Armidus Cookie Policy
Effective date: July 22, 2026
This Cookie Policy explains how Armidus, Inc. ("Armidus," "we," "us," or "our") uses cookies and similar technologies on armidus.com and in the Armidus clinic and owner applications.
This Policy should be read with our Privacy Policy at https://armidus.com/privacy. Terms not defined here have the meanings given in the Privacy Policy. Security information is available at https://armidus.com/security, and our provider list is available at https://armidus.com/subprocessors.
1. What cookies and similar technologies are
Cookies are small text files stored by a browser. They can allow a website to remember a browser, maintain a signed-in session, save a preference, protect a form, or measure how a site is used.
Similar technologies include local and session storage, pixels, software development kits, tags, scripts, and identifiers stored or read by a browser or application. We refer to all of these as "cookies" in this Policy unless a distinction matters.
Cookies may be:
- session cookies, which generally expire when the browser session ends;
- persistent cookies, which remain until their stated expiry or deletion;
- first-party cookies, set for an Armidus domain; or
- third-party cookies, set or read by a provider whose service appears on an Armidus page.
2. How we use cookies
Armidus uses cookies to:
- authenticate users and maintain secure sessions;
- protect accounts, forms, and the Service from abuse;
- route a returning user to the appropriate regional application;
- remember privacy, consent, and interface preferences;
- operate website forms and the HubSpot chat or messaging widget;
- measure marketing-site visits, sessions, referrals, and related analytics through HubSpot, subject to the visitor's consent choice where the banner is shown; and
- diagnose errors and maintain availability and performance.
We do not intentionally use Clinic Data for advertising. We do not currently intend to deploy third-party advertising pixels on the Site. If that changes, we will update this Policy and obtain any consent or provide any opt-out required by law before the change applies.
3. Cookie categories
3.1 Strictly necessary cookies
These cookies are needed to provide a feature you request, maintain security, authenticate an account, preserve a privacy choice, or route the Service. The Site or application may not work correctly if they are blocked.
Examples include authentication session cookies, security and bot-protection cookies, consent-choice cookies, and the optional Armidus region preference.
3.2 Functional cookies
These cookies remember choices or enable optional features, such as a messaging widget or interface preference. If they are disabled, the underlying Service may still work, but the optional feature may not.
3.3 Analytics cookies
These cookies help us understand visits, sessions, page views, referrals, and interactions so we can evaluate and improve the Site. They are not required for the Site's basic operation and should be set only in accordance with the visitor's consent or other choice where required.
3.4 Advertising cookies
Advertising cookies can be used to build an interest profile, measure ads, or track activity across services. Armidus does not currently intend to use advertising cookies. A generic ability in HubSpot or another provider does not mean Armidus has enabled that ability.
4. Current cookie inventory
Cookie names and durations can change when a provider updates its service or when browser behavior differs. The following table describes cookies that are used or may be set by the current configuration.
4.1 Armidus and authentication cookies
| Cookie or storage | Provider | Category | Purpose | Typical duration |
|---|---|---|---|---|
armidus_region | Armidus | Strictly necessary or functional | Optional country code used to direct a returning user to the corresponding Armidus application. It is a convenience only and does not grant access or determine where records belong. The marketing site reads this cookie if an Armidus application has set it. | Persistent if set; retained until it expires, is replaced, or is deleted through browser controls |
__session | Clerk | Strictly necessary | Stores the short-lived session token used to authenticate a signed-in user on the relevant application domain. | Controlled by the configured Clerk session lifetime and browser behavior |
__client or Clerk client-state cookies | Clerk | Strictly necessary | Maintains Clerk client and sign-in state on the configured Clerk domain. | Controlled by Clerk and the configured session lifetime |
_cfuvid or equivalent security cookie | Clerk or its infrastructure provider | Strictly necessary | Supports rate limiting, security, or abuse prevention for authentication services. | Usually session based or provider controlled |
Clerk cookies are set when a user interacts with an Armidus application in a way that requires authentication, such as signing in or signing up. They are not marketing-site analytics cookies.
4.2 HubSpot on the marketing site
The marketing site loads HubSpot in two ways:
- Forms embed (
js-na2.hsforms.net/forms/embed/...) so visitors can submit inquiry and interest forms; and - Site tracking code (
js-na2.hs-scripts.com/245941208.js), which enables HubSpot website analytics, the cookie consent banner, and the live chat or messaging widget when those features are turned on in HubSpot.
Because tracking and chat are enabled:
- HubSpot may show a site cookie consent banner and a separate in-chat consent prompt before chat cookies are used;
- analytics cookies may be set after the visitor accepts non-essential cookies where the banner requires a choice;
- chat or messaging cookies may be set when the visitor agrees to chat cookies or otherwise interacts with the widget under the HubSpot chat settings; and
- form delivery and related security cookies may still be set when a HubSpot form is shown or submitted.
