Personyze stores a small number of cookies and localStorage entries to maintain visitor identity, track sessions, and enforce campaign frequency rules across visits. This article documents what each entry stores, how long it lasts, and the privacy controls that apply to it. Your own account’s list, with its cookie lifetime filled in, is on Settings → Data & privacy → Access & documents.
Where data is stored
Everything is first-party. The tracking code writes its cookies on your own domain, and keeps its other entries in your site’s localStorage. Personyze sets no third-party cookies.
Cookies and localStorage entries
| Name | Lifetime | Notes |
|---|---|---|
stat_track_u_id |
The account’s cookie lifetime (default 730 days) | Visitor id |
_stat_track_s_id |
Browser session | Session id |
stat_track_off |
730 days, even with a shorter cookie lifetime | Set only for visitors who opt out |
stat_track_off (value off=1) exists because the visitor said no, and it is what stops Personyze tracking them on the next page load. A visitor who opts out still ends up with this one cookie, and cookie scanners will find it, so declare it in your cookie policy. The cookie lifetime is set on Settings → Data & privacy → What we collect.
Copies in localStorage
The tracking code also keeps a copy of each cookie in the browser’s localStorage, under the same name. The copy expires with its cookie: an expiry stamp is stored beside it, as stat_track_u_id.exp and stat_track_off.exp, and an expired copy is ignored and removed. The session id’s copy carries no stamp, as its cookie has no expiry date. Deleting a cookie with _S_T.delete_cookie() deletes its copy too.
Other entries in localStorage
| Name | Lifetime | Notes |
|---|---|---|
stat_track_actions |
No expiry of its own; display times older than 31 days are dropped as it is updated | When each campaign action was shown to this visitor, which frequency caps read |
stat_track_sessions |
No expiry of its own. Where localStorage is unavailable or full, it is kept in a cookie instead, with the visitor-id cookie’s lifetime | Start times of the visitor’s last 12 sessions, for recency-based targeting |
Note on the opt-out flag. The opt-out lives in its own cookie, stat_track_off. An opt-out stored the older way, as a flag inside stat_track_u_id, is still read, so those visitors stay opted out; the flag is never written there. How long data is kept and how consent is handled are set on Settings → Data & privacy.
GDPR / privacy controls
Personyze provides several controls to help with GDPR, CCPA, and other privacy regimes:
- Cookie lifetime. On Settings → Data & privacy → What we collect, Cookie lifetime sets how long
stat_track_u_idlasts: 30–730 days, or blank for the default of 730 days (2 years). Its localStorage copy expires with it. The opt-out cookie,stat_track_off, always lasts 730 days, so a refusal never runs out early. For a site with visitors in France, Suggest settings for my site suggests 395 days, applying the CNIL’s 13-month benchmark. - Opt-out controls. Visitors can be opted out of tracking entirely via the JavaScript API — see GDPR Compliance & Opt-Out. When a visitor opts out, Personyze writes a single cookie —
stat_track_off— to remember the refusal, stops writing all other tracking cookies, and honors any existing ones as read-only. - Cookie consent integration. Most cookie consent platforms (OneTrust, Cookiebot, etc.) can hold Personyze tracking until the visitor opts in — see Consent mode. The Consent mode switch is on What we collect.
- Data deletion on request. Settings → Data & privacy → Visitor requests finds everything held about a person, downloads it, or deletes it, and logs each request — for GDPR or CCPA access and erasure requests. A deletion doesn’t touch the cookies in the person’s browser: they last until they expire, unless your site calls
_S_T.delete_cookie()in that browser.
Third-party cookie restrictions
Browser restrictions on third-party cookies don’t apply to Personyze’s cookies: they are all first-party, set on your own domain.
How to inspect what’s stored
In your browser’s dev tools:
- Application → Cookies: filter by your domain and look for
stat_track_*entries. - Application → Local Storage: the same names, plus the
.expexpiry stamps besidestat_track_u_idandstat_track_off.
This is also a useful debugging step when investigating personalization issues — if cookies are missing or have unexpected values, the symptoms (visitor not recognized, campaigns not firing) become clear.