Skip to Content
LegalTracker Privacy & Compliance

Tracker Privacy & Compliance

This page is the full public disclosure for the Warm AI visitor-tracking scripts. It is intended for website visitors, customer security and privacy teams, regulators, and search-engine or ad-network reviewers performing diligence. If you’re a customer looking for practical CMP setup guidance, see the Cookies & Consent guide instead.

Last reviewed: 2026-07-24. Ported from the previous location at getwarmai.com/tracker. For material changes to what any script collects, we refresh this page and the changelog in §14. For urgent regulator or security queries, email support@getwarmai.com.

The tracker covered:

  • pulse-oem-1.1.8.js: the standard install for all customers, served per-tenant from cdn.menoinfra.com/p/<tracking-id>.js.

The legacy warm.js variant (served from assets.warmai.uk/warm.js) was retired on 2026-07-20; that URL now returns HTTP 410 Gone and the file has been removed from our CDN. See §14 for the deprecation timeline.


1) Identity of the controller / processor

Warm AI Ltd, a company registered in England and Wales.

When the tracker collects personal data on behalf of a customer site, Warm AI Ltd acts as a processor for that customer (the controller).

  • Registered office: 107 Highfield Lane, Oving, Chichester, PO20 2NN, United Kingdom.
  • ICO registration: ZC135250 (registered 28 April 2026, valid to 27 April 2027).
  • Data Protection contact: support@getwarmai.com.

2) Purpose of the scripts

The trackers enable Warm AI’s customers to identify the companies visiting their websites, so their B2B sales teams can prioritise outreach.

For a subset of US visitors, the trackers additionally surface individual identity signals (LinkedIn URL, name, job title, business email, and company firmographics) via a server-to-server data pipeline. This person-level path is enforced US-only at the resolver layer, and only fires where our identification providers have coverage for the visitor’s IP.

All scripts are loaded by Warm AI’s paying customers on their own websites under contract.


3) What the scripts collect

pulse-oem-1.1.8.js collects the following, sent to our beacon endpoint:

  • A session token (UUID v4) stored in sessionStorage under _p_session. 30-minute idle TTL. Cleared when the browser tab closes.
  • Page view events: url, path, title, referrer.
  • Active time on page (active_seconds, only counted when the tab is visible and the visitor has interacted within the last 30 seconds).
  • UTM parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content) read from the URL only, and only on the first beacon of a session.
  • User-agent string.
  • IP address (attached server-side by our edge, used for company-level and person-level identification via the providers noted in §8).

Person-level identification additionally receives, from our third-party identification providers via a server-to-server webhook (US visitors only, subject to provider coverage):

  • LinkedIn profile URL
  • First and last name
  • Job title
  • Company name, domain, industry, employee-count range, estimated revenue
  • Business email
  • City, state, postal code

Non-US visitors are filtered at the resolver layer before any person-level data is exposed. The webhook does not fire for non-US visitors, and no person-level data about non-US visitors reaches Warm AI.


4) What the scripts do NOT do

  • No HTTP cookies. pulse-oem-*.js does not call document.cookie.
  • No localStorage writes. The tracker may read localStorage if a CMP such as Framer’s built-in banner stores its own consent state there, but it never writes to it.
  • No reading of form-input values, no email capture, no field scraping.
  • No fingerprinting. No canvas, WebGL, font enumeration, or audio fingerprinting.
  • No cross-customer tracking. Each customer’s data is siloed by tracking ID.
  • No third-party pixel loading on the browser side for person-level identification. Person-level match delivery is entirely server-to-server via a provider webhook; nothing loads in the visitor’s browser beyond our own tracker file.
  • Beacons for pulse-oem-*.js go only to t.menoinfra.com. This is Warm AI infrastructure.

The tracker’s source is published at github.com/Nudge-AI-UK/warmai-tracker  so any of these claims can be independently verified by reading the code.


