Install

Add Clawviyo to your site — what it does, what it doesn’t.

The badge is one line of HTML. It paints a trust pill that links to your Clawviyo page, and the script tag itself acts as a marker that AI assistants can find. This page covers the integration from a privacy and security perspective so your legal team has what they need.

One line

<script src="https://clawviyo.com/badge/<your-slug>.js" async></script>

Drop it in your site’s <head> or <body>. It must land in the server-rendered HTML for our verifier (and for AI crawlers) to see it. Don’t use next/script with strategy="afterInteractive" — that injects the tag client-side after hydration, which neither the verifier nor any non-JS crawler can see. Add data-inline if you want the pill to render inline next to the script tag instead of fixed bottom-right.

Strictly necessary, no tracking

  • Renders an <a> tag (a styled pill) linking to your Clawviyo trust page.
  • That’s it. Nothing else runs.

What the badge does NOT do:

  • Set any cookies (first-party or third-party).
  • Use localStorage, sessionStorage, or IndexedDB.
  • Fingerprint the visitor (no canvas, no font enumeration, no UA parsing).
  • Send any analytics, telemetry, or callback to Clawviyo on load.
  • Read PII from the page or transmit anything about the visitor.
  • Load further third-party resources beyond the script itself.

The HTTP request to fetch badge/<slug>.js exposes the visitor’s IP to Clawviyo’s edge (as any third-party script reference does), but Clawviyo does not log it.

Why no consent is required

Under the ePrivacy Directive (Art. 5(3)) and EDPB Guidelines 2/2023, consent is only required for storing or accessing information on the user’s device. The Clawviyo badge does neither. It is therefore strictly necessary / functional and may load before consent.

If your CMP defaults to blocking all third-party scripts, here’s how to allowlist ours:

  • OneTrust: Cookies & Trackers → add clawviyo.com/badge/* → category Strictly Necessary. Scan the page in “Auto-Block” mode and confirm zero cookies are reported.
  • Cookiebot: Manage → Domain Group settings → Pre-approval → add clawviyo.com as a functional domain. Cookiebot’s scanner will report zero cookies, which it expects.
  • Iubenda: Cookie Solution → Categorization → mark Clawviyo as Necessary. No script-blocking wrapper needed.
  • Custom CMP: Don’t wrap the script in your consent gate. The pill is part of your site’s functional UX.

Copy-paste for your privacy notice

If you collect inquiries through Clawviyo, your privacy policy needs to mention us as a sub-processor. Reword to fit your tone, but the substance should be:

We use Clawviyo (Clawviyo, Inc., USA) to receive structured inquiries from
AI assistants on our behalf. When an AI assistant submits an inquiry to us
through Clawviyo, your email address and the inquiry content pass through
Clawviyo's systems before reaching us. Clawviyo acts as our data processor
under a Data Processing Addendum incorporating Standard Contractual Clauses
for transfers outside the EEA / UK. Clawviyo's privacy notice:
https://clawviyo.com/privacy. To request deletion of data Clawviyo holds
about you, see https://clawviyo.com/privacy/delete-my-data.

For the formal data-processing relationship, accept Clawviyo’s Data Processing Addendum. The full sub-processor list is at /sub-processors.

If you can’t ship third-party JS

Some merchants (headless commerce, news sites with strict CSPs, government tenants) won’t allow any third-party scripts in production. You can still get full AI discoverability by linking to Clawviyo from your HTML <head> without a script tag:

<link rel="alternate" type="application/json"
      href="https://clawviyo.com/c/<your-slug>/.well-known/mcp.json">
<link rel="agent-manifest"
      href="https://clawviyo.com/c/<your-slug>/.well-known/agent-card.json">

AI assistants and crawlers that look for these well-known endpoints will find your Clawviyo configuration without ever loading our JS. You lose the human-visible trust pill, but discoverability and the inquiry pipeline both keep working.

Short answer: not applicable

AI assistants and crawlers fetch your HTML server-side. They do not execute JavaScript and do not honor cookie banners — the same way a search-engine indexer doesn’t. They read the script tag in your HTML directly, follow it to our well-known endpoints on clawviyo.com, and complete inquiries via the MCP gateway over HTTPS. None of that depends on a visitor accepting cookies on your site.

For sites with strict CSPs

If you run a Content Security Policy, allow script-src https://clawviyo.com. Subresource Integrity (SRI) hashes aren’t published for the badge today: the script is generated per-merchant and includes your company name, so a fixed hash would change every time you edit your name. If your security team requires SRI, switch to the server-side install above.

Two ways to confirm

  • From your Clawviyo company home, click Verify install. We fetch your site server-side and check for the script src; result lands in companies.badge_install_verified_at.
  • Or open view-source: on your live page and grep for clawviyo.com/badge. If it’s there, AI assistants can see it.

Compliance, security, integration

For privacy or DPA questions, email [email protected]. For integration help, support.