Skip to content
Surhires

Cookies

What is stored in your browser, and what you can switch off

The marketing site and the signed-in application store different things for different reasons, and only one of them asks for your consent before doing it.

The Surhires marketing site uses strictly necessary, preference, analytics and marketing cookies, with granular consent and a working reject-all. The signed-in product uses strictly necessary storage only, because session and security state are required to deliver a service you asked for. The published cookie notice is the authoritative version.

By Surhires Editorial · Published · Reviewed

This is an explanation, and the published notice is the one that counts

This page describes the approach in plain English so you can decide what to allow. The binding documents are the cookie notice published on this site as it stands today and the privacy policy it sits under. Cookie inventories change as tooling changes, and the consent manager itself is the live record of what is set and by whom.

Nothing here is legal advice about your own site's cookie practice. If you are a recruitment firm reading this to work out what your own career portal needs to do, that is a question for your counsel and your own consent tooling, not for a vendor's explanation of its own approach.

The reason this page separates the marketing site from the product is that the two are genuinely different, and treating them as one thing is how consent banners end up either legally thin or annoyingly wrong.

Four categories, described by what they do

Strictly necessary covers what the site cannot function without: session integrity, load balancing, security tokens and the record of your own consent choices. That last one is worth noticing. Remembering that you rejected everything requires storing the fact that you rejected everything, which is why the consent record itself sits in this category rather than in the ones you can turn off.

Preference covers choices you have made that are not required: market selection between the United States, United Kingdom and Australia views, currency display, and interface preferences that survive a reload. Turning these off does not break anything; it just means the site forgets.

Analytics covers aggregate measurement of how pages are used, and marketing covers advertising and attribution technology set by third parties. Both are off until you consent, and both are described in the consent manager with the vendor, the purpose and the duration rather than as a single opaque toggle.

  • Strictly necessary: session, security, load balancing, and your consent record
  • Preference: market, currency and interface choices that survive a reload
  • Analytics: aggregate page and journey measurement, off until consented
  • Marketing: advertising and attribution technology, off until consented
  • Every entry lists vendor, purpose and duration in the consent manager

The consent manager offers per-category control rather than an accept button and a hidden settings link. Reject all is available at the same level as accept all, in the same visual weight, on the first screen. A reject-all that is one click harder than accept-all is a dark pattern with a legal opinion attached to it, and it is not what this site does.

Choices are revocable at any time from a persistent control, and revoking is as easy as granting. When consent is withdrawn, the categories stop firing on the next page load and the associated storage is cleared where the browser permits it. Some third-party storage can only be cleared by that third party, which is a limitation of the medium rather than a policy choice, and it is stated rather than glossed.

Consent is recorded with a timestamp and the version of the notice you were shown, because a consent record that cannot say what the person was told is not much of a record.

The signed-in product is a different surface with different rules

Once you log in, the storage the application uses is strictly necessary. Session tokens, authentication state, tenant context, security controls such as cross-site request protection, and a small amount of interface state such as which pipeline view you had open. These are required to deliver a service you have actively asked for, and there is no consent banner inside the product for them.

There is no advertising technology in the product, and no third-party marketing pixels on authenticated pages. Product analytics, where used, is aggregate telemetry about feature use and errors under the customer agreement rather than a consent-based cookie relationship with the individual recruiter.

The reason to say this explicitly is that recruiters are the population with the least appetite for surprises here. Somebody working a desk all day has a right to know that their own tooling is not also an advertising surface.

Your career portal is your surface, not ours

Where Surhires serves a white-labelled career portal for your firm, the candidates arriving on it are your visitors. The consent obligations there follow your firm, your jurisdiction and your own tracking decisions. If you add your own analytics or advertising tags to that portal, you have taken on the consent question for them.

The portal itself is built to run on strictly necessary storage: application state, form integrity and security. It does not carry vendor advertising technology, and it does not quietly attach a tracking relationship to a candidate applying for a job.

That boundary is worth writing into your own candidate privacy notice rather than assuming. Candidates who read anything tend to read the career portal notice, and it is the one place where a vague statement is most likely to be noticed.

