Solutions

Consent for a SaaS product, where the marketing site and the app differ.

Two surfaces with genuinely different conditions: a public marketing site full of advertising tags, and an authenticated product where you have a relationship, a contract and a different set of options.

Typical plan
Growth
Surfaces
Marketing site and product
Common tags
LinkedIn, HubSpot, product analytics
Watch
Session replay inside the product

Two surfaces, two conversations

On the marketing site, a stranger arrives from an ad. Everything applies in the usual way: prior consent where the jurisdiction requires it, advertising tags gated, evidence kept.

Inside the product, the visitor is signed in and may have received an account-level privacy notice, while their employer may have a contract with the provider. A notice is not necessarily something the user “accepts,” nor is it automatically a contract or lawful basis. Authentication changes the context and disclosure routes, but it does not make device-storage rules or data-protection duties disappear.

Decide deliberately, and write it down

The failure mode here is not choosing wrongly, it is not choosing at all: leaving the product surface unexamined because the marketing site got all the attention. If consent is the basis inside the product, the in-product preference has to be honoured by the same runtime.

B2B advertising has a longer tail

A B2B stack can include the LinkedIn Insight Tag, marketing automation such as HubSpot or Marketo, an intent-data vendor, and chat with visitor identification. Some services infer or identify companies, but that label does not establish that no personal data is processed; assess the actual data flow under each applicable regime.

  • LinkedIn sets an unusually long list of cookies, several of them first-party
  • Marketing automation cookies associate browsing with a contact record once a form is submitted, which is the part to disclose
  • Reverse-IP company identification is a processing activity even when no cookie is involved
  • Product analytics inside the app needs its own decision, not an inherited one

Common questions

Does an authenticated product need a cookie banner?

The storage rule does not stop at a login wall. What changes is that you have other disclosure routes and possibly another basis. Decide and document rather than assuming authentication answers it.

How do I handle a customer asking for our consent records?

Export them. Records are browsable and exportable as CSV, and each carries the configuration version that was live, which is what makes them answer the question rather than raise more.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.