Skip to content
Your account

Cookies, analytics and your tracking choices

Which technologies GetClinic actually runs, why none of the third-party ones run in private medical areas, and how consent and browser opt-out signals are handled.

4 min read

No third-party analytics, session-replay or advertising technology runs in authenticated medical-document, consultation, private message or other private health-information areas, regardless of your consent state. Section 6 of the Cookie Policy puts it that way deliberately: this is not something you switch on or off, and consenting to analytics elsewhere on the site does not turn it on there. Only necessary security, fraud-prevention and service-delivery technologies operate in those areas.

The four categories

Section 3 sorts everything into four categories.

CategoryPurposeTypical status
Strictly necessary and securityOperate core features, authenticate sessions, prevent fraud and abuse, route traffic, remember privacy choicesGenerally active where necessary to provide or secure the service
Preferences and functionalRemember language, display, region and other non-essential preferencesSubject to applicable consent and choice rules
Analytics and performanceUnderstand aggregate use, reliability, errors and performanceEnabled only where the law and your consent state permit
Advertising and measurementMeasure or support advertising on public, non-medical surfacesDisabled unless lawfully enabled and permitted by consent or opt-out state

What is actually running

Section 6 names the technologies rather than describing them generically. The Cookie Settings inventory remains the operational source of truth for exact identifier names and durations.

Strictly necessary and security: GetClinic session and authentication identifiers, including those set through GetClinic's identity provider; a synthetic-monitoring identifier, gc_synthetic, used to exclude GetClinic's own automated monitoring traffic from measurement; Cloudflare Turnstile, protecting forms against automated abuse; and Stripe, for payment integrity and fraud prevention when you pay.

Preferences and functional: display currency (gc_currency), language (gc_locale) and region (gc_region), retained for up to twelve months; a comparison-list identifier (gc_compare); and an anonymous landing-page attribution identifier (gc_lp_anon).

Analytics and performance: Google Analytics 4, loaded through Google Tag Manager, and Microsoft Clarity. Google identifiers may persist up to twenty-four months, Microsoft Clarity identifiers up to twelve months.

Error diagnostics: Sentry, capturing application errors and performance diagnostics so faults can be found and fixed. It is used for reliability, not advertising or audience building.

GetClinic does not currently operate third-party advertising or cross-context behavioural advertising technologies on patient-facing surfaces. If that changes, Section 6 requires the technology to be identified in the Cookie Settings inventory and in an updated policy first.

See the providers behind these services.

Treatment preferences are treated as health data

GetClinic may store a treatment-interest preference, gc_treatment_prefs, so you do not have to re-enter it. Because its contents can reveal a health interest, Section 6 treats it as health-related information under the Patient Privacy Policy and the Consumer Health Data Privacy Policy, rather than as an ordinary functional preference.

There is a matching rule about what leaves the site. GetClinic does not send treatment or procedure identifiers, clinical questionnaire content, or page addresses that reveal a specific treatment or condition to an analytics or advertising provider. Where a page address would reveal that information, it is generalised or removed before any analytics event is sent.

See how health inferences are protected in the US.

Section 5 says that where the law requires prior consent for a non-essential category, GetClinic keeps that category disabled until consent is obtained. Section 6 goes further and closes the usual loophole: where prior consent is required, the analytics technologies are not loaded at all until that consent is given, and setting a consent signal without withholding the technology is not sufficient.

Accepting GetClinic's contractual terms is not consent to optional cookies. The Cookie Policy states that in its opening paragraph, and Section 12 of the Patient Privacy Policy repeats it.

You can change your available choices through the Cookie Settings interface. Withdrawing consent does not make earlier processing unlawful where it was lawful at the time, but GetClinic stops future use of the withdrawn category as the law requires.

Browser and device signals

The two common browser signals are handled differently, and Section 12 of the Patient Privacy Policy explains why.

Do Not Track: there is no common industry standard for how a website must respond to it, and GetClinic does not currently respond to Do Not Track.

Global Privacy Control: GetClinic does honour a legally recognised Global Privacy Control signal where applicable law requires it.

Blocking cookies in your browser is always available, but blocking strictly necessary technologies can stop account login, security controls and payments working. Browser settings do not always control mobile SDK identifiers, so the Cookie Settings interface is the more reliable control where it is available.

GetClinic is a technology marketplace. The clinic you choose provides your healthcare and is responsible for it. This is general information about how GetClinic works, not medical advice.

See the full Cookie Policy. See how to exercise a privacy right.

Didn't find what you needed?

Browse the help centre, or write to us and a coordinator will pick it up.

Back to help centreEmail a coordinator
Cookies, analytics and your tracking choices · GetClinic