Cookie Policy
Last updated: 13 July 2026
This Cookie Policy explains how Kontrola Digital Ltd trading as ViralMouth ("we", "us", "our") uses cookies on viralmouth.com. For information about how we handle your personal data more broadly, see our Privacy Policy.
What cookies are
Cookies are small text files placed on your device when you visit a website. They allow the site to remember things like your preferences or whether you have visited before. Cookies are not programs and do not run code on your device.
How consent works on this site
On your first visit to viralmouth.com we show a cookie banner offering two independent
choices: analytics (Rybbit) and marketing (Meta Pixel and
Conversions API). Granting or refusing one does not affect the other. Your choices are stored
together in a first-party cookie called vm_consent for 180 days. You can change
or withdraw either choice at any time using the button below — no need to wait for the
banner to appear again.
Cookies we use
The table below lists every cookie this site may set. Some are strictly necessary and run without consent. Marketing cookies only run if you have granted marketing consent. Analytics uses no cookie of its own — manual tracking requests are sent to Rybbit only after you grant analytics consent, and in this configuration it sets no tracking cookie and no persistent user identifier.
| Name | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| vm_consent | ViralMouth | stores your analytics and marketing preferences — URI-encoded JSON version 2 | strictly necessary | 180 days |
| vm_report_auth | ViralMouth | authenticates access to private client reports — only set when logging into /reports/ | strictly necessary | 7 days |
| __cf_bm | Cloudflare | security/bot protection — may be set by our host when protection is active | strictly necessary | ~30 minutes |
| _fbp | Meta | distinguishes browsers for advertising measurement | marketing — consent required | 90 days |
| _fbc | Meta | stores the Meta ad click identifier | marketing — consent required | 90 days |
Rybbit analytics
When you grant analytics consent, our local wrapper makes manual tracking requests to
Rybbit — which we self-host at
rybbit.kontroladigital.com — and sends a single pageview for the page you
are on, followed only by named, non-PII interactions. These include clicks on major
call-to-action buttons, service links and email links, outbound link clicks (the destination
domain only, never the full URL or query string), the contact form lifecycle (started,
submitted, succeeded or errored), the service selected in the contact form, the Content Shoot
form lifecycle and purchase confirmation (amount and currency only — never card details
or the Stripe checkout reference), and scroll-depth
milestones. The wrapper also captures the page title, the origin of the referring page (scheme
and hostname only, never the full referrer URL or query string), your screen dimensions and
browser language, together with the network and user-agent information that the server
necessarily receives as part of every request.
We do not send Rybbit your name, email address, contact-form message, full page URLs, URL query strings, or any other field value from the contact form apart from the selected service. This implementation disables session replay, automatic error tracking, single-page-application route tracking, automatic outbound tracking and query-string collection, and it does not assign a user identifier. No event that occurred before you granted analytics consent is queued or sent later, with one narrow exception: if you grant analytics consent while the Content Shoot purchase confirmation page is still open, that confirmation is reported at that moment. Nothing else from before your consent is ever sent.
In this configuration Rybbit sets no tracking cookie and no persistent user identifier in your browser. The data controller for analytics data remains Kontrola Digital Ltd; no analytics data is passed to a third-party analytics provider. Withdrawing analytics consent stops Rybbit from receiving any further events from your browser.
Meta Pixel and Conversions API
When you grant marketing consent, the Meta Pixel fires a PageView event on every
page load. On contact form submission we also send a Lead event via the Meta
Conversions API, which includes your email and name in SHA-256-hashed form. When you complete
a Content Shoot booking, we send a Purchase event carrying the amount paid and
currency, your IP address, user agent and the Meta cookie identifiers — never your
name, email, card details or the Stripe checkout reference. It is sent via the browser Pixel
and, when your marketing consent was already recorded when the confirmation page loaded, also
via the Conversions API; when both are sent, a one-way hashed booking reference deduplicates
them. Both the Pixel and
the Conversions API share data with Meta Platforms Ireland Ltd; onward transfer to Meta
Platforms, Inc. in the United States is safeguarded under the UK Extension to the EU-US Data
Privacy Framework.
You can read Meta's privacy policy at facebook.com/privacy/policy. Rejecting or withdrawing marketing consent stops both the browser-side Pixel and the server-side Conversions API from running.
Managing cookies in your browser
Most web browsers let you view, block and delete cookies through their settings. How you do this depends on your browser. Blocking strictly necessary cookies may stop parts of the site from working — for example, logging in to private client reports.
For more detail on how we handle your personal data, see our Privacy Policy.