VATFIND LEGAL
Cookie notice
The storage VATFind uses, why it is used, how long it lasts and how to change your choice.
Updated 8 September 2026
Your choice
Essential storage supports sign-in, security, the service you request and your privacy preference. Optional analytics is off until you select Accept analytics. Selecting Reject optional keeps it off. Both choices are available in the same panel. You can use the service with either choice.
Use the Cookie settings button on every page to change your preference. We remember it on this browser for up to 180 days. A different browser, cleared cookies or an expired preference will require a new choice. If your browser cannot save the preference, optional analytics stays off. Withdrawing an existing analytics choice reloads the page to stop the previously loaded tag; save any unfinished form first.
Cookies and browser storage
| Technology | Purpose | Duration and category |
|---|---|---|
vf_analytics_consent | Remembers the accepted or rejected analytics choice, version and time | 180 days; essential privacy preference |
| vf_signup_attribution and vf_signup_attribution_signed | With analytics consent, retain the first observed public page, referrer hostname, campaign labels and whether a Google ad click parameter was present through signup, then attach them to the HubSpot registration. The signed handoff protects these details during authentication. No click identifiers, search terms or full referrer URLs are stored. | Up to 30 minutes; optional. Cleared on completed sign-in; withdrawal prevents use. |
| WorkOS authentication and OAuth state cookies | Keep the requested account session secure and validate sign-in flows | Session and configured authentication lifetimes; essential. Exact names and lifetime depend on the selected sign-in flow. |
| VATFind checkout proof and paid-account session cookies | Connect a confirmed payment to the browser that started checkout and open a new account securely | Checkout proof: up to two days. Paid-account session: up to seven days, ending earlier on sign-out or verified account sign-in; essential. |
| Hosting and security cookies | Deliver the site and protect it against automated abuse | Session or provider-defined security period when needed; essential |
| Save-result sign-in state | Connect a requested saved company result to the browser completing sign-in | Up to 30 minutes; essential for the requested save flow |
sidebar_state | Remember the sidebar preference when that control is used | Up to 7 days; service preference |
vatfind_checkout in local storage | Remember the selected plan during the requested checkout | Until checkout confirmation clears it or browser storage is cleared; essential checkout state |
vatfind:last-workspace-path in session storage | Attach the relevant workspace page to a support request you submit | Browser-tab session; requested support context |
vatfind:asset-recovery in session storage | Recover a failed page asset without repeatedly reloading | Cleared after recovery or at the end of the tab session; essential reliability |
vatfind_landing in session storage | Remember the first observed public page in this tab and its capture time; include it with a submitted sales enquiry to relate CRM outcomes to the page. No query strings or account pages are stored. | Up to 30 minutes, tab closure or rejection; optional analytics |
vatfind_analytics_session in session storage | Group limited product-use events within a browser session | Tab session or until rejection; optional analytics |
Google Analytics _ga and _ga_* | Measure public-page visits and interactions | Configured for up to 180 days without refreshing that cookie lifetime; optional analytics |
Cookies are small browser records. Local storage remains until removed; session storage normally ends when the browser tab closes. Your browser can remove these records earlier. Blocking essential storage may prevent sign-in, checkout recovery or saving results. Some listed storage is created only when you use the corresponding feature.
What analytics receives
With analytics permission, VATFind also reads campaign source, medium, name and ID from tagged public-page links. These labels are stored in vatfind_campaign for up to 30 minutes in the current browser tab and removed when optional analytics is rejected. They help attribute a subsequent enquiry to its campaign and are included in its HubSpot contact note. Click identifiers and search keywords are not included in this capture.
VATFind uses optional first-party product analytics and Google Analytics, supplied by Google. Google’s tag is requested only after permission and on public-page routes. Our own forwarded events use limited fields such as page path, country, search mode and plan; we do not deliberately send search text, email addresses or company-result payloads to Google. Google can process browser and device information, online identifiers and technical network information. See the Google privacy policy.
Optional analytics is independent from records necessary to apply credits, record purchases, secure accounts and operate the service. Rejecting analytics does not remove those essential records. See the privacy notice for their purposes and retention.
Sign-in and checkout providers
When you visit a WorkOS sign-in page, choose Google or another identity provider, or open Stripe checkout or its billing portal, those providers operate their own pages and may set their own cookies. Their privacy and cookie controls apply there. The VATFind preference controls the optional analytics we load; it does not change another site’s independent settings.
Questions and changes
We will update this inventory when technologies or purposes materially change and seek a new choice where required. Browser settings can also remove or block cookies and site storage.
For legal, privacy or support requests, click here with “VATFind” and the nature of your request in the subject, or use the support centre. Do not send passwords, API keys or full payment-card details.