This Cookie Policy explains how Hireall Technology ("Hireall", "we") uses cookies and similar technologies on hireall.com, in the Hireall application, and on the career pages, application forms and video-interview pages we host for employers. It should be read together with our Privacy Policy, which describes how we handle personal data more generally.
You are in control. The only cookies we set for our own analytics are the statistics cookies on the public marketing pages of hireall.com, and they are set only after you allow them in the banner shown on your first visit there. You can change or withdraw your choice at any time with the "Cookie preferences" or "Your Privacy Choices" link in the footer of every marketing page or the button at the top of this page. We use no advertising, retargeting or marketing cookies anywhere. Inside the Hireall application and on the pages we host for employers we load no analytics, advertising, retargeting or chat tag. Apart from static files and script libraries (icons, fonts, a date picker, a text editor, a map and small utility libraries) served from content-delivery networks, described in the section on the Hireall application below, the only third-party script that runs there is Stripe.js, loaded when you pay for an add-on inside the application. "Apply with Youthall" on job pages that offer it opens a Youthall window when you click the button; no Youthall script is loaded on the Hireall page. Both are described in this Policy.
01What cookies and similar technologies are
A cookie is a small text file that a website stores on your device. It lets the site recognise your browser on later requests, for example to keep you signed in or to remember a choice you made. Cookies set by Hireall are "first-party" cookies; cookies set by other companies whose tools we use are "third-party" cookies.
"Session" cookies are deleted when you close your browser; "persistent" cookies remain until they expire or you delete them. A cookie's name does not tell you which kind it is: our own sign-in cookie is a "session" cookie in function but a persistent cookie in duration, as the table below shows. We also use similar technologies: local storage, which stores small amounts of data in your browser (for example the light or dark theme you choose on the marketing pages, or interface settings inside the application), and scripts that tell an analytics provider that a marketing page was viewed. We refer to all of these as "cookies" in this Policy.
02How we group cookies
We group cookies into four categories that correspond to the choices you see in the banner on the marketing pages:
- Strictly necessary — required for the site or application to work: keeping you signed in, protecting forms against cross-site request forgery, remembering your cookie choice, and taking a card payment securely when you choose to pay. They cannot be switched off in the preferences panel, because the site would not work without them. You can still block or delete them in your browser, but you will then be unable to sign in, submit forms or pay.
- Preferences — remember a choice you made so that you do not have to make it again. The only item in this category is the light or dark theme on the marketing pages. It is written to your browser only when you use the theme switch, it is read only by the marketing pages, and nothing in it is sent to us or to anyone else. In the United Kingdom, storage used solely to adapt the appearance of a site to a preference you have expressed falls within a specific exemption from the consent requirement; elsewhere we treat it as a function you have expressly requested by using the switch, and we do not rely on the UK exemption outside the UK. The banner does not control it, because it is created by your own action rather than by a script; you can remove it by clearing site data for hireall.com in your browser.
- Statistics — help us understand how visitors use the public marketing pages of hireall.com, which pages are popular and where problems occur, so we can improve them. Reports are aggregated. These cookies are set only after you allow them and are never used inside the Hireall application or on the pages we host for employers.
- Marketing — we do not use advertising, retargeting or marketing cookies of any kind. The category appears in the banner only because our consent tool lists it by default.
03The cookies we use
The tables list the cookies and similar technologies in use on the date shown at the top of this page. They are taken from our own configuration and checked against the most recent scan of hireall.com by our consent tool; the "Show details" view in the banner shows that scan and the date it was run. Where a scan and this Policy differ, this Policy describes our actual settings, and we correct it when a provider changes a cookie. "Where set" tells you on which pages a cookie can be created and on which domain it is stored.
Strictly necessary
| Name | Provider | Purpose | Where set | Duration |
|---|---|---|---|---|
| Hireall session cookie | Hireall | Identifies your signed-in session and protects forms against forgery. The exact name is the one your browser shows for hireall.com; it is set in the application configuration and is not PHPSESSID. We do not print a guessed production name here. | The configured cookie domain for hireall.com and employer career subdomains. Created when you sign in or submit a form that needs a session; marketing pages alone do not create it | 60 days from the last time the session is written (application setting cookie_lifetime = 5,184,000 seconds); the cookie is not a browser-session cookie despite the word "session" in everyday use |
| CookieConsent | Cookiebot (Usercentrics) | Stores the consent choice you made in the banner | hireall.com, marketing pages | 12 months |
| __stripe_mid | Stripe | Fraud prevention when you pay by card | The Hireall application page on hireall.com where the purchase dialog for AI credits, video invites or other add-ons is open; set by Stripe.js only when that dialog loads | 1 year |
| __stripe_sid | Stripe | Fraud prevention when you pay by card | As above | 30 minutes |
Plan subscriptions, and add-on purchases started from the billing page, are paid on Stripe's own checkout page (checkout.stripe.com). Cookies set there are Stripe's, on Stripe's domain, and are described in the Stripe Cookies Policy.
