Legal
Cookie Policy
How WhiteHat Software uses cookies and similar tracking technologies on our website. Effective June 25, 2026. Last updated July 19, 2026.
This Cookie Policy is a draft provided for general information. It is not a substitute for legal advice. WhiteHat Software recommends that you consult with a qualified privacy attorney to ensure compliance with cookie and tracking technology regulations in your jurisdiction.
1. What are cookies?
Cookies are small text files that are stored on your device (computer, tablet, smartphone) when you visit a website. They contain information such as your preferences, login status, or tracking identifiers. Cookies can be:
- Session cookies: Deleted when you close your browser
- Persistent cookies: Remain on your device for a set period
- First-party cookies: Set by whitehatsoftware.com
- Third-party cookies: Set by other domains (e.g., service providers)
2. Cookies we use
2.1 Cloudflare Turnstile (security and bot protection)
We use Cloudflare Turnstile on our website to protect our forms and services from automated abuse, bots, and malicious activity.
- Purpose: Bot detection and security verification
- Type: Third-party cookie (Cloudflare)
- Duration: Session-based and persistent (up to 1 year)
- Data collected: Device fingerprinting, user agent, IP address, interaction patterns
Cloudflare may set cookies including cf_clearance, __cfruid, and similar identifiers. For more information, see Cloudflare's cookie list and privacy policy.
2.2 Cloudflare CDN and hosting
We use Cloudflare for content delivery, DDoS protection, and web optimization. Cloudflare may set cookies for performance monitoring and security purposes.
- Purpose: Website performance, caching, security
- Type: Third-party cookies
- Data collected: IP address, browser type, request time, technical identifiers
2.3 AWS hosting infrastructure
We host our website on Amazon Web Services (AWS). AWS may set cookies for performance measurement, load balancing, and security purposes (e.g., AWSALB, AWSALBCORS).
- Purpose: Load balancing, session stickiness, security
- Type: Third-party cookies
- Duration: Session-based (typically 7 days)
2.4 Resend (transactional email)
When we send you transactional emails (confirmations, project updates), Resend may include tracking pixels or links that set cookies to measure email delivery, open rates, and click-through rates. This data helps us understand if our communications are reaching you.
- Purpose: Email delivery and open tracking
- Type: Tracking pixel and email links
- Data collected: Open events, click events, email client type
See Resend's privacy policy for more details.
2.5 First-party attribution data (not a cookie)
Separately from cookies, we record a limited set of first-party attribution data server-side: UTM campaign parameters, HTTP referrer, landing page, and funnel events such as quote-form submission. This is derived from the request itself (the URL and headers your browser already sends), is not stored in your browser's cookie jar or local storage by us, and is not a "cookie or similar technology" for purposes of this policy.
See our Privacy Policy, Section 2.1, for what this data is and how it is used, and Section 6 for how long it is retained.
3. Cookies we do NOT use
We do not use:
- Google Analytics, Mixpanel, or similar third-party behavioral analytics: We do not use any third-party analytics tool, and we do not track session duration or on-site behavior beyond a single visit
- Advertising or marketing pixels: We do not set cookies for targeted ads or marketing profiling
- User preference or authentication cookies: Our marketing website has no user accounts or persistent login
- Retargeting pixels: We do not follow you across the web or use cookie-based retargeting
Note: We do record a limited set of first-party lead-attribution data (UTM parameters, referrer, landing page, and funnel events like quote-form submission) on our own servers. This is not a cookie and does not appear in your browser's cookie storage — see Section 2.5 and our Privacy Policy, Section 2.1, for details.
4. Cookie categories and consent
4.1 Necessary/Essential cookies
These cookies are required for core website functionality and security. They are set automatically and cannot be disabled without breaking core features:
- Cloudflare bot protection (Turnstile) — required to prevent abuse of forms
- AWS load balancing cookies — required for website stability
- Cloudflare CDN performance cookies — required for content delivery
Consent is not required for necessary cookies under most data protection laws (GDPR, CCPA, PIPEDA), as they are essential to the service.
4.2 Functional/Preference cookies
We do not currently use cookies to remember your preferences (language, theme, etc.). If we add such features in the future, we will update this policy.
4.3 Analytics cookies
We do not use Google Analytics, Mixpanel, or similar third-party behavioral analytics tools, and we do not set analytics cookies. We do record limited first-party attribution data server-side, without cookies — see Section 2.5.
4.4 Marketing/Advertising cookies
We do not set marketing or advertising cookies. We do not use Facebook Pixel, Google Ads, or retargeting services on our marketing website.
