Necessary Cookies and State
affiliate_tracking_consent: Stores your choice for necessary, analytics, and marketing categories so we can remember it over time. Duration: 180 days. Set when you make or reset a cookie choice. Consent not required.
affiliate_consent_subject: Stores a pseudonymous id so we can evidence when a consent version changed without relying only on the visible preference cookie. Duration: 365 days. Set the first time a consent decision is recorded on the server. Consent not required.
affiliate_consultant_session: Keeps a consultant signed in across page loads without affecting company or ops sessions. Duration: 30 days. Set only after successful consultant sign-in. The signed, not encrypted payload contains format version, user id, site-profile id, strategy key, member surface, and expiry. Signing protects integrity but does not hide the contents from the browser user or another person sharing the browser profile. Consent not required.
affiliate_tenant_session: Keeps a company user signed in to the tenant workspace without affecting consultant or ops sessions. Duration: 30 days. Set only after successful company sign-in. The signed, not encrypted payload contains format version, user id, site-profile id, strategy key, member surface, and expiry. Signing protects integrity but does not hide the contents from the browser user or another person sharing the browser profile. Consent not required.
affiliate_ops_session: Keeps an operator or administrator signed in to the separate control plane. Duration: 12 hours. Set only after successful operator sign-in. Consent not required.
active_member_workspace: Remembers the selected workspace between consultant and firm mode so the member stays in the correct context. Duration: Session. Set only for authenticated members who switch workspace. Consent not required.
affiliate_member_auth_attempt: Keeps an in-progress member sign-in attempt together. The sealed v2 payload contains only an opaque attempt id and its expiry. Durable workflow and provider state remain encrypted on the server. Duration: 10 minutes. Set when a member sign-in flow starts but has not completed yet. It contains no workflow snapshot, provider payload, identity attribute, or directly identifying value. Consent not required.
affiliate_member_auth_completion: Proves that a recently completed BankID sign-in belongs to the same member when a consultant interest submission is finalized or a company or consultant invitation is accepted. Duration: 10 minutes. Set after successful purpose-specific BankID confirmation and cleared on sign-out or expiry. The signed, not encrypted payload contains format version 1, attempt id, completed user id, site-profile id, strategy key, purpose-scoped references, and expiry. It contains no BankID provider payload or BankID identity attribute. Consent not required.
affiliate.interest-submission-recovery.v1: Stores an opaque submission attempt id, direct or matched flow, source surface, optional public listing reference, pending or completed state, and timestamp. This supports duplicate-safe recovery and server validation of a recently completed result. Duration: Browser session; pending no more than 24 hours, completed no more than 2 hours. Set when an interest submission starts. A pending attempt becomes invalid after 24 hours. After server-confirmed success, the same opaque attempt is retained as a receipt for no more than 2 hours. The marker is removed when malformed, expired, unauthorized, or when the browser session ends. It stores no lead, member, site-profile, contact, profile, message, legal-acceptance, or BankID data. Consent not required.
affiliate.analytics-session.v1: Stores random pseudonymous session and journey identifiers plus already-recorded steps for consented first-party analytics. The identifiers are not linked to an account, identity verification, interest lead, or consent evidence. Duration: Browser session; session and journey ids last no more than 24 hours from creation. Created only after Analytics is allowed. The session id rotates no later than 24 hours after creation. A new journey id is created when the surface changes, the previous journey completes, or 24 hours pass. All state is removed immediately when consent is revoked or reset. Consent required for Analytics.
affiliate:pending-public-search-event: Temporarily connects a consented search event to its results view. It does not store the search query, filter values, or any user identifier. Duration: Browser session, no more than 5 minutes. Set only after Analytics is allowed when a directory search is submitted, consumed on the results view, and removed immediately when consent is revoked or reset. Consent required for Analytics.
affiliate_ops_challenge: Keeps an in-progress operator challenge together, such as MFA verification, before the final session is issued. Duration: 10 minutes. Set when an operator sign-in requires an additional verification step. Consent not required.