WorkMonitor.

Legal and compliance

Every document, published in full

The DPA and its annexes, the sub-processor list, the platform terms and everything incorporated into them. Each at its own address, each dated, each clause numbered. Read them today and forward them to whoever signs off; nothing here waits on a sales call.

Privacy & data protectionEffective September 8, 2026Version 3.1

Cookie Policy

This Cookie Policy explains the cookies and similar technologies used on workmonitor.ai and in the WorkMonitor application, what each one does, how long it lasts, and how to change your mind.

Read it together with our Global Privacy Policy.

The short version: nothing that is not strictly necessary is set until you say yes, and that now includes advertising. We advertise WorkMonitor on Google and we measure how that advertising performs — which advertisements bring people to us and which lead to a sign-up. That needs cookies, and it needs your permission first.

Analytics and advertising are asked as one question with two answers recorded, so a visitor who accepted measurement under an earlier edition of this page has not thereby agreed to advertising, and is asked again.

01

What these technologies are

A cookie is a small text file a website asks your browser to store and send back on later visits. A first-party cookie is set by the site you are visiting; a third-party cookie is set by another domain whose content the page loads.

Related technologies include local storage and session storage, which hold data in your browser but are not sent automatically with every request. We use local storage for one important thing, described below.

02

Cookies we set ourselves

These are first-party cookies, set by us, on our own domains.

First-party cookies
NamePurposeCategoryDuration
wm_consentRecords the cookie choice you made, so we do not ask again on every page. It holds your decision and nothing else. It is set on our registrable domain, so accepting or declining on the website carries into the application.Strictly necessary180 days
wm_consent_adsRecords your decision about advertising and conversion measurement, which is a separate permission in law from the one above and is therefore recorded separately. It holds that decision and nothing else, on our registrable domain, so the answer carries between the website and the application. A visitor who holds the analytics record but not this one was never asked the advertising question: advertising is treated as refused for them until they answer it.Strictly necessary180 days
wm_hero_ctaKeeps the homepage layout you were shown consistent between visits, so a returning visitor does not see the page rearrange itself. It holds one of two values and identifies nobody.Strictly necessary30 days
wm_refRecords the referral or affiliate code of the link you arrived through, so that a partner is credited if you later sign up. It holds only a referral code, which is public by design and printed on the partner's own site. Set only when you arrive through a referral link.AttributionThe referring partner's window, 90 days by default
wm_gclidRecords which advertisement you arrived through, so that a sign-up later in the same window can be attributed to it. It holds one click identifier — the gclid, gbraid or wbraid Google puts in the address — and nothing about you. Set only if you arrive from an advertisement AND you have accepted advertising cookies; before you accept, the identifier is held in the page's memory for that visit and is discarded if you decline. The first advertisement wins: a later click does not overwrite it.Advertising90 days
_gcl_au, _gcl_aw, _gcl_dc, _gcl_gb, _gcl_gs and _gac_*Set by the Google tag on our own domain once you have accepted advertising cookies. They link an advertisement click to a later conversion — a sign-up, a demo request — so that Google can report which campaigns work without us sending it your identity. They are first-party cookies, which is why they are in this table rather than the third-party one, but Google is the party that reads what they enable. None of them is set for a visitor who declined, who was never asked, or whose browser sent a Global Privacy Control signal.AdvertisingUp to 90 days
Sign-in state parameterA short-lived value set when you begin signing in with Google, LinkedIn, GitHub or your company identity provider, checked when you return so the response cannot be forged. Without it, single sign-on cannot be made safe.Strictly necessaryThe sign-in attempt only
03

Analytics, and what it takes to switch it on

We use Google Analytics 4 to understand how the website and the application are used, as two separate properties measuring two different things.

It is off until you accept. If you decline, or simply have not answered, we do not request Google's script at all — and there is only one script, shared by the measurement tag and the advertising tag described in the next section — so no cookie of Google's is written, no identifier is stored, and your visit is not disclosed to Google in any form. This is a real refusal, not a suppressed one.

Measurement and advertising are honoured separately once the script does load. Where analytics is accepted and advertising is not — because your browser sent a Global Privacy Control signal, because you accepted under an earlier edition of this page that never put the advertising question, or because you used the "Do Not Sell or Share My Personal Information" control afterwards — the tag runs for measurement only: advertising storage stays denied, no advertising cookie is written, and no conversion is reported. Those three are the ways that combination arises; the banner itself does not produce it, for the reason given further down.

