What is the hubspotutk cookie?
hubspotutk ("HubSpot user token") is an HTTP cookie set by HubSpot scripts (tracking code, forms, live chat, embedded CRM widgets) when a visitor loads a page on a site using HubSpot services. The provider is HubSpot, Inc., a US-based marketing automation, sales, and CRM company.
The cookie typically appears as soon as the HubSpot tracking code loads on the page, whether the site uses only HubSpot forms, a chatbot, or the full Marketing Hub/CRM suite.
What data it stores
hubspotutk stores a unique token generated by HubSpot that identifies the visitor (browser) across multiple visits. The exact value format is internal to HubSpot and may vary; it does not typically contain direct identifiers like a name or email address, but it allows visitor behavior to be linked to a CRM contact once that person submits a form.
The value is sent to HubSpot's servers on each interaction with the site (page views, form submissions) to maintain an activity history tied to that visitor.
What it is used for
For HubSpot, this cookie underpins visitor tracking and attribution: it links an anonymous visitor's actions (pages viewed, traffic sources) to a contact later identified via a form or chat submission.
For the site owner, hubspotutk enables HubSpot's marketing automation features – lead scoring, behavior-triggered workflows, conversion attribution reports, and content personalization based on visit history.
Does it require consent?
hubspotutk is classified as a marketing/tracking cookie, since it collects visitor behavior data across sessions for analytics and commercial automation purposes. Under the GDPR (Regulation 2016/679) and the ePrivacy Directive (transposed in Romania via Law 506/2004), this type of cookie requires the visitor's prior, freely given consent, obtained through a consent banner, before the HubSpot script runs.
The site owner should: list this cookie in the cookie policy, classify it correctly under the marketing category in the CMP, and ensure the HubSpot script only loads after consent, not by default on page load.
How to block or delete hubspotutk
- Visitors can delete or block hubspotutk anytime from browser settings (Chrome, Firefox, Edge, Safari – cookies and site data section).
- Visitors can decline the "marketing" category directly from the consent banner if the site uses a compliant CMP.
- Tracker-blocking browser extensions can prevent HubSpot scripts from loading, though this may affect features like forms or live chat.
For site owners, the safest approach is to automatically block the HubSpot script until consent is given, using a CMP like CookieFix, which stops the HubSpot tracking code from running until the visitor accepts the marketing category.
Frequently asked questions
It's not malicious, but it is a tracking cookie – it stores a unique identifier that can later be linked to a CRM contact once the visitor submits a form, which brings it under GDPR scope.
It typically lasts 13 months from the last interaction, after which it expires automatically unless renewed by a new visit.
Yes, as a marketing/tracking cookie it requires prior visitor consent under GDPR and Law 506/2004, and cannot be set by default.
HubSpot will generate a new token on the next visit, treating the visitor as "new" in terms of prior tracking history.