Answers about privacy
Questions and answers from the Croct community about privacy.
Personalising for anonymous visitors without collecting personal data, realistic?
Our previous personalisation vendor leaned heavily on third-party data enrichment, and it failed our internal audit this spring. I direct marketing at a…
Can we run Croct analytics without collecting personal data?
Good morning. I coordinate data protection at a publisher and I am assessing whether we can operate personalization and experiment analytics strictly on…
We manage consent through GTM consent mode, how does the Croct tag behave?
I own our GTM container and every tag in it is mapped to a consent state, no exceptions. Before I add the Croct tag I need to understand its behavior…
Does Croct set any cookies at all out of the box?
I am completing a vendor privacy assessment and the form requires me to document exactly what is stored client-side, under which name, and for how long. Vague…
Fintech on Strapi, can we personalize without third-party cookies or PII leaving our stack?
Hello. I am an engineer at a fintech and our compliance team reviews every third-party script we add. Two hard requirements: nothing cookie-based from third…
What are ct.client_id and ct.user_token cookies and how long do they live?
I am auditing all cookies on our Next.js site ahead of an internal privacy review and found two set by the Croct proxy: ct.client_id and ct.user_token. Our…
Does personalisation still work now that third-party cookies are going away?
We are a UK insurer, so I have to be cautious about what data any tool actually uses. Our previous personalisation vendor leaned heavily on third-party data…
Tracked page URLs include email addresses from campaign links, can I scrub them?
Marketing sends campaign links like /promo?email=user@example.com. Users land on those URLs. The auto-tracked page events carry the full URL, email included.…
What are the data retention windows on each Croct plan?
I am documenting the data lifecycle of our stack for our internal records of processing activities, in the spirit of Article 30. I was pleased to find that…
Setting up Croct under LGPD, anything different from the GDPR guidance?
Hi all. I run product ops at a retailer in Brazil. Our legal team mapped our LGPD obligations and most of what I find in this forum about consent gating and…
What does anonymity scope actually change, and is it safe to switch it?
Consolidating two applications into one workspace. Goal: anonymous users recognized across both apps. Found the anonymity scope setting but the docs page I…
Pulling one user's profile and activity out of Croct for our CRM sync
Building an internal enrichment job: when an account manager opens a company record in our CRM, I want to show that user's on-site behavior from Croct next to…