Cookie Policy

Effective: 2026-08-12 · Version: 1.6

What are cookies

Cookies are small text files your browser stores on your device. Similar technologies include localStorage, sessionStorage, pixel tags, and mobile SDKs. This policy refers to all of these as "cookies".

Categories we use

We group cookies into three consent categories. Essential cookies and essential app storage are always on because they are needed for sign-in, security, and requested product workflows. Analytics and marketing require your consent, which you can change any time in the banner or at /cookies.

1. Essential (always on)

Required to deliver the service. Disabling these breaks core functionality.

CookiePurposeDuration
__Secure-next-auth.session-token / next-auth.session-tokenAuthenticate your sessionUp to 7 days (customer) / 12 hours (admin)
__Host-next-auth.csrf-token / __Secure-next-auth.csrf-tokenCSRF protectionSession
__Secure-next-auth.pkce.code_verifierOAuth PKCE flowSession
cookie_consentRemembers your cookie preferences12 months
hc_booking_access_<linkId>Authorizes only the requested public booking or booking-management workflow after the link credential is removed from the URL and exchanged for a signed, HttpOnly cookieUp to 4 hours or the booking link's earlier expiry

2. Essential app storage (always on)

Remember preferences and preserve requested workflows. No third-party tracking.

CookiePurposeDuration
themeLight / dark / system theme preference12 months
onboarding_stepWhere you are in onboarding30 days
hc_public_intentKeeps a signed public-offer purchase callback bound to the browser that requested email verificationUp to 15 minutes
hc_public_intent_readyCarries the signed, checkout-ready offer and pricing snapshot from email verification back to the exact offer pageUp to 5 minutes
hc_offer_image_<hash>Allows an invite-only offer page to load only the image files authorized for that offer and published versionUp to 15 minutes
hc-gift-claim:<intent> (sessionStorage)Keeps a gift acceptance capability in the current tab after removing it from the URL; cleared after successful acceptanceBrowser tab session or successful acceptance
hc-booking-request:<intent> (sessionStorage)Reuses one idempotency key if a booking-link request is retried; cleared after the link is issued or the request expiresBrowser tab session, usually one request
jobSearch.googleJobs.* (sessionStorage)Keeps requested job-search results and pagination cursors in the current tab, isolated by signed-in user and cleared on logoutUp to 15 minutes or browser tab session

3. Analytics (consent required)

Help us understand which features are used and where users get stuck. Data is processed by:

  • Vercel Analytics: site-level traffic and performance telemetry with query strings and fragments removed before pageviews are sent
  • Amplitude: product analytics
  • Mixpanel: product analytics
  • PostHog: product analytics (event capture, funnels). Distinct ID is the Firebase UID when signed-in; email is attached only after analytics consent.

These tools are initialized only after analytics consent. The PostHog client SDK loads in opted-out-by-default mode and only begins capturing events after analytics consent is granted; revocation immediately stops capture and clears the PostHog distinct ID. Browser session-replay integrations and GTM/GA/LinkedIn Insight tags are disabled.

StoragePurposeDuration
hc_offer_session (sessionStorage)Deduplicates consented views and funnel steps on public coach-offer pages. The server stores only keyed hashes and coarse allowlisted source labels, not the raw identifier, IP address, or referrer.Browser tab session

4. Marketing (consent required)

Measure campaign effectiveness and show relevant ads on partner platforms.

  • Meta (Facebook) Conversions API: server-side gift-flow conversion measurement with hashed identifiers. The client Meta Pixel is disabled.

Your choices

  • Banner: on your first visit (and again when you clear cookies), you can accept all, reject all, or choose per-category.
  • Account settings: /settings/privacy: change any time.
  • Browser controls: you can block cookies at the browser level. Blocking essentials may prevent signin.
  • Do Not Track: we honor Global Privacy Control (GPC) signals as a "do not sell / do not share" opt-out under CPRA.

Withdrawing consent takes effect immediately; we won't block your access to the site.

How we record your consent

When you make a choice in the cookie banner, we record:

  • Which consent categories you accepted (analytics, marketing, or essential-only)
  • The version of the consent notice you saw
  • The timestamp of your choice

If you are signed in, this record is persisted to your account so your choice follows you across devices. If you are not signed in, it is stored locally in your browser.

Consent change events are also appended to the application audit log and retained for 2 years per the data retention policy as evidence of your decision.

If we make a material change to the categories of cookies or the trackers we use (for example, adding a new analytics provider), we increment the consent-notice version and re-prompt you. Your prior consent then applies only to the previous version; you choose afresh for the new one.

Sub-processor links

ProviderPrivacy policy
Googlepolicies.google.com/privacy
Amplitudeamplitude.com/privacy
Mixpanelmixpanel.com/legal/privacy-policy
Metafacebook.com/privacy/policy
PostHogposthog.com/privacy
Sentrysentry.io/privacy
Vercelvercel.com/legal/privacy-policy

See hiringcoach.ai/sub-processors for our full list.

Changes

We review this policy annually and update it when we add or remove trackers. Material changes are communicated through the banner re-opening and, where required, by email.

  • 2026-08-12: Documented the short-lived essential booking-capability cookie used after a public booking or management credential is removed from the URL.
  • 2026-07-29: Removed Hotjar client initialization/session capture, GTM/GA/LinkedIn Insight browser tags, and the client Meta Pixel; stripped query metadata from remaining browser telemetry and disabled automatic Sentry DOM screenshots.
  • 2026-07-26: Documented the short-lived essential cookies and tab storage used for public-offer verification, invite-only images, gift acceptance, and replay-safe booking-link requests.
  • 2026-07-24: Added consent-gated, first-party coach-offer funnel measurement and its tab-session identifier; incremented the consent version so every user chooses again.

Contact

Questions: [email protected]

showUpgradeModal: false, modalType: migration, planName: