Legal
Cookie policy
Last updated: August 2026
What we use
The CrawlDrift dashboard uses a strictly necessary opaque, server-side session cookie with HttpOnly, Secure and SameSite attributes. The public Demo and Contact forms use a short-lived, strictly necessary HttpOnly CSRF cookie to protect same-origin submissions. It contains no personal form data and is not used for advertising.
Human verification
Demo and Contact forms use Cloudflare Turnstile as a strictly necessary security service to detect automated abuse. Turnstile may use browser storage or cookies required to perform and remember a challenge according to Cloudflare’s service behavior. CrawlDrift does not place names, email addresses, companies or message content into Turnstile metadata.
Analytics choices
CrawlDrift uses Google Tag Manager to configure Google Analytics 4 for product and marketing analytics. Analytics storage starts denied where prior consent is required and is granted only after Analytics consent. We do not use advertising pixels or session replay, and session and access tokens are never stored in browser local storage.
Analytics data
Analytics measures page and product interactions across crawldrift.com and app.crawldrift.com. CrawlDrift does not send passwords, session tokens, email addresses, names, customer domains, or customer URLs in analytics events.
Rejecting all keeps optional analytics storage disabled. Google Consent Mode may still send cookieless anonymous measurement signals. Your preference is stored for 180 days in a first-party cookie shared across CrawlDrift web surfaces.