Optional means optional
HQ, Access and the Tools public directory keep their optional analytics off until you accept on the relevant site. Tools workspaces do not load analytics. Essential sessions and security still operate. Status, Stripe and hosting control panels have separate provider controls described below.
- ALCO targeted-ad campaigns
- None
- Analytics default
- Off
- Reject button
- Available immediately
- GPC on HQ / Access / Tools
- Honored
Where to manage each system’s choices
This notice covers ALCO HQ, Access, Tools, the ALCO-hosted status page, ALCO hosting control panels and Stripe billing pages, including ALCO-operated legacy pages that link here. There is no single switch that changes browser storage on every service.
- HQ: use the controls above or Privacy choices in this site’s footer. A choice is local to the browser and site where it is saved.
- Access: open your ALCO account and choose Privacy choices in its footer. Its popup controls Access analytics; it does not end an authenticated session.
- Tools: open ALCO Tools and choose Privacy choices in its footer. Optional analytics is limited to its home, category and sitemap directory pages after acceptance; it stays off tool workspaces. Accepting does not authorize uploading tool input.
- Status: ALCO Status uses this site’s privacy choices. Its status indicator periodically requests current check results from ALCO.
- cPanel, WHM and Webmail: use the product’s own settings where offered, plus your browser’s site-data controls. The HQ popup cannot change product analytics or authentication settings.
- Stripe: use the privacy options offered on the Stripe or Link page and its policy. Payment and fraud-prevention technology is separate from ALCO analytics.
Repeat a choice on another device, browser, subdomain or legacy domain as needed. Clearing site data removes saved choices and can sign you out. Use the privacy-request process for access, correction or deletion of personal records; an analytics choice is not a record-deletion request.
Cookies, local storage and similar technologies
A cookie is a small value a website or service asks a browser to store and send with later requests. Local storage is a separate browser feature that keeps a preference on a device but does not automatically send it with every web request. Tags and pixels are code that can make requests to analytics or security providers.
This Policy uses “cookies” as a convenient umbrella term while identifying the actual storage type in the inventory below. Incognito or private-browsing modes, browser restrictions and manual clearing can shorten any stated duration.
Current technology inventory
This table describes ALCO-managed technologies by system as of the last-updated date. Provider-controlled systems are addressed separately below; not every technology runs on every page. Provider behavior can change; we review this inventory and update it when our implementation changes.
| Technology | Provider / storage | Purpose | When used | Typical duration |
|---|---|---|---|---|
alco.analytics-consent.v1 | ALCO HQ · browser local storage | Records granted or denied, policy version, decision time, expiry and source so the Site can honor the choice. | After a choice or a supported Global Privacy Control signal | Up to 180 days, unless changed, cleared or replaced sooner |
alco.access.analytics-consent.v1 | ALCO Access · browser local storage | Remembers the Access analytics choice, version and expiry. | After a choice on Access; an active GPC signal takes precedence | Up to 180 days; local to Access |
alco.tools.analytics-consent.v1 | ALCO Tools · browser local storage | Remembers the Tools choice for optional directory analytics; tool workspaces remain excluded. | After a choice or GPC signal on Tools | Up to 180 days; local to Tools |
| Access account sessions | ALCO Access · authentication cookies and server sessions | Keeps authorized client or staff users signed in, with security and recovery controls. | When an account session is created or renewed; independent of analytics | Client cookie: rolling 30 days; staff cookie: rolling 365 days. Server timeouts, revocation and browser settings can end access earlier. |
| Chat session and security state | ALCO HQ assistant, including its Access and Tools embeds · session cookie and server state | Maintains the requested chat, verifies admission and limits abuse. | When chat is used; independent of analytics | Browser-session cookie; chat admission lasts 30 minutes. Session cleanup is separate from the Access ticket and saved conversation, which follow support-record retention. |
__Host-alco_visit | ALCO HQ · secure, HttpOnly, host-only session cookie | Connects intentionally submitted contact details, pricing enquiries and shared chat exchanges to one Access ticket per visit. It contains an opaque identifier, not contact details or a ticket number. | On contact/pricing forms or when the shared chat opens; independent of analytics | Browser session, subject to browser restoration; server correlation ends after 30 minutes without a saved submission or four hours from the start. Expiry does not delete the ticket. |
| Chat display preferences | ALCO · browser session storage | Remembers a dismissed chat hint and display scaling on the current site. | When the interface is shown or used | Tab/session lifetime, subject to browser session restoration |
