Jobtiv Cookie Notice
Version 1.0
Last updated: [INSERT PUBLICATION DATE]
1. What this covers
This notice explains the small files and browser storage entries Jobtiv uses, what each one does, how long it lasts, and how you control them.
It covers more than cookies. UK law on this applies to anything that stores information on your device or reads information from it, so this notice also covers browser local storage, which Jobtiv uses in a few places and which does the same job as a cookie.
Jobtiv is operated by JOBTIV LTD, company number 17092844, 124-128 City Road, London, EC1V 2NX. Our Privacy Policy explains what we do with personal information more generally.
2. The short version
- We do not use advertising cookies. We have no advertising, no advertising networks and no advertising pixels. We do not track you across other websites.
- Most of what we set is strictly necessary to sign you in and keep the Service working. Those cannot be switched off, and the law does not require us to ask your permission for them.
- We use one analytics tool, PostHog, to understand which features people use. That is not necessary and we do not load it unless you agree.
- A small number of entries remember how you have arranged the interface. Those are not strictly necessary either, and you can switch them off.
- You can change your mind at any time.
3. Strictly necessary
These are set because the Service cannot work without them. They are exempt from the consent requirement in the Privacy and Electronic Communications Regulations 2003 because they are strictly necessary to provide the service you have asked for.
| Name | What it does | Type | How long |
|---|---|---|---|
sb-<project>-auth-token, and numbered parts of it | Keeps you signed in. Set by Supabase, which provides our sign-in system | Cookie. Not readable by scripts on the page. Sent only over HTTPS. Restricted to our own site | 7 days when you sign in with a password |
jobtiv_guest_id | Holds a random identifier so a CV you start before creating an account can be kept and attached to your account when you sign up. It is signed so it cannot be altered. We set it the first time you create or edit something, not when you arrive | Cookie. Not readable by scripts on the page. Sent only over HTTPS. Restricted to our own site | 30 days. Cleared when you sign in or sign out |
jobtiv:guest_id | The same identifier, kept in your browser so it survives being sent to Google and back when you sign in with a Google account | Local storage | Until you sign in or clear your browser storage |
portfolio_auth_<slug> | Remembers that you have entered the correct password for a password protected portfolio page, so you are not asked again on every page | Cookie. Not readable by scripts on the page | 24 hours |
portfolio_key_<slug> | Remembers that you arrived at a portfolio page using a valid access link, so the key does not have to stay in the web address. We remove it from the address once the cookie is set | Cookie. Not readable by scripts on the page. Sent only over HTTPS | 7 days |
jobtiv_cookie_choice | Remembers whether you accepted or rejected analytics, so we do not ask you again on every visit. Without it we could not honour the choice you made | Cookie. Restricted to our own site | 6 months, after which we ask you again |
| Form state | A small number of local storage entries hold where you were in a form, so you do not lose your place if something goes wrong | Local storage | Until you sign out or clear your browser storage |
4. Analytics, which we ask about
| Name | What it does | Type | How long |
|---|---|---|---|
Cookie set by PostHog, with a name beginning ph_, and matching entries in local storage | Records which features are opened and how far people get through a task, so we can see what works and what does not. It distinguishes one visitor from another and, once you sign in, it is linked to your account | Cookie and local storage, set by PostHog on our behalf | Up to 12 months |
We ask before we set this. PostHog is not loaded and nothing is stored until you choose "Accept analytics" on the banner we show you the first time you visit.
What we have switched off. We have turned off PostHog's automatic capture of clicks and page views, so it records only the specific events we have written. Session recording is disabled in our own code, not just in a dashboard setting, so PostHog does not record your screen. Our PostHog account is on their European Union cloud.
