Who we are and what this notice covers
Whitelabel AI Corporation ("Whitelabel", "we", "us", "our") uses cookies and similar technologies on our websites, including www.whitelabel.ai, and in the platform and embedded experiences we provide to our customers (together, the "Services"). This notice covers our own use of those technologies.
When one of our customers embeds our platform in its own website, for example as a donation page or an assistant, that customer decides why and how the information collected there is used and is the controller of it. The customer's own cookie and privacy notices apply to that use alongside this one, and questions about it should go to the customer in the first instance.
The categories we use
We group what we use into four categories.
- Strictly necessary. Required for the Services to work and to be secure: keeping you signed in to the platform, protecting forms against abuse, remembering that you have entered a password for a protected page, and balancing traffic. These cannot be switched off in our settings; you can block them in your browser, in which case parts of the Services will not work.
- Functional. Remember your preferences and where you were: your cookie choice itself, that you have already given us your details for a gated resource, and the progress of a form you were completing.
- Analytics. Help us understand how the Services are used so that we can improve them. We use PostHog for this, and the next section describes exactly what it does. Where the law requires it, analytics runs only once you have accepted it; everywhere, you can switch it off.
- Marketing. Used to measure or support advertising. We do not use marketing or advertising cookies on the Services, and no advertising network receives data from them. If that changes we will update this notice and, where required, ask for your consent first.
What we set on our website
On www.whitelabel.ai the following are set by us. Names are given so that you can find them in your browser.
- wl_consent (cookie, functional). Records the cookie choice you made in our banner, so that you are not asked again and so that the choice is applied on every visit. Lasts 12 months.
- wp_lead (cookie, functional). Set once you have given your details to read the sector whitepaper, so that you are not asked again. Lasts 12 months.
- A cookie for password-protected pages (strictly necessary). Set when you enter the password for a protected page, scoped to that page, and not readable by scripts. Lasts 30 days.
- wl-start-flow (sessionStorage, functional). Keeps your progress through our onboarding flow on your own device, including the name, organisation, email and answers you have entered and the plan generated from them, so that a page reload does not lose your place. It is deleted when the tab closes and is not sent anywhere by itself; what you submit is sent when you submit it.
- wl-start-session-id (sessionStorage, analytics). A random identifier for the tab in which you use our onboarding flow, so that we can see which steps of it are completed. It is created only if analytics is allowed under your cookie choice, is deleted when the tab closes, is sent only to our own servers, and is not shared with any third party. The details you submit in the flow itself are handled separately, as described in our Privacy Policy.
- ae-org, ae-report, ae-done, ae-workspace and similar (localStorage, functional). Keep your inputs and results in our free visibility scan on your own device so that the tool can pick up where you left off. The tool's reset clears your organisation and report but leaves your progress and workspace; all of them stay until you clear your browser storage.
Our website is hosted by Vercel and loads its typefaces from Google Fonts. Neither sets cookies on our site, though loading a font means your browser requests the file from Google, which sees your IP address in that request.
What the embedded assistant and donation experience sets
The assistant, donation and membership experience embedded on our website, and on our customers' sites, is delivered by our own widget from cdn.whitelabel.ai. It sets the following only once you interact with it, for example by giving your name or email, making a donation, registering for an event or signing in. Each is a cookie with a 12 month lifetime unless stated. Each is named for the particular form or assistant you used, and is readable across the whole of the site it was set on.
- hasProvidedUserInfo_… and anonymousUser_… (functional). Remember that this browser has already been introduced to the assistant, so that a conversation can continue and you are not asked for your details again.
- whl_user_name_…, whl_user_email_… and whl_user_provider_… (functional). Your name, email and how you signed in, so that forms are pre-filled and receipts reach you.
- whl_membership_status_… and whl_donation_status_… (functional). Whether you are a member and whether you have donated, so that the experience reflects that.
- whl_events_manage_token_… (functional). A token that lets you manage your own event registrations.
