> For the complete documentation index, see [llms.txt](https://docs.flip.to/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.flip.to/docs/integrations/websites/consent-management/for-hosted-pages.md).

# For hosted pages

Flip.to hosts some guest-facing pages on our own domain (your <mark style="background-color:purple;">post-stay experience</mark>, <mark style="background-color:purple;">storyteller invitations</mark>, <mark style="background-color:purple;">certificates</mark> and <mark style="background-color:purple;">landing pages</mark>, to name a few).

Your website's consent banner doesn't reach them, so here's **how we run your consent platform** on those pages instead, and **what we need from you**.

### What's different about hosted pages

You own everything on your site, from the experiences to the data. Flip.to **only** uses first-party cookies, and acts as your data processor.

On your own experiences we read the signal your platform provides when you set up [Consent Management for your Website](https://docs.flip.to/docs/integrations/websites/consent-management-for-your-website).

**Hosted pages are different**. They're served from a branded subdomain of your own domain, pointed at Flip.to. Rather than show our own consent banner, <mark style="background-color:purple;">we install</mark> *<mark style="background-color:purple;">yours</mark>*.

Using the consent platform <mark style="background-color:purple;">account ID,</mark> we load your platform's script on hosted pages. Guests see your consent banner so that your categories govern what runs, and their choices are honored.

{% hint style="info" %}
Where no consent platform is configured, hosted pages still apply a default policy (analytics storage denied in regions that require it) before any tags load.
{% endhint %}

### Setup at a glance

1. [Send us your account ID](#send-us-your-account-id) so we can load your platform.
2. [Confirm your branded subdomain](#domains-to-add) is covered by your platform, and allow our scripts.
3. [Add our cookies](#cookies-we-set) to your cookie declaration.

{% stepper %}
{% step %}

### Send us your account ID

If you use one of the consent platforms below, we load it on hosted pages directly. We need one value: <mark style="background-color:purple;">the consent platform account ID issued when you set up a site</mark>. It isn't a secret—it's visible in the script on any page where your banner already runs. Find it using the links below and send it to your Flip.to account manager.

{% hint style="warning" %}
**It's usually the same ID as your main website.** Because hosted pages are served from a branded subdomain of your own domain, they normally sit under a domain group your platform already covers.

Some platforms issue an account ID per site or domain group, so check yours before sending it—Cookiebot and OneTrust in particular can issue a separate CBID or domain script per group.

[See Domains to add.](#domains-to-add)
{% endhint %}

**Don't see your platform?** Tell your account manager which one you use—the list below is the set we currently load, and we can look at adding others.

| Platform                     | What to send us                                                                                                       | Where to find it                                                                                                                                                |
| ---------------------------- | --------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cookiebot                    | Your CBID (Domain Group ID)                                                                                           | [Finding your CBID](https://support.cookiebot.com/hc/en-us/articles/26407199363996-Your-CBID-or-Domain-group-ID-and-where-to-find-it-in-your-Cookiebot-Manager) |
| OneTrust                     | Your domain script ID, plus both category names                                                                       | [Finding your domain ID](https://my.onetrust.com/s/article/Finding-Domain-ID-in-Cookie-Consent?language=en_US)                                                  |
| Osano                        | Customer ID and configuration ID, as `customerId/configId`                                                            | [Consent prompt setup](https://developers.osano.com/consent-prompts/getting-started)                                                                            |
| CookieYes                    | Your website key                                                                                                      | [Banner installation code](https://www.cookieyes.com/documentation/banner-installation-code/)                                                                   |
| Termly                       | Your website UUID                                                                                                     | [Embed script versions](https://support.termly.io/hc/en-us/articles/30710458065681-Termly-CMP-embed-script-versions)                                            |
| TrustArc                     | Your provisioned domain                                                                                               | [Consent Manager reference](https://developer.trustarc.com/docs/cookieconsentmanager/consentmanagerapi)                                                         |
| Usercentrics                 | Your Settings ID                                                                                                      | [Finding your Settings ID](https://support.usercentrics.com/hc/en-us/articles/18097606499100-What-is-a-Settings-ID-and-where-can-I-find-it)                     |
| Didomi                       | Public API key, or `apiKey\|noticeId` for a specific notice                                                           | [Web SDK setup](https://developers.didomi.io/cmp/web-sdk/getting-started)                                                                                       |
| Iubenda                      | Site ID and cookie policy ID, as `siteId/cookiePolicyId`                                                              | [Finding your IDs](https://www.iubenda.com/en/help/3812-where-can-i-find-my-cookie-policy-and-site-ids-2/)                                                      |
| Ketch                        | Organization and property codes, as `organization/property`                                                           | [Web implementation](https://developers.ketch.com/docs/web-implementation)                                                                                      |
| Civic Cookie Control         | API key and product code, as `apiKey/product`                                                                         | [Getting started](https://www.civicuk.com/cookie-control/documentation/getting-started)                                                                         |
| Complianz                    | Your site ID                                                                                                          | [Complianz documentation](https://complianz.io/documentation/)                                                                                                  |
| Cookie Notice (Hu-manity.co) | Your site ID                                                                                                          | [Hu-manity.co documentation](https://www.hu-manity.co/docs/)                                                                                                    |
| Google Tag Manager           | Nothing—we read consent mode straight from your container                                                             | [Consent mode in GTM](https://support.google.com/tagmanager/answer/13802165)                                                                                    |
| Other (IAB TCF)              | Tell us which platform—if it implements the IAB Transparency & Consent Framework we read it generically, no ID needed | [About the TCF](https://iabeurope.eu/transparency-consent-framework/)                                                                                           |

{% hint style="warning" %}
**Didomi uses a vertical bar.** Sending an API key and a notice ID together? Separate them with `|` rather than a slash—`apiKey|noticeId`. Every other two-part value on this page uses a slash.
{% endhint %}

#### Matching your category names <a href="#categories" id="categories"></a>

To honor a guest's choice, we need to know which of your categories covers strictly necessary cookies and which covers analytics. Most platforms use standard names and we match them automatically.

