What is the __hssc cookie?
__hssc is an HTTP cookie set by the HubSpot platform on websites of businesses using the HubSpot suite (marketing, CRM, live chat, or embedded forms). It appears automatically as soon as the HubSpot tracking script (hs-scripts.js) or a HubSpot widget loads on the page, regardless of whether the visitor interacts with it.
It belongs to the family of HubSpot cookies alongside __hstc and hubspotutk, which work together to identify and track visitors across sessions.
What data it stores
__hssc stores information about the current browsing session: a domain identifier, the current page-view count within that session, and an expiration timestamp. The value is an alphanumeric string made up of several dot-separated segments; the exact format can vary depending on the HubSpot script version.
Data is sent to HubSpot's servers (hubspot.com) to be associated with the visitor profile in the site's HubSpot account.
What it is used for
Its main purpose is to help HubSpot determine whether a visit represents a "new session" or a continuation of an existing one, as part of the platform's analytics and tracking module. Based on this, HubSpot builds reports on site traffic and visitor behavior.
Indirectly, the cookie supports marketing functions such as traffic source attribution, lead scoring, and content personalization for returning visitors.
Does it require consent?
__hssc is classified as a marketing/tracking cookie and is not strictly necessary for the website to function. Under the ePrivacy Directive (transposed in Romania via Law 506/2004) and GDPR, setting it requires the visitor's prior consent, obtained explicitly through a consent banner.
Website operators must list the cookie in their cookie policy, avoid loading it by default, and allow consent to be withdrawn as easily as it was given.
How to block or delete __hssc
Visitors can delete or block __hssc through their browser's cookie settings (per-site cookie management) or by using tracker-blocking extensions.
- Website operators must block the HubSpot script itself until consent is obtained, not merely display a banner above it.
- A CMP such as CookieFix can automatically block the HubSpot tracking script from loading until the visitor accepts the marketing category, preventing the cookie from being set prematurely.
Frequently asked questions
It's a session cookie set by HubSpot to track page-view counts and determine whether a visit is a new session, used for analytics and marketing purposes.
It typically lasts 30 minutes and is renewed with each new page view during the same active session.
Yes, as a marketing/tracking cookie it requires prior consent under GDPR and Law 506/2004, and cannot be set by default.
You need to configure the HubSpot script to load only after consent, using a CMP that automatically blocks marketing-category trackers until acceptance.