- Form progress, pending donations and wallet availability (localStorage and sessionStorage, functional). Kept on your device so that an interrupted donation or form can be completed.
Analytics with PostHog
We use PostHog, provided by PostHog Inc. in the United States, to understand how the Services are used. On our website it runs inside the embedded widget described above, which is loaded on every page. On the platform at app.whitelabel.ai it runs as part of the application.
What it collects: page views and the point at which you leave a page, interactions inside the assistant and donation experience (for example that a step was started or completed, or that an error occurred), and technical information about your device and browser, including browser type, operating system, screen size, the page that referred you and an approximate location derived from your IP address.
What it does not do: it does not record your screen or your session, it does not automatically capture the content of pages or of what you type, and it does not build a profile of you as an individual unless you have identified yourself, for example by giving your email to the assistant.
How it is stored: PostHog keeps a device identifier, a session identifier and event properties in your browser's localStorage under a key beginning ph_, which stays until you clear your browser storage or switch analytics off. Event data is held by PostHog in the United States under our Data Processing Addendum, which lists PostHog as a subprocessor, and is transferred there on the safeguards described in our Privacy Policy. We keep it for as long as we need it for the purposes above and then delete or aggregate it.
Your choices
Cookie settings. The first time you visit our website we show a short notice with two choices: accept analytics, or essential only. Choosing essential only records that choice and sets PostHog's own opt-out in your browser, so that the analytics inside the widget does not run. You can change your choice at any time using the Cookie settings link in the footer of every page. A change takes effect at once; where analytics was already running on the page you are on, the page reloads so that it stops.
If you are in the European Economic Area, the United Kingdom or Switzerland, analytics does not run until you accept it. We work out where you are from the country your connection comes from, and if we cannot tell, we treat you as if consent were required. Elsewhere, analytics runs unless and until you choose essential only.
Global Privacy Control and Do Not Track. If your browser sends a Global Privacy Control signal or has Do Not Track switched on and you have not yet made a choice on our site, we treat the signal as choosing essential only and do not show you the notice at all. A choice you then make in Cookie settings is specific to this site and stands over the signal, until you change it again.
Browser controls. Most browsers let you see, delete and block cookies, either for all sites or for particular ones, and let you clear localStorage and sessionStorage. If you block strictly necessary cookies, parts of the Services will not work, and blocking storage for the widget means an interrupted donation cannot be resumed. If your browser blocks storage so that your essential-only choice cannot be saved for PostHog to read, we do not load the assistant and donation widget on our website at all, since that is the only way to keep its analytics off.
On the platform. If you use app.whitelabel.ai as a signed-in user of one of our customers, analytics is part of how we operate and secure the service for that customer. If you would like your account excluded from analytics, email privacy@whitelabel.ai and we will arrange it.
Legal basis in the EEA and the UK
Where the GDPR or the UK GDPR applies, we rely on our legitimate interest in providing a secure, working service for strictly necessary cookies and on the exemption for technologies that are strictly necessary to provide a service you have asked for. For analytics, and for any functional cookie that is not strictly necessary, we rely on your consent, which you can withdraw at any time from Cookie settings without affecting the lawfulness of what was done before you withdrew it.
Analytics data that identifies you is personal information, and the rights described in our Privacy Policy apply to it.
Changes to this notice
We may update this notice when what we use changes or when the law does. This page always describes our current practice. Where a change is material and the law requires it, we will ask for your consent again rather than rely on the choice you made before.
Contact us
If you have a question about our use of cookies or about your choices, you can reach us at:
- Email: privacy@whitelabel.ai
- Mail: Whitelabel AI Corporation, 823 Congress Ave, Austin, TX 78701, United States
Our security and compliance posture, including the current list of subprocessors, is published at trust.whitelabel.ai.
Questions about this document? Email privacy@whitelabel.ai. This page reproduces the current policy for convenience; where it differs from your signed agreement, the agreement controls.









