Cookie Policy
Effective: 2026-08-12 · Version: 1.6
What are cookies
Cookies are small text files your browser stores on your device. Similar technologies include localStorage, sessionStorage, pixel tags, and mobile SDKs. This policy refers to all of these as "cookies".
Categories we use
We group cookies into three consent categories. Essential cookies and essential app storage are always on because they are needed for sign-in, security, and requested product workflows. Analytics and marketing require your consent, which you can change any time in the banner or at /cookies.
1. Essential (always on)
Required to deliver the service. Disabling these breaks core functionality.
| Cookie | Purpose | Duration |
|---|---|---|
__Secure-next-auth.session-token / next-auth.session-token | Authenticate your session | Up to 7 days (customer) / 12 hours (admin) |
__Host-next-auth.csrf-token / __Secure-next-auth.csrf-token | CSRF protection | Session |
__Secure-next-auth.pkce.code_verifier | OAuth PKCE flow | Session |
cookie_consent | Remembers your cookie preferences | 12 months |
hc_booking_access_<linkId> | Authorizes only the requested public booking or booking-management workflow after the link credential is removed from the URL and exchanged for a signed, HttpOnly cookie | Up to 4 hours or the booking link's earlier expiry |
2. Essential app storage (always on)
Remember preferences and preserve requested workflows. No third-party tracking.
| Cookie | Purpose | Duration |
|---|---|---|
theme | Light / dark / system theme preference | 12 months |
onboarding_step | Where you are in onboarding | 30 days |
hc_public_intent | Keeps a signed public-offer purchase callback bound to the browser that requested email verification | Up to 15 minutes |
hc_public_intent_ready | Carries the signed, checkout-ready offer and pricing snapshot from email verification back to the exact offer page | Up to 5 minutes |
hc_offer_image_<hash> | Allows an invite-only offer page to load only the image files authorized for that offer and published version | Up to 15 minutes |
hc-gift-claim:<intent> (sessionStorage) | Keeps a gift acceptance capability in the current tab after removing it from the URL; cleared after successful acceptance | Browser tab session or successful acceptance |
hc-booking-request:<intent> (sessionStorage) | Reuses one idempotency key if a booking-link request is retried; cleared after the link is issued or the request expires | Browser tab session, usually one request |
jobSearch.googleJobs.* (sessionStorage) | Keeps requested job-search results and pagination cursors in the current tab, isolated by signed-in user and cleared on logout | Up to 15 minutes or browser tab session |
3. Analytics (consent required)
Help us understand which features are used and where users get stuck. Data is processed by:
- Vercel Analytics: site-level traffic and performance telemetry with query strings and fragments removed before pageviews are sent
- Amplitude: product analytics
- Mixpanel: product analytics
- PostHog: product analytics (event capture, funnels). Distinct ID is the Firebase UID when signed-in; email is attached only after analytics consent.
These tools are initialized only after analytics consent. The PostHog client SDK loads in opted-out-by-default mode and only begins capturing events after analytics consent is granted; revocation immediately stops capture and clears the PostHog distinct ID. Browser session-replay integrations and GTM/GA/LinkedIn Insight tags are disabled.
| Storage | Purpose | Duration |
|---|---|---|
hc_offer_session (sessionStorage) | Deduplicates consented views and funnel steps on public coach-offer pages. The server stores only keyed hashes and coarse allowlisted source labels, not the raw identifier, IP address, or referrer. | Browser tab session |
4. Marketing (consent required)
Measure campaign effectiveness and show relevant ads on partner platforms.
- Meta (Facebook) Conversions API: server-side gift-flow conversion measurement with hashed identifiers. The client Meta Pixel is disabled.
Your choices
- Banner: on your first visit (and again when you clear cookies), you can accept all, reject all, or choose per-category.
- Account settings:
/settings/privacy: change any time. - Browser controls: you can block cookies at the browser level. Blocking essentials may prevent signin.
- Do Not Track: we honor Global Privacy Control (GPC) signals as a "do not sell / do not share" opt-out under CPRA.
Withdrawing consent takes effect immediately; we won't block your access to the site.
How we record your consent
When you make a choice in the cookie banner, we record:
- Which consent categories you accepted (analytics, marketing, or essential-only)
- The version of the consent notice you saw
- The timestamp of your choice
If you are signed in, this record is persisted to your account so your choice follows you across devices. If you are not signed in, it is stored locally in your browser.
Consent change events are also appended to the application audit log and retained for 2 years per the data retention policy as evidence of your decision.
If we make a material change to the categories of cookies or the trackers we use (for example, adding a new analytics provider), we increment the consent-notice version and re-prompt you. Your prior consent then applies only to the previous version; you choose afresh for the new one.
Sub-processor links
| Provider | Privacy policy |
|---|---|
policies.google.com/privacy | |
| Amplitude | amplitude.com/privacy |
| Mixpanel | mixpanel.com/legal/privacy-policy |
| Meta | facebook.com/privacy/policy |
| PostHog | posthog.com/privacy |
| Sentry | sentry.io/privacy |
| Vercel | vercel.com/legal/privacy-policy |
See hiringcoach.ai/sub-processors for our full list.
Changes
We review this policy annually and update it when we add or remove trackers. Material changes are communicated through the banner re-opening and, where required, by email.
- 2026-08-12: Documented the short-lived essential booking-capability cookie used after a public booking or management credential is removed from the URL.
- 2026-07-29: Removed Hotjar client initialization/session capture, GTM/GA/LinkedIn Insight browser tags, and the client Meta Pixel; stripped query metadata from remaining browser telemetry and disabled automatic Sentry DOM screenshots.
- 2026-07-26: Documented the short-lived essential cookies and tab storage used for public-offer verification, invite-only images, gift acceptance, and replay-safe booking-link requests.
- 2026-07-24: Added consent-gated, first-party coach-offer funnel measurement and its tab-session identifier; incremented the consent version so every user chooses again.
Contact
Questions: [email protected]
Cookie Preferences
Choose which optional cookies HiringCoach can use. Changes are saved to your browser and, when signed in, to your account.
Required to keep your account secure and signed in.
Helps us understand usage patterns, performance, and where people get stuck.
Helps attribute campaign performance. HiringCoach does not use this to serve ads.