Privacy & consent
What Klickbee Tracking collects and stores, how visitors are identified without cookies, how long data is kept, and how to wait for consent.
Klickbee Tracking doesn't set any cookie on your visitors' browsers and never stores a visitor's raw IP address. This page explains exactly what is collected, what is stored, what the tracker does and doesn't do about consent, and what that means for your own site.
Your obligations stay yours
Whether you need your visitors' consent depends on your site, your country and what you configure. As the site owner, you are responsible for obtaining any consent the law requires. This page describes how the product behaves so you can make that call. It is not legal advice.
Cookies and visitor identifiers
The tracker sets no cookies. It uses the browser's own storage for three values:
| Where | Name | What it holds |
|---|---|---|
| Local storage | kb_anon_id | A random identifier for the visitor. It stays until the visitor clears their browser data, or until you call reset(). |
| Session storage | kb_session_id | A random identifier for one browser tab. A new tab starts a new session. |
| Local storage | kb_consent | granted or denied. Only used when you turn on consent mode (see below). |
If storage isn't available (private browsing, blocked storage), the tracker falls back to identifiers kept in memory only, so nothing is written to the device.
Keep in mind that third-party pixels you add (Meta, Google Ads, LinkedIn or custom code) may set their own cookies. That is outside Klickbee's own tracker. See "Ad pixels and consent" below.
The dashboard itself uses cookies only for you, the signed-in user: to keep you signed in, and to remember which site you were looking at.
What is collected
For each batch of events, the tracker sends:
- The page URL and path, the referrer and the page title.
- The browser's user-agent, language, and screen width and height.
- The anonymous visitor id and the session id.
- The tracker version.
- The visitor's first-touch acquisition data:
utm_source,utm_medium,utm_campaign,utm_term,utm_content, the landing path and the referrer. Ad click ids (gclid,gbraid,wbraid,fbclid,msclkid) are used to classify the visit as paid traffic, and the Google click id (gclid,gbraidorwbraid) is also stored, to match Google Ads conversions.
Depending on what you turn on:
- Click autocapture: for each click, the element's CSS selector, tag, visible
text (up to 255 characters),
aria-label, role, test id and link target, plus the click position and the page and window size. - Scroll depth and attention time: always collected while tracking is on. One scroll summary is sent each time a visitor leaves a page.
- Session replay: a recording of the page as the visitor sees it. See the masking section below.
- JavaScript errors: error messages, shortened to 255 characters.
- Your own events and identify calls (see the sections below).
On the server, Klickbee adds the visitor's country, region, city, latitude and longitude, derived from the request's IP address and stored on the session.
IP addresses
The raw IP address is never stored. Before the location lookup, the host part of the address is zeroed (the last number of an IPv4 address; everything past the network prefix of an IPv6 address). The lookup then runs against a MaxMind database bundled with the product, and only the coarse location is kept. A consequence is that the city is approximate.
Consent: what the tracker does
There are three ways to control what happens before a visitor agrees.
Consent mode (npm package only)
Set requireConsent: true in the npm package. Until you call grantConsent(),
the tracker does nothing: no capture, no replay, no autocapture, no timers,
no network request. The visitor's choice is stored in kb_consent and picked up
automatically on their next page load. revokeConsent() stops tracking and
replay at once and empties anything still waiting to be sent.
<TrackingProvider
pathname={pathname}
config={{
projectKey: "pk_xxx",
apiHost: "https://tracking.klickbee.com",
requireConsent: true,
}}
>
{children}
</TrackingProvider>Then, from your consent banner, using the client from useTracking():
const tracking = useTracking();
<button onClick={() => tracking.grantConsent()}>Accept</button>
<button onClick={() => tracking.revokeConsent()}>Decline</button>The script tag cannot gate on consent
The script tag has no consent setting. window.klickbee.grantConsent() and
revokeConsent() exist, but they have nothing to gate: the script starts
tracking as soon as it loads. If you use the script tag and need consent, add
the script to your page only after the visitor has agreed, or use the npm
package with requireConsent: true.
