Legal
Cookie policy
Last updated: 16 August 2026
HaloHR uses a small number of cookies and equivalent browser storage. Most of it exists to keep you signed in and to remember which workspace you were looking at. This page explains each category and how to control it.
01Strictly necessary
These are required for the platform to function and cannot be switched off. They include your authentication session, a cross-site request forgery token, and the load-balancing identifier that keeps a request on the right server.
The authentication session is stored in your browser by our identity provider, Supabase. Clearing it signs you out.
02Preferences
We store your active workspace, sidebar state, favourite pages, recently visited routes, notification preferences, and any product tour you have dismissed. These live in local storage in your browser rather than being sent to us on every request. Clearing them resets the interface to defaults; nothing else is affected.
03Impersonation and support sessions
When an authorised platform administrator views a workspace on your behalf during support, that state is held in session storage and ends when the browser tab closes. Every impersonation session is recorded in the audit log with the administrator, the workspace, and the time.
04Analytics
On our public marketing pages we measure aggregate page views and referrers to understand which pages are useful. We do not use advertising cookies, we do not run cross-site tracking pixels, and we do not build profiles of individual visitors. No analytics are collected inside the authenticated product.
05Third parties
A small number of subprocessors set storage in the course of providing their part of the service — our identity provider for authentication, our hosting provider for edge routing, and where enabled a bot-protection widget on public application forms. We do not permit them to use that storage for advertising.
06Controlling cookies
You can block or delete cookies and local storage in your browser settings. Blocking strictly necessary storage will prevent you from signing in. Blocking preference storage only means the interface will not remember your choices between visits.
Where local law requires consent for non-essential storage, we ask for it before setting anything beyond the strictly necessary category.
07Changes
If we add a new category of storage we will update this page and change the date at the top before the change takes effect.
Questions about cookies or privacy: privacy@halohr.ai