5) Lawful basis (UK GDPR / EU GDPR Article 6)

Customer sites loading the trackers rely on Article 6(1)(f), legitimate interest: B2B identification of company-level visitors for the customer’s sales workflow. The balancing test we and our customers rely on:

  • Data minimised to what is necessary for company-level identification.
  • No profiling of individuals beyond their company affiliation on the standard tracker; person-level identification is US-only and provider-gated.
  • B2B context: visitors interacting with a B2B website have a reasonable expectation of being contacted in connection with their employer.
  • Opt-out available via DNT, GPC, browser-level controls, or by contacting the customer site or Warm AI directly (see §11).

For consent-required jurisdictions (including UK, EU/EEA, Switzerland, Quebec, Japan, and a broad set of other GDPR-parity regimes across the Americas, APAC, MENA, and Africa), the tracker enforces a Tier B posture at the edge: it waits for a signal from the site’s CMP before firing any beacon. The full jurisdiction list is enforced in the Cloudflare Worker and updated as new regulations come into force. See the Cookies & Consent guide for the tier framework and CMP support, and email support@getwarmai.com for the current full jurisdiction list.


6) Cookies and storage notice (PECR / ePrivacy)

The tracker uses sessionStorage only. sessionStorage is cleared when the browser tab closes and is treated as necessary or strictly necessary by every cookie consent framework we are aware of (UK PECR, EU ePrivacy Directive, CCPA).

In principle no cookie banner is required for the tracker itself. In practice, because the tracker enables company-level identification and (US-only) person-level identification, most customers in consent-required jurisdictions still install a CMP and gate the tracker behind it. The tracker auto-detects the major CMPs (see the Cookies & Consent guide for the list) and only fires when consent is granted.


7) Data retention

Session events and identification records are held as product logs and security telemetry on Warm AI’s infrastructure. Retention follows our Privacy Policy  §9: typically 30 to 180 days for product logs and security telemetry. Aggregate (non-identifying) analytics may be retained beyond that. Specific retention periods for a customer’s own account can be requested at support@getwarmai.com.

Where Warm AI acts as processor for a customer, the customer (as controller) sets the applicable retention window in their contract and their own privacy policy.


8) Sub-processors and infrastructure

When the tracker fires, the following sub-processors may receive data:

  • Cloudflare, Inc.: DNS, R2 storage (script delivery), Workers (edge proxy and beacon ingestion). Global edge network. International transfers governed by EU Standard Contractual Clauses with the UK Addendum.
  • Supabase, Inc.: Postgres database and edge functions, used for event storage and processing. Currently US region.
  • Third-party IP-to-company identification providers under contract with Warm AI, used to resolve visitor IPs to company records. These providers receive the visitor’s IP address only. They do not receive personal data.
  • Third-party person-level identification providers under contract with Warm AI (for US visitors on OEM-enabled tracker builds only), which return matched personal data (LinkedIn URL, name, job title, business email) via a server-to-server webhook. These providers receive the visitor’s IP address and user-agent, geofence to US ranges on their side, and only return data for matched visitors.

For our current named list of identification-provider sub-processors, including each provider’s DPA and Trust Centre links, email support@getwarmai.com. We maintain it as a separate document because provider composition changes as we onboard, deprecate, or renegotiate contracts.


9) International transfers

Warm AI Ltd is established in the UK. Some sub-processors are established in the United States. Transfers from the UK and the EEA to the US are made under the applicable adequacy mechanism: UK International Data Transfer Agreement (IDTA), EU Standard Contractual Clauses, and where applicable the EU-US and UK-US Data Privacy Framework.


10) Data subject rights

Visitors and identified individuals have the right to:

  • Access the personal data held about them (Article 15).
  • Rectify inaccurate data (Article 16).
  • Erase their data (Article 17).
  • Restrict processing (Article 18).
  • Object to processing based on legitimate interest (Article 21).
  • Receive their data in portable form (Article 20).

Send a request to support@getwarmai.com. We acknowledge within 5 working days and respond in full within 30 days. Where Warm AI acts as processor for a customer, we route the request to the relevant customer (controller) and support their response.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office: ico.org.uk/make-a-complaint .


