Document WAC-POL-02 · Issued by WAC Standards Studio
Cookie policy. Nothing that measures ads is stored until you press Allow.
This site takes paid clicks from Google Ads and Microsoft Advertising, and from Meta Ads where a campaign runs there. That is the only reason anything beyond two browser keys is stored, and every one of those cookies waits for your answer on the banner.
Effective date and version
Version 1.0 took effect on September 29, 2026, and it was last updated the same day. When a cookie is added, removed or has its lifetime changed, the version number goes up and the date in the masthead changes with it. The table is never edited quietly.
What the inquiry form keeps, for how long, and how to have it deleted sits in the privacy policy. This document covers only what lives in your browser.
Three categories, and only one runs without asking
Strictly necessary. Two browser storage keys. One remembers your answer on the cookie banner so it does not ask on every page. The other holds the support chat token, so a conversation you started yesterday is still there today. Neither is used for advertising. They run without consent because the site cannot keep your choice or your chat without them.
Analytics. Aggregate counts of how visits arrive and which pages they reach, governed by the analytics_storage signal. Off by default.
Advertising. Conversion measurement for the three ad platforms: did a click on an ad lead to an inquiry. These cookies read the click identifier from the landing address and store it so the platform can match the inquiry to the click. Off by default, switched on only by Allow.
No cookie here is used to build a visitor profile, and no list of visitors is sold or rented.
The cookie and storage table
Every key this site writes or allows to be written. Rows marked advertising are never set before you press Allow.
| Name | Set by | Category | What it is for | Lasts |
|---|---|---|---|---|
site_consent_v2 | wac.us.org, local storage | Strictly necessary | Your Allow or Decline answer and when you gave it | 12 months, then the banner asks again |
| Chat token | wac.us.org, local storage | Strictly necessary | Reconnects you to your own support chat thread | Until you clear it; the transcript on our side is deleted after 6 months |
_gcl_au | Google Ads | Advertising | Links a conversion to the ad click that led to it | 90 days |
_gcl_aw | Google Ads | Advertising | Stores the gclid from the landing address | 90 days |
_uetsid | Microsoft Advertising | Advertising | Groups the pages of one visit for conversion counting | 1 day |
_uetvid | Microsoft Advertising | Advertising | Recognizes a returning browser for conversion counting | 13 months |
_uetmsclkid | Microsoft Advertising | Advertising | Stores the msclkid from the landing address | 90 days |
_fbp | Meta Ads | Advertising | Identifies the browser for Meta conversion measurement | 90 days |
_fbc | Meta Ads | Advertising | Stores the fbclid from the landing address | 90 days |
Ad platforms and their click identifiers
Google Ads, Microsoft Advertising and Meta Ads send traffic here today. When you arrive from one of their ads, the platform adds a click identifier to the end of the address:
gclid, added by Google Ads.msclkid, added by Microsoft Advertising.fbclid, added by Meta, where a campaign runs there.
The identifier is a random string and says nothing about who you are. It lets the platform connect a later inquiry to the click, which is how we learn that "iso 9001 gap assessment" brings people who need one and some other phrase burns budget. It sits in the address whatever you choose. It is only read into a cookie after you allow advertising storage.
No ad platform has reviewed or signed off this policy. It is our own account of what the site does.
Google Consent Mode v2 and its four signals
Before any Google tag can store anything, the page sets four signals to denied. They stay denied until you press Allow. Press Decline, or withdraw later, and they go back to denied at that moment and on every page after it. The Microsoft and Meta tags follow the same answer.
| Signal | Before you choose | After Allow | What it controls |
|---|---|---|---|
ad_storage | denied | granted | Whether advertising cookies such as _gcl_aw may be written |
ad_user_data | denied | granted | Whether data about the visit may be sent to Google for advertising |
ad_personalization | denied | granted | Whether the visit may shape the ads you see later |
analytics_storage | denied | granted | Whether measurement cookies may be written |
A browser that sends Global Privacy Control (the Sec-GPC header) is treated as having declined, and we do not ask it again.
Giving consent and taking it back
On your first visit a bar sits along the bottom of the screen. It covers nothing you need and blocks nothing. It has two buttons, Allow and Decline, and a link to this policy. Scrolling past it is not consent. Closing the tab is not consent either.
To change your answer, press Cookie settings in the legal row at the foot of every page. It reopens the same bar, and the other button applies straight away. Clearing this site's data in your browser removes the stored answer too, and the bar asks again next visit. The answer is kept for 12 months, because a year-old yes is not much of a yes.
What happens if you decline
Everything you came for keeps working. The gap assessment and audit readiness pages load the same. The scope builder runs in your browser and needs no cookie. The inquiry form still posts and the chat still answers.
What stops: no advertising or analytics cookie is written, the four signals stay denied, and the platforms cannot tie your inquiry to the click that brought you. That costs our reporting, not you. If you allowed earlier and then decline, the tags stop reading cookies already written; delete them in your browser to remove them entirely.
The platforms' own privacy documents
Once data reaches a platform, its own statement governs what happens next:
- Google: policies.google.com/privacy
- Microsoft: privacy.microsoft.com/privacystatement
- Meta: facebook.com/privacy/policy
Each also runs its own ad settings page, where you can switch off personalized ads on every site at once.
Asking about a specific cookie
Name the cookie or key and the page you saw it on. Write to [email protected], call (206) 464-3067, or post a letter to WAC Standards Studio, 1325 6TH AVE, SEATTLE, WA 98101, United States. A cookie that is missing from clause 3 is a defect. Tell us and we fix the table and raise the version.
For the inquiries themselves, use the data request route in the privacy policy. General terms of use are on the terms page.