Analytics cookies, set only after you accept
NameSet byPurposeDuration
_gaGoogle Analytics 4Distinguishes one browser from another so that repeat visits are not counted as new ones.Up to 2 years
_ga_<property>Google Analytics 4Holds the state of the current measurement session for the property being measured.Up to 2 years
  • What is sent: the page viewed and the action taken. Page addresses are rewritten before they leave your browser, so an identifier in a path — a team member, a certificate reference — is replaced with a placeholder, and query strings and fragments from the signed-in application are removed entirely rather than filtered.
  • What is never sent: names, email addresses, organization names, and any captured activity or screenshot data.
  • Advertising and personalization storage are granted only where you have accepted advertising cookies, and stay denied for everyone else. What the advertising tag does with them is a separate matter, described in the next section rather than folded in here, because it deserves its own answer.
  • Analytics is not loaded on our staging environment, and not on the public certificate verifier.
  • Google acts as our sub-processor for this and is listed, with what it receives and where, in our Sub-processor list.
04

Advertising and conversion measurement

We advertise WorkMonitor on Google, and we measure which advertisements led to a sign-up, a demo request or a download. That measurement is the reason for every advertising cookie on this page, and it is the one purpose here that most privacy laws treat as a question of its own — which is why we ask it as a question of its own.

Nothing in this section happens until you accept advertising cookies. Until then the advertising tag is not configured at all: no advertising cookie is written, no click identifier is stored, and no conversion is reported. Declining holds for 180 days, after which we ask again rather than assume the answer has not changed.

What accepting permits, rather than a running commentary on what is switched on today. Advertising consent covers two things: the remarketing described further down, which happens as soon as you accept; and conversion reporting, which is the reason the permission is asked for. A conversion is only ever reported for a conversion action that has been created in our advertising account, and those are created one at a time, so at any given moment some of the actions listed here report and others do not yet. We would rather describe the permission accurately than describe a stream of conversions as though all of it were already flowing, because the second version stops being true in whichever direction the account changes next. Switching one on changes nothing about the data, the cookies or the limits set out here.

When you arrive from one of our advertisements the address carries a click identifier — gclid, gbraid or wbraid, depending on the campaign. Before you have accepted advertising cookies that identifier is held in the page's memory for the length of the visit, which is not storage and needs no permission, and it is discarded if you decline or navigate away. If you accept, it is written to the wm_gclid cookie described above so that a sign-up in the following 90 days can be matched to the advertisement that brought you.

Enhanced conversions, in plain terms, and there are two ways an email address of yours can reach Google as a hash. The first is in your browser: where you have accepted advertising cookies and you then type an email address into our demo request or sign-up form, that address — that one, at the moment you submit that form — is hashed in your own browser with SHA-256, so that Google can match the conversion to an advertisement click without ever receiving the address itself. The digest goes out attached to the conversion report and to nothing else, so where no conversion is reported it is never sent at all, and it never reaches our analytics property. It is only ever the address you just typed, never one we hold for somebody else and never one read out of a link.

The second happens on our servers, and it is the one no amount of watching your own browser would show you, so it is written down here. A purchase usually happens days or weeks after the advertisement was clicked, often in a different browser, where no cookie can still connect the two. So where an organization was created from a visit that carried a click identifier and recorded an advertising consent, and that organization later pays its first invoice, we report that payment once to our advertising account — through a conversion action created in that account, on the same footing as any other, so the paragraph above applies to it too. What that report carries is the click identifier, an internal reference that stops the same payment being reported twice, the amount and currency of the invoice, and a SHA-256 hash of the email address of the person who created the account. We compute that hash ourselves before anything is sent; the address is never sent in the clear, and nothing is sent at all for an organization whose visit recorded no advertising consent.

In neither case is a raw email address sent, in neither case do we build a list from it, and in neither case is the address of a person monitored through the platform hashed or sent. That last limb is absolute: the addresses involved belong to the visitor who filled in our form and to the person who bought the subscription, which is a record of their own dealings with us, and no monitored worker's address can enter it.

Be clear about what accepting means, because we would rather you knew than found out. With advertising storage granted we do build remarketing audiences — groups such as "read our pricing and did not sign up" — and Google may use what the tag sends to select our advertisements for you on other sites. California law calls that sharing personal information for cross-context behavioural advertising; our US State Privacy Rights Notice says so in those words and explains how to opt out. You can withdraw at any time, in the ways described below.

