Cookie Policy
Last updated: August 2026
Short version: we don’t use cookies.BusinessMCP’s analytics are cookieless by design — pseudonymous, first-party, and never shared with advertisers. We honor Global Privacy Control as a Do-Not-Sell/Share opt-out for our optional ad-platform integrations. This notice explains the small amount of first-party browser storage we do use. See also our Privacy Policy.
No cookies, no cross-site tracking
We do not set cookies, and we do not use third-party advertising or cross-site tracking technologies. Because we don’t drop cookies, there is no cookie wall between you and the product.
First-party browser storage we use
Our tracking script keeps a few values in your browser’s own localStorage / sessionStorage — first-party only, never sent to advertisers:
- mcph_vid — a random, pseudonymous visitor id so a site can measure returning visits (no name, email, or profile attached).
- mcph_rsid — a per-tab session id (sessionStorage; cleared when you close the tab).
- mcph_ref0 — the first referring website of your visit (sessionStorage; cleared when you close the tab), so a site can correctly attribute where you arrived from.
- mcph_consent — remembers your Accept/Decline choice on sites that show a consent notice.
- mcph_ident / mcph_ident_x— set only if you submit your email to a site (so it isn’t captured twice); holds the email/traits you provided.
- mcph_q— a small offline queue so events aren’t lost on a flaky connection.
- as_vid — a legacy visitor-id key read only for backward compatibility.
Global Privacy Control (Do Not Sell or Share)
Our first-party analytics is cookieless and pseudonymous — it is not sold, and not shared with advertisers — so it runs to measure a site’s own audience under legitimate interest. Separately, some customers enable optional ad-platform integrations (server-side conversion measurement or audience matching); that transfer can count as a “sale” or “share” under US state privacy laws. For residents of states that recognize it, we treat a Global Privacy Control(GPC) browser signal as a valid opt-out of that sharing and exclude you from those transfers. Do-Not-Track has no agreed legal standard, so we don’t rely on it; a site can still enable a consent gate or ask us to respect DNT for its own install.
How to clear it
You can clear these keys any time by clearing site data for the website in your browser settings, or by declining on a site’s consent notice. Clearing them simply resets the pseudonymous id.
A note for our customers
If you install BusinessMCP on your own website, you remain the controller for your visitors’ data. Even though our tracker is cookieless, we recommend giving your visitors a clear privacy/cookie notice and, where your jurisdiction requires it, obtaining consent — our script supports a consent gate for exactly this.