What the Connect web SDK collects

Before you launch, you need clear answers to three questions: what does the SDK collect by default, what can you turn off, and what do its cookies do. This page covers all three.

DOM capture depends on your subscription tier and how you initialize the SDK

Whether the SDK captures page content (DOM data) for session replay depends on your subscription tier — and specifically, on which initialization method you use:

MethodTierDOM capture by default
TLT.initPro()Connect ProOff. Automatically disables DOM capture, mouse-movement tracking, and the overstat module. Only behavioral signals (page views, cart actions, orders, and so on) are collected — Pro doesn't include session replay or the Behavior Studio.
TLT.initPremium()Connect PremiumOn. The Behavior Studio is part of Premium, so in addition to behavioral signals DOM capture is enabled out of the box.
TLT.initUltimate()Connect UltimateOn. In addition to behavioral signals, Ultimate includes both the Behavior Studio and session replay, so DOM capture is enabled by default.
TLT.initLibAdv()Any tierYou control it directly. This is the advanced/manual init method — use it to override the default setting for DOM capture (enabled) and to fine-tune capture options.
📘

Only initPro() turns DOM capture off by default. If you're on Premium or Ultimate and use initPremium()/initUltimate() without further configuration, Connect does capture DOM snapshots of your pages for session replay — use privacy masking rules (below) and domCapture options to control what's included, or initLibAdv() to disable it entirely.

Default privacy behavior for captured data

When DOM capture is enabled, Connect masks input values by default — you don't have to configure anything to get baseline protection:

  • Password fields are fully masked.
  • Phone number fields are masked except for the last 3 digits.
  • All other free-text input, textarea, and select values (name, email, address, and so on) are masked by character type — letters become X and digits become 9 — so the shape of the data is visible but not the actual content.
  • Radio buttons, checkboxes, hidden fields, submit/button elements, and search boxes are the exception: these aren't masked by default, since they're needed to understand what a visitor did (which option they picked, which button they clicked) and don't typically carry free-text PII.

You can adjust this — tighten it further, loosen specific fields, or apply custom masking logic — using privacy masking rules.

Cookies the SDK sets

CookiePurposeDefault behavior
TLTSIDIdentifies a single visitor session.Set automatically by the SDK. Resets when a new session starts. Not httponly (the SDK needs JavaScript access to it) and not secure by default, since the SDK tracks both HTTP and HTTPS pages — you can configure it as secure for HTTPS-only sites. You can also store the session identifier in local storage instead of a cookie.
TLTDIDIdentifies the device being used, independent of any single session.Set automatically by the SDK. Disable it by setting disableTLTDID to true in the TLCookie configuration module — this stops the cookie from being set and stops the device identifier from being sent with signal data at all.

Behavioral scores Connect calculates from your signals

Beyond the signals you send or that Connect infers (like page views), Connect calculates a single In-market index per contact, a 0–100 score reflecting how likely that contact is to make a purchase, built from their behavioral signals (product views, cart activity, on-site search, and similar). It updates at the end of each session, weighted toward the last 90 days of activity. See the Behavioral attributes reference for the full list of attributes Connect calculates this way.

📘

This scoring happens automatically as part of standard signal processing and isn't something you can disable per subscription today.

For the full data flow — how a signal becomes a contact update — see How behavior signals are processed in Connect.

Next steps


Did this page help you?