11) Visitor-side opt-out

Consent-based opt-out (Tier B jurisdictions). In consent-required jurisdictions, the tracker waits for the site’s CMP to grant consent before firing. Declining consent in the site’s cookie banner is the primary opt-out mechanism: the tracker will not fire beacons and no identification will occur.

Person-level identification opt-out. Email support@getwarmai.com with your email address, LinkedIn URL, or IP address. We add the identifier to a global exclusion list at the resolver layer, so you won’t appear in person-level identifications on any Warm-tracked site. We honour opt-outs indefinitely unless you later request re-inclusion.

Company-level identification opt-out. Company-level identification is IP-based and stateless (nothing is stored in your browser). To exclude a specific IP range from company-level identification, email support@getwarmai.com with the IP or CIDR block.

CCPA “Do Not Sell or Share My Personal Information”. Send a request to support@getwarmai.com. We process it as a global opt-out on our resolver layer as above.

On DNT and GPC: the tracker does not currently short-circuit on the browser-level Do Not Track (DNT) or Global Privacy Control (GPC) signals. Neither signal is legally binding in the UK or EU (both are advisory), and the tracker’s Tier B consent gating (which is legally binding) supersedes it in every consent-required jurisdiction. Please use the site’s CMP or the direct email routes above to exercise your opt-out.


12) Customer-side opt-out

Customers can stop loading the tracker at any time by removing the script tag from their site. There is no friction, no contractual lock-in, and no residual tracking after removal. Existing event data linked to the customer’s account can be deleted on request via support@getwarmai.com.

Customers can also pause tracking on their account (which server-side rejects incoming beacons even if the script tag is still present) via the Warm dashboard or by contacting support.


13) Children’s data

Warm AI’s product is for B2B websites and is not designed for or directed at children. We do not knowingly collect data about children.


14) Changes to the scripts

When any of the scripts changes in a way that affects what data it collects or how, we update this page. Changelog:

  • warm.js retirement (2026-07-20): the legacy warm.js variant was fully retired. The Cloudflare Worker now returns HTTP 410 Gone for assets.warmai.uk/warm.js and related legacy paths, and the file has been removed from our CDN. All customers now use pulse-oem-*.js via the OEM install path at cdn.menoinfra.com/p/<tracking-id>.js.
  • pulse-oem-1.1.8 (2026-07-15, promoted to global default 2026-07-24): three-tier geo-fence added. Tracker resolves visitor country + region at the edge and routes to Tier A (US, Canada excluding Quebec, India until 2027-05-13: fires immediately, no CMP required), Tier B (UK, EU/EEA, Switzerland, Quebec, Japan, and a broad set of other consent-required jurisdictions across the Americas, APAC, MENA, and Africa: consent-gated), or Tier C (currently CN, RU, VN, IR, KP, SY, CU: silent bail, no beacons). Any jurisdiction not explicitly in Tier A or Tier C falls to Tier B by default. No change to what data is collected; adds enforcement of jurisdictional posture before any beacon fires.
  • pulse-oem-1.1.7 (2026-07-15): expanded CMP support to nine auto-detected consent management platforms: Cookiebot, OneTrust, CookieYes, Transcend, Framer built-in, HubSpot, Klaro, Google Consent Mode v2, and IAB TCF v2. Optional Klaro OSS banner auto-injection for customers without a CMP (opt-in per account, disabled by default).
  • safe-3.0.0 rollback (2026-05-29): reverted the 2026-05-28 localStorage change on the trackers. All trackers returned to sessionStorage-only, tab-scoped session identity with no persistent device_id. Reason: suspected classifier trigger from a Google Ads compliance re-scan.
  • pulse-oem (2026-06-11): first OEM variant. Adds server-to-server delivery of US person-level identifications from third-party providers under contract. Sub-processors §8 and visitor opt-out §11 updated accordingly.

15) Security


16) Contact

For all queries (privacy, security, data subject rights, regulatory): support@getwarmai.com. We respond within 48 hours on UK business days.

Last updated on