What it collects. Which feature you opened, whether a step succeeded or failed, and technical information such as your browser and approximate location. Events carry the shape of what you did, not what you wrote: lengths, counts, categories, yes or no flags and identifiers. No text you have typed is sent to PostHog. Web addresses are reduced to the path with a short list of permitted marketing and funnel parameters. Where an IP address is needed to detect abuse, it is hashed first. An automated check in our build fails if anyone reintroduces a free text property. Analytics events are kept for 30 days.
Why we ask rather than assume. UK law lets a website use analytics without permission only where the information is used purely for aggregate statistics about how the service is used and is not used to identify, track or monitor individual people. Our analytics is linked to your account, so it does not meet that test. We therefore ask.
5. Interface preferences, which you can switch off
A small number of local storage entries remember which parts of the interface you have opened and closed, so the Service looks the way you left it.
We set these without asking, because UK law allows a service to store information needed for how a page looks or behaves as long as we tell you what it is for and give you a free and simple way to say no. That way is Settings, then Privacy, then "Remember my interface preferences". Switching it off costs nothing and nothing else changes.
If you have not created an account, these entries are still yours to clear at any time through your browser's site data settings.
6. Error reporting, which runs before you choose
We should be straightforward about one thing our consent testing showed us.
Our error reporting starts working from your first page load, before you have made any cookie choice. If something breaks in the first few seconds of a visit, including the cookie banner itself, we want to see it, and a monitor that only starts after you have clicked is no use for that. The reports go to Sentry, whose servers are in Germany.
What a report contains: the type of error, the code path it happened in, and an anonymous identifier. Section 12 of our Privacy Policy lists what is stripped out before it leaves our servers, which is the request body, the headers, the cookies, the query string, the contents of breadcrumbs, and the value of any field that looks like a document, a salary, a token or a password.
It does not store anything on your device, so there is nothing here for you to accept or refuse.
Our basis for error reporting is our legitimate interests in a service that works. You can object by emailing support@jobtiv.ai.
7. Things we do not use
- No advertising or marketing cookies. None.
- No third party advertising networks or pixels. No Meta pixel, no Google Ads tag, no TikTok pixel, no LinkedIn insight tag.
- No cross site tracking.
- No selling of any information gathered this way.
- No session recording or screen replay.
Our payment pages run on Stripe's own website. Any cookies set there are Stripe's, and Stripe's cookie notice covers them.
8. Your choices
The banner. The first time you visit, we show a banner with two equally prominent choices: accept analytics, or reject them. Rejecting takes exactly as many clicks as accepting. Nothing beyond the items in sections 3 and 5, and the error reporting described in section 6, is set in your browser until you choose, and if you reject, nothing further is set.
Changing your mind. Go to Settings, then Privacy, and switch analytics on or off. If you switch it off, we stop collecting analytics events immediately and clear the analytics cookie and storage entries from your browser. You can also withdraw consent by clearing cookies and site data for jobtiv.ai in your browser settings, or by emailing support@jobtiv.ai with "Analytics opt out" in the subject line.
Events on our own servers. Separately from anything set in your browser, we record a small number of events on our own servers about whether a request or a background job succeeded. Those never touch your device, so this choice does not cover them. Section 6 of our Privacy Policy explains them and how to object.
Your browser. You can also block or delete cookies through your browser settings. If you block the strictly necessary ones you will not be able to stay signed in. Instructions for the main browsers are at aboutcookies.org.
9. Changes to this notice
If we add or remove a cookie or a storage entry, we will update this notice and change the date at the top. If we add anything that needs your permission, we will ask you again before we set it.
10. Questions
Email support@jobtiv.ai.
If you are not happy with how we handle this, you can complain to us using the process in section 13.5 of our Privacy Policy, and you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint at any time.
JOBTIV LTD, registered in England and Wales, company number 17092844. Registered office: 124-128 City Road, London, EC1V 2NX.
The other documents
These five documents work together, and each is a page on this site.
If any of these links does not work, tell us at support@jobtiv.ai and we will fix it. A legal page that does not load is a problem whatever it says.