Back to home

Cookie Policy

Which cookies we set, and which only run after you consent.

Last Updated: September 2026
Effective Date: September 2026

1. Introduction

This Cookie Policy explains how AceJobs ("we," "our," or "us") uses cookies and similar tracking technologies on our website and application. This policy should be read together with our Privacy Policy.

2. What Are Cookies?

Cookies are small text files stored on your device (computer, mobile phone, or tablet) when you visit our website or use our application. They help us provide you with a better experience by remembering your preferences and understanding how you use our service.

3. Types of Cookies We Use

3.1 Essential Cookies (Always Active)

These cookies are necessary for the basic functionality of our service and cannot be disabled.

Cookie NamePurposeDurationType
access_tokenAuthentication and login sessionsSession/7 daysHTTP-only
user_dataBasic user information for app functionalitySessionLocalStorage
csrf_tokenCross-site request forgery protectionSessionHTTP-only
session_idServer session managementSessionHTTP-only

Legal Basis: Necessary for contract performance and legitimate interest in security.

These cookies enhance your experience by remembering your preferences and settings.

Cookie NamePurposeDurationType
theme_preferenceRemember dark/light mode setting1 yearLocalStorage
language_preferenceRemember selected language1 yearLocalStorage
sidebar_collapsedRemember UI layout preferences30 daysLocalStorage
notification_settingsRemember notification preferences90 daysLocalStorage

Legal Basis: Your consent (can be withdrawn anytime).

These cookies help us understand how you use our service to make improvements.

Cookie NamePurposeDurationType
_gaGoogle Analytics - distinguish users2 yearsHTTP
_ga_*Google Analytics - session tracking2 yearsHTTP
_gidGoogle Analytics - distinguish users24 hoursHTTP
usage_analyticsInternal feature usage tracking30 daysLocalStorage
performance_metricsPage load times and errors7 daysLocalStorage

Legal Basis: Your consent (can be withdrawn anytime).

3.4 Advertising Cookies (Region-Based Default)

These let the ad platforms we advertise on tell us which of our ads led to a sign-up or a subscription, so we can measure campaigns and stop paying for ones that don't work.

Whether they are on before you choose depends on where you are:

  • EU/EEA, United Kingdom and Switzerland — off until you opt in. They are only set if you choose Accept All or switch Advertising on (in the banner's Customize panel or in Privacy settings). "Essential + AI Only" leaves them off.
  • Everywhere else — on until you opt out. They are on when you first visit, and the banner says so. To opt out of this sale or sharing of your information, choose Don't sell or share my info in the banner, untick Advertising in its Customize panel, or switch Advertising off in Privacy settings.
  • Global Privacy Control, everywhere. If your browser sends a Global Privacy Control signal, we treat it as an opt-out: advertising cookies stay off and any left from an earlier visit are deleted, whatever you chose before.

We tell where you are from your device's time-zone setting, not your IP address or precise location. It is a rough guide: if your device's clock is set to a European time zone you get the opt-in rules; if it is set elsewhere (for example while travelling, or behind a VPN), you get the opt-out rules. Either way the controls above always work. A choice you have already saved is kept as it is — the region default only applies until you make one.

Cookie / StorageSet byPurposeDurationType
_fbpMeta PixelIdentifies the browser to Meta for ad measurement90 daysHTTP
_fbcMeta PixelRecords the Meta ad click (fbclid) that brought you here90 daysHTTP
_gcl_au, _gcl_awGoogle AdsRecords the Google ad click (gclid) for conversion measurement90 daysHTTP
_rdt_uuid, _rdt_cidReddit PixelIdentifies the browser / Reddit ad click for measurement90 daysHTTP
_wuidWhop PixelIdentifies the browser to Whop for ad measurement (also kept in LocalStorage)Set by WhopHTTP + LocalStorage
acejobs_attribution (click ids)AceJobsRemembers the ad click id from the link you arrived onUntil sign-upLocalStorage

What is sent, and to whom:

