Cookie Policy
Version 1.0 · Effective August 2026 · GeoScript, Inc.
This Cookie Policy explains how GeoScript, Inc. ("GeoScript," "we," "our," or "us") uses cookies and similar tracking technologies on geoscript.ai and the GeoScript platform (collectively, the "Site").
This Policy should be read alongside our Privacy Policy, which provides broader context on how we collect and use personal data. If you have questions, contact us at hello@geoscript.ai.
1. What Are Cookies?
Cookies are small text files placed on your device (computer, phone, or tablet) by a website when you visit it. They allow the site to recognize your browser on subsequent visits and remember certain information about your session or preferences.
Cookies set by the website you are visiting are called first-party cookies. Cookies set by third parties (e.g., an analytics or advertising provider) are called third-party cookies.
Cookies can be session cookies (deleted when you close your browser) or persistent cookies (remain on your device for a set period or until you delete them).
We also use similar technologies such as pixel tags (web beacons), which are tiny invisible images embedded in pages or emails used to track activity and measure effectiveness of marketing campaigns. These are described in Section 4.
2. Why We Use Cookies
GeoScript uses cookies for three purposes:
Strictly Necessary
These cookies are required for the Site to function. They enable authentication, maintain your session, and enforce access controls (e.g., the site password gate and data room gate). Without these cookies, you cannot log in or use the platform. These cookies cannot be disabled — they are set in direct response to your actions (like entering a password or logging in).
Analytics
These cookies help us understand how visitors use the Site — which pages are visited, how long sessions last, and where errors occur. The data is aggregated and used to improve the Site experience. These cookies require your consent before being set (except for logged-in users where analytics are strictly necessary for service delivery).
Marketing and Retargeting
These cookies are set by third-party advertising platforms (Meta, LinkedIn, Google) and allow us to show relevant ads to visitors who have previously visited the Site. They track whether you arrived from an ad and measure campaign effectiveness. These cookies require your explicit consent before being set. They are not active until a consent banner is in place and you have opted in.
3. Cookies We Set on geoscript.ai
The tables below list every cookie currently in use on geoscript.ai, organized by category. We update this list whenever we add or remove cookies.
Strictly Necessary Cookies
— cannot be disabled| Cookie Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
| geoscript_access | GeoScript (first-party) | Stores the site access token after a visitor enters the site password. Required to access any page on geoscript.ai during the pre-launch password-protected phase. Set as httpOnly, Secure, SameSite=Strict. | Persistent | 30 days |
| geoscript_data_room | GeoScript (first-party) | Stores the data room access token after an investor enters the data room password. Required to access /data-room. Set as httpOnly, Secure, SameSite=Strict. | Persistent | 7 days |
| sb-[project]-auth-token | GeoScript / Supabase (first-party) | Stores the authenticated user's session token after login. Required to maintain your logged-in session and access protected dashboard features. Set by Supabase Auth. httpOnly, Secure. | Persistent | 1 hour (access token); up to 7 days with refresh token rotation |
| sb-[project]-auth-token-code-verifier | GeoScript / Supabase (first-party) | PKCE code verifier used during the OAuth authentication flow. Discarded after authentication completes. | Session | Session (deleted on auth completion) |
| __Host-next-auth.csrf-token | GeoScript (first-party) | CSRF protection token for form submissions. Prevents cross-site request forgery attacks. | Session | Session |
Analytics Cookies
— requires consent| Cookie Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
| _ga | Google Analytics (third-party) | Distinguishes unique users by assigning a randomly generated number as a client identifier. Used to calculate visit, session, and campaign data for site analytics reports. IP anonymization enabled. | Persistent | 2 years |
| _ga_[ID] | Google Analytics (third-party) | Stores and counts page views for Google Analytics 4 (GA4). Contains session state. | Persistent | 2 years |
| _gid | Google Analytics (third-party) | Stores and updates a unique value for each page visited. Used to distinguish users. | Persistent | 24 hours |
Analytics cookies are not set until you consent via the cookie banner. If analytics are not yet active on geoscript.ai, these cookies will not be present on your device.
Marketing and Retargeting Cookies
— requires explicit consent| Cookie Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
| _fbp | Meta (Facebook Pixel, third-party) | Used by Meta to deliver, measure, and improve the relevance of ads. Identifies browsers for retargeting across Meta platforms (Facebook, Instagram). Set on geoscript.ai when the Meta Pixel fires. | Persistent | 90 days |
| _fbc | Meta (Facebook Pixel, third-party) | Stores the Facebook click identifier (_fbc) when a visitor arrives from a Facebook ad. Used to attribute ad clicks to conversions. | Persistent | 90 days |
| li_fat_id | LinkedIn (third-party) | Used by the LinkedIn Insight Tag for conversion tracking, retargeting, and analytics for LinkedIn ad campaigns targeting geoscript.ai visitors. | Persistent | 30 days |
| AnalyticsSyncHistory | LinkedIn (third-party) | Used to store information about the time a sync with the lms_analytics cookie took place. | Persistent | 30 days |
| _gcl_au | Google Ads (third-party) | Used by Google Ads to store and track conversions. Associates ad clicks with visits to geoscript.ai pages that result in a conversion (signup, form submission). | Persistent | 90 days |
| _uetsid / _uetvid | Microsoft Advertising (third-party) | Used for conversion tracking and remarketing on Microsoft/Bing Ads. Planned for future use; not yet active. | Persistent | 1 day / 16 days |
Marketing cookies are not set until you explicitly consent. Pixels listed as "planned" are not yet active on geoscript.ai and will not be deployed before the consent banner is live. We will update this table when each pixel goes live.
