Table of contents
1. What is a cookie?
A cookie is a small text file that a website places on your device (computer, tablet or mobile) when you visit it. Cookies allow the site to recognise your device, remember preferences and measure how the site is used. "Similar technologies" include pixels, local storage and device fingerprinting — for simplicity we refer to all of them as "cookies" in this policy.
2. Your choices
You can accept all cookies, reject non-essential cookies, or customise your preferences category by category. Strictly necessary cookies cannot be disabled because the website cannot function without them.
You can change or withdraw your consent at any time by clicking "Manage my preferences" at the bottom of any page of the website. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
3. Categories we use
3.1 Strictly necessary always on
Required for the website to function — load balancing, security, session state, and remembering your cookie choices. These cookies do not collect information for marketing purposes.
3.2 Preferences optional
Remember choices such as your language, region or recently viewed plans to give you a smoother experience across visits.
3.3 Statistics & analytics optional
Help us understand how visitors use the website — which pages are most read, where people drop off, and how our content performs — so we can improve it. We use aggregated, pseudonymised data wherever possible.
3.4 Marketing & retargeting optional
Measure the effectiveness of advertising and allow us (or our partners) to show you relevant Sanitas-related ads on other websites and platforms after you leave ours. These are only set if you explicitly consent.
4. Full cookie list
The table below describes the main cookies we use. Exact names and lifetimes may change as we update our stack; you can see the current list at any time via the "Manage my preferences" panel.
| Name | Provider | Purpose | Category | Expiry |
|---|---|---|---|---|
| shi_session | spanish-healthinsurance.com | Maintains your session and quote-form state | Necessary | Session |
| shi_cookie_consent | spanish-healthinsurance.com | Stores your cookie-consent choices | Necessary | 12 months |
| shi_csrf | spanish-healthinsurance.com | Security — prevents cross-site request forgery on forms | Necessary | Session |
| shi_lang | spanish-healthinsurance.com | Remembers your selected language (EN/ES) | Preferences | 12 months |
| _ga, _ga_* | Google Analytics 4 | Distinguishes visitors and measures site usage | Statistics | Up to 24 months |
| _clck, _clsk | Microsoft Clarity | Heatmaps and session replay to improve usability | Statistics | 12 months / 1 day |
| _fbp | Meta (Facebook) | Tracks conversions and supports retargeting campaigns | Marketing | 3 months |
| _gcl_au | Google Ads | Conversion tracking for Google Ads | Marketing | 3 months |
| li_sugr, bcookie | LinkedIn Insight | Conversion tracking and audience building on LinkedIn | Marketing | Up to 12 months |
| hubspotutk | HubSpot | Identifies and tracks visitors across sessions; used by the chat widget to recognise returning users and preserve conversations | Preferences | 13 months |
| messagesUtk | HubSpot | Identifies returning chat visitors so conversation history is preserved | Preferences | 13 months |
| hs-messages-is-open | HubSpot | Stores whether the chat widget is open or closed | Preferences | 30 minutes |
| __hstc | HubSpot | Main HubSpot tracking cookie — records time of first and last visits, current session, and traffic source for marketing attribution | Marketing | 13 months |
| __hssc | HubSpot | Tracks session length and whether to increment the session counter | Marketing | 30 minutes |
| __hssrc | HubSpot | Determines if the browser was restarted between sessions | Marketing | Session |
| _fbc | Meta (Facebook / Instagram) | Stores the Facebook click identifier (fbclid) when a visitor arrives via a Facebook or Instagram ad | Marketing | 90 days |
| fr | Meta (Facebook / Instagram) | Delivers and measures the effectiveness of Facebook and Instagram advertising | Marketing | 90 days |
| _ttp | TikTok | Unique identifier used by TikTok Pixel for conversion tracking and ad attribution | Marketing | 13 months |
| _tt_enable_cookie | TikTok | Confirms TikTok Pixel is enabled and that the user has consented | Marketing | 13 months |
| tt_sessionid | TikTok | Session-level tracking for TikTok ad measurement | Marketing | Session |
| _gcl_aw | Google Ads | Stores the Google Ads click identifier (GCLID) for conversion attribution | Marketing | 90 days |
| IDE | Google (DoubleClick) | Used for targeted advertising across the web via Google's Display Network, and to measure ad effectiveness | Marketing | 13 months |
5. Third-party cookies
Some cookies are set by third parties whose services we embed, such as analytics, advertising platforms, chat tools or video players. These providers act as independent controllers or our processors (depending on the service) and are subject to their own privacy and cookie policies. Where relevant we link to them:
- Google (Analytics, Ads, Tag Manager, reCAPTCHA)
- Microsoft (Clarity)
- Meta (Facebook / Instagram Pixel)
- LinkedIn (Insight Tag)
- HubSpot (Live chat, CRM, email marketing)
- TikTok (TikTok Pixel)
6. Legal bases
We rely on the following legal bases for cookies under GDPR and Article 22 of LSSICE:
- Strictly necessary cookies: our legitimate interest in operating a secure, functional website (Article 6(1)(f) GDPR; Article 22.2 LSSICE exception).
- All other categories: your specific, informed and freely given consent (Article 6(1)(a) GDPR; Article 22.2 LSSICE).
7. Retention & international transfers
Cookie lifetimes vary by cookie and are listed in the table above. When third-party providers (e.g., Google, Meta, Microsoft, LinkedIn, HubSpot, TikTok) are based outside the EEA, transfers are protected by Standard Contractual Clauses, the EU–US Data Privacy Framework where applicable, and additional technical measures. TikTok's European operations are based in Ireland; transfers are additionally governed by SCCs under their EEA Data Transfer Impact Assessment. Details are in our Privacy Policy.
8. Managing cookies in your browser
In addition to our on-site preferences panel, you can block or delete cookies directly from your browser. Note that blocking strictly necessary cookies may break core site features.
To opt out of cross-site advertising more broadly, see youronlinechoices.com (EU).
9. Changes to this policy
We may update this Cookie Policy when we add, remove or change cookies, or when regulation evolves. The current version is the one published on this page with the "Last updated" date shown above. Material changes will be highlighted via the cookie banner at your next visit.
10. Contact
Spanish Health Insurance
Stephen Paul Gregory — Exclusive Insurance Agent of Sanitas S.A. de Seguros
C/ Alcalde Clemente García 19, 5, 30169 San Ginés, Murcia, Spain
NIE: Y2155969D · DGSFP reg. C0320Y2155969D
Email: info@spanish-healthinsurance.com
Sanitas Data Protection Officer: dpo@sanitas.es