Skip to main content
Cookie reference · HubSpot

The __hstc cookie

HubSpot's main visitor-tracking cookie, holding the visitor ID, visit timestamps and session count.

__hstc at a glance

Cookie name
__hstc
Vendor
HubSpot
Category
Analytics
Party
First-party
Typical duration
6 months
Set on
.<your-domain>
Value format
<domain-hash>.<hubspotutk>.<first-visit>.<last-visit>.<current-visit>.<session-number>
Name match
Exactly __hstc

What the __hstc cookie does

__hstc is the main cookie the HubSpot tracking code uses to track visitors. It stores the domain, the hubspotutk visitor ID, the first, last and current visit timestamps, and the session number, which HubSpot uses to build the visit history for a visitor.

HubSpot's current documentation gives a 6 month lifetime. Older lists often say 13 months, so check the date of any source you rely on.

What TagPipes observed

0.23%

of sites scanned set it (93 of 41,162)

180 days

median observed lifetime

TagPipes scanned 41,162 public websites between August 11, 2026 and September 13, 2026, loading up to three pages per site in a real browser as a first-time visitor. __hstc was present on 93 of them.

It was set as a first-party cookie on 81 sites and as a third-party cookie on 12. A site can count in both. Where it was stored as a persistent cookie, the median lifetime we recorded was 180 days.

Often found alongside

Percentage of sites with __hstc where the other cookie was also present.

Technologies detected on the same sites

  • HubSpot on 99% of them (0.32% of all sites scanned)
  • Google Analytics on 89% of them (55% of all sites scanned)
  • Google Fonts on 84% of them (78% of all sites scanned)
  • Google Tag Manager on 67% of them (30% of all sites scanned)
  • Google Ads on 59% of them (12% of all sites scanned)

Aggregate figures across all sites scanned. Websites of TagPipes customers are excluded, no individual site is named, and cookie values are never read or stored. Snapshot dated September 13, 2026.

How to check for __hstc on a website

  1. Open the site in Chrome, then open DevTools (F12, or Cmd+Option+I on a Mac).
  2. Go to the Application tab and expand Cookies in the left panel.
  3. Select each domain listed there and look for __hstc. The Expires column shows when it will be deleted.
  4. If it is not there, reload the page. Many cookies are only set after a tag has loaded, and some only after a visitor has made a consent choice.

Sources

Purpose, duration and value format checked against the vendor documentation above on . The figures under What TagPipes observed are TagPipes scan data from September 13, 2026, not values documented by the vendor. Vendors change their cookies, and sites can configure their own names and lifetimes. Browse all cookies.

Know every cookie your own site sets

TagPipes Pulse identifies the cookies dropped on your site and flags unclassified or miscategorized ones. Shield builds your cookie declaration from a real scan rather than a questionnaire.

TagPipes monitors, configures and reports. It does not determine legal compliance and does not provide legal advice. Output is informational and reflects observed state at the time of observation. Rawsoft's expertise is technology, not law; please confirm any regulatory interpretation with your own counsel.