This Cookie Policy explains how lead.box uses cookies and similar technologies on lead.box and within the application.
Cookies & similar storage in use
lead.box does not set third-party advertising cookies. The table below lists every browser-storage item we currently set, with its purpose, category and retention. Updated on every release.
| Name / Key | Category | Provider | Type | Purpose | Retention |
|---|---|---|---|---|---|
| sb-*-auth-token | Strictly necessary | lead.box (backend) | localStorage | Authentication session token. Required to keep you signed in. | 1 hour (refresh) / 7 days (session) |
| leadbox_cookie_consent | Strictly necessary | lead.box | localStorage | Stores your cookie consent choices so the banner is not shown again. | 12 months |
| leadbox_anon_id | Strictly necessary | lead.box | localStorage | Anonymous identifier used solely to attach your consent log to the audit record. | 12 months |
| i18nextLng | Functional | lead.box | localStorage | Remembers your interface language between visits. | 12 months |
| leadbox_pref_* | Functional | lead.box | localStorage | User preferences (timezone, density, dismissed hints, table sort). | 12 months |
| lb_vuid | Strictly necessary | lead.box tracking script (first-party) | localStorage | Anonymous visitor identifier used to link page views within a single browser to the same website session. | 12 months |
| leadradar_device_id | Strictly necessary | lead.box tracking script (first-party) | localStorage | Stable device identifier set by our tracking snippet on customer sites, used to deduplicate visits from the same browser. | 12 months |
| leadradar_session / leadradar_session_expires | Strictly necessary | lead.box tracking script (first-party) | localStorage | Session identifier and expiry timestamp for the current 30-minute visit session on the customer's own website. | 30 minutes (rolling) |
| _ga | Analytics | Google Analytics 4 | first-party cookie | Google Analytics 4 client identifier. Loaded only after you grant the analytics category; Google Consent Mode v2 signals stay 'denied' otherwise. | up to 12 months |
| _ga_* | Analytics | Google Analytics 4 | first-party cookie | Property-scoped GA4 session state. Only set with analytics consent under Google Consent Mode v2. | up to 12 months |
| ph_* | Analytics | PostHog (EU) | localStorage / first-party cookie | PostHog product-analytics identifier and event queue. Loaded only after you grant the analytics category; input masking is enforced. | up to 12 months |
Authentication session token. Required to keep you signed in.
- Provider
- lead.box (backend)
- Type
- localStorage
- Retention
- 1 hour (refresh) / 7 days (session)
Stores your cookie consent choices so the banner is not shown again.
- Provider
- lead.box
- Type
- localStorage
- Retention
- 12 months
Anonymous identifier used solely to attach your consent log to the audit record.
- Provider
- lead.box
- Type
- localStorage
- Retention
- 12 months
Remembers your interface language between visits.
- Provider
- lead.box
- Type
- localStorage
- Retention
- 12 months
User preferences (timezone, density, dismissed hints, table sort).
- Provider
- lead.box
- Type
- localStorage
- Retention
- 12 months
Anonymous visitor identifier used to link page views within a single browser to the same website session.
- Provider
- lead.box tracking script (first-party)
- Type
- localStorage
- Retention
- 12 months
Stable device identifier set by our tracking snippet on customer sites, used to deduplicate visits from the same browser.
- Provider
- lead.box tracking script (first-party)
- Type
- localStorage
- Retention
- 12 months
Session identifier and expiry timestamp for the current 30-minute visit session on the customer's own website.
- Provider
- lead.box tracking script (first-party)
- Type
- localStorage
- Retention
- 30 minutes (rolling)
Google Analytics 4 client identifier. Loaded only after you grant the analytics category; Google Consent Mode v2 signals stay 'denied' otherwise.
- Provider
- Google Analytics 4
- Type
- first-party cookie
- Retention
- up to 12 months
Property-scoped GA4 session state. Only set with analytics consent under Google Consent Mode v2.
- Provider
- Google Analytics 4
- Type
- first-party cookie
- Retention
- up to 12 months
PostHog product-analytics identifier and event queue. Loaded only after you grant the analytics category; input masking is enforced.
- Provider
- PostHog (EU)
- Type
- localStorage / first-party cookie
- Retention
- up to 12 months
Last reviewed: July 19, 2026. We audit this list with every release. If you spot a discrepancy, contact info@lead.box.
1. What are cookies?
Cookies are small text files stored on your device when you visit a website. They allow the site to recognise your device and remember information such as preferences or login state. Similar technologies include local storage, session storage and pixel tags.
2. Categories of cookies we use
Strictly necessary
Required for the Service to function: authentication, session management, security, load balancing and CSRF protection. These cannot be switched off.
Functional
Remember your preferences such as language, timezone, theme and dismissed onboarding hints. Disabling these may degrade your experience.
Analytics
Help us understand how visitors interact with lead.box (anonymised aggregate metrics) so we can improve the product. Set only with your consent.
Marketing
Currently we do not set any third-party advertising or retargeting cookies on lead.box. If this changes, this policy will be updated and consent will be requested.
3. Tracking script on customer websites
lead.box provides a first-party tracking script that customers install on their own websites to identify visiting companies. That script may set a first-party cookie or use local storage on the customer's website to maintain a session identifier. Customers are responsible for obtaining any required visitor consent and for disclosing this in their own cookie and privacy notices.
4. Managing your preferences
You can change or revoke your cookie consent at any time:
- By using the reset button below.
- By clearing cookies and site data in your browser settings.
- By configuring your browser to refuse cookies.
5. Retention
Strictly necessary cookies expire when you close your browser or after a defined session timeout. Functional and analytics cookies are stored for up to 12 months unless you delete them earlier.
6. Contact
For questions about this Cookie Policy, contact info@lead.box.