Preferences
| Name | Provider | Purpose | Where set | Duration |
|---|---|---|---|---|
| hireall-theme (local storage) | Hireall | Remembers whether you chose the light or dark theme | hireall.com marketing pages, only when you use the theme switch | Until you clear site data for hireall.com |
Statistics
| Name | Provider | Purpose | Where set | Duration |
|---|---|---|---|---|
| _ga | Google Analytics | Distinguishes visitors for aggregated usage statistics | Public marketing pages on the marketing host only, after you allow statistics cookies. Host-only (no Domain attribute); not sent to career subdomains | 2 years from your last visit to a marketing page (Google Analytics refreshes the cookie on every page view) |
| _ga_LC9VTJSZP2 | Google Analytics | Maintains the session state for our Google Analytics 4 property | As above | 2 years from your last visit, refreshed in the same way |
The durations above are the life of the cookie in your browser; they are not how long Google keeps analytics data. In Google Analytics 4 the Admin "Data retention" setting applies to user-level and event-level data used in explorations and funnel reports. It does not limit the standard aggregated reports in the property. If "Reset user data on new activity" is on, the retention clock for a user identifier is restarted on each new event from that user, so that identifier is not bound by a single fixed period. Age, gender and interest data are kept for two months regardless of the other settings. We have not treated a 14-month figure as a verified ceiling for every analytics record; the current Admin values are those shown in the Google Analytics property, and Google's explanation is at support.google.com/analytics/answer/7667196. Google Analytics 4 does not log or store IP addresses.
The analytics cookies are created as host-only cookies (no Domain attribute) on the marketing host. They are therefore not sent to employer career subdomains. SameSite and Secure do not by themselves stop a cookie reaching a subdomain; host scope does. If marketing pages and the application share the same host on different paths, host-only cookies are still sent on those paths — the application simply does not load or read the analytics script.
Marketing
None. We do not use Google Ads, Meta Pixel, chat widgets or any other advertising, retargeting or marketing tag.
Statistics tags are blocked by our consent tool until you allow that category.
Cookies on youthall.com after "Apply with Youthall"
| Name | Provider | Purpose | Where set | Duration |
|---|---|---|---|---|
| _ya_locale | Youthall | Remembers the language for youthall.com | www.youthall.com, as a first-party cookie in the Youthall window that opens when you click "Apply with Youthall". A Set-Cookie header on a cross-site script response is not the same as the browser storing the cookie; that header uses SameSite=Lax without SameSite=None, so current browsers do not keep it as a third-party cookie on Hireall pages | 30 days on youthall.com |
| Youthall session cookie | Youthall | Keeps you signed in to Youthall. The exact name is the one your browser shows on www.youthall.com | www.youthall.com, after you sign in in the Youthall window | As shown in the Youthall Cookie Policy |
These cookies belong to Youthall and are described in the Youthall Cookie Policy. Hireall pages do not load Youthall's script, so they do not set Youthall cookies. The next section explains what happens when you click the button.
04The Hireall application and pages we host for employers
Inside the Hireall application and on the pages we host for employers (career pages, application forms, the personal privacy page for sourced candidates and video-interview pages) we load no analytics, advertising, retargeting, chat or session-recording tag. No page title, address or event from a recruitment process is sent to an analytics or advertising provider, and no consent banner is shown there. These pages use the strictly necessary cookies listed above, plus the functions below that involve a third party:
- Card payments (Stripe). When you open the purchase dialog for AI credits, video invites or other add-ons in the application, we load Stripe.js from js.stripe.com so that your card details go directly to Stripe and never pass through our servers. At that moment Stripe sets the fraud-prevention cookies listed above. Stripe.js is not loaded on any other page.
- Apply with Youthall. Where an employer has connected its Youthall account, its job pages show an "Apply with Youthall" button. The button is Hireall's own markup. No Youthall script, token-validation request or impression/click measurement request is made when the page opens. Clicking the button opens a window on www.youthall.com so that you can sign in and apply with your Youthall profile. That is a request you have asked for; it is separate from measuring that the button was shown. We do not send Youthall a "button was displayed" or "button was clicked" event from the Hireall page. The Youthall window, like any visit to youthall.com, gives Youthall the connection token needed to complete the application, your IP address, browser information and the fact that you opened that window; Youthall's own Cookie Policy then applies. If you do not click the button, Youthall is not contacted from that page, no Youthall account is created and none of your application answers are shared with Youthall.
