BusinessMCP

Cookie Policy

Last updated: 26 September 2026

Short version: the product sets no cookies.BusinessMCP’s analytics — the script our customers install on their own sites — is pseudonymous, first-party, and never shared with advertisers; it keeps a pseudonymous id in browser storage instead (listed below). This marketing site is different: after you accept (or if you are outside a consent jurisdiction) two third-party tags set their own cookies here — DataFast, a second analytics tool, and Google Ads, to measure which of our ads work. All of it is described below. We honor Global Privacy Control as a Do-Not-Sell/Share opt-out. See also our Privacy Policy.

The product sets no cookies

Our tracking script — the one a customer installs on their website, and the one that produces every number in the dashboard — sets no cookies and uses no cross-site tracking technology. It does not follow anyone between sites, and nothing it collects is sold or shared with advertisers. It does store a pseudonymous id in the browser’s own storage (see First-party browser storagebelow), and in the EU/EEA and UK the ePrivacy rules treat that storage the same way as a cookie. So “cookieless” does not mean “no consent needed” there: the script has consent modes for exactly this (see A note for our customers).

Nothing in the logged-in app carries an advertising or third-party analytics tag. The cookies in the next section exist only on our public marketing pages.

Analytics and advertising cookies on this marketing site

DataFast. We use DataFast (datafa.st) as a second analytics tool on businessmcp.com to see which pages and channels bring sign-ups. Its script sets two first-party cookies: datafast_visitor_id, a random visitor id kept for 365 days, and datafast_session_id, kept for 30 minutes and refreshed while you browse. DataFast receives your IP address and browser details with each request. It is loaded under exactly the same rules as the Google tag below.

Google Ads.We buy ads, and we need to know which ones bring people who actually sign up. So on businessmcp.com (never in the app at /dashboard, and never on a customer’s website) we load Google’s advertising tag. It sets first-party cookies in the _gcl_* family — principally _gcl_au — which store an ad click identifier for up to 90 days so a later sign-up can be matched back to the ad that produced it.

  • If you are in the EU/EEA, the UK, or we cannot tell where you are: neither DataFast nor Google’s tag loads until you press Accept. Decline, and they are never requested — not blocked after loading, simply never fetched.
  • Elsewhere: both load under legitimate interest, and a Do Not Sell or Share signal (Global Privacy Control) turns off ad personalisation.
  • You can clear these at any time in your browser’s site-data settings, and opt out of personalised Google advertising at myadcenter.google.com.

Both are listed in our sub-processor register. We also count page views with Vercel Web Analytics, which sets no cookies and stores nothing on your device.

First-party browser storage we use

Our tracking script keeps a few values in your browser’s own localStorage / sessionStorage — first-party only, never sent to advertisers:

  • mcph_vid — a random, pseudonymous visitor id so a site can measure returning visits (no name, email, or profile attached). On our own site, EU/UK visitors get only a session-scoped id (sessionStorage, cleared when the tab closes) until they Accept our consent notice.
  • mcph_region — set on businessmcp.com only when you browse from outside the EU/EEA and UK, so the next visit is measured as the same visitor. It records your region, not a consent choice, and is removed if a later visit comes from a region that asks for consent.
  • mcph_rsid — a per-tab session id (sessionStorage; cleared when you close the tab).
  • mcph_ref0 — the first referring website of your visit (sessionStorage; cleared when you close the tab), so a site can correctly attribute where you arrived from.
  • mcph_consent — remembers your Accept/Decline choice on sites that show a consent notice. On businessmcp.com itself, declining keeps basic, pseudonymous analytics running under legitimate interest but turns off session replay, heatmaps, and visitor identification — those only run after you Accept.
  • mcph_ident / mcph_ident_x— set only if you submit your email to a site (so it isn’t captured twice); holds the email/traits you provided.
  • mcph_q— a small offline queue so events aren’t lost on a flaky connection.
  • as_vid — a legacy visitor-id key read only for backward compatibility.

Global Privacy Control (Do Not Sell or Share)

Our first-party analytics is cookieless and pseudonymous — it is not sold, and not shared with advertisers — so it runs to measure a site’s own audience under legitimate interest. Separately, some customers enable optional ad-platform integrations (server-side conversion measurement or audience matching); that transfer can count as a “sale” or “share” under US state privacy laws. For residents of states that recognize it, we treat a Global Privacy Control(GPC) browser signal as a valid opt-out of that sharing and exclude you from those transfers. The same signal turns off ad personalisation in our own Google Ads tag on this marketing site. Do-Not-Track has no agreed legal standard, so we don’t rely on it; a site can still enable a consent gate or ask us to respect DNT for its own install.

How to clear it

You can clear these keys any time by clearing site data for the website in your browser settings, or by declining on a site’s consent notice. Clearing them simply resets the pseudonymous id.

A note for our customers

If you install BusinessMCP on your own website, you remain the controller for your visitors’ data. By default the tracker collects everything with no consent gate — you decide how to handle your own data policies. Although it sets no cookies, it stores a pseudonymous id in localStorage, and in the EU/EEA and UK that storage falls under the same ePrivacy consent rule as a cookie. Give your visitors a clear privacy notice and, for visitors in those regions, obtain consent. The script supports two consent-gate modes: data-require-consent="true" holds everything, with no id stored, until you call mcph.consent('granted') — the most defensible option; and "split", which sends basic analytics with a session-only id while the persistent id, session recordings and identification wait for consent (the posture we use on this site). Split mode narrows what happens before consent but does not make that storage exempt. Company identification also uses your visitors’ IP addresses — see our Privacy Policy.