Skip to main content

Legal

Cookie Policy

What cookies we use, why we use them and how you can control them.

Last updated: 8 September 2026

1. What cookies are

Cookies are small text files stored on your device when you visit a website. We also use similar technologies such as local storage and pixels; we refer to them collectively as "cookies".

2. Categories we use

  • Strictly necessary — sign-in sessions, security, load balancing, saving cookie preferences. Always on.
  • Functional — remember your preferences, such as theme, saved jobs and referral attribution (described below).
  • Analytics — we use PostHog for two separate things, and they cover different parts of the site. The first is product analytics: a small, fixed list of named events — a public page viewed, a job search run, a filter applied, a job opened, an application started, a hiring call-to-action clicked — so we can see which journeys work and where people give up. These events carry no names or email addresses, no CV or application text, no form contents, and no sign-in or payment details. The second is session replay, a recording of how a page was used, and this happens on selected public browsing pages only: signing in, your account, applications and the CV tools, payment, and staff and admin areas are never recorded. Counting that an application was started is not the same as recording the application — the event may be counted on a page that replay does not cover. Both run only if you choose Analytics cookies. If you reject Analytics, or have not yet chosen, PostHog is not loaded, no analytics identifier is created and no analytics data is stored on your device. If you accept Analytics and later withdraw it, capture and replay stop at once, no further analytics request is sent, and the analytics identifiers and session data PostHog had stored on your device are removed. The only thing that remains is a single non-identifying record that you declined analytics, kept so the tool stays switched off until you choose otherwise; it contains no identifier and nothing about you. Your sign-in, saved jobs, theme and cookie choices are never touched by this. Our PostHog project uses their EU Cloud data region, and PostHog processes this data as our processor under a signed data processing agreement that includes international transfer terms. What you type is masked in recordings. Wherever a page address is recorded — whether for one of those events or inside a recording — we send only the site address and the page path, never the part after it, so a search, a referral code or anything else carried in a link stays out of both. Recordings are kept for 30 days. You can withdraw Analytics consent at any time from Cookie preferences, which stops further collection. The hosting platform's built-in visitor analytics remain disabled.
  • Marketing — would measure the effectiveness of campaigns and, where enabled, personalise content. Off by default; no marketing cookies are currently set.

Referral attribution. Our older general referral programme remains paused, so it creates no new attribution and any identifiers stored on your device before the pause are not used. Separately, if you arrive through an eligible Community Partner link and choose Functional cookies, we may store that partner referral code on your device for up to 30 days, so that a later application can be attributed to that Community Partner. If you decline or withdraw Functional consent, we do not retain that partner referral identifier for future attribution.

Separately from cookies, Humand records a limited set of first-party product events in its own systems — for example that a sign-in happened, or that a job search was run — to operate, secure and improve the service. These events do not include CV contents, application text or form contents, and these first-party records are not sent to PostHog or any other third-party analytics provider. Raw first-party event records are retained for 180 days and then automatically deleted.

3. Managing your choices

You can accept or reject non-essential categories via the cookie banner shown on your first visit, or reopen preferences at any time from the footer. You can also block or delete cookies via your browser settings — some parts of the site may not work as expected if you do.

4. Third parties

Some cookies are set by third-party services we use (for example embedded video or social sign-in). Those parties are responsible for their own use of cookies and have their own privacy notices. Our analytics provider, PostHog, is loaded only if you choose Analytics cookies — see the Analytics category above, including what stops and what is removed if you later withdraw that choice.

5. Questions

Contact privacy@humand.co.uk.