Privacy & data protectionEffective September 8, 2026Version 3.1
Cookie Policy
This Cookie Policy explains the cookies and similar technologies used on workmonitor.ai and in the WorkMonitor application, what each one does, how long it lasts, and how to change your mind.
Read it together with our Global Privacy Policy.
The short version: nothing that is not strictly necessary is set until you say yes, and that now includes advertising. We advertise WorkMonitor on Google and we measure how that advertising performs — which advertisements bring people to us and which lead to a sign-up. That needs cookies, and it needs your permission first.
Analytics and advertising are asked as one question with two answers recorded, so a visitor who accepted measurement under an earlier edition of this page has not thereby agreed to advertising, and is asked again.
What these technologies are
A cookie is a small text file a website asks your browser to store and send back on later visits. A first-party cookie is set by the site you are visiting; a third-party cookie is set by another domain whose content the page loads.
Related technologies include local storage and session storage, which hold data in your browser but are not sent automatically with every request. We use local storage for one important thing, described below.
Analytics, and what it takes to switch it on
We use Google Analytics 4 to understand how the website and the application are used, as two separate properties measuring two different things.
It is off until you accept. If you decline, or simply have not answered, we do not request Google's script at all — and there is only one script, shared by the measurement tag and the advertising tag described in the next section — so no cookie of Google's is written, no identifier is stored, and your visit is not disclosed to Google in any form. This is a real refusal, not a suppressed one.
Measurement and advertising are honoured separately once the script does load. Where analytics is accepted and advertising is not — because your browser sent a Global Privacy Control signal, because you accepted under an earlier edition of this page that never put the advertising question, or because you used the "Do Not Sell or Share My Personal Information" control afterwards — the tag runs for measurement only: advertising storage stays denied, no advertising cookie is written, and no conversion is reported. Those three are the ways that combination arises; the banner itself does not produce it, for the reason given further down.
| Name | Set by | Purpose | Duration |
|---|---|---|---|
| _ga | Google Analytics 4 | Distinguishes one browser from another so that repeat visits are not counted as new ones. | Up to 2 years |
| _ga_<property> | Google Analytics 4 | Holds the state of the current measurement session for the property being measured. | Up to 2 years |
- What is sent: the page viewed and the action taken. Page addresses are rewritten before they leave your browser, so an identifier in a path — a team member, a certificate reference — is replaced with a placeholder, and query strings and fragments from the signed-in application are removed entirely rather than filtered.
- What is never sent: names, email addresses, organization names, and any captured activity or screenshot data.
- Advertising and personalization storage are granted only where you have accepted advertising cookies, and stay denied for everyone else. What the advertising tag does with them is a separate matter, described in the next section rather than folded in here, because it deserves its own answer.
- Analytics is not loaded on our staging environment, and not on the public certificate verifier.
- Google acts as our sub-processor for this and is listed, with what it receives and where, in our Sub-processor list.
Advertising and conversion measurement
We advertise WorkMonitor on Google, and we measure which advertisements led to a sign-up, a demo request or a download. That measurement is the reason for every advertising cookie on this page, and it is the one purpose here that most privacy laws treat as a question of its own — which is why we ask it as a question of its own.
Nothing in this section happens until you accept advertising cookies. Until then the advertising tag is not configured at all: no advertising cookie is written, no click identifier is stored, and no conversion is reported. Declining holds for 180 days, after which we ask again rather than assume the answer has not changed.
What accepting permits, rather than a running commentary on what is switched on today. Advertising consent covers two things: the remarketing described further down, which happens as soon as you accept; and conversion reporting, which is the reason the permission is asked for. A conversion is only ever reported for a conversion action that has been created in our advertising account, and those are created one at a time, so at any given moment some of the actions listed here report and others do not yet. We would rather describe the permission accurately than describe a stream of conversions as though all of it were already flowing, because the second version stops being true in whichever direction the account changes next. Switching one on changes nothing about the data, the cookies or the limits set out here.
When you arrive from one of our advertisements the address carries a click identifier — gclid, gbraid or wbraid, depending on the campaign. Before you have accepted advertising cookies that identifier is held in the page's memory for the length of the visit, which is not storage and needs no permission, and it is discarded if you decline or navigate away. If you accept, it is written to the wm_gclid cookie described above so that a sign-up in the following 90 days can be matched to the advertisement that brought you.
Enhanced conversions, in plain terms, and there are two ways an email address of yours can reach Google as a hash. The first is in your browser: where you have accepted advertising cookies and you then type an email address into our demo request or sign-up form, that address — that one, at the moment you submit that form — is hashed in your own browser with SHA-256, so that Google can match the conversion to an advertisement click without ever receiving the address itself. The digest goes out attached to the conversion report and to nothing else, so where no conversion is reported it is never sent at all, and it never reaches our analytics property. It is only ever the address you just typed, never one we hold for somebody else and never one read out of a link.
The second happens on our servers, and it is the one no amount of watching your own browser would show you, so it is written down here. A purchase usually happens days or weeks after the advertisement was clicked, often in a different browser, where no cookie can still connect the two. So where an organization was created from a visit that carried a click identifier and recorded an advertising consent, and that organization later pays its first invoice, we report that payment once to our advertising account — through a conversion action created in that account, on the same footing as any other, so the paragraph above applies to it too. What that report carries is the click identifier, an internal reference that stops the same payment being reported twice, the amount and currency of the invoice, and a SHA-256 hash of the email address of the person who created the account. We compute that hash ourselves before anything is sent; the address is never sent in the clear, and nothing is sent at all for an organization whose visit recorded no advertising consent.
