What is the __hstc cookie?
__hstc is the main tracking cookie used by HubSpot, a marketing, sales, and CRM platform many websites rely on for marketing automation, forms, and traffic analytics. It is set by the HubSpot tracking script (hs-scripts.com / HubSpot Analytics) once that script is installed on a site.
The cookie is created the first time a user visits a page that has the HubSpot tracking code installed, regardless of whether the visitor fills out any form. It is considered a first-party cookie, set on the visited site's own domain.
What data it stores
__hstc stores a unique domain identifier, a visitor identifier (hub ID), and timestamps for the first visit, the previous visit, and the current visit. The value is a series of numbers separated by dots, generated and interpreted by HubSpot's systems.
Data collected through this cookie is sent to HubSpot's servers and may later be linked to other information in the site's HubSpot account (for example, CRM contact records), if the visitor submits contact details through a form.
What it is used for
For the provider (HubSpot) and the website owner, __hstc is used to:
- uniquely identify visitors across multiple sessions and visits;
- calculate the number of visits and the time between them;
- attribute a visitor or contact to a specific traffic source (organic, paid, referral);
- build marketing reports and on-site behavior analytics inside the HubSpot account.
Does it require consent?
__hstc is classified as a marketing/tracking cookie because it builds a long-term (13-month) behavioral profile of the visitor and can be used for marketing attribution. Under the ePrivacy Directive (2002/58/EC, transposed in Romania via Law 506/2004) and the GDPR, this type of cookie requires the visitor's prior, explicit consent before being set.
Website owners must list __hstc in their cookie policy, classify it correctly under the marketing category in the consent banner, and make sure the HubSpot script does not load before the visitor gives consent. Data protection authorities, including Romania's ANSPDCP, can penalize sites that set such cookies without valid consent.
How to block or delete __hstc
Visitors can delete or block __hstc manually through their browser settings (Chrome, Firefox, Edge, Safari — the cookies and site data section), or by using dedicated tracker-blocking extensions. Deleting the cookie resets the visitor identification on the next visit.
For website owners, proper blocking means the HubSpot script itself must not run before consent is given, not just hiding the banner. A CMP such as CookieFix can automatically block the HubSpot tracking script from loading until the visitor accepts the marketing category, preventing __hstc from being set prematurely.
Frequently asked questions
It is HubSpot's main tracking cookie, used to identify a website's visitors and keep a record of their visit history over an extended period.
Its typical duration is 13 months from the last interaction, after which the browser removes it automatically unless it is renewed by a new visit.
Yes, since it is a marketing/tracking cookie, it requires prior consent under the GDPR and Romania's Law 506/2004, and cannot be set automatically when a visitor arrives on the site.
It can be removed from the browser's privacy settings, in the section that manages cookies and data for visited websites.