BookkeeperHR
Log in

Cookies and Browser Storage

This page covers necessary browser storage, optional consent-based PostHog analytics and the separate Calendly booking choice. Analytics remains off until you allow it. The same permission also covers optional browser performance/error diagnostics sent to our hosting service.

What browser storage does

Cookies can accompany requests to a website. Local storage keeps values in your browser until removed; session storage normally lasts for a tab’s session. BookkeeperHR uses these mechanisms for sign-in, preferences and recovery of work you have not saved. Opening the homepage or legal pages does not load your profile or workspace. Existing sign-in cookies may still accompany requests to BookkeeperHR; account and app pages perform sign-in checks.

Types of cookies (how they are commonly classified)

By duration

  • Session cookies expire when you close the browser.
  • Persistent cookies remain until their expiry or deletion.

By provenance

  • First‑party cookies are set by this site.
  • Third-party content: Calendly can set or read its own storage once you choose to load its calendar. Opening Google sign-in or another provider’s site also subjects that interaction to the provider’s notice.

By purpose

  • Necessary cookies enable sign‑in, security, and basic functionality.
  • Functional preferences include language, workspace selection and acknowledgement of the storage information banner. Some app state, including unsaved hours, is stored locally.

How to manage cookies

You can inspect, block or remove site data in your browser settings. Blocking sign-in storage can prevent account access. Clearing local storage can remove unsaved timesheet drafts and preferences. On shared devices, save your work, sign out and clear site data when appropriate. Dismissing the information banner only remembers that you have read it; it does not enable optional services. Use the controls below to allow or reject analytics independently of Calendly. An old notice acknowledgement never grants analytics consent.

Your Calendly choice

No Calendly iframe is loaded until you select “Load Calendly”. Loading it connects your browser to Calendly, which receives technical information such as your IP address and browser details and may use cookies or similar storage. Calendly’s own cookie controls remain available; choosing to load the calendar does not accept every optional cookie it offers. You can choose “Keep calendar blocked” or email support instead. “Hide calendar” removes the embedded content and stops this page from loading it again until you choose to do so. It does not erase data already received or storage set by Calendly; use the provider’s controls or browser settings for that. We do not save the calendar choice across page reloads.

Read Calendly’s privacy and cookie information

Optional product analytics

With your consent, BookkeeperHR uses PostHog to measure completed enquiries and calendar bookings, new-account setup, workspace creation, uploads, invitation acceptance, and timesheet/leave submissions and approvals. We send only the action name, time, environment, schema version, an opaque event identifier and a pseudonymous identifier (your internal account ID when signed in, otherwise a random ID held in page memory). We do not send names, email addresses, document contents or filenames, hours, leave details, page URLs, query strings, sign-in tokens or referrers. There is no automatic page/click tracking, session replay, advertising, location enrichment or person-profile creation. Anonymous visits are not linked across page reloads or merged with accounts. PostHog necessarily receives network connection information; our project is configured to discard client IP data and each event disables location enrichment. Events use the EU ingestion endpoint; European hosting does not exclude international provider operations. The selected free plan currently provides one year of event retention; this is not a guarantee of deletion on an exact day. We act as controller for this optional service-improvement processing, based on your consent. You can refuse or withdraw in the Cookies page without affecting app access. Withdrawal stops future collection and cancels pending sends where possible; it cannot recall data already received. Contact support to exercise your rights. We review retention and this notice before changing the plan or collection.

Optional performance and error diagnostics

With the same optional analytics permission, and only when configured, your browser sends fixed operation categories, duration, outcome, HTTP status and a random per-request correlation ID to BookkeeperHR’s own diagnostic endpoint. These help us find slow navigation, session loading and API requests. Browser errors are reported as a fixed category; messages, stacks, page addresses, form contents and account identifiers are excluded. No additional tracking cookie or persistent identifier is created. These diagnostics go to our hosting logs, not PostHog. Essential server-side request, email-attempt and cleanup-job measurements may also be recorded to operate and protect the service, independently of optional browser consent. Email success means provider acceptance, not inbox delivery. Our application records exclude HR contents, credentials, raw IP addresses and user agents; the hosting service necessarily receives network information and may separately retain request metadata. Access, retention and processing locations follow the hosting account configuration and applicable agreements; no fixed retention or EU-only guarantee is made here. Optional browser collection stops when you reject analytics; records already received follow the applicable retention and rights process.

Legal basis

Storage necessary for sign-in, security or a feature you request is used for that functionality. The separate legal bases for processing personal data are explained in the Privacy Policy. Optional third-party booking content requires a separate choice; acknowledging the information banner is not that choice. Optional product analytics uses your consent and is never required for access.

BookkeeperHR browser-storage inventory

NamePurposeTypeExpiryEssential
sb-*Authentication session and sign-in flow; may be split into several cookies.CookieCurrent SDK default: up to 400 days, refreshed on account/app use. Session validity may be shorter.Required for sign-in
NEXT_LOCALELanguage selection.Cookie1 yearFunctional preference
COOKIE_NOTICE_ACK / cookie_notice_ack_v1Remember that the storage notice was acknowledged; not analytics consent.Cookie / local storageCookie: 1 year. Local storage: until cleared.Notice preference
currentWorkspaceIdLast selected workspace.Local storageUntil replaced or removed, or browser site data is cleared.App functionality
timesheet-draft:*Unsaved hours, project selections and the saved revision for a user/workspace/month.Local storageRemoved after a successful save or when an obsolete draft is detected; otherwise until cleared.Draft recovery
googleAuthInProgress / googleSignupInProgressTemporary sign-in state.Local storageRemoved when the flow consumes it; interrupted flows can leave it until cleared.App functionality
workspace-create:*Retry identifier for a workspace-creation request; the key includes the user identifier and entered workspace name.Session storageRemoved after confirmed creation or when the tab session ends.Safe retries
Calendly storageBooking and provider functionality after you choose to load the calendar. Other optional uses depend on the provider’s cookie choices.Third-party cookies / storageVaries by provider storage and browser settings; see Calendly’s notice.Optional external service
bhr_analytics_consent_v1Remember allow/reject; local storage notifies other tabs. No tracking identifier.Cookie / local storageCookie: 180 days. Local notification value: until replaced or cleared; expired choices are not used.Consent preference
bhr_analytics_auth_v1After consent only: pass confirmed signup/invitation completion across a sign-in redirect. Account ID, success flags and expiry; no auth credentials.Cookie5 minutes maximum; removed when consumed.Optional analytics

Last updated: 2026-09-23