ViralMouth
  • Studio
  • Case Studies ▾
    • Magnum Taxis
    • PDX Padel
    • DJS Taxis
    • iRide Taxis
    • All Case Studies
  • Services ▾
    • Social Content
    • Social Management
    • Campaign Creative
    • Websites
      • Web Design Stoke-on-Trent
    • SEO
    • PPC
  • Industries ▾
    • Restaurants
  • Contact
  • Start a Campaign
Legal

Cookie Policy

Last updated: 27 July 2026

This Cookie Policy explains how Kontrola Digital Ltd trading as ViralMouth ("we", "us", "our") uses cookies on viralmouth.com. For information about how we handle your personal data more broadly, see our Privacy Policy.

What cookies are

Cookies are small text files placed on your device when you visit a website. They allow the site to remember things like your preferences or whether you have visited before. Cookies are not programs and do not run code on your device.

How consent works on this site

On your first visit to viralmouth.com we show a cookie banner covering two independent controls: analytics (Rybbit) and marketing (Meta and Google Ads). Analytics runs by default because our implementation stores nothing on your device; you can switch it off at any time. Marketing tools run only if you grant consent. Once you make a choice, it is stored in a first-party cookie called vm_consent for 180 days. You can change or withdraw either choice at any time using the button below — no need to wait for the banner to appear again.

Use this to change or withdraw your consent at any time.

Cookies we use

The table below lists every cookie this site may set. Some are strictly necessary and run without consent. Marketing cookies only run if you have granted marketing consent. Analytics uses no cookie of its own — manual tracking requests are sent to Rybbit by default unless you refuse analytics, and in this configuration it sets no tracking cookie and no persistent user identifier.

Name Provider Purpose Category Duration
vm_consent ViralMouth stores your analytics and marketing preferences — URI-encoded JSON version 3 strictly necessary 180 days
vm_report_auth ViralMouth authenticates access to private client reports — only set when logging into /reports/ strictly necessary 7 days
__cf_bm Cloudflare security/bot protection — may be set by our host when protection is active strictly necessary ~30 minutes
_fbp Meta distinguishes browsers for advertising measurement marketing — consent required 90 days
_fbc Meta stores the Meta ad click identifier marketing — consent required 90 days
_gcl_au Google Ads supports advertising conversion measurement after marketing consent marketing — consent required 90 days
_gcl_aw Google Ads stores Google Ads click information when you arrive through an advert marketing — consent required 90 days

Rybbit analytics

Unless you refuse analytics, our local wrapper makes manual tracking requests to Rybbit — which we self-host at rybbit.kontroladigital.com — and sends a single pageview for the page you are on, followed only by named, non-PII interactions. These include clicks on major call-to-action buttons, service links and email links, outbound link clicks (the destination domain only, never the full URL or query string), the contact form lifecycle (started, submitted, succeeded or errored), the service selected in the contact form, the Content Shoot form lifecycle and purchase confirmation (amount and currency only — never card details or the Stripe checkout reference), and scroll-depth milestones. The wrapper also captures the page title, the origin of the referring page (scheme and hostname only, never the full referrer URL or query string), your screen dimensions and browser language, together with the network and user-agent information that the server necessarily receives as part of every request.

We do not send Rybbit your name, email address, contact-form message, full page URLs, URL query strings, or any other field value from the contact form apart from the selected service. This implementation disables session replay, automatic error tracking, single-page-application route tracking, automatic outbound tracking and query-string collection, and it does not assign a user identifier. Events are never queued or stored for later: if analytics is off when something happens, that event is simply not sent. One narrow exception exists: the Content Shoot purchase confirmation is reported while that page is open and analytics is active, including if you re-enable analytics from Cookie Settings while the confirmation page is still open.

In this configuration Rybbit sets no tracking cookie and no persistent user identifier in your browser. The data controller for analytics data remains Kontrola Digital Ltd; no analytics data is passed to a third-party analytics provider. Refusing or withdrawing analytics stops Rybbit from receiving any further events from your browser.

