Cookie and Tracking Policy
Operated by Jaspin LLC · Effective
At a glance
Six cookies and storage keys, and three of them are optional. All three optional ones belong to Microsoft Clarity, which records sessions. Signed-in pages also keep unsaved drafts and interface state locally, which never leave your device. A seventh key in the table, sc_internal, is set on SupaCV staff browsers only and never on yours.
Decline and Clarity never loads. It is not switched off after the fact; the script is not fetched at all.
We run no advertising cookies, no ad pixels, and no cross-site trackers. There is nothing here that follows you to another website.
This summary is for orientation only. The full text below is what actually applies.
This policy explains the cookies and similar technologies SupaCV uses, and how to change your mind at any time. Read it alongside the Privacy Policy, which covers everything else we collect.
1. Change your choice
Use the control below. It takes effect immediately and applies to this browser.
2. What these technologies are
Cookies are small text files a site stores in your browser. Related technologies do similar jobs: local storage and session storage keep values in the browser without sending them on every request, and session-replay tools record how a page is used.
A cookie is first-party when the site you are visiting sets it, and third-party when another company does. It is a session cookie when it disappears as soon as you close the browser, and persistent when it survives for a set time.
3. The categories we use
Strictly necessary
Sign-in, session security, and storing your cookie choice itself. These cannot be switched off through the control above, because without them you could not stay signed in and we would have nowhere to record that you declined.
One security check belongs here too. On the sign-up, sign-in and password-reset pages, when you change your password, and when you start a free scan, Cloudflare Turnstile runs in your browser to tell people from automated traffic. It looks at your IP address and technical signals from your browser and device. It cannot be switched off, for the same reason a lock cannot be optional, and we use its answer for nothing except deciding whether to accept the request. What Cloudflare does with that data is governed by its own policy, linked from our subprocessor list.
Analytics
Understanding which features get used and where they break. Of the four measurement tools SupaCV runs, two store nothing in your browser at all, one stores a short-lived attribution value we set ourselves, and only Microsoft Clarity sets cookies. Clarity is the only one that requires consent, and the only one the control above turns on or off.
Functional
Interface preferences such as which view you last had open. These stay in your browser and are never sent to a third party.
Marketing and advertising
None. SupaCV sets no advertising cookies and runs no ad-network pixels or conversion trackers. If that ever changes we will update this policy and ask for consent before anything loads.
4. Every cookie and key we set
| Name | Set by | Category | What it does | Lasts |
|---|---|---|---|---|
sb-*-auth-tokenCookie | SupaCV (Supabase Auth) | Strictly necessary | Keeps you signed in. Sent only over HTTPS. It is readable by scripts running on supacv.com, because the sign-in library refreshes your session in the browser rather than on the server. | Up to 400 days, refreshed while you stay active |
supacv:cookie-consentLocal storage | SupaCV | Strictly necessary | Remembers whether you accepted or declined analytics cookies, when you chose, and which version of this policy you chose against, so we stop asking until something material changes. | Until you clear site data |
sc_first_touchSession storage | SupaCV | Analytics | Remembers which page and referrer brought you to the site, so a sign-up can be attributed to a source. Any id in the page address is replaced by a placeholder before it is kept, and values are capped at 120 characters. Whether this key exists yet is also how our page view counter tells the first page of a visit from later ones. In a tab you open from another SupaCV page it holds only a note that your visit began in another tab, with no page and no referrer. If you sign up, the source category and landing page are written once against your new account, whatever you choose about analytics cookies. If you run a free scan without an account, the same source category and landing page are saved once with that scan. Nothing extra is stored in your browser for either use. | Until you close the tab |
sc_internalLocal storage | SupaCV | Analytics (SupaCV staff browsers only) | Set only on SupaCV staff browsers, never on a visitor’s. It is written when a member of our staff opens our admin pages, and it tells our own page view counter to leave that browser out, so our numbers count visitors and not ourselves. It holds a 1 or a 0, is read only inside the browser, and is never sent to our servers or to anyone else. | Until site data is cleared |
_clckCookie | Microsoft Clarity | Analytics (consent required) | Identifies a returning visitor to Clarity so recordings can be grouped together. | Up to 12 months |
_clskCookie | Microsoft Clarity | Analytics (consent required) | Joins the page views in a single visit into one recording. | 1 day |
CLIDCookie | Microsoft Clarity | Analytics (consent required) | Set by clarity.ms to link the recording to the correct Clarity project. | Up to 12 months |
The table covers what SupaCV sets for sign-in, consent and measurement. Signed-in pages also keep working state in your browser so a refresh does not lose your place, including unsaved editor drafts and interface preferences. Those never leave your device, are not sent to us or to anyone else, and clearing site data removes them.
