Skip to content

Legal

Cookie Notice / Tracking Disclosure

Exactly what trestlsolutions.com measures, the one optional cookie it can set, how we count visitors without cookies, and how to change your choice.

Last updated September 30, 2026

This notice describes the cookies and tracking on trestlsolutions.com, which Trestl Health Solutions, LLC operates. We designed our analytics to answer one question, which parts of our website are useful, without following people around the internet.

1. Summary

  • By default our website sets no cookies and measures visits without storing anything on your device.
  • If you are in the EEA, the UK, or Switzerland, it measures nothing until you choose “Accept.”
  • With your permission it sets one optional first-party cookie to recognize a return visit and, if you send us a request, connect it to your earlier visits.
  • We use no advertising, social-media, or third-party analytics trackers, and no session recording.
  • A Global Privacy Control or Do Not Track signal is treated as a refusal of the optional cookie and, in the EEA, the UK, and Switzerland, of all measurement.

2. Cookies we use

NamePurposeTypeDuration
trestl_consentRemembers whether you accepted or rejected the optional cookie (in the EEA, the UK, and Switzerland, whether we may measure your visits at all), so we do not ask again.Strictly necessary; first-party12 months
trestl_vidA random identifier that lets us recognize a return visit on a later day and, if you submit a request, connect it to your earlier visits. Set only after you choose “Accept,” and replaced with a new one when you submit a request.Analytics (optional); first-party13 months

3. What our analytics measure

Our analytics are built and run by Trestl; no analytics company receives the data. For each page view we record the following (in the EEA, the UK, and Switzerland, only after you choose “Accept”):

EventWhat is recorded
Page viewPage path; the referring site (its address without query strings); campaign tags in the link (utm_source, utm_medium, utm_campaign, utm_term, utm_content)
Call-to-action clickWhich button or link was used (for example, the “Request a demo” button in the page header)
Scroll depthReaching 25, 50, 75, or 100 percent of the page
Time on pageSeconds the page was visible
Form started / submittedThat the contact form was started or submitted (not what you typed)
File downloadWhich file was downloaded
Outbound linkThe website you left for (its domain only)

With every event we also record the time, a coarse device class (mobile, tablet, or desktop), your browser and operating-system family, your country as reported by our hosting provider’s network, whether your browser sent a Global Privacy Control or Do Not Track signal, and the pseudonymous daily visitor code described next. Query strings are removed from page and referrer addresses, and anything that looks like an email address or long number is discarded rather than stored.

4. How we count visitors without cookies

To tell one visitor from another within a day, our server combines your IP address and browser user-agent string with the date and a random salt, then applies a one-way hash. We store the hash only; your IP address and full user-agent string are used for that calculation and not stored with the analytics. (On the way to our server they pass through an encrypted message queue that deletes each message once processed, or after 2 days if it cannot be delivered.) Each day’s salt is held only in memory, never in our database, backups, or logs, and is erased at the end of the following day (midnight UTC, at most 48 hours). The same visitor produces a different, unconnected code each day; once a day’s salt is erased, that day’s codes cannot be recalculated, and an event that reaches us after that gets a one-off code that links to nothing. Page loads and requests to /api/t are left out of our hosting logs. People who share a network address and the same user-agent string (browser version and device), such as colleagues in one office, share the same daily code. If you are in the EEA, the UK, or Switzerland, none of this happens until you choose “Accept.”

If you submit a request through our contact form, we keep it with the visit in which you sent it, if we recorded one, under the same code (parts of that record can be missing if our systems were unavailable when you visited). With the optional cookie, we can also include your earlier visits, on the same day or before. About a day after the request (normally within 27 hours) we cut its links to our usage records, the day’s code and the cookie’s identifier; the record of the visit stays with the request.

5. Other technologies

  • Hosting logs. Our hosting provider (Google Cloud) records standard request logs, including IP address, user-agent string, and referring page, only for requests that send us data, such as our contact form, for security and operations, kept for 30 days; page loads and analytics requests to /api/t are not logged. Records of requests our firewall blocks (suspected attacks, and visitors who exceed our request-rate limit) are kept for up to 7 years as security records.
  • Bot protection. When enabled, our contact page loads Cloudflare Turnstile as soon as it opens, to check that a submission comes from a person. Cloudflare receives your IP address and the browser signals needed for that check and processes them under its own terms and privacy policy.
  • The Trestl platform. The separate, sign-in-only Trestl platform application uses strictly necessary session cookies to keep authorized users signed in. It does not use advertising or third-party analytics cookies.

6. Your choices

  • Change your mind at any time with “Your privacy choices” in the website footer. Choosing “Reject” deletes the optional cookie and, in the EEA, the UK, and Switzerland, stops all measurement.
  • Global Privacy Control / Do Not Track. If your browser sends either signal, we never set the optional cookie and we do not show the banner. Outside the EEA, the UK, and Switzerland, cookieless measurement (section 4) still runs and records that your browser sent the signal; in those countries, nothing is measured.
  • Browser settings let you block or delete cookies. The website still works with cookies blocked, but the privacy banner then appears on each visit, because your choice cannot be remembered. In the EEA, the UK, and Switzerland, blocking cookies also means we measure nothing, because your acceptance cannot be remembered either.
  • Cookieless measurement (outside the EEA, the UK, and Switzerland) helps us understand aggregate use of the site. It does not identify you unless you send us a request, which we keep with the visit in which you sent it. To object to it, email douglask@trestlsolutions.com, or use a browser privacy extension that blocks requests to /api/t.
  • Where you are is the country our hosting provider’s network reports for your connection. A VPN can change it, and if the network reports no country, you are treated as outside the EEA, the UK, and Switzerland. If the website cannot find out which rule applies, it measures nothing until you accept.

7. More information

Our Privacy Policy explains how long we keep information and your rights. We will update this notice before we change what we measure.