4. Pixel Tags and Similar Technologies
In addition to cookies, we use pixel tags (also called web beacons or tracking pixels). These are tiny 1×1 images embedded in pages or marketing emails that fire a request to a third-party server when loaded, confirming a page view or email open.
Pixel tags we use or plan to use:
- Meta Pixel — fires on key pages (homepage, for-agencies, pricing, signup confirmation) to build retargeting audiences on Meta platforms. Requires consent; blocked until consent is given.
- LinkedIn Insight Tag — fires site-wide to build retargeting audiences on LinkedIn. Also enables demographic data on site visitors (job title, company, industry) in aggregate. Requires consent.
- Google Ads conversion tag — fires on signup confirmation page to attribute conversions to Google Ad campaigns. Requires consent.
Pixel tags are linked to the marketing cookies listed in Section 3. Declining marketing cookies prevents pixel tags from firing and from setting cookies on your device.
GeoScript marketing emails may include a tracking pixel to confirm email delivery and record whether you opened the email. You can prevent this by disabling automatic image loading in your email client.
5. Consent and the Cookie Banner
On your first visit to geoscript.ai, a cookie consent banner will ask you to accept or decline non-essential cookies. Here is how consent works:
- Strictly necessary cookies are set immediately without consent — they are required for the Site to function.
- Analytics and marketing cookies are blocked until you actively consent. No pre-ticked boxes. No implied consent from continuing to use the site.
- Granular control: you can accept all, reject all, or accept specific categories (analytics only, marketing only).
- Withdrawing consent: you can change your preferences at any time by clicking "Cookie Preferences" in the footer. Changing preferences does not delete cookies already set, but stops new ones from being placed.
- Your consent is stored in a first-party cookie (
gs_cookie_consent) so the banner does not reappear on every visit. This cookie does not contain any personal data — only your consent preferences.
EU/EEA, UK, and Switzerland residents
We comply with the EU ePrivacy Directive and GDPR consent requirements. Non-essential cookies require freely given, specific, informed, and unambiguous consent. We do not use dark patterns (e.g., making "Reject" harder to click than "Accept") in our consent interface.
6. How to Manage and Delete Cookies
6.1 Via Our Cookie Banner
The easiest way to manage your preferences is the cookie consent banner or the "Cookie Preferences" link in the footer. This lets you change your choices at any time without affecting strictly necessary cookies.
6.2 Via Your Browser
All major browsers let you view, manage, and delete cookies. Here are direct links to instructions for each:
Note: Deleting or blocking strictly necessary cookies (such asgeoscript_accessorsb-[project]-auth-token) will log you out of the platform and require you to sign in again.
6.3 Opt Out of Third-Party Advertising Networks
You can opt out of targeted advertising from specific ad networks:
- Meta: Facebook Ad Settings
- LinkedIn: LinkedIn Retargeting Opt-Out
- Google: Google Ads Settings
- Industry-wide opt-out (US): Digital Advertising Alliance (DAA)
- Industry-wide opt-out (EU): Your Online Choices (EDAA)
Opting out of ad networks prevents targeted ads but does not prevent all advertising — you will still see generic, non-targeted ads.
7. Does the GeoScript Script Set Cookies on Other Websites?
No. The GeoScript JavaScript tracking Script installed on customer websites does not set any persistent cookies on those websites' visitors. It does not participate in cross-site tracking and does not plant advertising identifiers.
The Script operates by passively observing server-side and session-level signals (AI crawler bot user-agents, HTTP referrer headers from AI engine result pages) and reporting these events back to GeoScript servers. No cookie is placed on the website visitor's device as a result of the Script running.
For full details on what the Script collects and how it works, see the Data Policy.
8. Updates to This Policy
We update this Cookie Policy whenever we add, remove, or change any cookie or tracking technology on geoscript.ai. Significant changes will be flagged in the consent banner on your next visit. The "Effective" date at the top of this page reflects when the current version took effect.
If we add a new category of non-essential cookies (e.g., a new analytics provider), we will re-ask for consent for that category before setting those cookies.
9. Contact
Questions about this Cookie Policy or our cookie practices:
GeoScript, Inc.
hello@geoscript.ai
Related documents: Privacy Policy · Data Policy · Terms of Service
This Cookie Policy was last updated in August 2026. Prior versions are available upon request.