Cookie policy
How SEOH uses cookies and browser storage
This policy explains the cookies, browser storage, consent controls, analytics, session replay, heatmaps, performance, and diagnostic measurement used on SEOH's website.
Last updated August 25, 2026
Plain-language operating terms.
SEOH asks every visitor to choose optional preference, analytics, and marketing storage. PostHog Cloud EU is the active consent-gated analytics processor when the relevant deployment flags are enabled and the visitor accepts analytics. Google Analytics 4 measurement ID G-V7DPZPZJJ7 is reserved but inactive. Mautic browser tracking is inactive unless separate technical and privacy-approval flags are enabled and the visitor accepts marketing storage; Mautic campaign sends remain separately unauthorized. Google advertising signals remain denied under the current consent design.
Related path: AI Search / GEO/AEO Readiness Checklist
What cookies are
Cookies are small browser files that help websites remember settings, measure visits, secure sessions, and understand how pages are used. Similar technologies can include pixels, local storage, and analytics tags.
Current launch state
SEOH shows the consent control on every localized public page. Necessary storage supports the consent decision, compliance-sensitive access, short-lived share handling, session synchronization, authentication where used, and public offline caching. Preference storage covers theme, persona, audience, scope, drafts, planner, and game-display choices. Analytics storage covers SEOH analytics markers and PostHog. Marketing storage is a separate choice and does not activate Mautic unless both deployment approval flags are also enabled. PostHog starts only after analytics consent and its public deployment flags are enabled. Preference, analytics, and marketing categories are denied by default and can be selected independently.
Categories SEOH may use
Necessary storage provides a requested feature, protects a session, records the consent decision, supports a compliance gate, or keeps public offline content available. Preference storage remembers optional visitor choices. After analytics consent, PostHog may measure pageviews, referrers, campaign parameters, registered marketing and product events, autocaptured clicks and form interactions, dead clicks, page exits, scroll and heatmap behavior, Web Vitals, performance attribution, browser errors, network timing, surveys if configured, and session replay on permitted routes. Replay text and inputs are masked; canvas recording, console-log capture, request or response bodies, and headers are disabled. Auth-token query parameters and sensitive payload fields are scrubbed before capture, and IP anonymization is configured at the project boundary. Marketing storage is reserved for separately approved browser tracking. The current design always denies Google advertising storage, advertising user data, and advertising personalization signals.
Cookie table and future updates
The table below lists the current website cookies and browser-storage families, the active PostHog Cloud EU analytics path, the reserved Google Analytics 4 measurement ID, and the fail-closed Mautic browser-tracking path. Non-essential rows apply only when the visitor accepts the matching category and any required deployment flags are enabled. Provider-generated names can vary by browser and provider version; SEOH will update this table before a materially different public use.
Managing cookies
Visitors can accept all, reject all optional storage, or manage preference, analytics, and marketing categories independently on every localized public page. The footer control lets a visitor reopen the choice. Browser settings can also block, delete, or limit cookies, local storage, session storage, and Cache Storage. Clearing storage may reset consent, theme, persona, audience, scope, drafts, planning state, the adult-page gate, authentication, analytics identifiers, or public offline content, but it should not prevent access to the main public website while online. Withdrawing a category stops future site use governed by that category; deletion from a separate provider or backup may require a rights request and remains subject to the Privacy Policy.
Questions and updates
Cookie questions can be sent through the contact page. SEOH may update this policy when analytics, consent, advertising, or measurement tools change.
