If a cookie scan of your website surfaced a cookie named ADS_VISITOR_ID and you are trying to figure out what it does, whether it needs consent, and which category it belongs in on your cookie banner, this explainer covers everything a compliance team needs to know.
What the ADS_VISITOR_ID Cookie Does? Purpose, Classification, and Consent Requirements
ADS_VISITOR_ID is an advertising identifier cookie. The name describes its function precisely: it assigns a persistent unique ID to a visitor so that advertising systems can recognize that same browser across page views and sessions. It is most commonly observed on websites built on the Wix platform, where it supports Wix’s advertising and marketing measurement functionality. Once set, the identifier allows ad delivery and attribution systems to tie together a visitor’s activity — which pages they viewed, which campaigns brought them to the site, and whether they eventually converted — into a single profile keyed to that ID.
That makes ADS_VISITOR_ID functionally similar to better-known advertising identifiers like Google’s _gcl_au or Meta’s _fbp. The mechanism is the same in every case: a pseudonymous unique identifier written to the browser for advertising purposes. And under every major privacy framework, that mechanism carries the same legal consequences regardless of which vendor’s name is on it.
How to Classify It
- Category: Advertising / Targeting. This cookie is not strictly necessary, not a performance cookie, and not a functionality cookie. It exists to identify visitors for marketing purposes and belongs in the advertising category of your consent banner without exception.
- Party: Typically set as a first-party cookie on the visited domain, but serving a third-party advertising function. This distinction matters: regulators and plaintiff attorneys look at what a cookie does, not which domain sets it. A first-party cookie feeding advertising systems is still an advertising cookie.
- Persistence: Persistent rather than session-based — the entire point of a visitor ID is that it survives across sessions. Verify the exact expiration your site sets, because durations vary by platform version and configuration, and your cookie policy needs to state the value your visitors actually receive rather than a generic figure copied from a cookie database.
Consent Requirements Under GDPR, the ePrivacy Directive, and US State Law
Under the ePrivacy Directive and GDPR, ADS_VISITOR_ID requires prior opt-in consent before it is written to the browser. It is not exempt under the strictly necessary carve-out, and no legitimate-interest argument rescues an advertising identifier. If this cookie fires before a visitor clicks accept, your consent management implementation is broken — and that is exactly the kind of defect that cookie audits, data protection authorities, and increasingly automated compliance scans catch first, because pre-consent cookie writes are trivially easy to detect and impossible to explain away.
Under US state privacy laws, the analysis runs through the sale and sharing definitions. A persistent advertising identifier that supports cross-context behavioral advertising sits squarely within what the CCPA/CPRA treats as “sharing,” which means it must be disclosed, must honor Global Privacy Control signals, and must stop firing when a visitor opts out. California’s enforcement sweeps and the current wave of CIPA pen register litigation have both targeted precisely this pattern: identifier cookies that keep operating after an opt-out or that fire before any consent interaction at all.
What to Do If ADS_VISITOR_ID Shows Up in Your Scan
- Confirm the source on your own site. Identify which platform or tag is writing the cookie in your specific stack, and record the actual expiration value set in your visitors’ browsers. Your cookie policy should reflect observed behavior, not vendor documentation.
- Gate it behind advertising consent. Verify through testing — not assumption — that the cookie is not written until a visitor affirmatively opts into advertising cookies in jurisdictions that require it.
- Wire it to your opt-out signals. GPC signals and “Do Not Sell or Share” requests must suppress it for California visitors, and your CMP configuration should prove it.
- Disclose it accurately. Name, purpose, category, duration, and provider belong in your cookie policy, kept current automatically rather than through an annual manual review that drifts out of date within weeks.
Keep Every Cookie on Your Site Accounted For
ADS_VISITOR_ID is one cookie among the dozens most websites set, and the compliance risk is never any single identifier — it is the gap between what your site actually does and what your banner and policy claim. Captain Compliance continuously scans your website, classifies every cookie and tracker it finds, gates them behind an IAB TCF-validated consent management platform, honors GPC automatically, and keeps your cookie policy synchronized with reality. Book a demo and see every identifier your site is setting right now — including the ones your last audit might have missed.