Cookies Policy
This Cookies Policy explains how CallBotAgent.ai (the "Service", "we", "us") uses cookies and similar technologies (e.g., pixels, local storage, SDKs) on the marketing site and inside the customer admin panel, and how you can manage your preferences. This Policy should be read together with our Privacy Policy and Terms of Service.
1. Introduction & Scope
This Policy applies to cookies and similar technologies set on devices used to access the Service. It is designed to satisfy the requirements of the EU ePrivacy Directive 2002/58/EC and its Member-State implementations (including French Loi Informatique et Libertés, German TTDSG, Polish Telecommunications Law cookie provisions, equivalents elsewhere), the United Kingdom Privacy and Electronic Communications Regulations, and the cookie / tracking-technology rules of the California Consumer Privacy Act / California Privacy Rights Act. Where mandatory local law provides additional rights or obligations, we honour those to the minimum extent required.
2. What Are Cookies and Similar Technologies
- Cookies are small text files stored on your device by your browser when you visit a website.
- Similar technologies include local storage and session storage, pixels, tags, beacons, scripts, fingerprinting techniques, and SDKs used by web and mobile components.
- These technologies help us provide core functionality (e.g., session management, security), remember your preferences, measure performance, and (where you have consented) support marketing and attribution.
3. Categories We Use
We classify cookies into four categories. Only the first two are set by default; the others are set only with your consent where required.
Strictly necessary
Always on · cannot be disabledRequired for the Service to function. They include cookies for session management, authentication, CSRF protection, load balancing, language preferences, and security (e.g., bot / fraud protection). Without them the Service cannot operate.
Examples: session ID cookie · authentication cookie · CSRF token cookie · cookie-consent state cookie.
Preferences / functional
On by default · can be disabledRemember choices that personalise your experience: language, theme (light / dark), region settings, recent panel views, navigation state. They do not track you across sites.
Performance & analytics
Off by default · requires consent in EU/UK/EEAHelp us understand how the marketing site and admin panel are used: which pages are visited, which features are clicked, where users drop off, page load timings, error rates. We use this data only in aggregate to improve the Service.
Examples: first-party product-analytics cookies · error-monitoring cookies. We do not use Google Analytics on the marketing site by default.
Marketing & attribution
Off by default · requires consentUsed to measure the effectiveness of advertising campaigns (e.g., on Meta, Google, LinkedIn) and to attribute conversions. They may also be used to suppress ads to existing customers and to build look-alike audiences. We set these cookies only after you give explicit consent through the cookie banner.
Examples: Meta Pixel · Google Ads conversion tag · LinkedIn Insight Tag · TikTok Pixel · click-tracking parameters from advertising partners.
We do not engage in cross-context behavioural advertising as defined under CPRA without your prior consent and an applicable opt-out mechanism.
4. Legal Basis & Consent
- Strictly necessary cookies: legitimate interests in operating and securing the Service (Article 6(1)(f) GDPR) and / or performance of contract (Article 6(1)(b) GDPR). No consent is required under the ePrivacy Directive.
- Preferences / functional cookies: legitimate interests; consent is not required under most ePrivacy regimes for cookies that are strictly necessary to deliver a service requested by the user.
- Performance / analytics cookies: consent (Article 6(1)(a) GDPR) where required by ePrivacy. We provide a banner on first visit and a preferences centre to capture and to allow withdrawal of consent at any time with future effect.
- Marketing / attribution cookies: consent (Article 6(1)(a) GDPR), always.
You can withdraw consent at any time using the "Open cookie preferences" link in the page footer. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Some cookies are set by Stripe inside the checkout flow and are necessary for fraud prevention and SCA / 3-D Secure 2 authentication; those cookies are governed by Stripe's own cookie notice.
5. Managing Your Preferences
- Cookie preferences centre: open the "Cookie preferences" link in the footer of any page. Toggle each non-essential category on or off. The change applies immediately and persists across visits.
- Browser controls: most browsers let you block, delete, or limit cookies through their settings. Blocking strictly-necessary cookies will break the Service. Each browser maker publishes a help page (Chrome, Edge, Firefox, Safari, Brave, etc.).
- Mobile OS: on mobile, your operating-system privacy settings provide additional controls (e.g., "Limit Ad Tracking", "App Tracking Transparency" on iOS).
