Clear choices about website technology.
Ask Bennett uses website technology to make the service function, protect visitors and accounts, support the Bennett experience, remember privacy choices, and understand whether pages are working properly. This policy separates technologies that are necessary from those that require a choice under applicable law.
Scope and Relationship to the Privacy Policy
This Cookie Policy applies to Ask-Bennett.com, pages hosted for Ask Bennett, the Bennett website voice and chat experience, forms, scheduling tools, account or support features, purchase and checkout flows, and other online services that link to this policy.
Ask Bennett is responsible for the first-party technologies described here. A customer that installs Bennett on its own website is ordinarily responsible for the cookie notice, consent interface, and technology choices on that customer website. Ask Bennett may act as the customer’s service provider or processor for parts of that deployment, as described in the Data Processing Addendum.
The Privacy Policy explains how personal information is collected, used, disclosed, retained, and protected. This policy provides additional detail about storage and access technologies. If mandatory law provides greater rights, mandatory law controls.
What Cookies Are
A cookie is a small data file that a website or service stores on, or reads from, a browser or device. Cookies can recognize a browser, maintain a session, remember a choice, support security, measure use, or enable a feature.
Cookies may be temporary and expire when the browser closes, or persistent and remain until their stated expiration or earlier deletion. A cookie may contain a random identifier, preference, timestamp, or technical value. It should not contain a full payment-card number, bank-account number, password, or unnecessary sensitive information.
Similar Storage and Access Technologies
This policy also covers local storage, session storage, pixels, tags, scripts, software development kits, browser or device identifiers, link decoration, server-assisted identifiers, and comparable technologies that store information on a device, access information from a device, or help recognize an interaction.
Microphone permission is controlled by the browser or device and is not itself a cookie. Voice audio, transcripts, typed questions, emails, form submissions, appointments, and payment records are also not cookies, although related technologies may help transmit or secure those interactions. Those data practices are addressed in the Privacy Policy and AI Voice Disclosure.
Device fingerprinting, session replay, cross-site tracking, or a new advertising technology should not be introduced merely because it falls within the phrase “similar technologies.” Any material new use must be evaluated, disclosed, categorized, and controlled as required by law.
First-Party and Third-Party Technologies
First-party technologies are set or controlled through an Ask Bennett domain. Third-party technologies are set or operated by another service provider whose technology appears on or supports the website, widget, form, scheduling flow, or checkout.
Third-party providers may process technical and interaction data under their own terms and privacy notices, while also acting as Ask Bennett’s service provider for specified purposes. We evaluate providers, limit access by contract and configuration where appropriate, and expect them to use information only for permitted services unless a separate lawful disclosure says otherwise.
Technology Categories
The technologies used by Ask Bennett may fall into the categories below. A single provider can support more than one category, but each live technology should be classified according to its actual purpose.
Core operation, security, session management, consent storage, load balancing, forms requested by the user, and checkout.
Remember language, display, accessibility, region, or other choices that improve a requested experience.
Enable Bennett, chat, scheduling, media, integrations, or enhanced website features.
Measure traffic, page use, errors, performance, and aggregate engagement.
Measure campaigns or personalize advertising only when separately enabled, disclosed, and lawfully controlled.
Detect abuse, fraud, malicious traffic, suspicious login activity, and payment risk.
Strictly Necessary Technologies
Strictly necessary technologies support a function the visitor expressly requests or a core operation that cannot reasonably be provided without the technology. Examples may include:
- Maintaining a secure session, routing traffic, balancing website load, or preventing malicious activity.
- Remembering a visitor’s cookie and privacy choices so the website does not repeatedly ask.
- Submitting a form, keeping information entered during a requested flow, or scheduling an appointment.
- Completing checkout, preventing payment fraud, authenticating an account, or preserving an active login.
- Providing accessibility, language, or communications functionality specifically requested by the visitor.
These technologies may be used without consent where the law permits the strictly necessary exemption. The exemption is interpreted narrowly. A technology is not strictly necessary merely because it is useful to Ask Bennett, improves marketing, or provides general analytics.
Preference and Functional Technologies
Preference technologies may remember a selected language, region, display option, accessibility choice, or other setting. Functional technologies may support Bennett’s interface, embedded media, chat, calendar, forms, or integrations that make the requested experience easier to use.
Some functional technologies may be necessary after a visitor actively requests the relevant feature. Others may require consent before activation, depending on their purpose, provider, data use, and the visitor’s location. The live consent interface should classify and block them accordingly.
