CookiePal Logo
CookiePal Logo
Log in
Consent

HubSpot Tracking Code and Cookie Consent: Common Setup Mistakes

October 1, 2026

•

Book

7 min read

HubSpot Tracking Code and Cookie Consent: Common Setup Mistakes

Table of contents

back

to the top

HubSpot Tracking Code and Cookie Consent: Common Setup Mistakes

HubSpot tracking code is easy to install. Add the script to your website, connect forms, enable tracking, and start seeing visitor activity in HubSpot.

But that simplicity can create cookie consent mistakes.

The HubSpot tracking code can collect visitor activity, use cookies, support forms, connect with ads, and help identify contacts when they interact with your website. If it loads before consent, is installed on some pages but not others, or is mixed with a separate cookie banner that does not control it properly, your setup can become messy fast.


What does the HubSpot tracking code do?

The HubSpot tracking code lets HubSpot monitor activity on your website and connect visitor behaviour to your HubSpot account.

HubSpot explains that its tracking code can collect visitor activity and that the tracking code listens to the HubSpot cookie banner to gather cookie consent status from website visitors. You can read HubSpot’s page here: Data collected by the HubSpot tracking code.

The tracking code can support page view tracking, traffic analytics, contact activity history, form tracking, chatflows, lead capture, ad conversion features, CRM attribution, and behaviour-based segmentation.

This can be valuable for marketing and sales. But because it may use cookies and process visitor activity, it needs to work correctly with your consent setup.


Mistake 1: assuming HubSpot tracking is always essential

HubSpot tracking is useful, but that does not automatically make it strictly necessary.

A visitor can usually read your website, submit a basic form, or browse a service page without being tracked for marketing analytics or CRM attribution.

The UK Information Commissioner’s Office explains that organisations using cookies and similar technologies should tell people what cookies are used, explain what they do, and get consent unless an exemption applies. You can read the ICO guidance here: Cookies and similar technologies.

For many websites, HubSpot tracking cookies should be treated as non-essential analytics or marketing cookies, depending on how they are used.


Mistake 2: using the wrong HubSpot banner type

HubSpot provides different consent banner types. This matters because not every banner gives the same level of user control.

HubSpot explains that an opt-in consent banner prevents HubSpot cookies from loading on a visitor’s browser without consent to be tracked. You can read HubSpot’s explanation here: Understand consent banner types.

If your website needs prior consent before non-essential cookies load, a simple notice banner may not be enough.

Before choosing a banner type, check whether it blocks HubSpot cookies before consent, lets users reject tracking, supports categories, lets users reopen settings, and applies to all relevant URLs.

The real question is whether the banner controls tracking properly.


Mistake 3: adding HubSpot tracking to only some pages

HubSpot consent banners can work across HubSpot-hosted pages and external pages that have the HubSpot tracking code installed. HubSpot explains this in its guide to cookie tracking settings and consent banners: Set up cookie tracking settings and consent banners.

A common issue is that the tracking code is present on the main website but missing from landing pages, subdomains, help centres, microsites, or campaign pages.

This creates inconsistent consent behaviour.

For example, the homepage may show the banner while a landing page does not, or a campaign page may load ad pixels outside the HubSpot consent setup.

Map every page where HubSpot tracking appears. Then check whether the banner works on each one.


Mistake 4: mixing HubSpot banner with another CMP badly

Some websites use HubSpot’s banner. Others use a separate Consent Management Platform.

Both approaches can work, but mixing them badly can break consent.

HubSpot’s consent banner FAQ notes that managing HubSpot cookies with a third-party banner can require a custom-developed setup unless using supported integrations. You can read the FAQ here: HubSpot consent banner FAQ.

If you use a third-party CMP like CookiePal, make sure HubSpot tracking is actually controlled by it.

Check whether the CMP blocks HubSpot tracking before consent, whether HubSpot receives the visitor’s consent status, whether cookies are created after rejection, whether users can change consent later, and whether duplicate banners appear.

CookiePal’s consent management page explains consent banners, cookie scanning, and auto-blocking, which are useful when managing scripts like HubSpot tracking.


