Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Marketing

__hssrc Cookie (HubSpot) – What It Is and How to Manage It

__hssrc is a session cookie set by HubSpot to determine whether a visitor has started a new browsing session. It works alongside other HubSpot cookies (such as __hstc and __hssc) to track on-site behavior for marketing purposes.

Name
__hssrc
Provider
HubSpot
Category
Marketing
Type
HTTP cookie
Lifetime
Session
Consent
Yes, before it is set (GDPR / ePrivacy)

What is the __hssrc cookie?

__hssrc is an HTTP cookie set by the HubSpot platform, which many websites use for marketing, contact forms, live chat, and sales automation. It typically appears as soon as a site loads the HubSpot tracking code or an embedded HubSpot widget, such as a form, chat tool, or call-to-action button.

It is not set directly by the site owner but by HubSpot's own script, which runs in the background on pages where it is installed.

What data it stores

__hssrc does not directly store personally identifiable information. Its value is usually a simple flag (e.g. "1") used only as a technical marker to signal whether the browser was closed and reopened, helping HubSpot decide if a new session has started.

The data captured through this cookie, together with other cookies in the HubSpot family, is sent to HubSpot's servers for processing and linked to the visitor's activity on the site.

What it is used for

The main purpose of __hssrc is technical: it helps HubSpot distinguish between a visitor's browsing sessions, information later used to correctly interpret other HubSpot tracking cookies (such as __hstc, which counts visits).

For the website using it, this information feeds into a behavioral profile of the visitor — how many sessions they have, how often they return — data that supports marketing reports, lead scoring, and retargeting campaigns within HubSpot.

Does it require consent?

CookieFix classifies __hssrc under the marketing category, since it belongs to HubSpot's suite of tracking cookies used for behavioral analysis and, indirectly, for marketing and sales activities.

  • Under GDPR and the ePrivacy Directive (2002/58/EC, transposed in Romania via Law 506/2004), marketing-category cookies require the visitor's prior consent before being placed.
  • Site owners must disclose this cookie in their cookie policy and ensure the HubSpot script does not load before the visitor gives explicit consent.

How to block or delete __hssrc

Visitors can manually delete or block __hssrc through their browser settings (Chrome, Firefox, Edge, Safari — per-site cookie management), or use private/incognito browsing, which discards cookies once the session ends.

For site owners, the correct approach is to automatically block the HubSpot script until consent is given. A CMP like CookieFix can do this automatically, preventing the HubSpot tracking code — and therefore __hssrc — from loading until the visitor accepts the marketing category.

Frequently asked questions

It flags whether the visitor's browser was reopened, helping HubSpot determine the start of a new browsing session.

Not directly — its value is a simple technical marker, but it is part of a set of cookies that together can contribute to identifying a visitor's behavior.

Yes, since it is classified as marketing, it requires the visitor's prior consent under GDPR and the ePrivacy rules.

It is a session cookie — it expires automatically when the browser is closed, with no fixed duration in days or months.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.