Overview
When ObservePoint defines a cookie or tag, we add a standard set of fields that explain what the item is, who provides it, and how sensitive it may be. In the app, you’ll see a short description next to each field. This article gives you the fuller explanation behind those “learn more” links.
The fields are grouped by where they apply: fields used for both cookies and tags, cookie-only fields, and tag-only fields. Each field has its own section so you can link directly to it. If you’re new to the Cookie & Tag Database, start with Using the Cookie & Tag Database. If you want to add your own context, see Creating & Managing Definitions.
Fields on Cookies and Tags
Vendor
The company or organization behind the cookie or tag. Think of this as the answer to, “Whose technology is this?” For example, Google is the vendor for _ga, and Meta is the vendor for _fbp.
Sometimes the same cookie name is used by more than one vendor. Because cookie names are not guaranteed to be unique across the internet, ObservePoint uses Unknown instead of guessing. When that happens, the definition may include possible vendors and examples in other fields.
Vendor URL
A link to the vendor’s website, so you can quickly learn more about the company behind the cookie or tag.
Privacy Policy URL
A link to the vendor’s privacy policy. This is helpful when you’re reviewing how the vendor handles data or documenting a privacy or compliance decision.
Summary
A short, plain-language explanation of what the cookie or tag does—the quick answer to, “What is this for?”
Description
A more detailed explanation of how the cookie or tag works. Use this when the summary does not provide enough context.
Risk Level
A general rating of how sensitive a cookie may be, based on the type of data it can hold and how broadly that data may be shared.
Risk Level | Definition | Examples |
High | May help share Personally Identifiable Information (PII), such as email, SSN, or health data, with third parties. | Social media tracking pixels, third-party CRM integrations. |
Medium | Collects pseudonymous data or behavioral patterns. It may not identify a person directly, but vendors can still use it for profiling or cross-site tracking. | Analytics cookies, behavioral advertising IDs, functional third-party tools. |
Low | Supports site functionality or aggregate reporting. It usually does not contain unique user identifiers and is typically first-party only. | Session IDs, load balancing, language preferences, security or CSRF tokens. |
Risk is a general guide based on ObservePoint’s analysis, not a compliance ruling. How you use a cookie can raise or lower the actual risk on your site.
Risk Reasoning
The explanation behind the assigned risk level. Read this with Risk Level to understand why an item was rated High, Medium, or Low instead of relying on the label alone.
Category
The functional category for the technology, such as Analytics, Advertising Tracker, or Social Media. Categories help group similar technologies so you can evaluate them together.
Category Name | Definition | Examples |
Digital Measurement & Attribution | General-purpose event collection pipelines that capture user events and feed other platforms, plus attribution tools that track which marketing channels (ads, email, social) deserve credit for a conversion. | Segment, Mixpanel, Amplitude, Rockerbox, Northbeam, Triple Whale, AppsFlyer |
Advertising & Paid Media | Ad serving, programmatic buying, and paid campaign tools. Excludes retargeting-only. | Google Ads, The Trade Desk, Xandr |
A/B Testing & Optimization | Experimentation, personalization testing, and conversion optimization. | Optimizely, VWO, Adobe Target |
Personalization | Real-time content and experience customization. | Monetate, Evergage, Dynamic Yield |
Tag Management | Systems for managing tags and script loaders. | Google Tag Manager, Tealium iQ, Adobe Launch |
Ecommerce | Shopping carts, checkouts, and platform tools. | Shopify, Magento, PayPal, Stripe |
Audience Research & Feedback | Market research panels, audience intelligence, and on-site surveys and feedback tools. | Nielsen, comScore, Kantar, Qualtrics, SurveyMonkey, Medallia, Pendo |
Social Media | Pixels, share buttons, and social login tools. | Facebook Pixel, Twitter/X, LinkedIn Insight |
Data Management (DMP) | Audience data collection and segmentation. Excludes CDPs. | Oracle BlueKai, Adobe Audience Manager, Lotame |
Privacy & Consent | Cookie consent and privacy compliance platforms (CMPs). | OneTrust, TrustArc, Cookiebot, Sourcepoint |
Marketing Automation & Email | Platforms for automated marketing campaigns, lead nurturing, and email sending. | HubSpot, Marketo, Pardot, Eloqua, Mailchimp, SendGrid, Klaviyo, Braze |
Customer Support & Chat | Live chat, helpdesks, and support tools. | Intercom, Zendesk, Drift, LivePerson |
Identity & Authorization | User identity, SSO, and authentication tools. | Auth0, Okta, ForgeRock |
Web Analytics | Tools whose primary deliverable is a self-contained traffic/session reporting dashboard — pageviews, sessions, bounce rate, user flows. Excludes event pipelines that feed other tools and attribution platforms. | Google Analytics, Adobe Analytics, Matomo, Heap |
JavaScript Libraries | General-purpose JS libraries and utilities loaded on the page. Not analytics, ads, or martech. | MomentJS, jQuery, Bootstrap Loader, Polyfill, ESRI Leaflet, Bootstrap Icons |
Heatmap & Recording | Session recording and click/scroll visualization. | Hotjar, FullStory, Mouseflow, Contentsquare |
Site Infrastructure & Security | CDN, performance monitoring, bot detection, fraud prevention, and web security. | Akamai, Cloudflare, Amazon CloudFront, Fastly, New Relic, PerimeterX, reCAPTCHA, Sift |
Video | Hosting, streaming, and player analytics. | YouTube, Brightcove, Wistia, JW Player |
Customer Data Platform (CDP) | Platforms that unify first-party data from multiple sources to create a persistent, single customer view for identity resolution and activation across owned channels. | mParticle, Tealium AudienceStream, Treasure Data, Lytics, ActionIQ |
Affiliate & Partner | Affiliate network tracking and referral tools. | Impact, CJ Affiliate, ShareASale, Rakuten |
Content & Asset Management | Platforms for creating, managing, and publishing web content. | WordPress, Drupal, Contentful, Sitecore, Adobe Experience Manager |
Retargeting | Specifically focused on re-engaging past visitors. | AdRoll, Criteo, Rtbhouse |
CRM | Customer relationship management. Excludes marketing automation. | Salesforce, Microsoft Dynamics |
SEO | Search optimization and structured data/schema loaders. | SEMrush, Moz, http://Schema.org |
Most Common Consent Category
The consent category this cookie or tag most often falls under across the sites ObservePoint scans. Because sites and consent tools use different labels, ObservePoint normalizes them into four standard categories:
Consent Category | Examples Included |
Strictly Necessary | Strictly Necessary, Essential, Required, GDPR Essential |
Performance & Analytics | Performance, Analytics, Adobe Analytics, Statistics |
Functional | Functional, Functionality, Personalization, Personalisation |
Targeting & Advertising | Targeting, Advertising, Marketing, Sale of Personal Data, Social Media Cookies |
This field shows how the item is typically categorized. It is not a compliance decision for your site. Use it as a starting point when deciding how the item should fit into your own consent setup.