- Industry opt-outs: in the EU, the Your Online Choices portal (youronlinechoices.eu) lets you opt out of behavioural advertising from participating networks. In the US, see Network Advertising Initiative (thenai.org/opt-out) and Digital Advertising Alliance (optout.aboutads.info).
6. Third-Party Providers
Where we use third-party providers that set cookies on your device, we contractually require those providers to act as our processors and to honour the consent state you have configured through our preferences centre. The current set of providers includes (subject to change):
| Function | Provider | Category | Consent required |
|---|---|---|---|
| Authentication / session | First-party (CallBotAgent.ai) | Strictly necessary | No |
| CDN / WAF / DDoS | Google Cloud (CDN provider) | Strictly necessary | No |
| Subscription billing / SCA | Stripe | Strictly necessary (during checkout) | No |
| Product analytics | First-party / vendor (selected from Sub-Processors List) | Performance / analytics | Yes (in EU/UK) |
| Error monitoring | Vendor (selected from Sub-Processors List) | Performance / analytics | Yes (in EU/UK) |
| Meta Pixel | Meta Platforms Ireland Ltd | Marketing / attribution | Yes |
| Google Ads conversion | Google Ireland Ltd | Marketing / attribution | Yes |
| LinkedIn Insight Tag | LinkedIn Ireland Unlimited Co. | Marketing / attribution | Yes |
The set above is illustrative for the launch period. The current set of marketing-tag vendors may change as campaigns are launched and retired; the cookie preferences centre always shows the current set with toggles. The Sub-Processors List tracks data-processing relationships more broadly.
7. International Transfers
Where data collected via cookies is transferred from the EEA, UK, or Switzerland to a country not subject to a Commission / ICO / FDPIC adequacy decision, we rely on the Standard Contractual Clauses Module 2 or Module 3 (as applicable), the UK Addendum, and Swiss adaptations, supplemented by the technical measures described in our DPA Annex on Technical and Organisational Measures. A Transfer Impact Assessment summary is published on the public legal pages of callbotagent.ai.
8. Retention
Cookie lifetimes vary by purpose and category:
- Session cookies: deleted when you close the browser tab.
- Authentication cookies: typically 30 days (extendable on "remember me").
- Preferences cookies: typically up to 12 months.
- Performance / analytics cookies: typically 6 to 13 months (per CNIL standard guidance).
- Marketing / attribution cookies: typically 30 days to 13 months, depending on the campaign and the network's defaults.
- Cookie-consent state cookie: typically 6 months, after which we re-prompt for consent on next visit.
Backups containing aggregated, hashed, or pseudonymised analytics data may be retained for a limited period (typically 90 days) before automated deletion.
9. Security
We set Secure, HttpOnly, and SameSite attributes on cookies wherever appropriate. Sensitive cookies (e.g., authentication) are not accessible to client-side scripts and are transmitted only over TLS. We rotate session keys regularly. Backend access controls and audit logs are described in DPA Annex 4 (Technical and Organisational Measures).
10. Your Rights
Where the cookies process personal data, you have the rights described in Privacy Policy Section 11 (access, rectification, erasure, restriction, portability, objection, withdraw consent, lodge a complaint). To exercise these rights, contact [email protected]; for European data subjects, our designated EU representative is also a valid contact (see Legal Notice).
11. Do Not Track / Global Privacy Control
Where applicable law requires us to honour the Global Privacy Control (GPC) browser signal, we do so. There is no industry consensus on responding to "Do Not Track" (DNT) browser signals; we do not currently respond to DNT outside the legal scope of GPC. Where required, our cookie preferences centre provides parity-equivalent controls.
12. Updates
We may update this Cookies Policy from time to time to reflect changes in our cookie use, third-party providers, or applicable law. We will post the updated Policy with a new "Last Updated" date and, where required by law, provide additional notice. Continued use of the Service after the updated Policy takes effect constitutes acknowledgment.
13. Contact
- Cookie / tracking questions: [email protected]
- Data subject rights: see Privacy Policy Section 11
- EU contact: [email protected] (designated EU representative — see Legal Notice)
- Operator phone: +1 (719) 624-4435
- Operator postal address: CallBotAgent, Inc., 1111B S Governors Ave STE 39750, Dover, DE 19904, USA