| Name | Provider | Category | Purpose | Duration | Status |
|---|---|---|---|---|---|
| seoh-consent-v1 | SEOH website | Necessary consent storage | Stores whether the visitor accepted, rejected, or customized optional preference, analytics, and marketing storage. | Until cleared by the visitor. | Active on every localized public page |
| seoh_adult_gate and seoh_adult_gate_expires_at | SEOH website | Necessary compliance storage | Remembers acceptance of the lawful 18+ adult-page gate and its expiry time. | 30 days. | Active when an adult page is opened |
| seoh:pwa-share:v1:* | SEOH website | Necessary functional session storage | Temporarily holds a title, text, or URL shared into the installed web app so the requested share can be opened. | Removed after reading and treated as invalid after 5 minutes; otherwise until the browser session ends. | Used only when the visitor invokes the PWA share feature |
| seoh:pwa-granted-subscription-sync:v1 | SEOH website | Necessary functional session storage | Marks a granted browser-push subscription synchronization attempt so it is not repeated during the same browser session. | Browser session. | Used only where push is enabled and browser permission is already granted |
| seoh-pwa-offline-* | SEOH website service worker | Necessary functional Cache Storage | Caches localized public pages and assets so the installed web app can provide the requested offline experience. | Versioned cache; replaced by a later cache version or removed when the visitor clears site data. | Active where the browser supports the public offline experience |
| Supabase authentication cookies (provider-generated, for example sb-…-auth-token) | Supabase | Necessary authentication storage | Maintains an authenticated account or portal session and supports session refresh and security controls. | Session or provider-configured authentication lifetime; exact names and periods depend on the enabled project. | Used only when an account or portal feature is configured and the visitor signs in |
| seoh-theme and theme | SEOH website | Preference storage | Remembers the visitor's selected light or dark theme and supports the existing compatibility path. | Until cleared by the visitor. | Denied by default; stored only after preference consent |
| seoh-persona | SEOH website | Preference storage | Remembers the visitor's selected persona path after URL navigation. | 180 days. | Denied by default; stored only after preference consent |
| seoh_audience, seoh_audience_contact, and seoh_scope_v1 | SEOH website | Preference storage | Remembers the selected audience, direct-contact path, and scope so the website can keep the visitor's chosen route consistent. | Until cleared by the visitor. | Denied by default; stored only after preference consent |
| seoh_fit_quiz_draft_v1, seoh_direct_brief_draft_v1, seoh_service_lead_draft_v1:*, and seoh_gamification_result_v1 | SEOH website | Preference storage | Saves optional fit-quiz, brief, service-lead, or gamification draft state on the visitor's device. | Up to 90 days or until cleared. | Denied by default; stored only after preference consent |
| seoh_funnel_draft | SEOH website | Preference storage | Saves the optional funnel-planner draft on the visitor's device. | Up to 90 days or until cleared. | Denied by default; stored only after preference consent |
| seoh:funnel-planner-game-visible-v3 | SEOH website | Preference storage | Remembers whether the optional funnel-planner game preview is shown. | Until preference consent is withdrawn or site data is cleared. | Denied by default; stored only after preference consent |
| seoh:analytics-entry-dimensions, seoh:analytics-acquisition-dimensions, seoh:analytics-page-depth, seoh:analytics-visit-profile, and seoh:app-opened:* | SEOH website | Analytics session storage | Holds consented entry, acquisition, depth, visit-profile, and app-opened measurement state for the current browser session. | Browser session. | Denied by default; used only after analytics consent |
| seoh:analytics-visit-number, seoh:analytics-last-visit-at, and seoh:analytics-original-referrer | SEOH website | Analytics local storage | Supports consented visit-frequency, recency, and original-referrer measurement without placing those values in necessary storage. | Until analytics consent is withdrawn or site data is cleared. | Denied by default; used only after analytics consent |
| seoh:analytics-qa-mode and _postHogToolbarParams | SEOH website and PostHog | Analytics QA storage | Supports an explicitly enabled analytics quality-assurance or PostHog toolbar session in development or authorized QA use. | Until disabled, consumed, expired by the tool, or site data is cleared. | Not an ordinary visitor purpose; analytics consent remains required on public pages |
| Google Analytics 4 (G-V7DPZPZJJ7) | Analytics | Reserved for future aggregate website measurement after consent tooling and the GA4 tag are enabled. | Inactive. Google-set duration must be confirmed before enablement. | Not active; advertising signals remain denied under the current design | |
| PostHog Cloud EU provider-generated identifiers and opt-out state | PostHog | Analytics, session replay, heatmaps, errors, and performance diagnostics | Measures consented pageviews, referrers, campaign parameters, registered events, autocaptured clicks and form interactions, dead clicks, page exits, scroll and heatmap behavior, Web Vitals, performance attribution, browser errors, network timing, surveys if configured, and masked session replay on permitted routes. Text and inputs are masked. Canvas recording, console-log capture, headers, and request or response bodies are disabled. Sensitive properties and auth-token query parameters are scrubbed before capture; IP anonymization is configured. Consented device or person identifiers may support profiles and feature behavior. | Analytics events are retained for 12 months and session replays for 30 days. Browser identifiers or an opt-out marker can remain until they expire or the visitor clears storage; consent withdrawal stops future site capture but does not promise immediate deletion of every identifier already held by the browser or provider. | Active only after analytics consent and the consent-gated PostHog flags are enabled |
| Mautic provider-generated browser identifiers | SEOH self-hosted Mautic | Marketing browser tracking | Reserved for separately approved, consented browser engagement tracking. Browser tracking does not itself authorize marketing email or another campaign send. | Inactive. Exact provider-set names and periods must be verified before privacy approval is enabled. | Inactive unless technical enablement, privacy approval, and visitor marketing consent are all present |
Questions can be sent to [email protected].

