What it does
`__hstc` carries several values at once: the tracked domain, the visitor token, timestamps for the first and most recent visits, and the number of sessions. It is the record from which HubSpot reconstructs a visitor’s history.
Two companions sit beside it: `__hssrc`, which indicates whether the visitor restarted their browser, and `__hssc`, which tracks session state.
What to write in a cookie declaration
List the `__hs` family together, name HubSpot, and describe the purpose as behavioural tracking tied to a CRM contact record.
| Field | Value |
|---|---|
| Name | __hstc |
| Provider | HubSpot |
| Purpose category | advertising |
| Consent category | Marketing |
| Expiry | Six months in current HubSpot defaults (vendor default) |
| Storage | First-party, written by script |
Treat the expiry as indicative
The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.
Can a visitor refuse it?
Yes, in marketing, on the same basis as `hubspotutk`.
A verification scan supplies runtime evidence for the pages and states it exercises. Test a fresh profile with no choice made, then after refusal, and reconcile observed storage with response headers, server-side integrations and paths the scan did not visit.
Common questions
Can I keep HubSpot forms without the tracking cookies?
Often, in a similar shape to the Klaviyo split, but it depends on your portal configuration and needs testing against your own account rather than assuming.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- HubSpot: cookies set in a visitor browser
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.