The application also keeps a few interface settings in your browser's local storage — for example which settings shortcuts you pinned, list layouts and column widths, dashboard widgets you hid and, on career pages, the jobs you saved for later. They are written only when you make the choice, are read only by the page that stores them, are never sent to us or to a third party, and are removed when you clear site data in your browser.
Static files from content-delivery networks. The application and the pages we host for employers load some static files and script libraries from third-party servers: the icon set (Font Awesome, from kit.fontawesome.com and ka-f.fontawesome.com), the date-picker script and stylesheet (flatpickr, from cdn.jsdelivr.net), utility libraries used on a few screens — text highlighting on candidate profiles, date handling in the automation editor and the e-mail template editor — from cdnjs.cloudflare.com (Cloudflare), the map library (from unpkg.com) and map tiles (from tile.openstreetmap.org, OpenStreetMap Foundation) on the company address editor, icons from api.iconify.design and code.iconify.design (Iconify) in the application settings and on the product pages of hireall.com, and Google Fonts (fonts.googleapis.com and fonts.gstatic.com) on the early-access page of hireall.com and on career pages and application forms whose employer chose a Google font for its branding. Each request sends your IP address and browser information to that provider so the file can be delivered; none of these providers sets a cookie through our pages and none is used to track you. Cloudflare Turnstile, the bot check on our demo-request and early-access forms on hireall.com, works the same way and keeps its own state inside the Cloudflare widget frame rather than in a Hireall cookie.
Where an employer embeds our job widget on its own website, the cookies on that website are governed by the employer's own cookie policy.
05Managing your choices
- Banner and preferences. On your first visit to the marketing pages the banner asks for your choice. Use "Cookie preferences" or "Your Privacy Choices" in the footer, or the button at the top of this page, to change it at any time. When you withdraw consent for statistics, three things happen at once: the analytics script is blocked and no longer loads; the Google Analytics identifier for our property is disabled and analytics storage is marked denied, so nothing is sent even if a script is still in memory; and we delete the analytics cookies we control, trying the host-only cookie and the usual Domain and Path variants so that a leftover copy under another scope is not left behind. You do not need to clear your browser for tracking to stop. Clearing site data in your browser remains available as an extra step if you also want to remove cookies set by other sites, such as Youthall's.
- Browser settings. Every browser lets you view, block and delete cookies through its settings or preferences menu. Blocking strictly necessary cookies will prevent you from signing in, submitting forms or paying.
- Provider opt-outs. Google Analytics offers a browser add-on at tools.google.com/dlpage/gaoptout.
- Global Privacy Control. Our consent tool detects the GPC browser signal. For visitors from jurisdictions where the signal must be treated as an opt-out (including California, Colorado and Connecticut) it does not set statistics or marketing cookies and shows a confirmation that the opt-out was honoured.
- Do Not Track. We do not respond to the older Do Not Track header, for which there is no agreed standard; use the banner or GPC.
- Renewal. We ask for your choice again every 12 months, or sooner if we add a new category or provider.
06Third-party providers
The third parties whose code can set cookies through our pages, and where to read their notices:
- Cookiebot by Usercentrics (consent management, marketing pages only): usercentrics.com/privacy-policy
- Google (Analytics, marketing pages only): policies.google.com/privacy and policies.google.com/technologies/cookies
- Stripe (card payments in the application, and plan checkout on checkout.stripe.com): stripe.com/privacy and stripe.com/legal/cookies-policy
- Youthall, our affiliate ("Apply with Youthall" on job pages): Youthall Cookie Policy and Youthall Privacy Policy
07Content-delivery networks and bot protection
These providers deliver static files or a bot check and receive only the connection data needed to do so (IP address, browser information, the file requested). They do not set cookies through our pages:
- Font Awesome (icons, in the application and on hosted pages): fontawesome.com/privacy
- jsDelivr (date-picker script and stylesheet, in the application): jsdelivr.com/terms/privacy-policy-jsdelivr-net
- Google Fonts (on the early-access page of hireall.com and on career pages and application forms whose employer chose a Google font): policies.google.com/privacy
- Cloudflare (cdnjs.cloudflare.com script libraries and the Turnstile bot check): cloudflare.com/privacypolicy
- unpkg (map library) and OpenStreetMap Foundation (map tiles on the company address editor): osmfoundation.org/wiki/Privacy_Policy
- Iconify (icons in the application settings and on product pages): iconify.design/docs/api
- Cloudflare Turnstile (bot check on the demo-request and early-access forms): cloudflare.com/privacypolicy
08Changes to this Policy
We update this Policy when we add or remove cookies or providers. The date at the top shows the latest revision; when a change is material, the banner asks for your choice again.
09Contact
Questions about cookies: privacy@hireall.com.