🎯 Free Trial

Know exactly who's visiting your site — person-level ID in 173+ countries. Start free, no card needed.

Start free trial →

TECHNOLOGY & DATA PROTECTION DATASHEET

How Happierleads Actually Works — Cookies, IPs & Compliance

"How does the tech work? What about the cookies? We're conscious of data protection." Fair questions — here are the full answers. Two identification methods, step by step, and exactly why both are compliant.

CASE 1 · USA + 172 COUNTRIES

Exact-Visitor Identification — the Cookie, Explained

Meet Bob. Bob works at IBM. Here's exactly how Happierleads can tell you Bob visited your website — and why Bob agreed to it long before he got there.

1. Bob identifies himself somewhere on the internet

One day Bob lands on a free net-worth calculator, a comparison site, or signs up for a webinar. He drops his name and work email to get access — and accepts that site's terms and conditions, which include identification across the partner network. Millions of these partner touchpoints exist.

2. A safe identity cookie is saved

At that moment, a tiny encrypted token is stored in Bob's browser. Think of it as a private key. It contains no readable personal data — no name, no email, no phone. Just an encrypted reference that only resolves through a secure server-to-server lookup.

3. Days later, Bob lands on your website

Maybe he Googled you. Maybe he clicked an ad. Different day, different intent — same Bob, same browser, same cookie.

4. Your pixel reads the key — instantly

The Happierleads pixel checks for the encrypted token. If it's there, a two-step, sub-second, server-to-server verification resolves who it belongs to. Nothing is scraped from Bob's browser; the pixel only reads the key.

5. You see exactly who came

Bob, from IBM — name, work email, phone, LinkedIn, company — appears in your dashboard the same day. Outreach-ready, no form fill needed. Happierleads is the only platform doing this in 170+ countries.

⚖️ Why Case 1 Is Compliant

  • Consent at the point of collection. Identification only works for people who shared their details on a partner site and accepted its terms — including network identification. No consent, no cookie, no identification.
  • The cookie holds a key, not a profile. No plaintext name, email, or phone ever sits in the browser. The encrypted token is useless without the secure server-side lookup.
  • Region-gated. This flow runs only where person-level identification is lawful — the USA and 172 other countries. It is never used for EU or UK visitors.
  • Opt-out, honored network-wide. Anyone can permanently remove themselves at happierleads.com/opt-out — aligned with CCPA and US state privacy laws.
  • No selling of personal data. Identified data is delivered to you for your own B2B outreach — it is not resold or broadcast.
CASE 2 · EU + UK

Company Identification + Suggested Contacts — GDPR by Design

Meet Amanta. She's a director at Northwind, a German manufacturer, browsing from her corporate connection — even from home via the company VPN. Under GDPR we never try to identify Amanta personally. That's the law, and we respect it. Here's what happens instead.

1. Amanta lands on your website

She's browsing from Northwind's corporate network — a corporate connection with a corporate IP address.

2. GDPR protects her — and we comply

No identity cookie is used. No personal identification is attempted. Amanta stays anonymous, exactly as EU law requires.

3. We look up her IP in public registries

Corporate IP addresses are publicly registered business information. We match the IP against those public registries in under a second — company data, not personal data.

4. You see the company

Northwind GmbH appears on your dashboard. You now know exactly which company is interested in what you sell — without touching anyone's personal data.

5. We suggest the right decision-maker

Who visited isn't always who buys — a junior researcher might be doing the clicking. So you tell us your ICP ("I sell to VPs of Operations"), and we surface that exact person inside Northwind from public B2B business data — name, role, LinkedIn, best channel. The suggested contact is not the visitor — that's the point.

⚖️ Why Case 2 Is Compliant

  • No personal identification is ever attempted. The visitor remains anonymous. Only the company is resolved, from publicly registered corporate IP data.
  • Suggested contacts are not the visitor. They come from public B2B business data matched to the job titles you sell to — professional information about a business role, not tracking data about a person's browsing.
  • Outreach runs on legitimate interest — GDPR Article 6(1)(f). Contacting decision-makers at a company that has shown interest in what you sell is lawful when the message is relevant to their job and easy to opt out of. Every B2B outreach on the planet runs on this basis — you're not spamming a stranger, you're following up on a warm signal.
  • Easy opt-out, always. Every email includes an unsubscribe link, and contacts can be suppressed permanently on request.

🍪 The Cookie, Side by Side

The single most common data-protection question we get: "what exactly is in the cookie?" Here's the datasheet view.

Case 1 — Exact Visitor (USA + 172 countries)Case 2 — Suggested Contact (EU + UK)
Identity cookie used?Yes — one encrypted tokenNo — IP resolution only
What it containsAn encrypted key only — no name, email, or phone in the browserNothing — no personal identifier is stored
Where consent comes fromAccepted terms on the partner site where the person shared their detailsNot needed — only public business data is processed
Who you seeThe exact visitor — name, work email, phone, LinkedInThe company + a suggested decision-maker (not the visitor)
Legal alignmentCCPA & US state privacy laws, CAN-SPAM for outreachGDPR — Article 6(1)(f) legitimate interest for outreach
Opt-outhappierleads.com/opt-out, honored network-wideUnsubscribe in every email + permanent suppression on request

Data Protection FAQ

What does the Happierleads cookie actually store?

A single encrypted identity token — a private key. No name, email, phone, or any readable personal data ever sits in the browser. The token only resolves through a secure, two-step, server-to-server lookup, and only for people who agreed to identification on a partner website.

Is the suggested contact the person who visited my site?

No — and that's precisely why it's compliant. In the EU and UK we identify the company, then suggest the right decision-maker inside it based on your ICP. Their details come from public B2B business data, not from tracking the visitor. Who visited isn't always who buys anyway — the visitor is rarely the decision-maker.

Is it legal to email these people?

Yes, for B2B outreach. GDPR Article 6(1)(f) — legitimate interest — allows contacting decision-makers at a company that has shown interest in what you sell, as long as the message is relevant and easy to opt out of. In the US, CAN-SPAM permits B2B email with a clear unsubscribe. You're not cold-blasting strangers — you're following up on a warm signal.

Do I need to update my privacy policy or cookie banner?

We recommend disclosing visitor identification in your privacy policy, as you would for any analytics vendor. For EU/UK traffic no identity cookie is set by the flow described above, and for other regions the identification consent was gathered on the partner network. See our GDPR-compliant tracking guide for copy you can borrow.

Where can someone opt out?

At happierleads.com/opt-out — permanent, honored across the whole network. Full details live in our privacy policy.

See It Working on Your Own Traffic

Install the pixel in two minutes and watch your first identified companies and visitors appear — compliantly — within 15 minutes.