Third-Party Scripts
The authoritative, current list of third-party scripts and services that run in the browser on the WorkSlate website and web application, as referenced in our Cookie and Web Application Policy.
Last updated September 3rd, 2026. This page is the authoritative current list; the categories described in the Cookie and Web Application Policy are illustrative.
| Provider | Origins | Purpose | Category |
|---|---|---|---|
| Stripe | js.stripe.com, connect.stripe.com, connect-js.stripe.com | Payment processing and Stripe Connect embedded components; Stripe sets cookies for fraud prevention | Strictly necessary (payments) |
| PostHog | first-party reverse proxy (proxied to PostHog Cloud US) | Product analytics and feature-flag evaluation; browser traffic is routed through a first-party proxy rather than loading PostHog's domain directly | Analytics |
| Sentry | *.ingest.sentry.io (bundled SDK, no third-party script tag) | Error and performance monitoring; the SDK ships inside the app bundle and posts events to Sentry. Optional session replay (a masked recording captured only on error) runs only with analytics consent | Strictly necessary (error monitoring, sets no cookies); session replay is consent-gated (Analytics) |
| Google Fonts | fonts.googleapis.com | Web font stylesheet delivery (CSS only; no JavaScript) | Functional |
| Google Analytics 4 | www.googletagmanager.com, www.google-analytics.com | Aggregate marketing-site traffic measurement; gtag.js is injected only after you grant the Analytics category, so no GA cookies or hits fire before consent | Analytics (consent-gated) |
| HubSpot Meetings | static.hsappstatic.net, meetings-na2.hubspot.com | Demo-booking calendar on the /demo page only, never on any other page. HubSpot sets its own visitor cookies, so the embed loads only for visitors who have accepted analytics cookies or who click to load it on that page | Scheduling (consent-gated) |