This page describes how Default works. It is not legal advice. How you classify each item,
and which laws apply to your visitors, is a decision for your own privacy or legal team.
At a glance
The Pixel sets its cookies on your own domain (for example
.yourcompany.com), so they are
first-party cookies. Items marked sessionStorage live only in that browser tab and are gone
when the tab closes.
Strictly necessary
These make the thing the visitor asked for work. Without them, a visitor who submits a form would not see the scheduler.Form capture: no storage needed
When a visitor fills in your form and selects submit, they choose to send you that information so you can respond. Default captures the submission, runs your workflow, and uses what they typed to show them the right scheduler with their details filled in. This needs no cookie. It works the same whether the visitor accepted or declined tracking.The scheduler after a form
Default only writes this when your workflow opens the scheduler on another page, for example
after your form sends the visitor to a thank-you page (Redirect to scheduler page on the
Display Scheduler step). It holds the link to the scheduler the visitor is about to see,
nothing about the visitor. When the scheduler opens on the same page as the form, nothing is
stored. See How Default books a meeting from a form submission.
Remembering the visitor’s consent choice
It holds only the choice itself: whether analytics and marketing are allowed. Default writes it
only after your consent banner tells Default the visitor’s answer.
Analytics
These let Default recognize the same visitor across pages and visits. They are optional.
What they power:
- Page views and sessions for your website, so you can see which pages a lead read before they submitted.
- The Account Signal in Reveal: the real-time lookup of the company behind a visit. It runs from the start of a session, so it cannot run without analytics consent.
Marketing
These identify visitors who have not filled in a form. They are optional. The People Signal in Reveal uses Default’s partner Vector to identify a visitor as a person, by name, title, and email, so your team can follow up with people who showed interest but never filled in a form. Results arrive in batches, about every 30 minutes, and can start a workflow. The Pixel loads Vector’s script on every page where it is installed, as long as Vector is on under Settings → Integrations. See Vector.
When a visitor declines marketing before Vector loads, the Pixel does not load it, so none of
these are set. If a visitor withdraws marketing consent after Vector has already loaded, the
Pixel stops loading Vector on later pages, but it cannot remove the script from the open page or
delete the cookies Vector already set. Send the visitor’s answer before tracking starts (see
Recommended setup) so this does not happen.
If you don’t use the People Signal, turn Vector off and the Pixel stops loading it for every
visitor.
The scheduler page
The scheduler itself is a Default page atbook.default.com. When it opens on your site, it
shows inside a frame, so what it stores belongs to Default’s domain, not yours. It stores these
items itself, and today they don’t follow the choice your banner passes to the Pixel.
When the scheduler opens inside your site, most browsers block its analytics cookies, because
they belong to another domain. The scheduler then keeps the same IDs in the browser’s storage
for that frame instead. A visitor who opens a booking link directly, for example from an email,
gets the cookies as listed.
Recommended setup
1
Install the Pixel outside your consent gate
Load the Pixel on every page, for every visitor. Don’t wait for consent before loading it.
Your banner controls what the Pixel tracks; it should not control whether the Pixel loads. If
the Pixel only loads after consent, a visitor who declines, or ignores the banner, submits your
form and never sees the scheduler.
2
Send a no before tracking starts, where you need opt-in
Out of the box, the Pixel allows analytics and marketing until it hears otherwise. If your
visitors must opt in first (for example under GDPR), tell the Pixel “no” on the visitor’s first
page, right after the install snippet and before they have made a choice. A call made before the
Pixel finishes loading is applied before it starts any tracking:The check means you only send it while no usable choice is stored. A damaged or outdated
_dflt_consent cookie counts as no choice, the same way the Pixel treats it. Don’t send “no” on every page load
while your banner is still loading; that clears the visitor’s ID on every page. Your forms and
the scheduler keep working while the answer is “no”.3
Tell Default what the visitor chose
When the visitor answers your banner, pass the answer on:Default remembers it in
_dflt_consent for later pages and visits. See
Wiring up your consent banner.4
Treat a browser privacy signal as a no
Some browsers, such as Brave, send Global Privacy Control (a “do not sell or share my data”
signal) by default. If your site honors it, keep loading the Pixel and send a no for both
categories:The visitor’s form submission and the scheduler keep working. On your pages, the Pixel stores
no visitor ID, does not run the fingerprint, and does not load Vector. The scheduler page itself
still stores its own items today (see The scheduler page). Don’t skip the
Pixel for these visitors: that also stops the scheduler. Send this before tracking starts, the
same way as the opt-in “no” above.
5
Classify the items in your cookie tool
Add the items on this page to your consent tool under the categories in
At a glance. Most tools, such as Cookiebot and OneTrust, let you add an item
by name and pick its category.
6
Mention Default in your privacy policy
Name Default as the service that captures your form submissions and runs your scheduler. If you
use the People Signal, also say that a partner identifies visitors on your site.