4.5 Transactional/Service cookies
Resend (our transactional email provider) may set tracking pixels in emails to measure delivery and opens. This is a legitimate service necessity and does not require separate consent.
5. Similar technologies
5.1 Web Storage (LocalStorage, SessionStorage)
Our website may use browser localStorage or sessionStorage to store preferences, form data, or session information on your device. These technologies function similarly to cookies but are not transmitted to our servers on every request.
5.2 Server-side session tokens
When you submit a consultation form, we may use a server-side session token to track your form submission and prevent duplicate submissions. This is a temporary token and does not create a persistent user profile.
5.3 Tracking pixels
Resend may include a tracking pixel in transactional emails to measure open rates. This pixel does not collect personally identifiable information beyond confirmation that the email was opened.
6. Your cookie choices and controls
6.1 Browser controls
Most web browsers allow you to control cookies through settings. You can typically:
- View cookies and clear them individually or in bulk
- Block all cookies or only third-party cookies
- Set preferences for specific websites
- Receive notifications when cookies are set
Note: Disabling cookies may break website functionality (e.g., form submission may fail due to bot protection).
6.2 Browser "Do Not Track" signal
Some browsers include a "Do Not Track" (DNT) signal. We respect DNT signals where applicable, though most of our cookies are necessary for functionality rather than tracking.
6.3 Cloudflare Turnstile bypass
If you object to Cloudflare Turnstile cookies, please contact us at hello@whitehatsoftware.com. We may be able to provide alternative verification methods for form submission.
6.4 Opting out of Resend email tracking
If you wish to opt out of email open tracking, you can disable images in your email client or contact us to request that tracking pixels be disabled for your emails.
7. Third-party service providers
The following third-party services may set cookies on our website:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Cloudflare | CDN, security, bot protection | cloudflare.com/privacy |
| AWS | Web hosting, infrastructure | aws.amazon.com/privacy |
| Resend | Transactional email | resend.com/privacy |
8. International data transfers
Cookies and tracking technologies may result in data being processed in countries outside your home country. This includes:
- Cloudflare: Processes data globally; maintains privacy protections under GDPR and similar laws
- AWS: Processes data in multiple regions; we use Canadian and US regions
- Resend: Processes email data in the US; complies with GDPR and CCPA
9. Retention of cookie data
Cookie retention varies by type and service provider:
- Cloudflare Turnstile: Up to 1 year (security cookies)
- AWS load balancing: Session-based (typically 7 days)
- Cloudflare CDN: According to Cloudflare's caching policies (typically 24 hours–1 year)
- Resend email tracking: Permanent (linked to your email address)
10. Changes to this policy
We may update this Cookie Policy at any time to reflect changes in our use of cookies, new service providers, or evolving legal requirements. We will post the updated policy on our website with a new "Last updated" date. Your continued use of our website constitutes acceptance of the updated policy.
11. Contact us about cookies
If you have questions about our use of cookies or wish to request opt-outs from specific tracking technologies, please contact us:
WhiteHat Software Inc.
Email: hello@whitehatsoftware.com
Phone: 604-200-3676
Location: British Columbia, Canada
Website: whitehatsoftware.com
12. GDPR and ePrivacy Directive compliance
For EU and UK visitors: Our necessary cookies (Cloudflare Turnstile, AWS load balancing, Cloudflare CDN) are exempt from consent requirements under GDPR and the ePrivacy Directive because they are essential to provide the service you have requested (form submission, website stability).
We do not use non-essential cookies (analytics, marketing, profiling) on our marketing website, so no cookie banner is required for cookie-based tracking. We do record limited first-party, server-side attribution data without cookies or client-side storage (Section 2.5); if we add cookie-based or client-storage-based tracking in the future, we will implement an explicit consent mechanism.
13. CCPA and California privacy rights
For California residents: Cookies are considered "personal information" under the California Consumer Privacy Act (CCPA). You have the right to:
- Know what cookies and identifiers are set
- Request deletion of cookie data (see browser controls above)
- Opt-out of cookies used for profiling or targeted marketing (we do not use these)
Our cookies are limited to functional and security purposes, so there are no targeted marketing cookies to opt out of.
Disclaimer: This Cookie Policy is a draft provided for general information and is not a substitute for legal advice. We strongly recommend consulting with a qualified privacy attorney regarding cookie compliance with GDPR, CCPA, PIPEDA, ePrivacy Directive, and other applicable laws. Cookie regulations vary by jurisdiction and continue to evolve.