Skip to content

Legal

Cookies and Similar Technologies (2026-07-13)

Inventory of cookies and similar technologies used on the site, including purpose, duration, and whether consent is required.

Privacy owner, Compliance ownerEffective July 13, 2026Updated July 13, 2026

Contents

Necessary Cookies and State

affiliate_tracking_consent: Stores your choice for necessary, analytics, and marketing categories so we can remember it over time. Duration: 180 days. Set when you make or reset a cookie choice. Consent not required.

affiliate_consent_subject: Stores a pseudonymous id so we can evidence when a consent version changed without relying only on the visible preference cookie. Duration: 365 days. Set the first time a consent decision is recorded on the server. Consent not required.

affiliate_consultant_session: Keeps a consultant signed in across page loads without affecting company or ops sessions. Duration: 30 days. Set only after successful consultant sign-in. Consent not required.

affiliate_tenant_session: Keeps a company user signed in to the tenant workspace without affecting consultant or ops sessions. Duration: 30 days. Set only after successful company sign-in. Consent not required.

affiliate_ops_session: Keeps an operator or administrator signed in to the separate control plane. Duration: 12 hours. Set only after successful operator sign-in. Consent not required.

active_member_workspace: Remembers the selected workspace between consultant and firm mode so the member stays in the correct context. Duration: Session. Set only for authenticated members who switch workspace. Consent not required.

affiliate_member_auth_attempt: Keeps an in-progress member sign-in attempt together, such as password or BankID, until the flow completes or is cancelled. Duration: 10 minutes. Set when a member sign-in flow starts but has not completed yet. Consent not required.

affiliate_member_auth_completion: Proves that a recently completed BankID sign-in belongs to the same member when a consultant interest submission is finalized or a company invitation is accepted. Duration: 10 minutes. Set after successful purpose-specific BankID confirmation and cleared on sign-out or expiry. Consent not required.

affiliate.interest-submission-recovery.v1: Stores an opaque submission attempt id, direct or matched flow, source surface, optional public listing reference, pending or completed state, and timestamp. This supports duplicate-safe recovery and server validation of a recently completed result. Duration: Browser session; pending no more than 24 hours, completed no more than 2 hours. Set when an interest submission starts. A pending attempt becomes invalid after 24 hours. After server-confirmed success, the same opaque attempt is retained as a receipt for no more than 2 hours. The marker is removed when malformed, expired, unauthorized, or when the browser session ends. It stores no lead, member, site-profile, contact, profile, message, legal-acceptance, or BankID data. Consent not required.

affiliate.analytics-session.v1: Stores random pseudonymous session and journey identifiers plus already-recorded steps for consented first-party analytics. The identifiers are not linked to an account, identity verification, interest lead, or consent evidence. Duration: Browser session; session and journey ids last no more than 24 hours from creation. Created only after Analytics is allowed. The session id rotates no later than 24 hours after creation. A new journey id is created when the surface changes, the previous journey completes, or 24 hours pass. All state is removed immediately when consent is revoked or reset. Consent required for Analytics.

affiliate:pending-public-search-event: Temporarily connects a consented search event to its results view. It does not store the search query, filter values, or any user identifier. Duration: Browser session, no more than 5 minutes. Set only after Analytics is allowed when a directory search is submitted, consumed on the results view, and removed immediately when consent is revoked or reset. Consent required for Analytics.

affiliate_ops_challenge: Keeps an in-progress operator challenge together, such as MFA verification, before the final session is issued. Duration: 10 minutes. Set when an operator sign-in requires an additional verification step. Consent not required.

Analytics

Vercel Web Analytics is used for page views on public pages. A limited set of public interactions is measured in our first-party analytics using the consent-controlled session storage listed above.

Raw first-party events are retained for 30 days and anonymous daily aggregates for 24 months. Session and journey identifiers are not linked to an account, BankID, an interest lead, or consent evidence.

The current implementation does not rely on third-party analytics cookies on this site. Analytics is enabled only when the Analytics category is explicitly allowed.

Core service functions such as sign-in, applications, timesheets, and billing are not controlled by the analytics choice and continue to work when Analytics is disabled.

Marketing

The marketing category exists in the interface for future use but is not active in the product today.

Google tags, advertising cookies, or remarketing technologies are not loaded before they are introduced with a separate consent model and updated documentation.

How This List Is Updated

When we add or remove cookies or similar technologies, we update this page, and we update the consent version if consent-controlled processing changes.

If a new technology requires consent, it must not be enabled in production until categories, banner, settings, and documentation are updated.

Allow analytics cookies?