Skip to content

Legal

Cookies and Similar Technologies

Inventory of cookies and similar technologies used on the site, including purpose, duration, and whether consent is required.

Version 2026-09-07Privacy owner, Compliance ownerEffective September 7, 2026Updated September 7, 2026

Contents

Necessary Cookies and State

affiliate_tracking_consent: Stores your choice for necessary, analytics, and marketing categories so we can remember it over time. Duration: 180 days. Set when you make or reset a cookie choice. Consent not required.

affiliate_consent_subject: Stores a pseudonymous id so we can evidence when a consent version changed without relying only on the visible preference cookie. Duration: 365 days. Set the first time a consent decision is recorded on the server. Consent not required.

affiliate_consultant_session: Keeps a consultant signed in across page loads without affecting company or ops sessions. Duration: 30 days. Set only after successful consultant sign-in. The signed, not encrypted payload contains format version, user id, site-profile id, strategy key, member surface, and expiry. Signing protects integrity but does not hide the contents from the browser user or another person sharing the browser profile. Consent not required.

affiliate_tenant_session: Keeps a company user signed in to the tenant workspace without affecting consultant or ops sessions. Duration: 30 days. Set only after successful company sign-in. The signed, not encrypted payload contains format version, user id, site-profile id, strategy key, member surface, and expiry. Signing protects integrity but does not hide the contents from the browser user or another person sharing the browser profile. Consent not required.

affiliate_ops_session: Keeps an operator or administrator signed in to the separate control plane. Duration: 12 hours. Set only after successful operator sign-in. Consent not required.

active_member_workspace: Remembers the selected workspace between consultant and firm mode so the member stays in the correct context. Duration: Session. Set only for authenticated members who switch workspace. Consent not required.

affiliate_member_auth_attempt: Keeps an in-progress member sign-in attempt together. The sealed v2 payload contains only an opaque attempt id and its expiry. Durable workflow and provider state remain encrypted on the server. Duration: 10 minutes. Set when a member sign-in flow starts but has not completed yet. It contains no workflow snapshot, provider payload, identity attribute, or directly identifying value. Consent not required.

affiliate_member_auth_completion: Proves that a recently completed BankID sign-in belongs to the same member when a consultant interest submission is finalized or a company or consultant invitation is accepted. Duration: 10 minutes. Set after successful purpose-specific BankID confirmation and cleared on sign-out or expiry. The signed, not encrypted payload contains format version 1, attempt id, completed user id, site-profile id, strategy key, purpose-scoped references, and expiry. It contains no BankID provider payload or BankID identity attribute. Consent not required.

affiliate.interest-submission-recovery.v1: Stores an opaque submission attempt id, direct or matched flow, source surface, optional public listing reference, pending or completed state, and timestamp. This supports duplicate-safe recovery and server validation of a recently completed result. Duration: Browser session; pending no more than 24 hours, completed no more than 2 hours. Set when an interest submission starts. A pending attempt becomes invalid after 24 hours. After server-confirmed success, the same opaque attempt is retained as a receipt for no more than 2 hours. The marker is removed when malformed, expired, unauthorized, or when the browser session ends. It stores no lead, member, site-profile, contact, profile, message, legal-acceptance, or BankID data. Consent not required.

affiliate.analytics-session.v1: Stores random pseudonymous session and journey identifiers plus already-recorded steps for consented first-party analytics. The identifiers are not linked to an account, identity verification, interest lead, or consent evidence. Duration: Browser session; session and journey ids last no more than 24 hours from creation. Created only after Analytics is allowed. The session id rotates no later than 24 hours after creation. A new journey id is created when the surface changes, the previous journey completes, or 24 hours pass. All state is removed immediately when consent is revoked or reset. Consent required for Analytics.

affiliate:pending-public-search-event: Temporarily connects a consented search event to its results view. It does not store the search query, filter values, or any user identifier. Duration: Browser session, no more than 5 minutes. Set only after Analytics is allowed when a directory search is submitted, consumed on the results view, and removed immediately when consent is revoked or reset. Consent required for Analytics.

affiliate_ops_challenge: Keeps an in-progress operator challenge together, such as MFA verification, before the final session is issued. Duration: 10 minutes. Set when an operator sign-in requires an additional verification step. Consent not required.

Analytics

Vercel Web Analytics is used for page views on public pages. A limited set of public interactions is measured in our first-party analytics using the consent-controlled session storage listed above.

Raw first-party events are retained for 30 days and anonymous daily aggregates for 24 months. Session and journey identifiers are not linked to an account, BankID, an interest lead, or consent evidence.

The current implementation does not rely on third-party analytics cookies on this site. Analytics is enabled only when the Analytics category is explicitly allowed.

Core service functions such as sign-in, applications, timesheets, and billing are not controlled by the analytics choice and continue to work when Analytics is disabled.

Marketing

The marketing category exists in the interface for future use but is not active in the product today.

Google tags, advertising cookies, or remarketing technologies are not loaded before they are introduced with a separate consent model and updated documentation.

How This List Is Updated

When we add or remove cookies or similar technologies, we update this page, and we update the consent version if consent-controlled processing changes.

If a new technology requires consent, it must not be enabled in production until categories, banner, settings, and documentation are updated.

Version history

  • Version: 2026-09-07

    Effective from: September 7, 2026

    Last updated: September 7, 2026

    Current version

  • Version: 2026-07-25

    Effective from: July 25, 2026

    Last updated: July 25, 2026

    View version

  • Version: 2026-07-13

    Effective from: July 13, 2026

    Last updated: July 13, 2026

    View version

Allow analytics cookies?