanned by ObservePoint.


Cookie-Only Fields

Party Type

Shows whether the cookie is first-party or third-party. A first-party cookie is set by the site the visitor is on. A third-party cookie is set by a different domain. ObservePoint determines this from what it observes during scans.

How to Remove

Guidance for stopping or removing the cookie. This may point to the tag, vendor setting, or implementation detail that controls it, so you know where to take action.

Expiration Type

Shows whether the cookie expires at a specific time (Timestamp) or when the browser session ends (Session).

Expiration Duration

How long the cookie lasts before it expires, shown as a formatted duration. This applies to cookies with timestamp-based expiration.

Reference Sources

The verified references and technical documentation ObservePoint used to define the cookie’s behavior. These sources let you review the evidence behind the definition instead of taking it on faith.

Data Classification

The kind of information stored in the cookie’s value, such as an online identifier, contact data, or behavioral data. This field focuses on what the cookie holds, which is often more useful than the cookie name when you’re assessing privacy impact.

Classification

What it stores

Examples

Online Identifier

UUIDs, device IDs, cookie IDs, fingerprint hashes, anything that uniquely tags a browser, device, or user.

_ga, _fbp, IDE, MUID, _hjid, hubspotutk, deviceId, clientId

Session Identifier

Session tokens, login state, OAuth/JWT tokens, or signed credentials.

JSESSIONID, PHPSESSID, ASP.NET_SessionId, connect.sid, A1, LSID, glt_

Contact Data

User IDs, customer or account numbers, email hashes, or internal account references.

sa-user-id, identity_customer_account_number, account_id

Behavioral Data

Page views, last visited pages, scroll or dwell time, on-site clickstream, or view counts.

_hjSession_*, _pk_ses.*, amplitude_session, _ce.s, sailthru_content

Attribution Data

UTM parameters, gclid, fbclid, referrer source, or campaign IDs.

_gcl_*, gclid, utm_campaign, UserMatchHistory

Preference Data

Language, locale, currency, region, theme, or layout choice.

lang, locale, country, tz, EL_PREF, portalLanguage

Consent State

What the user agreed to, such as cookielaw flags, OptanonConsent, or IAB TC strings.

OptanonConsent, cmplz_consented_services, CookieConsent, euconsent-v2

Security Context

CSRF/XSRF tokens, anti-bot challenges, or nonces.

csrf_token, XSRF-TOKEN, __cf_bm, cf_clearance, ak_bmsc

Operational

Load balancer routing, A/B test buckets, feature flags, viewport details, or debug state.

_gat, ServerPool, ROUTEID, AWSALB, s_cc, s_sq

Unknown

Encrypted blobs or vendor-specific formats with no public schema. This is the default when the value does not provide a clear signal.

No common examples available.


Tag-Only Fields

Is Deprecated

Shows whether the technology behind the tag is still in use or has been discontinued. The value is Yes or No. If a deprecated tag is still firing on your site, it may be worth removing.

Deprecation Date

The date the vendor discontinued the technology, when that information applies.

Formerly Known As

Previous names, rebrands, or ownership changes for the vendor or technology. This helps you recognize a technology that may appear under an older name. For example: “NewsCred rebranded to Welcome in 2020, was acquired by Optimizely in 2021, and is now Optimizely CMP.”

Date Added

The date this entry was added to the dictionary.


Common Questions

Where do these values come from?

ObservePoint maintains these values through its own analysis across scanned sites and the reference sources listed on each definition. Because these are ObservePoint-managed fields, they stay consistent for everyone and cannot be edited directly.

Can I change these for my account?

You cannot edit an ObservePoint-managed field directly, but you can add custom fields to any definition if you need to capture account-specific notes or decisions. See Creating & Managing Definitions.

Is the consent category or risk a compliance decision for my site?

No. Both are general guidance based on how an item is typically used. Your own implementation determines how it should be categorized and how risky it is on your properties.

Did this answer your question?