What it does
`hubspotutk` stores a token identifying the browser. When a visitor submits a HubSpot form or clicks a tracked link, the token is associated with their contact record, and the browsing history collected up to that point becomes attached to a named person.
That retroactive association is why the cookie classifies as advertising rather than as measurement, even though HubSpot’s script hosts classify as analytics. Category follows purpose.
What to write in a cookie declaration
Say what it actually does: links browsing activity to a contact record in the CRM. "HubSpot analytics cookie" does not convey that, and the association is the part a visitor would care about.
| Field | Value |
|---|---|
| Name | hubspotutk |
| Provider | HubSpot |
| Purpose category | advertising |
| Consent category | Marketing |
| Expiry | Six months in current HubSpot defaults (vendor default) |
| Storage | First-party, written by script |
Treat the expiry as indicative
The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.
Can a visitor refuse it?
Yes, in marketing. HubSpot also publishes its own consent banner and cookie API. Use one consent system, not two, or the recorded states will contradict each other.
A verification scan supplies runtime evidence for the pages and states it exercises. Test a fresh profile with no choice made, then after refusal, and reconcile observed storage with response headers, server-side integrations and paths the scan did not visit.
Common questions
Does hubspotutk collect data before someone fills in a form?
Yes. That is the point of it: the history exists first and is associated retroactively when identification happens. Which is why it needs consent at the point the cookie is set, not at the point of the form.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- HubSpot: cookies set in a visitor browser
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.