In neither case is a raw email address sent, in neither case do we build a list from it, and in neither case is the address of a person monitored through the platform hashed or sent. That last limb is absolute: the addresses involved belong to the visitor who filled in our form and to the person who bought the subscription, which is a record of their own dealings with us, and no monitored worker's address can enter it.
Be clear about what accepting means, because we would rather you knew than found out. With advertising storage granted we do build remarketing audiences — groups such as "read our pricing and did not sign up" — and Google may use what the tag sends to select our advertisements for you on other sites. California law calls that sharing personal information for cross-context behavioural advertising; our US State Privacy Rights Notice says so in those words and explains how to opt out. You can withdraw at any time, in the ways described below.
- What is sent from your browser: the kind of page you are on as a coarse bucket, the conversion action taken where one is reported, the click identifier of the advertisement you arrived through, and — only on a form you submitted — a SHA-256 hash of the email address you typed into it.
- And one thing worth naming rather than burying: each advertising page view carries a coarse bucket for the kind of page it was — pricing, comparison, integrations, legal, and nine others. That bucket is what makes a remarketing audience possible, so with advertising accepted you may later be shown our advertisements elsewhere because of the kind of page you read here. It is a bucket and not an address. The page's own address is not sent to the advertising account: not the path, not the query string, not the fragment. The only location that goes with an advertising page view is the site's origin, which is the same for every page on it.
- What is sent from our servers, separately and only after a purchase: the click identifier, an internal account reference, the amount and currency of the first invoice, and a SHA-256 hash of the buyer's email address, as described above.
- What is never sent: names, organization names, raw email addresses, and any captured activity, window title, screenshot or other data belonging to a customer's workforce. Nothing the monitoring software records about anyone reaches Google, through this tag or any other. A person who signs in and browses the application is a website visitor for this purpose like anyone else, and what they chose about cookies governs — but the two are entirely separate paths and they do not meet.
- Where it runs: our public website and the signed-in application, on production hosts only. The advertising tag is not loaded on our staging environment, on the public certificate verifier, or in embedded views.
- Google acts as our sub-processor for this and is listed, with what it receives and where, in our Sub-processor list.
Consent, and changing your mind
Strictly necessary cookies are set without asking, because the site and the sign-in process cannot function without them. Every privacy law we are subject to permits this.
Everything else waits for you. When you first arrive we ask about two things in one question — analytics, and advertising with the conversion measurement that goes with it — and the banner offers one Accept and one Decline, each covering both. Until you answer, both stay off. Consent Mode defaults every storage category to denied before the question is put, so a visitor who never answers is treated as a visitor who declined.
The two answers are recorded separately, in wm_consent and wm_consent_ads, because they are separate permissions in law even where they are asked together. That separation does real work in one case: if you accepted analytics under an earlier edition of this page, you were never asked about advertising, so advertising is treated as refused for you and the banner opens once more to put the question properly. Your analytics choice is not disturbed while that happens, and measurement keeps running on the answer you already gave.
If your browser sends a Global Privacy Control signal, we do not ask about advertising at all. It is recorded as refused, no advertising cookie is written, and the banner tells you that your browser's signal was honoured rather than quietly acting on it. The signal also overrides an advertising acceptance already recorded in that browser: turning it on withdraws that acceptance rather than being ignored because an answer was already on file. Analytics may still be offered, because that signal is an opt-out of sale and sharing rather than a refusal of measurement.
There are two controls in our footer and they do two different things, so it is worth being exact about which is which. Cookie Settings reopens the banner, which asks both permissions together: Accept there grants analytics and advertising, Decline refuses both, and it cannot be used to keep one and drop the other. "Do Not Sell or Share My Personal Information" beside it is the advertising-only control: one click records a refusal of advertising, leaves your analytics decision exactly where it was — including leaving it unanswered if you have not answered it — and asks nothing further.
What a withdrawal actually removes. Withdrawing analytics stops collection immediately and deletes the analytics cookies already set. Refusing advertising stops the conversion measurement immediately, deletes the advertising cookies already set — wm_gclid, and Google's _gcl_au, _gcl_aw, _gcl_dc, _gcl_gb, _gcl_gs and _gac_* cookies — and sends a request to our own servers to delete the click identifier stored against your account, along with any conversion that has been queued and not yet reported. That last part matters: the cookies are the half of a withdrawal you can check for yourself, and the stored record is the half you cannot. Declining takes effect immediately, and the site behaves exactly as it does when you accept.
The attribution cookie is set only when you follow a referral link, and only records a code the partner already published. You can remove it with your browser's controls, which affects nothing except whether that partner is credited.
Changes to this policy
We will update this policy whenever we add, remove or change a cookie, and always before a new non-essential cookie is set. That is a sequencing commitment rather than a formality, and the advertising cookies added in this edition are where it was tested: they are described here in the same release that carries the tag, and none of them can be written until you have accepted a banner that names advertising and conversion measurement in terms.
The effective date at the top shows when the current version took effect, and every change is recorded in our Legal Change Log.
Questions: privacy@workmonitor.ai.