Cookie Policy

Effective Date: June 8, 2026 · Last Updated: June 8, 2026

Version: 2026-06-08

1. Introduction

HeadHonta ("we," "us," or "our") uses cookies and similar technologies on our website and services (collectively, the "Service"). This Cookie Policy explains what these technologies are, which categories we use, and how you can control them.

When you first visit HeadHonta, we show a consent banner. Until you accept, all non-essential trackers — analytics and session replay — are disabled, and choosing "Decline" keeps them off. Your choice is stored in your browser (using localStorage) and remembered for future visits.

This Cookie Policy supplements our Privacy Policy, which describes how we handle personal data more broadly.

2. What Are Cookies

Cookies are small text files stored on your device when you visit a website. We also use related technologies such as browser localStorage and similar trackers, which we refer to collectively as "cookies" in this policy. They help the Service function, remember your preferences, keep you signed in, and — where you consent — understand how the Service is used.

Cookies may be set by us ("first-party") or by the third-party tools we rely on ("third-party"). They may persist after your session ends ("persistent") or be cleared when you close your browser ("session").

3. Categories We Use

3.1 Strictly Necessary

These are always on and cannot be disabled because the Service cannot function correctly without them. They include:

  • Authentication and session — a JWT access token held in memory and a refresh token stored in an httpOnly cookie to keep you securely signed in.
  • Security and CSRF protection — to guard against cross-site request forgery and other attacks.
  • Load balancing — to route your requests reliably across our infrastructure.
  • Cookie-consent choice — remembering whether you accepted or declined non-essential cookies.

3.2 Functional

These remember your preferences to improve your experience. They include:

  • UI preferences — such as your sidebar state and similar interface settings.

3.3 Analytics & Session Replay (Consent-Required)

These are disabled by default and only run after you accept them via the consent banner. They include:

  • Mixpanel — product usage analytics and session replays of UI interactions to help us understand how the Service is used. No keystrokes or form-input content are recorded.
  • Nodge — onboarding funnel measurement using event-level data only (such as stage name, timestamps, and field-level error reasons). Nodge does not record session replays or form-input content.

You can change or withdraw your consent at any time. To do so:

  • Re-open the cookie banner or clear your stored consent choice to be prompted again.
  • Adjust your browser settings to block or delete cookies and similar storage.

Please note that disabling strictly-necessary cookies may break the Service or prevent it from functioning correctly.

5. Third-Party Cookies

The consent-required tools we use may set and read their own cookies or storage when enabled:

  • Mixpanel — see Mixpanel's Privacy Policy.
  • Nodge — an onboarding analytics provider that receives event-level data only.

For a full list of the third parties that process data on our behalf, see our sub-processor list.

6. Changes to This Policy

We may update this Cookie Policy from time to time. We will post any changes on this page and update the "Last Updated" date above. We encourage you to review this policy periodically.

7. Contact Us

If you have questions about this Cookie Policy or how we use cookies, contact us at: