Cookie Policy
What cookies are, which types this website and the QliqSOFT platform use, and how to control them. Companion documents: the Privacy Policy, App Privacy Policy, and Terms of Service.
What this policy covers
Last updated: August 14, 2026
This Cookie Policy explains how QliqSOFT uses cookies and similar browser-storage technologies, and the choices you have. It covers three places you may encounter our technology:
- This website (www.qliqsoft.com) and its subdomains, including blog.qliqsoft.com.
- The QliqSOFT platform - the applications customers and their users sign in to (for example app.qliqsoft.com and webprod.qliqsoft.com), including patient-facing chat, virtual visits, and forms.
- The embedded chat widget that healthcare organizations place on their own websites.
Advertising cookies are an optional category you control. Outside the EEA, the UK, and Switzerland they are on until you turn Advertising off in "Your Privacy Choices" or your browser sends a Global Privacy Control signal; inside those regions they stay off until you accept. Showing you QliqSOFT ads on other sites based on your visit here is what California law calls sharing personal information for cross-context behavioral advertising, and "Your Privacy Choices" is how you opt out. We do not sell personal information. For how we handle personal information generally, see our Privacy Policy; for the mobile and web applications, see the App Privacy Policy.
Interpretation and Definitions
For the purposes of this Cookie Policy:
- Company (referred to as either "the Company", "We", "Us" or "Our") refers to QliqSOFT, Inc., Three Galleria Tower, 13155 Noel Road, Suite 900, Dallas, Texas 75240.
- Cookies are small files placed on your computer or mobile device by a website. "Session" cookies are deleted when you close your browser; "persistent" cookies remain until they expire or you delete them.
- Browser storage means similar technologies the browser provides - localStorage, sessionStorage, and caches - which store data on your device without sending it automatically with every request. Where this policy says "cookies," it includes these technologies unless stated otherwise.
- Website refers to www.qliqsoft.com and its subdomains. Platform refers to the signed-in QliqSOFT applications and the patient-facing experiences they serve.
Cookies on www.qliqsoft.com
We host our own fonts. What loads when you arrive depends on where you are. If you are in the EEA, the UK, or Switzerland, nothing optional loads until you choose: analytics and advertising stay off, and the only thing stored is your own choice. Everywhere else, analytics and advertising load when the page does and a notice at the bottom of the screen tells you so, explains what they cover, and lets you turn either off in one click. Your choice is remembered, and you can change it at any time from "Your Privacy Choices" in the footer of every page.
The two optional categories. Analytics covers Google Analytics 4, the HubSpot tracking code, and Contentsquare session recording (the product formerly called Hotjar), and tells us which pages are useful and how visitors move through them. Advertising covers Google Ads (remarketing and conversion measurement), the LinkedIn Insight Tag, Microsoft Advertising (UET), and the Meta Pixel, which let us show QliqSOFT ads to people who have visited this site and tell us when an ad led to a demo request. The Meta Pixel records page views only; we do not send it form or lead events. Advertising is active on this website as of September 2026. The Advertising control sits alongside Analytics in the choices panel: outside the EEA, the UK, and Switzerland it is on until you turn it off, and inside those regions it is off until you allow it. Essential storage, which keeps the site working and protects our forms from spam, is always on and is not a category you can switch off.
The complete list of storage this website can create:
| Name | Type | Set by | Purpose | Duration |
|---|---|---|---|---|
| qs-consent | localStorage | Us | Records the choices you make in our consent notice, one setting per category, along with the date and whether your browser sent a Global Privacy Control signal, so we do not ask again. We ask again if the record is more than 12 months old. | Until you clear it |
| _ga / _ga_* | Cookie (third party) | Google Analytics 4 | Privacy-respecting site analytics (page views and engagement), on unless you turn Analytics off, or until you accept if you are in the EEA, the UK, or Switzerland. Measurement ID G-56NZ3RY17K. The advertising signals in Consent Mode follow your Advertising choice. See the Google Privacy Policy. | Up to ~2 years |
| _GRECAPTCHA | Cookie (third party) | Google reCAPTCHA | Fraud and abuse prevention on our contact and demo forms, when reCAPTCHA protection is active. Google's use is described in the Google Privacy Policy. | ~6 months |
| __hstc | Cookie | HubSpot | Main HubSpot analytics cookie, set while Analytics is on. Records the domain, a visitor identifier, and the timestamps of your first, previous, and current visit, plus a visit counter. | ~6 months |
| hubspotutk | Cookie | HubSpot | The visitor identifier described under "How HubSpot connects visits to people" below. Set while Analytics is on. | ~6 months |
| __hssc | Cookie | HubSpot | Tracks a single browsing session so page views within it are counted together. | 30 minutes |
| __hssrc | Cookie | HubSpot | Records whether you restarted your browser, so HubSpot can tell a new session from a continued one. | Browser session |
| _cs_id | Cookie | Contentsquare | A visitor identifier for session recording, with your visit count and the times of your first and most recent visits. Set while Analytics is on and no Global Privacy Control signal is present. See the Contentsquare Privacy Center. | 13 months |
| _cs_s | Cookie | Contentsquare | The current recording session: pages viewed this session and whether this session is being recorded. | 30 minutes, renewed with each action |
| _cs_s_ctx | Cookie | Contentsquare | Context for the current session: when it started, the first page, and the referring page. | 30 minutes, renewed with each action |
| _cs_c | Cookie | Contentsquare | Contentsquare's own record of your consent state, which it uses to decide how much of a page to mask in a recording. | 13 months |
| _cs_optout | Cookie | Contentsquare, set by us | Tells Contentsquare not to record you. We set it when you turn Analytics off or send a Global Privacy Control signal, and remove it if you turn Analytics back on. | 13 months |
| _cs_t, _cs_same_site, _cs_root-domain | Cookie | Contentsquare | Checks whether your browser accepts cookies and which settings it supports. Written and removed again immediately. | Removed immediately |
| _gcl_au, _gcl_aw, _gcl_dc, _gcl_gs, _gac_* | Cookie | Google Ads (set on qliqsoft.com) | Links an ad click to a later demo request and builds the audience for QliqSOFT remarketing ads. Only with Advertising on. See the Google Privacy Policy. | Up to ~90 days |
| IDE, test_cookie | Cookie (third party) | Google (doubleclick.net) | Google Ads remarketing and conversion measurement. Set on Google's domain, so we cannot delete it from this site; turning Advertising off stops it being used here. | Up to ~13 months |
| li_fat_id (URL parameter), bcookie, lidc, li_gc, UserMatchHistory | Cookie (third party) | LinkedIn (linkedin.com) | LinkedIn Insight Tag: audience building and demo-request conversion measurement for QliqSOFT ads on LinkedIn. Set on LinkedIn's domain; turning Advertising off removes the tag. See the LinkedIn Privacy Policy. | Up to ~2 years |
| _uetsid, _uetvid, _uetmsclkid | Cookie | Microsoft Advertising (UET) | Audience building and demo-request conversion measurement for QliqSOFT ads on Microsoft search. Only with Advertising on. See the Microsoft Privacy Statement. | Up to ~13 months |
| MUID | Cookie (third party) | Microsoft (bing.com) | Microsoft's advertising identifier, set on Microsoft's domain when the UET tag loads. | Up to ~13 months |
| _fbp | Cookie | Meta Pixel | Audience building for QliqSOFT ads on Meta platforms from page views only; we send no form or lead events. Only with Advertising on. See the Meta Privacy Policy. | ~90 days |
| qs-geo | localStorage | Us | Caches which region (EEA/UK/Switzerland or elsewhere) the site last detected for your browser, for seven days, so the right consent rules apply from the first moment of your next visit. Contains a country code only. | 7 days |
In the EEA, the UK, and Switzerland these load only after you choose "Accept all" or turn Analytics on in "Manage choices". Everywhere else they load with the page, and turning Analytics off stops them. You can change your mind at any time: the "Your Privacy Choices" link in the footer of every page reopens the choices panel with your current settings. Turning Analytics off also deletes any Google Analytics and HubSpot cookies this website previously set, including the HubSpot visitor identifier.
How HubSpot connects visits to people. This is the part worth reading twice. While you browse anonymously, HubSpot records the pages you view and the links you click against the hubspotutk identifier in your browser, not against your name. If you later submit a form on this site and give us your email address, HubSpot associates that stored browsing history - including pages you viewed before you filled anything in - with your contact record in our CRM. From that point it is no longer anonymous. We use this to understand what a prospective customer was researching before they contacted us. If you would rather this did not happen, turn Analytics off in "Your Privacy Choices", either now or later, and we will delete the identifier.
HubSpot also receives your IP address, which it uses to estimate your general location and, for business visitors, the organization you are browsing from. HubSpot is our customer relationship management provider and processes this information on our behalf under a data processing agreement. Their handling is described in the HubSpot Privacy Policy.
Session recording. With Analytics on, Contentsquare records how a visit unfolds: where the pointer moves, what is clicked, how far the page is scrolled, and the page content as it was displayed, so we can watch a replay of the visit and see where the site is hard to use. What you type into our forms is not part of it: the request-a-demo, contact, and feedback forms are marked so their contents are masked before anything leaves your browser. A replay is tied to the _cs_id identifier, not to your name, unless you later submit a form and we connect the two ourselves. Turning Analytics off stops recording and deletes the identifier. Contentsquare processes this on our behalf; their handling is described in the Contentsquare Privacy Center.
Google Tag Manager. We use Google Tag Manager to load the tools listed above. It is a loader, not a tracker: it sets no cookies of its own and collects nothing about you. It runs only while at least one optional category is on, and it can only load the tools described in this policy. If we ever add another tool through it, this policy is updated first.
blog.qliqsoft.com. Our blog uses a privacy-focused analytics service (Datafast) whose vendor states it operates without cookies, and stores reading preferences you create - bookmarks and highlights - in your browser's localStorage. These stay on your device and are not transmitted to us.
Cookies in the QliqSOFT platform
The signed-in QliqSOFT applications use first-party cookies that are strictly necessary or functional - they sign you in, keep you signed in, secure your account, and remember your preferences. The platform contains no analytics, advertising, or social-media tracking cookies.
| Name | Purpose | Category | Duration |
|---|---|---|---|
| _session_id | Keeps you signed in during a session (identifies your server-side session). | Strictly necessary | 1 day |
| jwt | Completes single sign-on from partner health systems. | Strictly necessary | 6 hours |
| _api_web_key | Administrative dashboard session (QliqSOFT staff only). | Strictly necessary | 1 hour |
| device_uuid | Recognizes a device you have used before, to support two-factor authentication and block suspicious sign-ins. | Security / functional | 365 days |
| fingerprint | Recognizes a returning device in patient chat so your conversation can continue securely. | Security / functional | 30 days |
| short_url_hash, app_id, mid | Let a patient chat opened from a secure link survive a page reload. | Strictly necessary | Browser session |
| kiosk_visitor_uuid, prev_kiosk_visitor_uuid | Keep the right visitor's session active on shared check-in kiosks. | Strictly necessary | Browser session |
| language_selected | Remembers your language choice in patient chat. | Functional | 365 days |
| use_prerelease_app | Remembers which version of the application to show you. | Functional | Browser session |
| Per-screen paging preferences | Remember your rows-per-page choices on administrative screens. | Functional | Browser session |
The platform also uses browser storage (localStorage and sessionStorage) on your device for session continuity - for example your sign-in session, language and accessibility preferences, and short-lived caches of your own conversations so a page reload doesn't lose your place. This data stays in your browser, is removed by signing out or clearing browser data, and is never used for advertising.
Third-party services inside the platform. Some features rely on service providers that may set their own cookies or storage, strictly to deliver the feature:
- Google reCAPTCHA - fraud prevention at sign-in and registration (sets _GRECAPTCHA, ~6 months).
