Cookie & Browser Storage Policy
Effective date: July 29, 2026
Orbiton Inc. ("Orbiton", "we", "us") provides an AI-powered investor relations chat that public companies embed on their own websites, plus chat and research surfaces on our own domain. This page explains, in plain language, everything the chat can store in your browser, what each item is for, how long it lasts, and what consent is required before it appears. It supplements our Privacy Policy.
First, what we do not do
- We set no HTTP cookies. The chat uses browser storage (localStorage and sessionStorage) only. EU ePrivacy rules treat browser storage the same as cookies, so we apply the same consent standards to it.
- No advertising or cross-site tracking. There are no third-party ad cookies, no data sale, and no tracking of you across unrelated websites. Identifiers below are scoped to the specific company site and chat you use.
Consent tiers
Storage is gated by a three-tier consent model. The chat itself works at every tier — consent controls what is stored, not whether you can use the chat.
- Tier 0 — Minimal: no consent given. Nothing is stored; any state lives in page memory and disappears when you leave.
- Tier 1 — Session: you engage with the chat. Session-scoped items only (cleared when the browser tab session ends); your conversation works, but no persistent identifier and no analytics.
- Tier 2 — Full: you explicitly consent (pre-chat card, the site's cookie banner, or its consent management platform). A persistent identifier enables cross-visit chat history and first-party analytics for the company whose site you are visiting.
Storage on the company's website (the embedded widget)
These keys can be set by the chat widget on the investor-relations site you are visiting:
| Key | Type | Purpose | Duration | Appears at |
|---|---|---|---|---|
profileIdentifier |
localStorage | Random anonymous visitor identifier. Links your page visits and chat history for the company whose site you are on; contains no personal details itself. | Until consent is withdrawn or you erase your data | Tier 2 |
orbiton_consent_<company> |
localStorage | Your consent decision itself: tier, policy version, timestamp, and how it was given. Written only when you make an explicit choice. | Until changed or withdrawn | Any explicit decision |
orbiton_tc_consent_<company> |
localStorage | Legacy terms-banner decision from older embeds; migrated into orbiton_consent_* on first read. |
Until migrated or withdrawn | Explicit banner decision (legacy) |
orbiton_prechat_<company> |
sessionStorage | Receipt that you accepted the pre-chat consent card, so the card is not shown again during the same browsing session. | Browser session | Card accept |
orb_session_id, orb_last_activity_ms |
sessionStorage | Groups your page views into one visit for the company's analytics (a new session starts after 30 minutes of inactivity). | Browser session | Tier 1+ |
hasExistingChats |
localStorage / sessionStorage | A yes/no flag ("true") so the widget can offer to continue an earlier conversation. Stored persistently only at tier 2; session-only at tier 1; page memory below that. | Follows its tier (persistent / session / none) | Tier-routed |
orbiton_chat_dismissed |
localStorage / sessionStorage | Remembers that you closed the chat, so it does not automatically reopen. Tier-routed like the flag above. | Follows its tier | Tier-routed |
__orbiton_storage_test__ |
localStorage | Technical availability probe: written and immediately removed to detect blocked storage. Never holds data. | Milliseconds | Always (stores nothing) |
Storage inside the chat window (chat.orbiton.app)
The chat itself runs in a frame on our domain. Browsers keep its storage separate from the host site's:
| Key | Type | Purpose | Duration | Appears at |
|---|---|---|---|---|
profileIdentifier |
localStorage | The chat's copy of your anonymous visitor identifier, so your conversation history can be retrieved on later visits. On consent-gated sites it is only used at tier 2. | Until withdrawn or erased | Tier 2 (gated sites) |
chatId_<company> |
localStorage | The id of your current conversation, so a page reload resumes the same thread instead of starting over. | Until you start a new chat or erase data | Using the chat |
analyticsConsent_<company> |
localStorage | Your answer to the in-chat analytics consent prompt ("granted"/"denied"), so you are not asked twice. | Until changed or erased | Explicit prompt answer |
userEmail |
localStorage | Stored only if you type your email into the chat (e.g. to retrieve past conversations or receive a transcript). Never collected automatically. | Until you erase your data | Explicit submission |
Third-party scheduler embeds (Calendly / cal.com)
Some companies let you book a meeting with their team directly inside the chat. When that option is enabled and you click "Load scheduler", the chat loads a scheduling widget from Calendly or cal.com in its own frame. That widget is operated by the third party and may set its own cookies under its own policy — see the Calendly cookie notice and the cal.com privacy policy. Before you click, no request is made to either provider: the scheduler is never loaded automatically, so simply opening or using the chat sends nothing to Calendly or cal.com.
Withdrawing consent and erasing data
- Through the site's cookie tool: if the company's website runs a consent banner or CMP, rejecting or withdrawing analytics consent there tears down our storage automatically — the persistent identifier and every Orbiton key above are erased from the site, and tracking stops immediately. The chat stays available.
- Through the chat: the chat's data controls let you withdraw consent and request deletion of your stored conversations, analytics, and contact details from our servers. Deletion requests are honored without needing an account.
- Manually: clearing your browser's site data for the company's website and for chat.orbiton.app removes every key listed here.
Each consent grant and withdrawal is also recorded server-side (decision, policy version, timestamp) as an audit trail, as described in our Privacy Policy — which also covers retention periods for server-side data such as conversations and analytics.
Changes to this page
When we add, rename, or re-scope a storage key, we update this page and its effective date. Material changes to what consent covers are versioned — your stored decision records the policy version it was given under.
Contact
Questions about this policy: privacy@orbitonfinancial.com.