Analytics and Performance Technologies
Analytics and performance technologies may help us understand visits, page paths, approximate device and browser characteristics, load time, errors, referral sources, feature use, and aggregate interaction trends. We use this information to maintain, secure, and improve the website and service.
Where consent is required, analytics technologies should remain blocked until the visitor provides a valid affirmative choice. Analytics should be configured to minimize data, shorten retention, avoid unnecessary cross-site tracking, and prevent sensitive information, form content, typed questions, voice transcripts, or payment details from being captured.
Advertising, Campaign Measurement, and Targeted Advertising
Ask Bennett does not sell personal information for money. We do not use or disclose personal information for cross-context behavioral advertising as defined by California law unless we first provide the legally required notice, choice, and opt-out method.
If advertising or campaign-measurement technologies are later enabled, they must be separately identified in the live Cookie Settings control, remain blocked until consent where required, honor legally recognized opt-out preference signals, and comply with applicable sale, sharing, targeted-advertising, profiling, children’s privacy, and sensitive-data restrictions.
Contextual advertising that does not track a person across unrelated services may be treated differently under some laws, but it must still be transparent, proportionate, and configured to avoid unauthorized personal or sensitive information.
Security, Abuse Prevention, and Fraud Technologies
Security technologies may identify malicious traffic, automated abuse, suspicious login or payment activity, repeated failed requests, unusual device behavior, or attempts to interfere with the website or Bennett. These technologies may use IP address, session identifiers, browser information, timestamps, request patterns, or fraud-risk signals.
Security use must remain proportionate to the risk, limited to authorized purposes, protected from unauthorized access, and retained only as long as reasonably necessary for security, legal, dispute, or fraud-prevention needs.
Bennett Voice, Chat, and Embedded Tools
The Bennett website experience may rely on HighLevel or LeadConnector and other approved infrastructure to load the interface, establish a session, route a voice or typed interaction, remember widget state, support microphone access, transmit questions, create transcripts, deliver notifications, or connect a requested next step.
A visitor’s decision to select “Talk with Bennett” may activate technologies needed to provide that requested feature. Where non-essential functionality or analytics is involved, the technology should follow the visitor’s consent choices and applicable regional requirements.
Bennett’s answers, voice audio, transcripts, and conversation records are governed by the Privacy Policy, AI Voice Disclosure, and customer-specific notice. They must not be inserted into advertising pixels, analytics URLs, or unrelated third-party tracking tools.
Forms, Scheduling, Accounts, and Checkout
Forms, scheduling, account, support, and checkout flows may use session, security, preference, and fraud-prevention technologies to preserve user-entered information, validate requests, prevent duplicate submissions, maintain login state, schedule an appointment, or complete a purchase.
Stripe or another disclosed payment provider may use necessary technologies on hosted or embedded payment pages to authenticate a transaction, reduce fraud, comply with financial obligations, and remember a secure checkout session. Ask Bennett does not place a full payment-card number or bank-account number into its own analytics or advertising cookies.
Technology Provider Summary
The exact provider list depends on the page and feature used. The production consent manager and live technology inventory should identify each active provider. The following services may be used when the corresponding feature is enabled:
| Provider or Service | Potential Purpose | Typical Category | When Activated |
|---|---|---|---|
| Ask BennettFirst-party website | Security, page operation, consent choices, preferences, forms, and support. | Necessary, preference, or functional. | Necessary items may operate automatically; others follow applicable choice requirements. |
| HighLevel / LeadConnectorWebsite, CRM, forms, voice, chat, and communications infrastructure | Load and operate Bennett, submit forms, route communications, maintain sessions, schedule requests, and support service delivery. | Necessary or functional; analytics only when separately configured. | When the relevant website, Bennett, form, calendar, or communications feature is used. |
| StripePayment processing and fraud prevention | Secure checkout, payment authentication, transaction processing, and fraud reduction. | Strictly necessary for requested checkout and security. | When a visitor opens or uses a Stripe-supported purchase or billing flow. |
| Hosting, CDN, email, security, and support providersApproved infrastructure | Deliver pages and media, protect the service, send requested communications, and diagnose technical issues. | Usually necessary; may vary by specific function. | When needed to deliver or secure the requested service. |
| Analytics or campaign providerOnly if enabled and listed in Cookie Settings | Measure visits, performance, attribution, or campaign results. | Analytics or advertising. | Only after consent where required and subject to applicable opt-outs. |
A provider name in this summary does not mean every provider sets a cookie on every visit. Some providers operate only on a specific page, after a user action, or through server-side processing that does not access the visitor’s device.