Meta Pixel and Conversions API

When you grant marketing consent, the Meta Pixel fires a PageView event on every page load. On contact form submission we also send a Lead event via the Meta Conversions API, which includes your email and name in SHA-256-hashed form. When you complete a Content Shoot booking, we send a Purchase event carrying the amount paid and currency, your IP address, user agent and the Meta cookie identifiers — never your name, email, card details or the Stripe checkout reference. It is sent via the browser Pixel and, when your marketing consent was already recorded when the confirmation page loaded, also via the Conversions API; when both are sent, a one-way hashed booking reference deduplicates them. Both the Pixel and the Conversions API share data with Meta Platforms Ireland Ltd; onward transfer to Meta Platforms, Inc. in the United States is safeguarded under the UK Extension to the EU-US Data Privacy Framework.

You can read Meta's privacy policy at facebook.com/privacy/policy. Rejecting or withdrawing marketing consent stops both the browser-side Pixel and the server-side Conversions API from running.

Google Tag Manager, Google Ads and Consent Mode

Cloudflare supplies the first-party Google Tag Gateway bootstrap across our site. Private report pages set every Google consent purpose to denied before it loads. The Gateway container loads there under denied consent, but no Google page-view or conversion measurement events are initiated. On public pages, before Google Tag Manager starts, Google Consent Mode v2 applies any valid choice already saved on your device. If there is no valid saved choice, analytics storage, advertising storage, advertising user data and advertising personalisation are set to denied. Until you grant marketing consent, Google Ads may receive a cookieless consent-state page ping containing the page address, the denied consent state and the network and browser information necessarily sent with a web request, such as your IP address and user agent. These pings cannot read or write Google advertising cookies and are marked as non-personalised. The Content Shoot enquiry and purchase conversion events are not sent without marketing consent.

When you grant marketing consent, the Google tag and Conversion Linker may set _gcl_au and, when you arrive through a Google advert, _gcl_aw. Google Ads then receives page and advertising measurement data. A successful Content Shoot enquiry sends only a randomly generated event identifier; it does not send any form field. A confirmed Content Shoot purchase sends the amount, currency and a one-way event identifier for deduplication. It does not send your name, email, card details or Stripe checkout reference, and checkout query parameters are removed before Google Tag Manager loads.

Google Tag Manager and Google Ads are provided by Google Ireland Ltd. You can read Google's privacy policy at policies.google.com/privacy. Withdrawing marketing consent returns Google Consent Mode to denied, deletes Google advertising cookies from this site and stops future enquiry and purchase conversion events from being sent.

Managing cookies in your browser

Most web browsers let you view, block and delete cookies through their settings. How you do this depends on your browser. Blocking strictly necessary cookies may stop parts of the site from working — for example, logging in to private client reports.

For more detail on how we handle your personal data, see our Privacy Policy.

ViralMouth

Social-first creative, websites and growth systems built to make brands impossible to ignore.

Services
Social ContentSocial ManagementCampaign CreativeWebsitesSEOPPC
Industries
Restaurants
Locations
Web Design Stoke-on-Trent
Studio
StudioCase StudiesServicesIndustriesContact
START
THE NOISE.
START A CAMPAIGN
© 2026 VIRALMOUTH. WORD OF MOUTH. TURBOCHARGED.
Privacy Policy | Terms of Service | Cookies |

COOKIES & TRACKING

We use strictly necessary cookies to run this site. Privacy-first analytics (Rybbit) also runs by default: it records page views and named on-site actions without cookies or user IDs, and you can switch it off in settings. With your consent, we use Meta and Google Ads tools to measure advertising performance. See our Cookie Policy.

COOKIE PREFERENCES

Manage how ViralMouth uses cookies on this device. You can change these at any time. See our Cookie Policy.

STRICTLY NECESSARY Required for the site to function. Includes vm_consent (stores your cookie choice) and vm_report_auth (password-protected report access). Cannot be disabled.
ANALYTICS — RYBBIT Lets us count page views and record named on-site actions (button clicks, form interactions, scroll depth). No cookies, no session replay, no user IDs, no automatic error collection, no query-string tracking. On by default because it stores nothing on your device; switch off to opt out.
MARKETING — META & GOOGLE ADS Measures advertising results with the Meta Pixel, Meta Conversions API and Google Ads conversion tracking. May set _fbp, _fbc and _gcl_* cookies and share online identifiers, page details and conversion data with Meta and Google. Off by default.