  • Meta (Facebook/Instagram) — Meta Pixel and Conversions API: page views; that you signed up (CompleteRegistration); that you started checkout and completed a purchase, with the amount and currency. With the event we send your email address hashed with SHA-256 (never in plain text), a hashed AceJobs user id, the _fbp/_fbc values, your IP address and browser user agent.
  • Google Ads — Google tag: page views, sign-up and purchase conversions (with amount and currency), and — for "enhanced conversions" — your email address, which the Google tag hashes in your browser before sending. Ad personalisation (remarketing) signals are kept off.
  • Reddit — Reddit Pixel and Conversions API: page views, sign-up and purchase (with amount and currency), your email address hashed with SHA-256, a hashed user id, the Reddit click id and browser id, IP address and user agent.
  • Whop — Whop Pixel (we run some Meta ad campaigns through Whop Ads, which measures them with its own pixel): page views; that you signed up (complete_registration), with your email address in plain text, your AceJobs account id and your name — Whop does not accept hashed emails and matches them itself; and that you completed a purchase, with the amount and currency. Whop also receives the _wuid browser id, the page address, your IP address and browser user agent, as any website request does. Whop is browser-only: nothing is sent to Whop from our server.

Sign-up and purchase are also sent from our server to Meta and Reddit, so they are measured even when a browser blocks the pixel. This only happens while Advertising is on for you (your saved choice, or the region default if you have not made one, and never under Global Privacy Control); the server checks the state your browser last reported before sending.

Legal Basis: In the EU/EEA, UK and Switzerland, your consent. Elsewhere, our legitimate interest in measuring our advertising, subject to your right to opt out. Opting out (or withdrawing consent) in Privacy settings stops the pixels immediately, deletes the cookies above, and stops server-side sends. Each platform processes what it receives under its own privacy policy: Meta, Google, Reddit, Whop.

These cookies manage your AI processing preferences and consent.

Cookie NamePurposeDurationType
gdpr_consentGeneral privacy consent preferences1 yearLocalStorage
ai_consent_resumeConsent for AI resume processing1 yearLocalStorage
ai_consent_interviewConsent for AI interview simulation1 yearLocalStorage
ai_consent_parsingConsent for AI document parsing1 yearLocalStorage
freeUserNotificationDismissedRemember dismissed notificationsSessionSessionStorage

Legal Basis: Your explicit consent for AI data processing.

4. Third-Party Cookies

4.1 Google Services

When you log in using Google OAuth or when analytics is enabled:

ServiceCookie PurposeDurationControl
Google OAuthAuthentication and loginSessionRequired for login
Google AnalyticsUsage analytics and insightsUp to 2 yearsCan be disabled
Google AdsAd conversion measurementUp to 90 daysAdvertising consent

More Info: Google's Cookie Policy

4.2 Meta, Reddit and Whop

Only while Advertising is on — see section 3.4 for exactly what is sent, and when it is on by default.

ServiceCookie PurposeDurationControl
Meta PixelAd conversion measurementUp to 90 daysAdvertising setting
Reddit PixelAd conversion measurementUp to 90 daysAdvertising setting
Whop PixelAd conversion measurement (Whop Ads)Set by WhopAdvertising setting

4.3 Stripe

For payment processing:

ServiceCookie PurposeDurationControl
Stripe CheckoutSecure payment processingSessionRequired for payments

More Info: Stripe's Cookie Policy

4.4 AI Service Providers

Our AI partners may set cookies during processing:

ServicePurposeData LocationControl
OpenAIAPI session managementUnited StatesConsent-based
ElevenLabsVoice processing sessionsUnited StatesConsent-based

5. How to Manage Cookies

When you first visit AceJobs, you'll see a cookie consent banner allowing you to:

  • Accept All: Enable all categories, including Analytics and Advertising
  • Essential + AI Only (EU/EEA, UK, Switzerland): Only what the service needs to work; Analytics and Advertising stay off
  • Don't sell or share my info (everywhere else): Turns Advertising off (and leaves Analytics off)
  • Customize: Choose specific cookie categories (Analytics and Advertising are separate switches)

The banner is shown to everyone until they answer it. Until then, Advertising follows the region default described in section 3.4.

If you answered the banner before Advertising was added (consent version 1.0), your answer is kept and Advertising is treated as off; you are not asked again, and you can switch it on in Privacy settings.