Consent and Choice Framework
Where law requires consent for non-essential storage or access technologies, Ask Bennett’s implementation should:
- Provide clear information before non-essential technologies activate.
- Use an affirmative action rather than silence, continued browsing, inactivity, or a preselected box.
- Allow a visitor to reject non-essential technologies without unnecessary friction.
- Offer category-level or provider-level choices when required and technically appropriate.
- Avoid making acceptance of non-essential technologies a condition of an unrelated service unless lawfully necessary.
- Record the choice and retain evidence only as long as reasonably necessary to demonstrate compliance.
- Make withdrawal as easy as giving consent and stop future non-essential use after withdrawal.
A changed purpose, new provider, materially different data use, or expired consent may require a renewed choice. Consent does not authorize a provider to use information for an undisclosed or incompatible purpose.
Managing and Withdrawing Cookie Choices
Where available, use the Cookie Settings control in the website consent banner or persistent privacy control to accept, reject, or revise non-essential categories. A revised choice applies prospectively to the browser or device used to make it.
You can also delete or block cookies through browser settings, clear local storage, manage site permissions, restrict cross-site tracking, reset advertising identifiers, or use privacy tools supported by your browser or device. Browser instructions differ by provider and version.
The production website must connect its visible Cookie Settings control to the installed consent-management platform. This page does not itself delete third-party cookies or override browser permissions.
Global Privacy Control, Universal Opt-Out Signals, and Do Not Track
Where applicable law requires recognition of a browser-based universal opt-out mechanism, including Global Privacy Control or another recognized opt-out preference signal, we will process the signal as a request to opt out of covered sale, sharing, or targeted advertising for the browser or device that sends it.
A signal may not disable technologies that are strictly necessary, do not involve covered processing, or cannot reasonably be linked to an authenticated account without additional information. Where law requires account-level application and the user is known, we will apply the request as required.
Because there is no uniform legal standard for the traditional “Do Not Track” browser setting, the website may not respond to that signal unless required by law. This does not limit rights provided through Global Privacy Control, the Cookie Settings control, or a jurisdiction-specific privacy request.
Session and Persistent Technologies
Session technologies generally expire when the browser, tab, or active session ends. Persistent technologies remain for a defined period or until deleted. A technology’s duration should be proportionate to its purpose and no longer than reasonably necessary.
Consent records may be retained long enough to remember a choice and demonstrate compliance. Security and fraud identifiers may be retained for a period proportionate to the risk. Preference, analytics, and advertising durations should be minimized and reviewed regularly.
The exact maximum duration for each active identifier must appear in the live Cookie Settings inventory. Provider defaults do not excuse Ask Bennett from configuring a shorter lawful duration when appropriate.
Live Cookie and Technology Inventory
The authoritative identifier-level inventory should be available through the website’s Cookie Settings control and should state, for each active item:
- The cookie, local-storage, pixel, tag, script, SDK, or other identifier name.
- The provider and domain responsible for it.
- Whether it is first party or third party.
- Its specific purpose and legal category.
- When it activates and whether consent is required.
- Its maximum lifespan or retention period.
- How the visitor can reject, withdraw, or otherwise control it.
Technology names and durations can change when a provider updates its software or a business changes configuration. Ask Bennett should rescan the production site, reconcile the results with this policy and the consent manager, and remove unknown or unnecessary technologies.
Effects of Disabling or Deleting Technologies
Rejecting non-essential technologies should not prevent access to ordinary public content. Certain optional analytics, personalization, embedded media, campaign measurement, or enhanced functionality may be unavailable or less accurate.
Blocking strictly necessary technologies may prevent secure login, checkout, form submission, appointment scheduling, consent storage, fraud prevention, or the Bennett experience from functioning correctly. Deleting a consent cookie may cause the website to ask for choices again.
