Cookie Policy
Effective Date: May 17, 2026 | Last Reviewed: May 17, 2026
This Cookie Policy ("Policy") explains how Law Hired ("Law Hired," "we," "us," or "our") uses cookies and similar tracking technologies on the Law Hired website (https://lawhired.com), mobile application, and related services (collectively, the "Platform"). This Policy is incorporated by reference into our Privacy Policy and Terms of Service. By using the Platform, you consent to the use of cookies as described in this Policy.
1. What Are Cookies
Cookies are small text files that a website or application places on your device (computer, smartphone, or tablet) when you visit it. They are widely used to make websites work efficiently, to remember your preferences, and to provide information to site operators. Cookies are not programs and cannot carry viruses or install malware on your device.
In addition to cookies, we may use similar tracking technologies such as:
Local Storage and Session Storage: Browser-side key-value stores used to persist user interface state (e.g., sidebar open/closed, draft form data) within or across sessions without sending data to our servers on each request.
Pixels and Web Beacons: Tiny transparent image files that help us understand how pages and emails are accessed. Law Hired does not currently use advertising pixels.
Device Fingerprinting: Used exclusively by our payment processor, Stripe, for fraud detection purposes. Law Hired does not conduct independent device fingerprinting.
This Policy uses "cookies" as a shorthand for all such technologies collectively unless a distinction is material.
2. How Law Hired Uses Cookies
Law Hired uses cookies for the following categories of purposes. We do not use advertising, retargeting, or behavioral profiling cookies, and we do not sell cookie data to third parties.
2.1 Essential / Strictly Necessary Cookies
These cookies are required for the Platform to function and cannot be disabled. They include authentication tokens that keep you logged in, CSRF protection tokens that secure form submissions, and session identifiers that maintain your state across page loads. Without these cookies, core Platform features — including logging in, processing payments, and accessing your account — would not work. These cookies do not require your consent under applicable law.
2.2 Performance and Analytics Cookies (PostHog)
Law Hired uses PostHog, a product analytics platform, to collect information about how users interact with the Platform. PostHog analytics help us understand which features are used, identify friction points, measure funnel conversion, and prioritize product improvements. PostHog analytics on Law Hired are configured as follows:
Data is collected at the session and event level (page views, button clicks, feature usage).
PostHog is configured to respect opt-out signals and our cookie consent mechanism.
We do not use PostHog session recording (video replay) in a manner that captures sensitive legal content, form inputs, or personal data fields.
PostHog data is processed under a Data Processing Agreement. PostHog does not share Law Hired user data with third parties for advertising purposes.
Analytics data is retained for 12 months on the PostHog platform.
You may opt out of PostHog analytics at any time through our cookie consent settings or by using PostHog's opt-out mechanism at posthog.com/docs/privacy.
2.3 Functional Cookies
Functional cookies remember your preferences and choices to provide a more personalized experience. Examples include remembering your selected language, storing your cookie consent choice so you are not prompted repeatedly, and preserving your UI preferences (e.g., dashboard layout). These cookies do not track your activity across third-party websites.
2.4 Advertising Cookies — NOT USED
Law Hired does not use advertising cookies, retargeting pixels, or behavioral profiling technologies. We do not share your browsing data with advertising networks, social media platforms, or data brokers for advertising purposes.
3. Specific Cookies Used
The table below lists the specific cookies currently set by Law Hired and its key third-party partners. Cookie names that include dynamic identifiers (such as Supabase project IDs or PostHog API key fragments) are shown with placeholder notation.
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
| sb-<project>-auth-token | Supabase | Stores the authenticated user session token for secure login and API access across the Platform. | Session / up to 7 days (rolling refresh) |
| sb-<project>-auth-token-code-verifier | Supabase | Stores the PKCE code verifier used during the OAuth 2.0 authentication flow to prevent authorization code interception attacks. | Session |
| ph_<project_id>_posthog | PostHog | Identifies a distinct anonymous or identified user session for product analytics. Tracks page views, feature usage, and funnel events to improve the Platform. | 1 year |
| __ph_opt_in_out_<project_id> | PostHog | Records whether the user has opted in or out of PostHog analytics tracking. | 1 year |
| __stripe_mid | Stripe | Fraud detection and machine learning cookie used by Stripe to identify devices and prevent fraudulent payment transactions. | 1 year |
| __stripe_sid | Stripe | Session-level fraud detection cookie used by Stripe during the payment checkout flow. | Session (30 minutes) |
| m | Stripe | Device fingerprinting cookie used by Stripe to associate payment activity with a device for fraud prevention. | 2 years |
| lawhired_cookie_consent | Law Hired | Records the user's cookie consent preferences (accepted / declined / categories selected) to avoid re-prompting on subsequent visits. | 1 year |
| lawhired_session | Law Hired | Maintains the user's Platform session state, current route context, and UI preferences (e.g., sidebar state, theme). | Session |
| lawhired_csrf | Law Hired | Cross-Site Request Forgery (CSRF) protection token used to validate that form submissions and API requests originate from legitimate Platform sessions. | Session |
This list is updated periodically. If you believe a cookie is in use that is not listed here, please contact us at legal@lawhired.com.
4. Third-Party Cookies
Law Hired integrates with the following third-party services that may set cookies on your device. These third parties have their own privacy and cookie policies, which Law Hired does not control.
4.1 Stripe (Payment Processing)
Stripe sets cookies on the Law Hired Platform solely for the purpose of fraud detection, security, and payment processing. Stripe does not use these cookies to deliver advertising. You can review Stripe's cookie policy at stripe.com/cookies-policy. To opt out of Stripe's device fingerprinting, you may need to block Stripe's cookies in your browser settings; however, doing so may prevent payment processing from functioning correctly.
