RTI HubSpot Site Cookie and Tracker Scan

Site scanned: https://22124978.hs-sites-na2.com/
Scan date: August 3, 2026 (America/Boise; August 4 UTC)
Scope: Fresh-browser crawl of 30 published URLs, including primary content, solution, news, contact, privacy, and terms pages. The scan recorded cookies after scripts had executed and inspected the site’s public HubSpot consent configuration.

Executive summary

Observed cookies

“First-party” below describes the browser context: the cookie is stored against the site’s current registrable domain. It does not mean RTI wrote the cookie; several first-party cookies are supplied by HubSpot or Google. “Third-party” means the cookie is stored against another registrable domain.

Cookie Domain observed Party on staging site Provider Purpose Observed duration Recommended category
__cf_bm .hs-sites-na2.com First-party Cloudflare for HubSpot Bot detection and protection for the main hosted site 30 minutes of inactivity Strictly necessary / security
__cf_bm .hubspotusercontent-na1.net Third-party Cloudflare for HubSpot Bot protection for HubSpot-hosted static/module assets 30 minutes of inactivity Necessary for the associated asset endpoint
__cf_bm .hsappstatic.net Third-party Cloudflare for HubSpot Bot protection for HubSpot static resources 30 minutes of inactivity Necessary for the associated asset endpoint
__cf_bm .hs-banner.com Third-party Cloudflare for HubSpot Bot protection for HubSpot’s consent/geolocation service 30 minutes of inactivity Necessary for the consent service
__cf_bm .hsadspixel.net Third-party Cloudflare for HubSpot Bot protection for HubSpot’s advertising-pixel endpoint 30 minutes of inactivity Treat with the parent advertising service
__cf_bm .hs-analytics.net Third-party Cloudflare for HubSpot Bot protection for HubSpot’s analytics endpoint 30 minutes of inactivity Treat with the parent analytics service
__cf_bm .hubspot.com Third-party Cloudflare for HubSpot Bot protection for HubSpot interactive/API resources 30 minutes of inactivity Functionality; necessary only if that HubSpot service is required
__cf_bm .hsforms.com Third-party Cloudflare for HubSpot Bot protection for HubSpot form resources 30 minutes of inactivity Necessary for form delivery; do not use for unrelated tracking
__hstc .hs-sites-na2.com First-party HubSpot Main visitor-tracking cookie; stores visit timestamps, session number, and visitor token 180 days / 6 months Optional analytics under RTI’s functional classification
hubspotutk .hs-sites-na2.com First-party HubSpot Visitor identifier used for tracking and form/contact deduplication 180 days / 6 months Optional analytics / form attribution
__hssc .hs-sites-na2.com First-party HubSpot Counts page views in the current session and determines session changes 30 minutes Optional analytics
__hssrc .hs-sites-na2.com First-party HubSpot Detects whether the browser was restarted and a new session should begin Browser session Optional analytics
_ga .hs-sites-na2.com First-party Google Analytics 4 Distinguishes visitors for site-usage measurement 400 days observed in Chrome; Google’s configurable default is 2 years, subject to browser limits Optional analytics
_ga_JPPYHVKFVL .hs-sites-na2.com First-party Google Analytics 4 Persists the GA4 property’s session state 400 days observed in Chrome; Google’s configurable default is 2 years, subject to browser limits Optional analytics
_gcl_au .hs-sites-na2.com First-party Google Ads Stores advertising/conversion information used to measure ad interactions 90 days observed Optional advertising
test_cookie .doubleclick.net Third-party Google/DoubleClick Tests whether the browser accepts cookies for Google advertising services 15 minutes observed Optional advertising
IDE .doubleclick.net Third-party Google/DoubleClick Advertising delivery, personalization where enabled, frequency control, and effectiveness measurement 400 days observed in the US scan; Google states 13 months in the EEA/UK/Switzerland and 24 months elsewhere, subject to browser limits Optional advertising

These were not present in the scan because no active banner policy is published, but HubSpot’s current banner code can set them:

Cookie Provider Purpose Duration Category
__hs_cookie_cat_pref HubSpot Remembers the visitor’s choices by category 180 days Strictly necessary / consent preference
__hs_gpc_banner_dismiss HubSpot Remembers dismissal of a Global Privacy Control notice 180 days Strictly necessary / consent preference
__hs_notify_banner_dismiss HubSpot Remembers dismissal of a notification-only banner 180 days Strictly necessary / consent preference

Legacy or migrated HubSpot banner configurations may also expose older consent cookies such as __hs_opt_out (180 days) and __hs_initial_opt_in (7 days). HubSpot’s current v2 script treats these as deprecated and removes them during initialization.

Trackers and external services loaded

The scan observed these tracking-capable services:

The LinkedIn and Google Maps references seen in page content were outbound links; those vendors were not embedded as trackers during this crawl.

Strictly necessary versus optional

Strictly necessary

Optional

HubSpot’s own documentation currently places its four core tracking cookies under a “Necessary cookies” heading. Functionally, however, they perform visitor/session analytics and HubSpot provides consent-revocation behavior that removes them. RTI should have privacy counsel approve the final category mapping and, where available, configure the banner/scanner categories to match that decision.

Current state

No active consent banner is published for the staging domain. The site loads the HubSpot banner code, but the public configuration contains no enabled policies. A US fresh-browser visit therefore created analytics and advertising cookies without a banner interaction.

  1. Publish an opt-in, by-category policy for all EU, EEA, and UK countries. Analytics, advertising, and optional functionality must start off and remain blocked until the visitor consents.
  2. Publish an opt-out, by-category policy for the United States. This permits cookies by default but gives visitors a clear way to reject them.
  3. Enable Global Privacy Control (GPC) handling for applicable US privacy-law requirements.
  4. Categorize GA4 under Analytics and Google Ads/DoubleClick under Advertising. Confirm that the HubSpot ads pixel and HubSpot analytics are controlled by the corresponding choices.
  5. Add a persistent “Cookie Settings” or “Your Privacy Choices” control so visitors can reopen the dialog and revoke consent.
  6. Verify both pre-consent and post-consent behavior from EU/UK and US locations, then repeat the scan on the final custom domain.

HubSpot’s current documentation says consent-banner setup, country selection, and opt-in/opt-out banner types are available on all products and plans. The documented plan limitation applies to advanced banner styling, which requires Marketing Hub or Content Hub Starter, Professional, or Enterprise. If the specific RTI portal presents a plan gate because of its account state or v1-to-v2 migration, confirm that limitation with HubSpot Support before promising the feature or an upgrade.

Important limitations

Sources