_ga_ga_<container-id> | Google Analytics on HQ / Tools directories · first-party cookies | Distinguishes browsers and sessions and measures aggregate Site use. | Only after “Accept analytics” | Typically up to 2 years, subject to browser limits and Google/ALCO configuration |
_clck_clsk | Microsoft Clarity · first-party cookies | Persists a pseudonymous Clarity ID and connects page views into a session. | On HQ, Tools directory pages or the Access public sitemap only after that site’s “Accept analytics”; subject to route restrictions | _clck: typically up to 1 year; _clsk: typically 1 day |
CLID, ANONCHK, MR, MUID, SM | Microsoft Clarity · third-party cookies | Supports Clarity identification, session operation and synchronization across Microsoft domains. Microsoft’s terms and privacy statement govern its independent use. | Only after “Accept analytics,” where the browser and Clarity configuration allow | From a browser session or minutes to about 1 year, depending on the cookie and provider configuration |
| Cloudflare Turnstile | Cloudflare · form security | Checks browser and network signals and validates a short-lived token to prevent automated submissions. | On protected public forms and customer sign-in | Verification tokens expire after five minutes and can be validated once; our widget does not enable pre-clearance |
| Security/challenge cookies, if triggered | Cloudflare · necessary edge security | Routes traffic, identifies malicious or automated requests and remembers successful security challenges. Cookies such as __cf_bm or cf_clearance may be used when the applicable protection is active. | Only when the edge security service needs them | Session or provider-controlled duration, depending on the protection triggered |
The placeholder <container-id> represents the Site’s analytics property suffix. Third-party cookies may be blocked, partitioned or shortened by your browser.
Essential preferences, delivery and security
HQ, Access and Tools use separate local preferences to remember whether analytics were granted or denied. Without it, the choice would have to be requested on every page. The preference record contains no name, email address or advertising identifier. This does not mean authentication or chat records contain no personal information: those serve different purposes.
Normal requests also pass through hosting, content-delivery and security infrastructure. Those systems process IP address, request, device and security information and may use short-lived security cookies when a challenge or anti-bot feature requires one. These functions are used to deliver the Site and protect it from abuse, not to measure marketing performance.
Optional analytics
Google Analytics 4
HQ uses Google Analytics to understand visits, pages, approximate region, device/browser characteristics and navigation in aggregate. Access uses a separate integration on selected sign-in and dashboard entry routes, only after Access consent: it does not run on URLs containing query strings or fragments, omits referrers, sends a generic page title and keeps analytics and advertising storage signaled as denied. Accepting Access analytics therefore does not enable the HQ analytics-cookie configuration on Access. We configure advertising storage, ad-user-data storage and ad-personalization storage as denied. We do not send form content to Google Analytics.
Tools has its own Google Analytics and Clarity properties. Only the home page, five category directories and sitemap are eligible, and only after Tools consent. Tool pages, pages containing a tool workspace and URLs with query strings or fragments do not load these providers. Eligible events use a generic page title and no referrer. Tools sets the analytics cookie domain to tools.alcohq.com and denies advertising storage and personalization.
Microsoft Clarity
Clarity produces interaction analytics, heatmaps and session replays from page structure and actions such as clicks, scrolling and navigation. ALCO uses it to find usability problems. Tools enables it only on eligible directory pages after consent and instructs it to mask page text; individual tool inputs are outside that integration. HQ does not load Clarity on contact or general-interest careers form pages. Access loads optional Clarity only on its public sitemap at /sitemap.php, after Access analytics consent, with page-text masking requested and query-string or fragment URLs excluded. Clarity is not loaded on sign-in forms or private account pages. Access’s separate, limited Google Analytics events do not send ticket text, attachments or account-page content. Visitors should still avoid placing sensitive information in a public form unless specifically asked.
