This Cookie Policy explains how Touchpoint Security, LLC. uses cookies and similar tracking technologies on tp-security.com and its subdomains. It should be read alongside our Privacy Policy. We operate globally and comply with applicable cookie and tracking laws in each jurisdiction, including the EU ePrivacy Directive (2002/58/EC), UK Privacy and Electronic Communications Regulations 2003 (PECR), and US state privacy laws including the CCPA/CPRA (California), CTDPA (Connecticut), CPA (Colorado), and others as applicable.
1. What are cookies?
Cookies are small text files placed on your device when you visit a website. They enable the site to remember information about your visit. We also use related technologies including web beacons (tracking pixels), local storage, session storage, and fingerprinting-resistant device identifiers. This policy covers all such technologies collectively as "cookies".
2. Cookie categories and the cookies we use
We categorize cookies in line with the IAB Europe Transparency and Consent Framework (TCF) and ICO guidance:
2.1 Strictly necessary
Required for the website and platform to function. Cannot be disabled. Legal basis: not required for strictly necessary cookies under PECR / ePrivacy; exempt from consent under most US state laws.
- Session cookies: maintain your login state and authentication session.
- CSRF tokens: prevent cross-site request forgery attacks.
- Load balancer cookies: route requests consistently across our infrastructure.
- Security cookies: bot detection, fraud prevention, and rate limiting.
- Consent record cookie: stores your cookie preferences to honor them on return visits.
2.2 Analytics and performance
Help us understand how the site is used so we can improve it. Legal basis: consent (EU/UK); opt-out under CCPA/CPRA and applicable US state laws.
- Google Analytics 4 (_ga, _ga_*, _gid, _gac_*): measures traffic, page performance, user journeys, and conversion events. IP anonymization is enabled. Data processed by Google LLC (US). Retention: 13 months.
- Microsoft Clarity (_clck, _clsk, MUID, CLID): provides heatmaps and session recordings to identify usability issues. No PII is recorded. Data processed by Microsoft Corporation (US). Retention: 12 months.
2.3 Functional
Enable enhanced features and remember your preferences. Legal basis: consent.
- Language and regional preference cookies.
- Form autofill state (non-sensitive fields only).
- Notification and banner dismissal preferences.
- Live chat widget state (if deployed).
2.4 Marketing and targeting
Used to measure campaign effectiveness and, where consent is given, to deliver relevant advertising. Legal basis: consent (EU/UK/most US states); opt-out right available to all US visitors.
- LinkedIn Insight Tag (li_fat_id, UserMatchHistory, AnalyticsSyncHistory, bcookie, bscookie): enables campaign conversion tracking and remarketing to B2B audiences. Data processed by LinkedIn Corporation (US / IE). Retention: 90 days – 2 years.
- Google Ads (_gcl_au, _gcl_dc): measures conversions from Google Ads campaigns. Data processed by Google LLC (US). Retention: 90 days.
- Brevo / Sendinblue web tracking (if enabled): tracks email link clicks back to site visits for campaign attribution. Data processed in EU.
3. Third-party cookies
Third-party services embedded on our site may set their own cookies. We do not control these. We recommend reviewing the privacy policies of:
- Google: policies.google.com/privacy
- LinkedIn: linkedin.com/legal/privacy-policy
- Microsoft / Clarity: privacy.microsoft.com
- Brevo: brevo.com/legal/privacypolicy
4. Your consent and choices
4.1 EU and UK visitors
Under PECR (UK) and the ePrivacy Directive (EU), we obtain your prior, freely given, specific, informed, and unambiguous consent before placing non-essential cookies. Our consent banner:
- Appears before any non-essential cookie or script loads.
- Does not use pre-ticked boxes, all non-essential categories are opt-in.
- Does not condition site access on accepting non-essential cookies (no cookie walls).
- Logs the date, banner version, and scope of your consent.
- Provides an equally prominent "Reject all" option alongside "Accept all".
- Allows granular category-level control.
Our consent mechanism is designed to comply with ICO guidance (2024), EDPB Guidelines 05/2020 on consent, and EDPB Guidelines 03/2022 on dark patterns.
4.2 US visitors (CCPA/CPRA and state laws)
We do not sell personal information. We do not share personal information for cross-context behavioral advertising without offering an opt-out. US visitors may:
- Opt out of analytics and targeting cookies via the consent banner or our "Do Not Sell or Share My Personal Information" link in the website footer.
- Use the Global Privacy Control (GPC) signal , we honour GPC as an opt-out from sale/sharing where required by applicable state law.
4.3 All visitors , managing cookies
You can also manage cookies through:
- Cookie preferences: click "Cookie settings" in the website footer at any time.
- Browser settings: most browsers allow you to block or delete cookies. Note that blocking strictly necessary cookies may impair site functionality.
- Opt-out tools:
- Google Analytics: tools.google.com/dlpage/gaoptout
- LinkedIn: linkedin.com/psettings/guest-controls
- Microsoft Clarity: clarity.microsoft.com (via browser opt-out)
- Network Advertising Initiative: optout.networkadvertising.org
- Your Online Choices (EU): youronlinechoices.eu
5. Consent management platform (CMP)
We use a third-party Consent Management Platform to manage cookie consent. Our CMP:
- Automatically scans and categorises cookies found on our site.
- Blocks non-essential scripts prior to consent.
- Stores consent records with timestamp, banner version, jurisdiction, and categories accepted.
- Triggers re-consent when the cookie inventory changes materially or every 12 months.
- Provides an audit log of consent records for regulatory compliance.
Consent records are retained for 3 years to demonstrate compliance.
6. Do Not Track
Some browsers send a "Do Not Track" (DNT) signal. There is currently no legally recognised standard for DNT. We rely on our CMP consent mechanism and honour the Global Privacy Control (GPC) as described in Section 4.2.
7. International transfers
Some cookies involve transfer of data to service providers in the United States and other countries. Where these transfers involve EU or UK personal data, they are made under Standard Contractual Clauses or other appropriate safeguards as described in our Privacy Policy.
8. Changes to this policy
We update this Cookie Policy when we add, remove, or change the cookies we use, or when applicable law changes. Material changes will be communicated via the consent banner, which will request fresh consent where required. The "Last reviewed" date at the top reflects the most recent update.
9. Contact
For questions about this Cookie Policy or our use of cookies and tracking technologies:
Email: privacy@tp-security.com
Touchpoint Security, LLC., 82 Wendell Ave, Ste 100, Pittsfield, MA 01201, United States