4.2 PostHog (Product Analytics)
PostHog sets analytics cookies as described in Section 2.2. PostHog's privacy documentation is available at posthog.com/privacy. To opt out of PostHog tracking specifically, you may use the cookie consent toggle in the Platform footer, or follow PostHog's opt-out instructions at posthog.com/docs/privacy.
4.3 Supabase (Authentication Infrastructure)
Supabase sets authentication-related cookies that are strictly necessary for login and session management. These are first-party in the sense that they are set in response to Law Hired's authentication system, but are powered by Supabase infrastructure. They cannot be disabled without disabling login functionality. Supabase's privacy policy is available at supabase.com/privacy.
5. Cookie Consent
5.1 How We Obtain Consent
On your first visit to the Platform (or after clearing cookies), you will be presented with a cookie consent banner. The banner gives you the ability to accept all cookies, reject non-essential cookies, or customize your preferences by category (Essential, Analytics, Functional). Essential cookies are always active. Your consent choice is stored in the lawhired_cookie_consent cookie for up to 12 months so you are not re-prompted on every visit.
5.2 How to Withdraw Consent
You may update or withdraw your cookie consent at any time by:
Clicking the "Cookie Preferences" link in the footer of any page on the Platform.
Clearing your browser cookies, which will remove your stored consent and prompt the consent banner on your next visit.
Using browser-level controls as described in Section 6.
Withdrawal of consent for non-essential cookies does not affect the lawfulness of processing that occurred before withdrawal. It will, however, disable PostHog analytics tracking and any other non-essential cookies from that point forward.
6. Managing Cookies — Browser Settings
You can control and delete cookies through your browser settings. The following instructions apply to the most common browsers. Note that disabling all cookies may impair Platform functionality, including preventing you from logging in.
Google Chrome: Settings → Privacy and security → Cookies and other site data. You can block all cookies, block third-party cookies, or clear cookies for specific sites.
Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data. Firefox allows you to block cookies by category and to manage exceptions per site.
Apple Safari (macOS): Safari menu → Settings → Privacy → Manage Website Data. You can remove all cookies or remove cookies for specific websites.
Apple Safari (iOS): Settings → Safari → Advanced → Website Data. Tap "Remove All Website Data" or select individual sites.
Microsoft Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data. Edge allows blocking by category and per-site exceptions.
For browsers not listed above, refer to your browser's official help documentation on cookie management. You may also use tools such as youronlinechoices.com or optout.networkadvertising.org to manage opt-outs across participating networks.
7. Do Not Track
Some browsers offer a "Do Not Track" (DNT) setting that sends a signal to websites requesting that your browsing activity not be tracked. There is currently no universally accepted technical standard for how websites must respond to DNT signals.
Law Hired's current response to DNT signals: We acknowledge DNT signals but do not currently alter our Platform's data collection practices in response, because the lack of a universal standard means DNT signals cannot be reliably interpreted across all contexts. Our PostHog analytics integration, however, does support explicit user opt-out through the cookie consent mechanism described in Section 5, which is a more reliable and controllable method for managing analytics collection.
We will revisit our DNT response as legal standards and technical specifications evolve. California residents have additional rights under the CPRA as described in Section 8.
8. CCPA / CPRA — California Residents
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you specific rights with respect to personal information collected through cookies and similar technologies.
8.1 Categories of Information Collected via Cookies
Through the cookies described in this Policy, Law Hired may collect the following categories of personal information as defined by the CCPA:
Identifiers: such as device ID, session ID, and IP address (processed by PostHog and Stripe for analytics and fraud detection).
Internet or other network activity: such as pages visited, features used, and time spent on the Platform (PostHog analytics).
Inferences: PostHog may derive inferences about feature preferences or usage patterns from collected data. Law Hired does not use these inferences for advertising.
8.2 Your California Privacy Rights Regarding Cookie Data
Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you through cookies, the sources, the business purpose, and the third parties with whom it is shared.
Right to Delete: You may request deletion of personal information collected through cookies, subject to certain exceptions (e.g., information necessary for security or fraud prevention).
Right to Opt Out of Sale or Sharing: Law Hired does not sell your personal information or share it with third parties for cross-context behavioral advertising. If this changes, we will update this Policy and provide an opt-out mechanism.
Right to Limit Use of Sensitive Personal Information: Law Hired does not use sensitive personal information (as defined by the CPRA) collected through cookies for purposes beyond those permitted without limitation under the CPRA.
Right to Non-Discrimination: Exercising your CCPA/CPRA rights will not result in discriminatory treatment.
To exercise your California privacy rights, submit a verifiable consumer request to legal@lawhired.com with the subject "CCPA Rights Request." We will respond within 45 days as required by law.
8.3 "Opt Out of Sale" — GPC Signal
The CPRA requires businesses to treat a Global Privacy Control (GPC) signal as a valid opt-out-of-sale request. Law Hired honors GPC signals. If your browser transmits a GPC signal, we will treat it as a request to opt out of the sale and sharing of your personal information. Because Law Hired does not sell or share personal information as those terms are defined by the CPRA, this signal will not change our current data practices but is logged and respected as required by law.
9. Updates to This Policy
We may update this Cookie Policy from time to time to reflect changes in cookies we use, third-party integrations, applicable law, or our business practices. When we make material changes, we will:
Update the "Effective Date" and "Last Reviewed" date at the top of this Policy.
Notify registered users by email or in-app notice at least 14 days before changes take effect.
Re-prompt your cookie consent if the changes affect the categories of non-essential cookies used.
Continued use of the Platform after an updated Policy's effective date constitutes your acceptance of the changes.
Contact
Law Hired
Cookie and privacy inquiries: legal@lawhired.com
Website: https://lawhired.com