  • Career portal visitors are your data subjects, under your notice
  • Portal runs on strictly necessary storage by default
  • Tags you add to the portal bring their own consent obligations to you
  • No vendor advertising technology is attached to candidate-facing pages
  • State the position in your own candidate notice rather than assuming ours

Browser controls, do-not-track and the limits of each

Browser-level controls sit above anything a site can do. Blocking third-party storage, clearing site data or running a strict privacy mode will affect the site, and the parts that break will be the parts that depend on remembering things. Strictly necessary storage is required for authentication, so blocking it entirely will prevent login rather than degrade it.

Global privacy signals sent by the browser are respected where they apply, and the position on them is stated in the consent manager rather than assumed. Older do-not-track headers are not a reliable signal and are not treated as one, which is the honest position rather than a claim of universal support.

None of this substitutes for the consent controls on the page. A browser setting is a blunt instrument applied to every site; the consent manager is the specific record of what you decided here, and it is the one that gets logged.

What you get

Four described categories

Strictly necessary, preference, analytics and marketing, each defined by what it actually does.

Reject all up front

Same screen, same visual weight as accept all, rather than buried behind a settings link.

Per-category control

Consent granted or withheld category by category rather than as a single opaque toggle.

Vendor-level disclosure

Each entry names the vendor, the purpose and the duration inside the consent manager.

Revocable at any time

A persistent control lets you change your mind, and withdrawing is as easy as granting.

Versioned consent record

Choices stored with a timestamp and the version of the notice that was shown.

Consent stored as necessary

Remembering a rejection requires storing it, which is why that record is strictly necessary.

Product uses necessary only

Session, tenant context and security state inside the application, with no consent banner.

No ad tech behind login

No third-party marketing pixels on authenticated pages, and none in the recruiter app.

Aggregate product telemetry

Feature and error metrics under the customer agreement rather than a personal tracking relationship.

Career portal boundary

Portal visitors are your data subjects; tags you add there carry your consent obligations.

Portal necessary-only default

The white-labelled portal ships without advertising technology attached to candidate pages.

Global privacy signals

Respected where they apply, with the position stated rather than assumed in the manager.

Honest third-party limits

Storage only a third party can clear is named as such instead of promised as cleared.

Questions recruiters ask

Can we reject everything and still use the site?

Yes. Rejecting analytics and marketing leaves the marketing site fully usable, and rejecting preference cookies only means the site forgets your market and currency choices between visits. Strictly necessary storage cannot be rejected while still using the site, because it carries session integrity, security tokens and the record of the rejection itself.

Does the signed-in product show a cookie banner?

No, because the storage it uses is strictly necessary: session tokens, authentication state, tenant context and security controls required to deliver a service you asked for. There is no advertising technology behind login and no third-party marketing pixels on authenticated pages. Product telemetry is aggregate feature and error data under the customer agreement.

Who is responsible for cookies on our career portal?

You are. Candidates arriving on your white-labelled portal are your visitors, under your notice and your jurisdiction. The portal ships on strictly necessary storage with no vendor advertising technology attached, but any analytics or advertising tags you add are yours, and the consent question travels with them. Say so in your own candidate notice.

What happens to cookies already set when we withdraw consent?

The affected categories stop firing on the next page load and associated storage is cleared where the browser allows it. Some third-party storage can only be removed by the third party that set it, which is a limitation of the medium rather than a policy decision. We state that rather than claiming a clean sweep we cannot deliver.

Do you honour do-not-track?

Older do-not-track headers are not a reliable or consistently implemented signal, and treating them as consent decisions would be misleading. Global privacy signals are respected where they apply, and the current position is stated in the consent manager rather than left to inference. Browser-level blocking always sits above anything the site can decide.

Is this page the cookie notice?

No. It explains the approach so you can decide what to allow. The binding document is the cookie notice published on this site as it currently stands, sitting under the privacy policy, and the consent manager is the live record of what is set, by whom and for how long. Inventories change; explanations age.

See it against your own reqs

Bring one live role and three resumes. In twenty minutes you will see the match scores, the shortlist and the placement invoice that comes out the other end.