5.2 Privacy Settings

Access your cookie preferences anytime:

  1. Go to Privacy Settings
  2. Adjust your cookie preferences
  3. Save changes (takes effect immediately)

5.3 Browser Settings

You can also control cookies through your browser:

Chrome:

  1. Settings → Privacy and Security → Site Settings → Cookies
  2. Choose your preferred cookie setting
  3. Manage exceptions for specific sites

Firefox:

  1. Settings → Privacy & Security → Cookies and Site Data
  2. Choose standard, strict, or custom protection
  3. Manage exceptions as needed

Safari:

  1. Preferences → Privacy → Manage Website Data
  2. Adjust cookie and website data settings
  3. Block or allow cookies from specific sites

Edge:

  1. Settings → Cookies and Site Permissions → Cookies
  2. Choose your cookie handling preference
  3. Add site exceptions

5.4 Mobile Applications

In our mobile apps, cookie settings are managed through:

  • In-App Settings: Privacy & Data section
  • Device Settings: App-specific permissions
  • Account Settings: Online privacy preferences

6. Impact of Disabling Cookies

6.1 Essential Cookies

Disabling essential cookies will prevent:

  • Logging into your account
  • Maintaining secure sessions
  • Proper application functionality
  • Protection against security threats

6.2 Functional Cookies

Disabling functional cookies will result in:

  • Loss of personalization settings
  • Repeated consent requests
  • Default language/theme settings
  • Less convenient user experience

6.3 Analytics Cookies

Disabling analytics cookies will:

  • Prevent usage tracking
  • Reduce our ability to improve the service
  • Not affect core functionality
  • Still allow full feature access

6.4 Advertising Cookies

Disabling advertising cookies will:

  • Stop the Meta, Google Ads, Reddit and Whop pixels and our server-side sends to Meta and Reddit
  • Not affect any feature of the service

6.5 AI Service Cookies

Disabling AI service cookies will:

  • Require repeated consent for AI features
  • May limit AI functionality effectiveness
  • Not prevent using non-AI features
  • Reset AI processing preferences

7.1 Data Storage Location

  • Essential & Functional: Stored locally on your device
  • Analytics: May be transferred to Google (US) for processing
  • Advertising: Transferred to Meta, Google, Reddit and Whop (US) for ad measurement
  • AI Service: Consent data stored locally, processing globally

7.2 Data Sharing

Cookie data may be shared with:

  • Google Analytics: For usage insights (if consented)
  • Meta, Google Ads, Reddit, Whop: For ad conversion measurement (while Advertising is on)
  • Payment Processors: For transaction security
  • AI Providers: For service functionality (if consented)
  • Legal Authorities: When required by law

7.3 Data Security

We protect cookie data through:

  • Encryption: Sensitive cookies are encrypted
  • HTTP-Only Flags: Prevent client-side script access
  • Secure Flags: HTTPS-only transmission
  • SameSite Attributes: CSRF protection
CategoryRetention PeriodDeletion Trigger
EssentialSession to 7 daysLogout/session end
Functional30 days to 1 yearUser preference or expiry
Analytics24 hours to 2 yearsGoogle's retention policy
AdvertisingUp to 90 daysExpiry or consent withdrawal
AI ConsentUp to 1 yearConsent withdrawal

9. Your Rights

Under GDPR and other privacy laws, you have the right to:

  • Withdraw consent for non-essential cookies at any time
  • Modify preferences through our privacy settings
  • View consent history and changes

9.2 Data Access

  • View cookie data stored on your device
  • Understand cookie purposes through this policy
  • Access processing records for analytics cookies

9.3 Data Deletion

  • Clear cookie data through browser settings
  • Request deletion of analytics data
  • Reset consent preferences to defaults

10. Updates to This Policy

We may update this Cookie Policy to reflect:

  • Changes in our cookie usage
  • New features or services
  • Legal or regulatory requirements
  • Industry best practices

Notification Methods:

  • Email notification for significant changes
  • In-app notification upon login
  • Updated effective date at the top of this policy
  • 30-day notice period for material changes

11. Contact Us

For questions about our cookie practices:

All cookie enquiries — general questions, GDPR concerns and technical issues — reach the same address: [email protected].

This Cookie Policy complies with:

  • GDPR (EU): General Data Protection Regulation
  • ePrivacy Directive: EU cookie consent requirements
  • CCPA/CPRA (California) and other US state privacy laws: the right to opt out of the sale or sharing of personal information, including through Global Privacy Control
  • PIPEDA (Canada): Personal information protection

Supervisory Authority: EU residents can lodge complaints with their local data protection authority regarding cookie practices.


Document Version: 1.2
Language: English
Next Review: July 2025

For the most current version of this policy, please visit: https://acejobs.ai/cookie-policy