Regional Cookie and Tracking Standards
Ask Bennett uses a protective cross-border baseline. The summary below is not exhaustive and does not replace market-specific legal review.
| Region | General Standard | Ask Bennett Implementation |
|---|---|---|
| European Union and IrelandePrivacy rules and GDPR | Consent is normally required before storing or accessing non-essential information on a device. Strictly necessary technologies may qualify for a narrow exemption. Consent must meet GDPR standards. | Block non-essential categories before consent, provide clear purposes and durations, use affirmative granular choices, and make withdrawal easy. |
| United KingdomPECR and UK data protection law | PECR applies to cookies and other storage and access technologies, including pixels, scripts, local storage, and certain tracking methods. Consent or a specific legal exemption is required. | Follow the current ICO guidance, identify each technology, apply exemptions narrowly, and maintain a usable consent and withdrawal mechanism. |
| United StatesFederal and state privacy and consumer law | Requirements vary. State laws may regulate sale, sharing, targeted advertising, profiling, sensitive data, notices, and universal opt-out signals. Deceptive tracking practices may also violate consumer-protection law. | Provide transparent notice, avoid undisclosed cross-context advertising, honor recognized opt-out signals where required, and provide state privacy rights through the Privacy Policy. |
| CanadaFederal and provincial privacy law | Online tracking that involves personal information must have an appropriate purpose, meaningful notice, and valid consent. Limited opt-out consent may be appropriate for some behavioural advertising only when regulator conditions are met. | Use clear notice, easy controls, data minimization, no behavioural advertising directed at children, and express consent for sensitive or unexpected uses. |
| AustraliaPrivacy Act and Australian Privacy Principles | Tracking pixels and similar tools must satisfy collection, transparency, purpose, disclosure, data-quality, security, sensitive-information, and overseas-transfer obligations. | Provide clear collection information, minimize data, prevent sensitive information from reaching pixels, conduct provider due diligence, and use consent where required. |
| New ZealandPrivacy Act 2020 and Information Privacy Principles | Organizations must be open about collection, use information for a lawful and necessary purpose, protect it, maintain accuracy, and manage overseas disclosures. | Explain tracking clearly, minimize collection, provide meaningful controls, respect supported privacy preferences, and apply the Privacy Policy to personal information collected through technologies. |
Where several laws apply, Ask Bennett may apply the stricter practical control to simplify a cross-border experience. Customer websites using Bennett remain responsible for their own audience, technology stack, consent interface, and local legal requirements.
Children and Young People
Ask Bennett is designed for business websites and is not intended to use advertising or profiling technologies to target children. We do not knowingly sell or share personal information of individuals under 16 for cross-context behavioral advertising.
A customer directing Bennett or a website experience to children must obtain specialized legal review, use age-appropriate notices, minimize technologies, disable unnecessary profiling and advertising, obtain parental authorization where required, and follow applicable children’s privacy and design rules.
Information Disclosure and International Processing
Technology providers may receive IP address, browser or device information, identifiers, timestamps, page or feature interactions, security signals, consent choices, and other data needed for the disclosed purpose. We do not authorize providers to receive passwords, full payment credentials, voice transcripts, typed questions, form content, or sensitive information through an unrelated analytics or advertising technology.
Providers may process information in the United States or other countries. International transfers and provider safeguards are described in the Privacy Policy and Data Processing Addendum. A cookie choice does not waive a person’s privacy rights or authorize an unlawful overseas disclosure.
Security, Retention, and Technology Governance
We use reasonable administrative, technical, and contractual safeguards for information collected through website technologies. No internet service is completely secure, and cookies stored on a user-controlled device may be affected by the security of that device and browser.
Ask Bennett should maintain an approved tag and script inventory, restrict publishing permissions, review provider contracts, scan production pages, test consent blocking, minimize identifiers, prevent sensitive-data leakage, remove abandoned technologies, and document material changes.
Information associated with a technology is retained according to its purpose, provider setting, legal obligations, security needs, dispute requirements, and the retention framework described in the Privacy Policy.
Changes to This Cookie Policy
We may update this policy when laws, regulatory guidance, website features, providers, technologies, purposes, retention periods, or business operations change. The revised policy will display a new effective date.
Where a change requires new consent, we will request a new choice before the affected non-essential technology is used. Materially different processing will not be treated as authorized merely because a visitor accepted an older, narrower purpose.
Cookie and Privacy Contact
Questions about cookies, similar technologies, consent choices, a provider, or an identifier found on an Ask Bennett page may be sent to:
Ask Bennett
United States
Email: [email protected]
Phone: (888) 515-8088
Use the subject “Cookie Policy Question.” Include the page address, browser and device type, approximate date, the technology or identifier involved, and enough detail for review. Do not include passwords, full payment credentials, authentication codes, or unnecessary sensitive information.