Answers about privacy
Questions and answers from the Croct community about privacy.
If I send Croct audiences into Clarity replays, does any PII go with it?
I just connected the new Clarity integration so I can filter replays by which experience a visitor saw. Before I roll this out to the team, I want to be…
What customer data does VTEX profile enrichment capture, and can I keep it minimal?
We just added the Croct tag to our VTEX IO store and I am mapping out what the visitor profile actually ends up holding. I would like to keep collection to…
Does Croct rely on any third-party cookies to identify visitors?
we are auditing every script that touches visitor identity right now. Chrome's third-party cookie changes broke our previous tool's setup and I do not want to…
Personalising for anonymous visitors without collecting personal data, realistic?
Our previous personalisation vendor leaned heavily on third-party data enrichment, and it failed our internal audit this spring. I direct marketing at a…
Can we run Croct analytics without collecting personal data?
Good morning. I coordinate data protection at a publisher and I am assessing whether we can operate personalization and experiment analytics strictly on…
We manage consent through GTM consent mode, how does the Croct tag behave?
I own our GTM container and every tag in it is mapped to a consent state, no exceptions. Before I add the Croct tag I need to understand its behavior…
Does Croct set any cookies at all out of the box?
I am completing a vendor privacy assessment and the form requires me to document exactly what is stored client-side, under which name, and for how long. Vague…
Fintech on Strapi, can we personalize without third-party cookies or PII leaving our stack?
Hello. I am an engineer at a fintech and our compliance team reviews every third-party script we add. Two hard requirements: nothing cookie-based from third…
What are ct.client_id and ct.user_token cookies and how long do they live?
I am auditing all cookies on our Next.js site ahead of an internal privacy review and found two set by the Croct proxy: ct.client_id and ct.user_token. Our…
Does personalisation still work now that third-party cookies are going away?
We are a UK insurer, so I have to be cautious about what data any tool actually uses. Our previous personalisation vendor leaned heavily on third-party data…
Tracked page URLs include email addresses from campaign links, can I scrub them?
Marketing sends campaign links like /promo?email=user@example.com. Users land on those URLs. The auto-tracked page events carry the full URL, email included.…
What are the data retention windows on each Croct plan?
I am documenting the data lifecycle of our stack for our internal records of processing activities, in the spirit of Article 30. I was pleased to find that…