HubSpot advertising, enrichment, or third-party ad-pixel integrations are not described here unless Armidus separately enables and discloses them.
| Cookie or storage | Category | Purpose | Typical duration |
|---|---|---|---|
__hs_opt_out, __hs_initial_opt_in, __hs_cookie_cat_pref, or equivalent HubSpot consent cookies | Strictly necessary | Remember the visitor's HubSpot cookie banner choice so the banner is not repeatedly forced after a decision. | Typically about 6 months, subject to HubSpot configuration |
__cf_bm, __cfruid, __cfuvid | Strictly necessary | CDN security, bot protection, and rate limiting for HubSpot-delivered form, chat, or tracking resources. | Session to approximately 30 minutes, depending on the cookie |
| HubSpot form or captcha session storage | Strictly necessary | Supports loading, securing, and submitting an embedded HubSpot form. | Session or provider controlled |
messagesUtk | Functional | Identifies a chat visitor so HubSpot can maintain conversation continuity and quality for the messaging widget. | Typically about 6 months, subject to HubSpot chat and consent settings |
__hstc | Analytics | Primary HubSpot visitor tracking cookie (domain, visitor token, visit timestamps, and session count). | Typically about 6 months |
hubspotutk | Analytics | Opaque visitor identity used to associate browsing activity with form submissions and CRM records. | Typically about 6 months |
__hssc | Analytics | Tracks HubSpot session activity and page-view count for the current session. | Typically about 30 minutes |
__hssrc | Analytics | Determines whether the visitor restarted the browser for HubSpot session handling. | Session |
4.3 Stripe-hosted pages
When a Clinic opens Stripe Checkout or the Stripe customer portal, the browser leaves an Armidus-hosted page and interacts with a Stripe-hosted surface. Stripe may use necessary cookies and other technologies for payment processing, fraud detection, security, preferences, and its own legal obligations. Stripe's cookie and privacy notices apply on those surfaces. Armidus does not control the name or duration of Stripe's cookies.
4.4 Netlify hosting
The marketing site is delivered through Netlify as static hosting and content delivery. Netlify processes request and technical information needed to host and secure the Site (for example IP address, user agent, and request path in server or edge logs). The Site does not currently rely on Netlify Identity, Netlify Forms, or Netlify analytics cookies for visitor measurement. If a Netlify feature later sets a browser identifier on armidus.com, we will add it to this inventory.
5. Your choices
5.1 Cookie settings on the Site
Where HubSpot shows a cookie consent banner on the Site, use that banner to accept, reject, or (where HubSpot offers it) manage non-essential cookie categories. Rejecting non-essential cookies should not prevent access to ordinary public-site content. Forms may still work; analytics association and optional chat features may be limited.
The chat widget may show a separate HubSpot consent step for chat cookies. That choice is specific to chat continuity and does not replace the site banner choice for analytics cookies.
Your choice is generally specific to the browser and domain. You may need to set it again if you clear storage, use another browser or device, visit another Armidus domain, or the preference cookie expires.
Strictly necessary cookies cannot be disabled through the preference tool because the requested feature or security function may not work without them.
5.2 Browser controls
Most browsers allow you to view, delete, or block cookies and clear local storage. Blocking all cookies may prevent authentication, forms, regional routing, and other Service features from working correctly.
5.3 Global Privacy Control
Where legally required, we will treat a valid Global Privacy Control signal as a request to opt out of sale or sharing for cross-context behavioral advertising. Armidus does not currently sell personal information for money or intend to share it for cross-context behavioral advertising.
5.4 Provider controls
Some providers offer their own privacy controls. A provider-level control may apply across sites using that provider. It does not replace choices that Armidus is required to provide on its own Site.
6. Do Not Track
Some browsers offer a Do Not Track setting, but there is no consistently accepted technical standard for responding to it. We do not currently respond to ordinary Do Not Track headers. This does not affect our response to a Global Privacy Control signal where applicable law requires one.
7. International processing
Cookie and website interaction information may be processed by HubSpot, Netlify, Clerk, Stripe, and their subprocessors in the United States or other locations where they operate. Regional storage of core Clinic application records does not mean that all website, authentication, or payment information stays in the Clinic's country. See the Privacy Policy and Subprocessors and Service Providers page for more information.
8. Changes to this Policy
We may update this Policy when our technology, providers, legal obligations, or practices change. We will post the revised version with a new effective date. Where required, we will ask for a new choice before using a new non-essential cookie category.
9. Contact us
Use the Privacy option at https://armidus.com/submit-request if you have a question about cookies or this Policy. Do not include patient records, passwords, payment-card information, or claim links in the form.
You may also contact Armidus's Data Protection Officer at privacy@armidus.com.
You may also contact us by post:
Armidus, Inc. 1111B South Governors Avenue #49736 Dover, DE 19904 United States