Cookie Disclosure
Cookie Policy
Last Updated: August 28, 2026
2. Cookies and Storage Items We Set
Below is a detailed breakdown of every storage identifier this site sets, what writes it, and how long it lasts.
| Key Name | Type | Purpose | Duration |
|---|---|---|---|
| cais-cookie-consent | Local Storage | Remembers the choice you made in the consent banner (“all” or “essential”) so we stop asking and so the analytics and advertising tags know what you decided. (Strictly essential) | Until you clear this site’s data |
| cais-diagnostic-session | Local Storage | Holds your part-finished scorecard run on this device: which kind of business you picked, the answers so far, the figures you typed and the last question you saw. It is what stops a reload sending you back to question one. (Strictly essential) | Cleared when you submit the scorecard, when the question set changes, or when you clear this site’s data |
| cais:diagnostic:result | Session Storage and Local Storage | The result we calculated for you: your monthly estimate, the components it is built from and the ranked builds. The results page and the print view read it so they can re-render exactly what you saw after a reload. (Strictly essential) | Session copy goes when you close the tab. The local copy stays until your next run replaces it, or you clear this site’s data |
| cais:diagnostic:booking-context | Session Storage and Local Storage | A short summary of that result (session id, the kind of business, the monthly total and the top-ranked build), written on this device when you click through to book a call. It stays on your device: it is not sent to Cal.com or to us. (Functional) | Session copy goes when you close the tab. The local copy stays until your next run replaces it, or you clear this site’s data |
| cais-utm | Session Storage and Local Storage | The campaign parameters on the link you arrived through (utm_source, utm_medium, utm_campaign, utm_content, utm_term), plus the referring address and the page you landed on, so we can tell which ad or article brought you here. The first value captured wins, so a later internal link does not overwrite it. This is first party: it stays on your device and, if you submit the scorecard, on your own record. It is written whatever you choose in the banner, and it is shared with an advertising network only if you accept advertising cookies. (Functional, first party) | Session copy goes when you close the tab. The local copy stays until you clear this site’s data |
| cais-admin-session | Cookie (httpOnly, sameSite strict) | The signed-in session for the CAIS admin dashboard. It is set only when a member of the CAIS team logs in, and never on a visitor’s browser. (Strictly essential) | 5 days |
| _GRECAPTCHA | Third-party cookie (Google) | Google reCAPTCHA v3, which protects the scorecard and the contact form from bots. Google’s script loads only on those two forms, scores the submission, and may set this cookie to tell people and automated traffic apart. It is not used for advertising. Google’s own privacy policy applies. (Strictly essential, security) | 6 months (set by Google) |
| ph_*_posthog | Cookie and Local Storage | PostHog analytics identifiers, used to understand which steps people leave at and how they move through the site. (Analytics, consent required) | Up to 1 year (opt-in only) |
| _ga, _ga_* | Cookie | Google Analytics 4. Counts visits and tells us which pages people read and which ad brought them, so we can see whether the site is doing its job. (Analytics, consent required) | 13 months (opt-in only) |
| _fbp, _fbc | Cookie | Meta pixel (Facebook and Instagram). Connects your visit to the ad you clicked, so we can tell which ads work and stop paying for the ones that do not. (Advertising and measurement, consent required) | 90 days (opt-in only) |
| Cal.com embed | Third-party cookie | Set by Cal.com inside the booking widget, and only on the /book-consultation page, so a booking you have started keeps working while you finish it. No other page loads it. (Functional) | Set and controlled by Cal.com |
| Funnel counter (/api/track) | Not a cookie. Nothing is stored on your device | Adds 1 to a running total when someone reaches a step of the scorecard or books a call. It records the name of the step, the date, and the campaign parameters from the link you arrived on (utm_source and similar), and nothing else: no name, no email, no IP address, no device or session ID. (Essential / legitimate interest, see section 3) | Not applicable |
3. The Funnel Counter, and Why It Does Not Ask for Consent
We keep a plain tally of how many people reach each step of the scorecard: how many started, how many got to step two, how many finished, how many went on to book a call. It runs on our own server, at /api/track. We include it here because you deserve to know about anything we measure, even the things that never touch your device.
What it records: the name of the step, the date, and the campaign parameters from the link you arrived on (utm_source and similar), so we can tell which ad or article the people who finished came from. That is the whole of what the counter holds. When you book a call, Cal.com tells our server a booking was made and the same counter goes up by one, with the same campaign parameters and nothing else.
What it does not record: your name, your email, your IP address, a device or browser ID, a cookie, or a session ID. There is nothing in it that could link one step to another, or any step to you. It is a tally, not a trail. We can see how many people finished, and we cannot see who any of them were.
That is why it sits outside the consent banner, and we would rather explain the reasoning than ask you to take it on trust. Consent rules for cookies exist because something is being written to or read from your device; this counter writes nothing and reads nothing. Consent rules under privacy law exist because personal data is being processed; a count with no identifiers in it is not personal data. We rely on our legitimate interest in knowing whether our own website works.
There are two caveats worth stating plainly. Like every website, our hosting provider writes ordinary server logs, and those logs contain IP addresses. That is a normal part of serving a page and keeping the site secure. And to stop automated abuse of our forms, our own server keeps short-lived counters keyed by IP address (and, for form submissions, by email address) that are deleted within hours; the contact form also records the IP address and browser a message was sent from. None of that is joined to the counter, none of it is used for advertising or profiling, and section 2 of our Privacy Policy lists it in full.
4. Consent and Opt-Out
When you first load the site, a cookie consent banner appears. Everything that is not strictly essential (Google Analytics, the Meta pixel and PostHog) is off until you switch it on. If you choose “Essential Only”, close the banner, or leave it alone, the Meta pixel and PostHog do not load at all, and Google Analytics runs only in a cookieless mode that sets nothing on your device and stores no identifier. Doing nothing is a valid answer, and the answer it gives is no.
If your browser sends a Global Privacy Control signal, we treat it as that same “no” automatically and do not show you the banner.
We use Google Consent Mode v2. In plain terms, the Google and Meta tags are told what you chose and have to honor it: if you have not said yes, they set no cookies and send nothing that identifies you. The same choice travels with you if you book a call: the server-side booking report to Meta described in our Privacy Policy is sent only if you accepted advertising cookies.
If you choose “Accept All”, the analytics and advertising cookies listed in the table above are set, and nothing beyond them.
To change your mind, clear this site’s data in your browser and the banner will ask again on your next visit. Clearing site data also removes the strictly essential and functional items in the table, including any part-finished scorecard run. You can also email us at info@caismd.com and we will record your opt-out at our end.
5. The Privacy Laws This Policy Sits Under
This cookie policy forms part of our Privacy Policy, and both sit under the same three laws:
- The Maryland Online Data Privacy Act (MODPA): Creative AI Solutions is a Maryland business, based in Annapolis, Maryland.
- The EU and UK GDPR, if you are reading this from Europe or the UK.
- The California Consumer Privacy Act, as amended (CCPA/CPRA), if you are a California resident.
Under all three you can opt out of targeted advertising, and ask to see, correct or delete what we hold about you, and appeal if we say no. Those rights are set out in section 6 of our Privacy Policy, and section 7 of that page tells you exactly how to make a request.
6. Contact Us
If you have any questions about our use of cookies or technical storage, contact us at:
