What it is
HubSpot’s tracking script records page views and events and (this is the part that matters) associates them with a contact record once the visitor is identified, usually by submitting a form or clicking a tracked email link. That association is what makes it more than measurement.
The catalogue reflects the dual nature: analytics loaders are classified as analytics, form hosts as functional, and tracking cookies that link browsing to a contact as advertising. Do not force the whole suite into one category when the integration can be separated by purpose.
What a scan matches
A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so HubSpot is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.
- hs-scripts.com and hs-analytics.net: the tracking script and analytics endpoint
- hsforms.net and hsforms.com: forms, classified as functional
- hscollectedforms.net: collected-form analytics
- Generic hubspot.com pages are not classified as the tracking product without more specific endpoint evidence
Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.
| Cookie | What it is for |
|---|---|
| hubspotutk | The visitor token that links browsing to a contact record |
| __hstc | Main tracking cookie: domain, timestamps and session count |
| __hssrc | Whether the visitor restarted the browser |
| __hssc | Session state |
| __hs_do_not_track, __hs_opt_out and preference cookies | Consent-control state, classified as functional rather than tracking |
Controlling it with consent
No named adapter. Gate the tracking script as a custom script attached to marketing. HubSpot also publishes its own consent banner and a cookie-consent API, and running two consent systems on one page is a reliable source of confusion. Pick one.
Forms and chat can often be kept available while tracking is not, in the same shape as the Klaviyo split, but that depends on how your portal is configured and needs testing against your own account.
No named adapter: choose the appropriate control
The product ships named adapters for Google Tag Manager, Google Analytics, the Meta and TikTok pixels, and Klaviyo. Choose the control route that fits this technology: a custom HTTPS script declaration for a browser loader, an individual consent condition inside a tag manager, a platform or app setting, or a click-to-load placeholder for a frame. Server-side integrations need their own enforcement because a browser runtime cannot stop them.
What breaks if it is refused: attribution of a contact’s browsing history, and any workflow that depends on page-view triggers.
Verifying it
Before consent there should be no hubspotutk or __hstc. Then submit a form and confirm the association behaves the way you intend for a visitor who has refused tracking.
- Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
- After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
- After granting the relevant category: the expected loader or embed appears and the feature behaves normally
- After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior
Common questions
Why is HubSpot classified as advertising by its cookies?
Because the tracking cookies exist to link browsing behaviour to an identified contact for marketing purposes. Category follows purpose rather than the vendor’s product category, and that is the conservative reading.
Can I use HubSpot’s own consent banner instead?
You can, but not alongside another one. Two banners on a page produce contradictory states and unexplainable records. Decide which system owns the decision and disable the other.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- HubSpot: cookies set in a visitor browser
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.