Mistake 5: installing ad pixels through HubSpot without checking consent

HubSpot can connect with advertising tools. That can make campaign tracking easier, but it also increases consent risk.

HubSpot’s ads privacy page notes that pixels installed through Google Tag Manager will not be automatically prompted with a HubSpot cookie consent banner. You can read HubSpot’s guidance here: Understand privacy and consent while using HubSpot ads.

This is a common problem.

A team may assume HubSpot controls all tracking, while Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, or other ad scripts are firing separately.

Do not assume one consent banner controls every pixel. Test it.


Mistake 6: not configuring Google Consent Mode properly

Many websites use HubSpot alongside Google Analytics, Google Ads, or Google Tag Manager.

HubSpot provides guidance on Google Consent Mode and explains that some setups require manual implementation, especially when using a non-HubSpot banner or code snippets. You can read HubSpot’s page here: Understand and implement Google Consent Mode.

If your website uses Google tags, check whether Consent Mode is enabled, whether default consent is set before tags fire, whether consent updates after accept or reject, whether consent signals are mapped correctly, and whether tags are installed through HubSpot, GTM, or hardcoded snippets.

CookiePal’s features page highlights Google Consent Mode v2 support, scheduled scanning, auto-categorisation, multilingual banners, and cookie auto-blocking.


Mistake 7: not using consent listeners for custom code

Some websites need custom behaviour when a visitor accepts or rejects tracking.

HubSpot provides developer documentation for adding a privacy consent listener, which can help custom scripts respond to the visitor’s consent status. You can read it here: Add privacy consent listener.

This is useful when HubSpot consent choices need to control other scripts.

Do not hardcode custom scripts to fire on page load if they should wait for consent.


Mistake 8: not testing reject and withdrawal

Testing only “accept all” is not enough.

You should test first visit before any choice, reject all, accept all, category choices, return visits, consent withdrawal, HubSpot forms, chat widgets, landing pages, subdomains, and ad pixels.

Use browser developer tools to inspect cookies, storage, network requests, and tag firing.

If reject all still creates HubSpot tracking cookies, the setup needs fixing.


Mistake 9: not updating the cookie policy

If HubSpot tracking is used, your cookie policy should explain it clearly.

Your policy should cover which HubSpot cookies are used, what they do, why they are used, how long they last, whether HubSpot forms, chat, or ads are used, and how users can change consent.

For smaller teams comparing CMP options, the CookiePal pricing page can help match consent management features with website size and traffic.


Practical checklist

Before relying on HubSpot tracking, check:

  • Is the HubSpot tracking code installed on all intended pages?
  • Is the correct HubSpot consent banner type selected?
  • Does the banner block cookies before consent where required?
  • Is a third-party CMP controlling HubSpot correctly?
  • Are ad pixels installed through HubSpot, GTM, or hardcoded snippets?
  • Does reject all block non-essential HubSpot tracking?
  • Can users reopen and change consent settings?
  • Is Google Consent Mode configured where needed?
  • Are external landing pages and subdomains tested?
  • Are HubSpot cookies listed in the cookie policy?
  • Is there an owner for future HubSpot tracking changes?

Conclusion

HubSpot tracking code can be useful, but it should not be treated as a simple copy-paste script.

If HubSpot tracks visitors, sets cookies, connects to ads, or powers CRM attribution, it needs to work properly with cookie consent. The biggest mistakes usually come from assuming the banner controls everything, failing to test rejection, or mixing HubSpot with other tracking tools without a clear consent plan.

The safest approach is practical: map where HubSpot tracking runs, choose the right banner setup, test accept and reject flows, control ad pixels, configure Google Consent Mode where needed, and keep your cookie policy accurate.

Good HubSpot tracking should support better marketing without ignoring user choice.

Explore further

Elevate Your Compliance with
CookiePal Today

View PlansTry for FREE

Privacy made simple!

Powered by WESTPOINT

© CookiePal 2026. All rights reserved. CookiePal Limited is registered in the UK. Company no. 15835702.

Terms and ConditionsPrivacy PolicyGet in Touch