<mark style="background-color:purple;">If yours was set up with custom category names</mark>, send those along with your account ID.

{% hint style="warning" %}
**OneTrust customers: both category names are required.** OneTrust identifies categories by codes specific to your configuration (commonly `C0001` through `C0004`) so there's nothing for us to fall back on. Send the code for your strictly necessary category and the code for your analytics category along with your domain script ID. You'll find them in Cookie Consent under your site's categories.
{% endhint %}
{% endstep %}

{% step %}

### Domains to add

#### Your hosted page domain

Consent platforms only run on domains listed in your account.

{% hint style="warning" %}
**A branded subdomain is required.** Running your consent platform on hosted pages is supported only when those pages are served from your own domain via CNAME—for example `stories.yourhotel.com`. Ask your account manager to set one up before starting here.
{% endhint %}

Because the subdomain sits under a root domain your consent platform already covers, there is usually nothing new to add and no new account ID to send us. Your account manager will confirm the exact hostname.

{% hint style="warning" %}
**Cookiebot treats every subdomain as a separate domain**, each with its own subscription. If you're on Cookiebot, check whether your branded subdomain is covered by your existing plan before sending us the CBID.
{% endhint %}

Add the same hostname to your platform's cookie scanner. A scan pointed only at your website won't crawl the hosted pages, so the cookies below would be missing from the declaration it generates.

#### Scripts to allow

If your platform offers automatic script blocking, we turn it on for hosted pages. Since this feature holds back any script it doesn't recognize, you must categorize our scripts as follows:

| Domain                     | What it serves                                  | Category  |
| -------------------------- | ----------------------------------------------- | --------- |
| Your hosted page domain    | The page itself, and the scripts that render it | Necessary |
| `integration.flip.to`      | Flip.to's own tag container                     | Necessary |
| `cdn.flip.to`              | Flip.to scripts and assets                      | Necessary |
| `sa.flip.to`               | Spacetime analytics                             | Analytics |
| `www.googletagmanager.com` | Your own Google Tag Manager container           | Analytics |

{% hint style="warning" %}
**Blocking a necessary domain stops the page rendering.** It doesn't reduce tracking—Flip.to already applies your guest's choice before anything is measured. The analytics domains above are gated by that choice whether or not your platform also blocks them.
{% endhint %}
{% endstep %}

{% step %}

### Cookies we set

Most of these are named with a prefix and a suffix specific to your property or campaign. Include the asterisk (`*`) when you add them to your consent platform.

#### Analytics <mark style="background-color:$primary;">`ANALYTICS`</mark>

Set only when a guest grants analytics consent. If a guest later withdraws it, we remove any that were already set. A guest who denies analytics is still measured anonymously—we count the visit, without an identifier tied to them.

| Cookie    | What it does                                                                | Duration                |
| --------- | --------------------------------------------------------------------------- | ----------------------- |
| `sa_ft*`  | Spacetime analytics identifiers. Also stored in local storage.              | Up to 2 years           |
| `ft-it*`  | Remembers which parts of the experience a guest engaged with.               | Session, 6 or 18 months |
| `flipto*` | Set on *your* website after a guest signs up, so they aren't invited twice. | Varies                  |

#### Strictly necessary `NECESSARY`

These keep the experience working and are never used for measurement.

| Cookie                      | What it does                                                                     | Duration           |
| --------------------------- | -------------------------------------------------------------------------------- | ------------------ |
| `ftvoter*`                  | Records a photo contest vote so it isn't counted twice.                          | 6 months to 1 year |
| `ftcontestpromotioncode*`   | Remembers whether the visitor arrived as a guest, a friend or a browser.         | 6 months to 1 year |
| `ft-invitee*`               | Stops a guest being invited to the same contest twice.                           | 1 year             |
| `ftDiscoveryState`          | Local storage. Keeps the guest's plan state as they move through the experience. | Until cleared      |
| `ftReturningUserPopupState` | Session storage. Stops a message repeating within the same visit.                | Session            |
| {% endstep %}               |                                                                                  |                    |
| {% endstepper %}            |                                                                                  |                    |

### What happens once it's set up

* Your platform's script loads first on every hosted page, before anything that could set a cookie.
* Guests see your banner, with your branding, categories and language.
* Your own Google Tag Manager container is loaded on these pages too, and the guest's decision reaches it, so tags gated on `analytics_storage` behave the way they do on your site.
* Every hosted page carries a control to reopen your banner, so a guest can change their mind.
* Consent given on a hosted page is recorded by your platform as usual, so it appears in your consent records alongside everything else.

{% hint style="info" %}
**If the banner doesn't appear.** Check the hosted domain is listed in your consent platform first—that's the most common cause, and the script will load without rendering anything.

After that, check the account ID wasn't copied incompletely: a missing character, or only one half of a two-part value. Then let your account manager know so we can confirm what's stored.
{% endhint %}

### Compliance

Hosted pages operate under the same terms as the rest of the platform: first-party cookies only, Flip.to as data processor, and full ownership of collected data remaining with you. The experiences served on these pages comply with GDPR, CCPA and other privacy regulations.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.flip.to/docs/integrations/websites/consent-management/for-hosted-pages.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