To add the script after consent, create it from your consent banner's code:
function loadKlickbee() {
const s = document.createElement("script");
s.src = "https://tracking.klickbee.com/t.js";
s.dataset.key = "pk_xxx";
s.defer = true;
document.head.appendChild(s);
}
// call loadKlickbee() once the visitor acceptsDo Not Track
By default the tracker respects the browser's Do Not Track signal: when it is
on, the tracker does nothing at all, with the script tag and with the npm package
alike. The npm package lets you override this with respectDoNotTrack: false; the
script tag doesn't.
Ad pixels and consent
Ad pixels do not wait for consent
Meta, Google Ads, LinkedIn and custom pixels you configure on the Pixels
page load as soon as the tracker starts. They are not held back by
requireConsent, and they are not stopped by Do Not Track. Consent mode only
gates Klickbee's own events, replay and browser-side conversion calls.
What follows from that, in practice:
- If you don't use ad pixels, you can ignore this: the tracker alone sets no cookie.
- If you use ad pixels and need consent for them, don't let the tracker start before consent. With the script tag, insert it after the visitor agrees (as above). With the npm package, only mount the provider after consent, or leave the pixel off in the dashboard until you're ready. You can switch a pixel on or off from the Enabled checkbox on the Pixels page without redeploying.
- Your own consent banner remains the right place to decide. Klickbee gives you the building blocks, not a consent banner.
Session replay and masking
Replay records what the visitor sees so you can watch the session later. Its defaults protect typed data:
- All typed input values are masked. Password, email and phone fields are always masked.
- Ordinary page text is not masked. If a page shows personal data (an account page, an order summary), mark it yourself.
- Images, fonts and canvas content aren't captured; at playback they load from your live site.
Add one of these attributes (or the matching class) to any element:
| Attribute | Class | Effect |
|---|---|---|
data-kb-block | kb-block | The element is replaced by a placeholder. |
data-kb-mask | kb-mask | The element's text is masked. |
data-kb-ignore | kb-ignore | Changes inside the element aren't recorded. |
<div data-kb-block>Everything in here is hidden from recordings.</div>Recording pauses after 5 minutes without activity, and a single session records
at most 30 minutes. To turn replay off entirely, use data-replay="false" on
the script tag, or replay: false in the npm package.
Identifying visitors
By default visitors are anonymous. If you call identify, you link a visitor to
an identifier of your own, for example your user id:
window.klickbee.identify("user_1234", { plan: "pro" });The identifier (255 characters at most) is attached to every following batch of
that visitor and appears in the dashboard next to the visitor id on the session
page and in the live feed. Call reset() when the user logs out: it forgets the
identifier and gives the browser a new anonymous id.
Traits are stored exactly as you send them
The identifier and the traits you pass are stored as given, in the visitor record and in the identify event. They are not hashed or masked. Prefer an internal id over an email address, and don't pass anything sensitive as a trait.
One exception exists on purpose: when a goal sends a conversion to Meta or Google Ads from Klickbee's servers, an email found in the traits (or used as the identifier) is trimmed, lower-cased and sent to the ad platform only as a SHA-256 hash, never in clear text. See Conversions.
How long data is kept
A daily clean-up removes old data. These are the periods the clean-up uses:
| Data | Free | Pro |
|---|---|---|
| Events | 180 days | 180 days |
| Session replays | 7 days | 60 days |
When you delete a site, everything tracked for it is deleted with it. Data is also kept when a site goes over its quota or is suspended: it is only removed by the normal clean-up. See Billing.
AI features
If you use the Pro AI features, the content needed to produce the result is sent to Anthropic's Claude to generate it:
- AI summary of a session: the session's journey (pages and time spent), event names and types, the browser, and the city and country.
- Suggested goals: a brief of your site: top pages and events, channel mix, most-clicked labels, and text visible on a recent recording of your top page.
- Suggest variations (Experiments, Page A/B): a brief of one page: its top clicks, how far visitors scroll and where they spend time, a sample of its visible text, and engagement figures.
These run only when you click the button, and only on Pro sites.