Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Necessary

__hs_opt_out Cookie (HubSpot) – What It Is and Does

__hs_opt_out is a strictly necessary cookie set by HubSpot to remember that a visitor has chosen to opt out of tracking by HubSpot's scripts on a website. It does not track user behavior itself; it only stores the opt-out preference so it can be respected on future visits.

Name
__hs_opt_out
Provider
HubSpot
Category
Necessary
Type
HTTP cookie
Lifetime
13 months
Consent
No, but it must be listed in the cookie policy

What is the __hs_opt_out cookie?

__hs_opt_out is an HTTP cookie used by the HubSpot platform (CRM, marketing automation, live chat, forms) when a website has HubSpot tracking scripts installed (for example from hs-scripts.com or the HubSpot chat widget). It is set by the HubSpot code embedded on the site's own domain, not by an unrelated third party.

It typically appears as soon as the HubSpot script loads on a page and a visitor interacts with HubSpot's built-in consent mechanism (or the site's CMP integration) to decline tracking.

What data it stores

The value is essentially binary: it indicates whether the visitor has explicitly opted out of, or accepted, HubSpot tracking (commonly a "yes"/"no"-style value; the exact format can vary depending on the HubSpot script version). It does not store personally identifiable data such as name or email.

The value is read by HubSpot's scripts on the page to decide whether other HubSpot cookies (analytics or marketing) may be set; it is not sent externally beyond the normal communication HubSpot's scripts make with HubSpot's own infrastructure.

What it is used for

Its main purpose is technical and functional: it lets HubSpot and the website honor a visitor's choice to opt out, preventing other HubSpot analytics or marketing cookies from being set until the preference changes.

For the site owner, this cookie supports consent compliance by acting as the "memory" of a visitor's refusal, similar to a technical consent-state cookie.

Does it require consent?

CookieFix classifies __hs_opt_out as strictly necessary, since its sole role is to remember a privacy preference rather than to track the user for marketing or analytics purposes. Under GDPR and the ePrivacy Directive (transposed in Romania via Law 506/2004), strictly necessary cookies do not require prior consent, but they must still be disclosed in the site's cookie policy.

  • Site owners should list __hs_opt_out among the strictly necessary cookies in their published cookie policy.
  • No separate consent toggle is needed for it, but its role should be clearly explained to visitors.
  • It's worth periodically checking that installed HubSpot scripts aren't also setting other cookies (analytics, advertising) that do require separate consent.

How to block or delete __hs_opt_out

A visitor can delete or block __hs_opt_out through browser settings (Chrome, Firefox, Edge, Safari – per-site cookie management), though doing so may actually undo a previously recorded opt-out choice.

For site owners, while this cookie itself doesn't need to be blocked pending consent, the broader set of HubSpot scripts (including any non-essential tracking components) should be managed properly — a CMP such as CookieFix can automatically prevent non-essential HubSpot scripts from loading until the visitor gives consent.

Frequently asked questions

It's a cookie set by HubSpot to remember that a visitor has chosen to opt out of tracking by HubSpot scripts installed on a website.

No, it's classified as strictly necessary since it only stores a privacy preference, but it must still be listed in the site's cookie policy.

Its typical duration is 13 months, after which the visitor's choice needs to be reconfirmed if they return to the site.

The previous opt-out choice is lost, and HubSpot's scripts may resume standard tracking until the visitor expresses their preference again.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.