  • What is sent from your browser: the kind of page you are on as a coarse bucket, the conversion action taken where one is reported, the click identifier of the advertisement you arrived through, and — only on a form you submitted — a SHA-256 hash of the email address you typed into it.
  • And one thing worth naming rather than burying: each advertising page view carries a coarse bucket for the kind of page it was — pricing, comparison, integrations, legal, and nine others. That bucket is what makes a remarketing audience possible, so with advertising accepted you may later be shown our advertisements elsewhere because of the kind of page you read here. It is a bucket and not an address. The page's own address is not sent to the advertising account: not the path, not the query string, not the fragment. The only location that goes with an advertising page view is the site's origin, which is the same for every page on it.
  • What is sent from our servers, separately and only after a purchase: the click identifier, an internal account reference, the amount and currency of the first invoice, and a SHA-256 hash of the buyer's email address, as described above.
  • What is never sent: names, organization names, raw email addresses, and any captured activity, window title, screenshot or other data belonging to a customer's workforce. Nothing the monitoring software records about anyone reaches Google, through this tag or any other. A person who signs in and browses the application is a website visitor for this purpose like anyone else, and what they chose about cookies governs — but the two are entirely separate paths and they do not meet.
  • Where it runs: our public website and the signed-in application, on production hosts only. The advertising tag is not loaded on our staging environment, on the public certificate verifier, or in embedded views.
  • Google acts as our sub-processor for this and is listed, with what it receives and where, in our Sub-processor list.
06

Third-party cookies

Some third-party services we use set their own cookies when their content loads.

Third parties that may set cookies
ProviderWhere it loadsWhat it is for
IntercomThe in-product support messenger, and the sign-in, sign-up and password-reset pagesKeeps your support conversation together across visits and identifies you to the support agent when you are signed in. It does not load on the public certificate verifier or in embedded views.
StripeThe hosted checkout and billing pagesFraud prevention and payment security on the page where card details are entered. Card details are handled entirely by Stripe and never reach our systems.
GoogleOnly after you accept. Measurement follows the analytics answer; advertising follows the advertising answerGoogle Analytics 4 and Google Ads conversion measurement, described in the two sections above. Nothing is requested from Google before you accept, and the two purposes are configured separately from the two answers on record: where analytics is granted and advertising is not — under a Global Privacy Control signal, under an older analytics-only acceptance, or after the "Do Not Sell or Share" control has been used — the measurement tag loads and advertising storage stays denied.
  • These providers act as our sub-processors and are listed, with what each is engaged to do and where it processes data, in our Sub-processor list. Their own privacy policies describe the cookies they set: Intercom at https://www.intercom.com/legal/privacy, Stripe at https://stripe.com/privacy and Google at https://business.safety.google/privacy/.
  • Our public API reference page loads its viewer and fonts from a content delivery network. That sends your IP address and browser details to those hosts, but sets no cookie and carries no account data. It is described in the Sub-processor list.
08

How to control cookies in your browser

Every major browser lets you see the cookies stored for a site, delete them, and block new ones. The controls are usually under Settings, then Privacy.

You can also browse in a private or incognito window, which discards cookies and local storage when you close it.

Blocking strictly necessary cookies will stop single sign-on from working, and will mean we ask about analytics on every visit because the record of your answer cannot be kept. Blocking local storage for our domain will stop you from staying signed in. Neither will stop you reading the public parts of our website.

Browser-level signals: we honour the Global Privacy Control signal, and since this edition it does something concrete rather than something notional — it refuses advertising and conversion measurement for you, without asking and without a click. We do not respond to Do Not Track, because no common standard exists for what a site should do with it, and we would rather say so than imply a response we do not make.

09

Changes to this policy

We will update this policy whenever we add, remove or change a cookie, and always before a new non-essential cookie is set. That is a sequencing commitment rather than a formality, and the advertising cookies added in this edition are where it was tested: they are described here in the same release that carries the tag, and none of them can be written until you have accepted a banner that names advertising and conversion measurement in terms.

The effective date at the top shows when the current version took effect, and every change is recorded in our Legal Change Log.

Questions: privacy@workmonitor.ai.

Questions about this document:legal@workmonitor.aiBack to the register