Prevalence
How often ObservePoint sees this cookie across scanned websites. Prevalence helps you tell whether an item is widely used and well understood, or uncommon enough that it may deserve a closer look.
Quantile | Description |
Very Common (>2%) | Found on more than 2% of websites scanned by ObservePoint. |
Common (0.5% – 2%) | Found on 0.5% – 2% of websites scanned by ObservePoint. |
Rare (0.1% – 0.5%) | Found on 0.1% – 0.5% of websites scanned by ObservePoint. |
Very Rare (<0.1%) | Found on less than 0.1% of websites scanned by ObservePoint. |
Cookie-Only Fields
Party Type
Shows whether the cookie is first-party or third-party. A first-party cookie is set by the site the visitor is on. A third-party cookie is set by a different domain. ObservePoint determines this from what it observes during scans.
How to Remove
Guidance for stopping or removing the cookie. This may point to the tag, vendor setting, or implementation detail that controls it, so you know where to take action.
Expiration Type
Shows whether the cookie expires at a specific time (Timestamp) or when the browser session ends (Session).
Expiration Duration
How long the cookie lasts before it expires, shown as a formatted duration. This applies to cookies with timestamp-based expiration.
Reference Sources
The verified references and technical documentation ObservePoint used to define the cookie’s behavior. These sources let you review the evidence behind the definition instead of taking it on faith.
Data Classification
The kind of information stored in the cookie’s value, such as an online identifier, contact data, or behavioral data. This field focuses on what the cookie holds, which is often more useful than the cookie name when you’re assessing privacy impact.
Classification | What it stores | Examples |
Online Identifier | UUIDs, device IDs, cookie IDs, fingerprint hashes, anything that uniquely tags a browser, device, or user. | _ga, _fbp, IDE, MUID, _hjid, hubspotutk, deviceId, clientId |
Session Identifier | Session tokens, login state, OAuth/JWT tokens, or signed credentials. | JSESSIONID, PHPSESSID, ASP.NET_SessionId, connect.sid, A1, LSID, glt_ |
Contact Data | User IDs, customer or account numbers, email hashes, or internal account references. | sa-user-id, identity_customer_account_number, account_id |
Behavioral Data | Page views, last visited pages, scroll or dwell time, on-site clickstream, or view counts. | _hjSession_*, _pk_ses.*, amplitude_session, _ce.s, sailthru_content |
Attribution Data | UTM parameters, gclid, fbclid, referrer source, or campaign IDs. | _gcl_*, gclid, utm_campaign, UserMatchHistory |
Preference Data | Language, locale, currency, region, theme, or layout choice. | lang, locale, country, tz, EL_PREF, portalLanguage |
Consent State | What the user agreed to, such as cookielaw flags, OptanonConsent, or IAB TC strings. | OptanonConsent, cmplz_consented_services, CookieConsent, euconsent-v2 |
Security Context | CSRF/XSRF tokens, anti-bot challenges, or nonces. | csrf_token, XSRF-TOKEN, __cf_bm, cf_clearance, ak_bmsc |
Operational | Load balancer routing, A/B test buckets, feature flags, viewport details, or debug state. | _gat, ServerPool, ROUTEID, AWSALB, s_cc, s_sq |
Unknown | Encrypted blobs or vendor-specific formats with no public schema. This is the default when the value does not provide a clear signal. | No common examples available. |
Tag-Only Fields
Is Deprecated
Shows whether the technology behind the tag is still in use or has been discontinued. The value is Yes or No. If a deprecated tag is still firing on your site, it may be worth removing.
Deprecation Date
The date the vendor discontinued the technology, when that information applies.
Formerly Known As
Previous names, rebrands, or ownership changes for the vendor or technology. This helps you recognize a technology that may appear under an older name. For example: “NewsCred rebranded to Welcome in 2020, was acquired by Optimizely in 2021, and is now Optimizely CMP.”
Date Added
The date this entry was added to the dictionary.
Common Questions
Where do these values come from?
ObservePoint maintains these values through its own analysis across scanned sites and the reference sources listed on each definition. Because these are ObservePoint-managed fields, they stay consistent for everyone and cannot be edited directly.
Can I change these for my account?
You cannot edit an ObservePoint-managed field directly, but you can add custom fields to any definition if you need to capture account-specific notes or decisions. See Creating & Managing Definitions.
Is the consent category or risk a compliance decision for my site?
No. Both are general guidance based on how an item is typically used. Your own implementation determines how it should be categorized and how risky it is on your properties.