Cookie library

The hubspotutk cookie

The HubSpot visitor token, the cookie that turns anonymous browsing into a contact record once someone submits a form.

Set by
HubSpot
Classified as
advertising
Typical expiry
Six months in current HubSpot defaults
Storage
First-party, written by script

What it does

`hubspotutk` stores a token identifying the browser. When a visitor submits a HubSpot form or clicks a tracked link, the token is associated with their contact record, and the browsing history collected up to that point becomes attached to a named person.

That retroactive association is why the cookie classifies as advertising rather than as measurement, even though HubSpot’s script hosts classify as analytics. Category follows purpose.

What to write in a cookie declaration

Say what it actually does: links browsing activity to a contact record in the CRM. "HubSpot analytics cookie" does not convey that, and the association is the part a visitor would care about.

FieldValue
Namehubspotutk
ProviderHubSpot
Purpose categoryadvertising
Consent categoryMarketing
ExpirySix months in current HubSpot defaults (vendor default)
StorageFirst-party, written by script

Treat the expiry as indicative

The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.

Common questions

Does hubspotutk collect data before someone fills in a form?

Yes. That is the point of it: the history exists first and is associated retroactively when identification happens. Which is why it needs consent at the point the cookie is set, not at the point of the form.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.