> ## Documentation Index
> Fetch the complete documentation index at: https://docs.invoca.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Cookie Classification

> Invoca uses a first-party cookie that stores no PII. This article explains how it works and helps you choose the right consent-management classification for your account.

Like most online platforms, Invoca uses a cookie to function at its best, identifying callers and customers across different browser sessions. Cookie consent practices, classification, and management are important topics for most Invoca accounts — especially for complying with consumer privacy regulations and best practices.

<Note>
  **Note**

  Because this article addresses compliance and regulation, it's intended for technical information only and does not, and is not intended to, constitute legal advice.
</Note>

## How the Invoca cookie works

Invoca uses a first-party cookie, along with local storage, to retain a unique identifier for visitors on your landing page, named "InvocaID." Any other user data, including attribution data linked to that visitor's InvocaID, is stored server-side, not within the cookie — this helps keep the Invoca cookie size small. **The Invoca cookie stores no PII, including the user's phone number, IP address, or other personally identifiable information.**

The Invoca cookie is considered a first-party cookie — owned by your organization, not by Invoca — because it's generated by your own website via the Invoca Tag. Your Invoca Tag checks each visitor's Invoca cookie and local storage for an existing InvocaID and connects all attribution data from their current session to it. If the Tag can't find an InvocaID, it creates a new cookie with a new one.

## Classifying your Invoca cookie

To help comply with common consumer privacy regulations — including GDPR, CCPA, and others — many consumer-facing websites use a cookie consent management system, giving visitors the option to opt out of some or all cookies by classifying them into types such as Strictly Necessary, Functional, Performance, Statistical, and Marketing.

Because Invoca is a multifaceted tool with many use cases, the Invoca cookie might not fit the same classification for every account. **It's your organization's responsibility to choose the classification that's best for how you use Invoca.**

Here are common classifications and the situations in which they typically apply:

### Performance cookie

A performance cookie collects information about how visitors use a website, including which pages were visited and which links were clicked, so a site can assess and improve its performance. Data collected is aggregated and anonymous.

**When to choose this classification:** If your account relies on Invoca primarily for marketing insights and uses call treatment (IVR) options to understand the caller's experience, "Performance" is typically the most appropriate classification.

### Functional cookie

A functional cookie provides a personalized experience for website visitors and remembers settings or choices from a previous visit.

**When to choose this classification:** If you use Invoca data to provide a tailored call experience to returning visitors, "Functional" is typically the most appropriate classification.

### Strictly necessary cookie

Strictly necessary cookies are essential for the website to function and can't be disabled. They don't store personally identifiable information.

**When to choose this classification:** This is rarer for the Invoca cookie, but possible — for example, if your website can't forward calls to any destination without the routing options in your Invoca campaign.

### Classifications that typically don't apply

Most cookie consent platforms also offer "Marketing" or "Statistical" classifications. Statistical cookies monitor browsing behavior for aggregate analysis and reporting; marketing cookies (typically third-party, persistent cookies) track activity to serve targeted ads. Neither use case matches how the Invoca cookie typically functions.

## FAQs and troubleshooting

**Does Invoca still work if a visitor declines or opts out of cookies?**

When presented with a consent prompt, visitors can reject all cookies or opt out of specific categories. Cookies categorized as "Strictly Necessary" always remain active.

If your organization doesn't categorize the Invoca cookie as "Strictly Necessary" and a visitor opts out, no InvocaID is assigned to them — your account won't be able to assign a unique phone number to that visitor or collect attribution data for them. You can still gather some attribution data for these visitors by provisioning a static promo number as an overflow number, or for whenever a visitor rejects the Invoca cookie.

**If a visitor opts out of the Invoca cookie, will that affect my integrations?**

If a visitor opts out, your account won't be able to track that call or transmit data for it. If you use static numbers as a fallback (as described above), some integrations may still receive data, depending on the integration and its setup. Reach out to your account team or [support@invoca.com](mailto:support@invoca.com) if you'd like to learn more.

## Where to go next

* [Configuring Content Security Policy (CSP) for the Invoca Tag](/s/article/content-security-policy)
* [What Happens to the Invoca Tag When an Ad Blocker Is On?](/s/article/invoca-tag-ad-blocker)
* [Does the Invoca Cookie's 100-Year Max Age Mean Data Is Stored That Long?](/s/article/invoca-cookie-max-age)