Microsoft and ALCO act independently for their respective processing under Clarity’s terms. Microsoft states that Clarity data may be used to provide and improve Microsoft products and services and for purposes described in the Microsoft Privacy Statement, which can include advertising-related uses. ALCO does not use Clarity to run targeted ads. Clarity remains blocked unless you consent, and advertising storage is signaled as denied.
Microsoft generally retains Clarity playback data for 30 days. Click and heatmap data, labeled or selected sessions and related aggregate information may be retained for up to nine months under its published schedule.
Cloudflare Turnstile on forms
Protected public forms and customer sign-in use Cloudflare Turnstile to help prevent automated abuse. Cloudflare processes technical signals such as IP address, browser information, TLS characteristics and the site origin. ALCO validates the resulting short-lived verification token before accepting a protected request.
This security control operates separately from optional analytics. Read Cloudflare’s Turnstile Privacy Addendum for its processing practices. Our Turnstile widget has pre-clearance disabled; separate edge protections may still use security cookies as described above.
Video embeds and provider-controlled systems
YouTube training content
Published videos can load a thumbnail from Google/YouTube and a privacy-enhanced YouTube player. The image or player may contact Google when loaded, and playback can use additional storage or identifiers. These requests are separate from ALCO’s Google Analytics choice. The video-coming-soon example does not load a player. See Google’s privacy notice; avoid opening the embedded content if you do not want it to contact the provider.
ALCO service status
The status page and indicators are hosted by ALCO. Their required refresh requests retrieve public service-check results. The status system adds no separate advertising or analytics provider; any optional site analytics follows the ALCO HQ choices above.
cPanel, WHM and Webmail
Control panels use their own session, login, request-verification and preference storage. Names and lifetimes depend on the product, version, administrator settings and session. Product analytics or enabled extensions can use additional technology under their own notices. Manage optional product settings where offered; blocking necessary session storage can prevent login or administration. See WebPros/cPanel’s notice.
Stripe payment systems
Stripe-hosted payment and billing pages use technology for sessions, payment functionality, fraud prevention and other purposes explained in Stripe’s Cookie Policy. The cookies and their lifetimes depend on the Stripe feature and provider settings; consult its current inventory rather than assuming all Stripe or Link technologies are present on every ALCO visit. Blocking necessary payment technology can prevent a transaction.
ALCO cannot clear cookies on another provider’s domain from this page. Provider notices describe their own durations, purposes and controls; browser limits and provider settings can change the actual behavior.
How to reject or withdraw analytics consent
For HQ, use the controls at the top of this page or the Privacy choices link in this footer. For Access and Tools, use their own footers as explained above. Acceptance and rejection are both immediate. If you withdraw after HQ analytics has loaded, HQ sends denied consent signals, clears reachable first-party analytics cookies and reloads without requesting the tags again. Access disables its entry-route analytics and removes reachable analytics cookies without reloading account work; its public sitemap reloads if Clarity had already loaded; Tools disables its directory analytics, removes reachable analytics cookies and reloads an eligible directory page if analytics had already loaded.
Clearing all cookies or site data in your browser also removes the saved choice. The banner will return so you can choose again. An ALCO analytics decision applies only to the site, browser and device where it was made and expires after 180 days so that site can request a fresh choice. Withdrawing consent does not automatically delete previously collected records; see the Privacy Policy for deletion requests.
Browser controls and privacy signals
Most browsers let you view, block or delete cookies and local storage. Blocking essential storage does not prevent you from reading public content, but the Site may be unable to remember a preference or complete a protected form.
If the browser sends a supported Global Privacy Control (GPC) signal, HQ, Access and Tools treat it as a request to decline their optional analytics. Provider-controlled systems have their own practices. A GPC denial takes precedence over a previously stored analytics grant while the signal remains enabled.
“Do Not Track” is not a uniform or widely implemented standard. ALCO does not use it as a separate signal, but HQ, Access and Tools directory analytics remains off unless consent is granted, and HQ, Access and Tools honor GPC as described above.
Changes and contact
We may update this Policy when the Site, our vendors or applicable requirements change. The last-updated date identifies the current inventory. If a change requires a fresh consent decision, the Site will ask again rather than silently carrying an older choice forward.
Ask ALCO
For a question about a particular cookie, browser request or analytics choice, contact us and include the browser and page involved.