- Twilio - video visits and calling (no advertising cookies).
- Mapbox - maps in visit-scheduling features.
- YouTube / Vimeo - only when your care team shares a video with you inside a conversation; the video host may set its own cookies when the video loads.
- Microsoft / Okta - if your organization signs in with corporate single sign-on, your identity provider sets its own cookies on its own domain.
The chat widget
The QliqSOFT patient-chat widget runs on the home page of this website, and healthcare organizations can also embed it on their own websites. In both cases the widget runs in a frame served from app.qliqsoft.com: it does not read or write cookies on the host site, and the host site cannot read the widget's data. Inside the frame, the widget uses the platform cookies and browser storage described above - on the host organization's website these count as "third-party" storage from QliqSOFT. Modern browsers may isolate ("partition") that storage for each host website, so the widget can behave as a fresh session on each organization's site. If you use a chat widget on a healthcare organization's site, that organization's own privacy notice and cookie choices apply alongside this policy. On this website the widget is treated as essential, because it is a way to reach us rather than a way for us to measure you: it loads on the home page whichever way you answer the notice, including if you reject everything or send a Global Privacy Control signal. It is deferred, though. It does not load while the notice is still on screen, so nothing is stored until you have been told what this site does. On a later visit, when no notice is due, it loads with the page. In the EEA, the UK, and Switzerland the widget does not load at all, whichever way you answer, because there the standard is consent rather than notice and we do not treat storage you did not ask for as essential. It sets no cookies and no browser storage on www.qliqsoft.com itself. Once loaded it writes three items inside its own frame on app.qliqsoft.com: crd and peerProps in local storage, which hold the chat session so a conversation survives a page reload, and locale in session storage, which remembers the language you are chatting in and is discarded when you close the tab.
Your Choices Regarding Cookies
The notice, and where you are. If you are in the EEA, the UK, or Switzerland, we ask before loading anything optional and nothing from Google Analytics, HubSpot, or any advertising vendor runs until you say yes. Everywhere else we tell you instead of asking: analytics and advertising load with the page, the notice explains them, and one click turns either off. Either way the notice is not a wall, the page stays usable underneath it, and your setting is remembered. Essential storage does not require consent because the services you request cannot work without it.
Global Privacy Control. We honor the Global Privacy Control (GPC) signal. GPC is a request not to sell or share your personal information, so if your browser sends it we turn advertising off and keep it off, and we do not record your session even though the rest of Analytics stays on. In the EEA, the UK, and Switzerland we treat it as a refusal of everything optional and show you no notice at all. Elsewhere, first-party analytics is not a sale or a share, so analytics stays on and you can still turn it off yourself; we show the notice once, with a line confirming the signal was received and honored.
Your Privacy Choices. The "Your Privacy Choices" link in the footer of every page opens the choices panel, pre-filled with your current settings. Turning a category on takes effect right away. Turning one off reloads the page once, which is what guarantees that nothing from that category keeps running.
Other requests. To opt out of any sharing that does not happen in your browser, email privacy@qliqsoft.com. We respond within 15 business days, which is the deadline California sets for opt-out requests. To access, correct, or delete the personal information we hold about you, email the same address; we respond within 45 days, extendable once where the law allows and we will tell you if we need it. Depending on where you live you may have the right to access your information, correct it, delete it, opt out of its sale or sharing, and not be treated differently for exercising any of those rights. See our Privacy Policy for the full description.
Browser controls. You can block or delete cookies in your browser settings. Blocking strictly necessary cookies will prevent sign-in and patient chat from working.
- Chrome: Manage cookies in Chrome
- Firefox: Manage cookies in Firefox
- Safari: Manage cookies in Safari
- Edge: Manage cookies in Edge
If you are in a jurisdiction that requires consent for non-essential cookies (for example the EEA or UK), we rely on your consent for any optional analytics and on legitimate interest / necessity for the essential cookies above.
Contact Us
If you have questions about this Cookie Policy or want to exercise a privacy right, contact us:
- By email: privacy@qliqsoft.com