Two more measurement tools run without storing anything on your device. Vercel Web Analytics counts visitors using an identifier it discards within 24 hours, and strips query strings to a marketing-parameter allowlist before the measurement leaves your browser. Ahrefs Web Analytics measures our marketing pages in aggregate. Neither sets a cookie, so neither is consent-gated: there is no storage to consent to and nothing the control above could switch off.
5. What we deliberately do not use
- No Google Analytics and no Google Tag Manager. Our product analytics are first-party and stay in our own database.
- No advertising or retargeting pixels. No Meta pixel, no LinkedIn Insight tag, no Google Ads conversion tag.
- No Stripe cookies on this site. Payment happens on Stripe’s own hosted checkout page, so any cookies Stripe sets are set there, under Stripe’s domain and its own policy, not by supacv.com.
- No fingerprinting to recognise youand no attempt by us to identify you across other websites. The one place your browser’s technical signals are examined is the Turnstile security check described in section 3, which exists to tell people from bots, not to work out who you are. Microsoft Clarity is the one third party that sets cookies here, and only with your consent; what Microsoft does with them is governed by its own policy, linked below.
6. How consent works here
On your first visit a small banner in the corner of the page asks whether to accept analytics cookies. It does not block the page: you can keep using SupaCV without answering. Accept all and Reject all sit side by side, and each takes one click. A third option, Cookie settings, opens a panel that lists each category. The Analytics switch in that panel starts in the on position, so if you open it and want to decline, either turn the switch off and confirm, or use Reject all, which is in the panel too.
Nothing requiring consent loads before you choose. Clarity stays unloaded while your choice is unset, including while the banner is on screen and unanswered, rather than loading and being told not to report. The position of a switch you have not confirmed counts for nothing.
Your choice governs one thing: whether Microsoft Clarity records your sessions. It does not switch our own product records on or off, and it does not decide whether they are tied to you. While you are signed in, what you do in SupaCV (uploading a resume, running an analysis, exporting, opening a paywall, and the days on which you were active) is recorded against your account whether you accept or decline, because we need it to support you and to see where the product fails. Those records sit in our own database, set no cookie, and are not sent to any analytics vendor. The Privacy Policy sets out the legal basis. Page views are the exception: they are never tied to an account. Before you sign in there is no account to tie anything to.
One of those records is written when you sign up, not while you are signed in: how you first arrived (the source category and landing page held in sc_first_touch), a two-letter country, and whether the device was a phone, tablet, or desktop. It is written once, against the new account, whatever you chose about cookies. The same source category and landing page are also saved once with a free scan you run without an account, described in section 7 of the Privacy Policy, which also lists these records in section 3.
You can change your choice at any time using the control in section 1, reachable from the footer of every page. Withdrawing consent is exactly as easy as giving it. Because Clarity cannot be unloaded from a page it has already begun recording, reload the page after switching to Decline if you want it to stop within the same visit.
One limit worth knowing: declining stops Clarity loading again, but it does not reach into cookies Clarity has already set. Those stay until they expire or you clear site data.
Your choice is stored per browser. Clearing site data or moving to another device means you will be asked again.
We also keep a record of the choice itself: which option you picked, when, and which version of this policy it applied to. Data-protection law expects us to be able to show that a choice was actually made, and a flag living only in your browser cannot show that, because it disappears when you clear site data. If you are signed in, the record is kept against your account, including when the choice was to decline, because a record of a choice has to show whose choice it was. The record holds no IP address. Your choice is tied to the version above, so when we change this policy materially we will ask again rather than carrying an old answer forward.
7. Browser controls and opt-outs
Every major browser lets you block or delete cookies in its settings, and most offer a private mode that discards them when you close the window. Blocking strictly necessary cookies will stop you signing in.
We honour Global Privacy Control. If your browser sends the GPC signal we treat it as a standing instruction to decline: Clarity does not load, no sessions are recorded, and you are not shown the banner. It does not change the product records described in section 6, which we do not sell or share and so are not what the signal is about. We do this everywhere, not only in the states that require it, and the signal wins over a stored choice rather than the other way round. You can also read about Microsoft Clarity in Microsoft’s privacy statement.
8. Changes to this policy
Our stack changes, and this inventory changes with it. We post the updated version here with a new effective date, and where a change is material, such as adding a technology that needs consent, we will ask again before it loads.
9. Contact
Questions about cookies: privacy@supacv.com
Jaspin LLC
30 N Gould St Ste N
Sheridan, WY 82801
United States
Other policies
- Terms of ServiceThe contract between you and Jaspin LLC covering accounts, subscriptions, your content, AI output, and dispute resolution.
- Privacy PolicyWhat we collect, who receives it, how long we keep it, and the controls you have over all of it.
- Refund, Cancellation and Subscription PolicyHow billing, renewal, cancellation, trials, price changes, and refunds work on the Pro and Career plans.
- Acceptable Use PolicyWhat you may not do with SupaCV, including the line between tailoring a resume and falsifying one.
- Sub-processorsEvery third party that receives SupaCV data, what each one receives, and where it is processed.