What This Policy Covers
This covers the Grasshire Platform — this site, where you search jobs, hold an account and apply. It lists every cookie the site sets and every value it stores in your browser.
We use the word “cookie” loosely here, as most people do, to mean anything the site stores in your browser. The tables are precise about which mechanism each entry uses, because they behave differently — a cookie is sent to our server on every request, while local and session storage never leave your device.
Local and Session Storage
These live in your browser and are never sent to our servers. Clearing them loses a preference and nothing else.
| Key | Mechanism | What it remembers |
|---|---|---|
ros-theme | Local storage | Your Light, Dark or System theme choice. Read before the first paint, which is why the site does not flash white on load. |
ros-csrf-token | Local storage | A copy of the CSRF token above, for deployments where the cookie cannot be read across sites. Not a login credential — on its own it authenticates nothing. |
ros-analytics-consent | Local storage | Your answer to the analytics question in §6 — yes or no, and which version of this policy you were shown. This one is how we remember not to ask you again, and it is the only reason the next two entries may or may not exist. |
ros-visitor-id | Local storage | A random number identifying this browser, so a job you open twice is not counted as two people. Only written if you said yes, and deleted the moment you change your mind. It is not built from your name, email, phone or account — it is not connected to who you are, and it is the only entry on this page you are asked about. |
ros-application-drafts | Local storage | Which jobs you have an unfinished application for, so the Drafts tab can find them — the job id, its title and when you last saved, for at most 25 jobs. Not your answers: those stay on our servers, and this list is only used to ask for them. It is per-browser, which is why a draft saved on your phone does not appear on your laptop, and kept separately for each account that signs in on that browser, stored under this name followed by your internal account ID. |
ros-view-session | Session storage | A random number for this browser tab, sent with the same view signal. Only written if you said yes, and gone when you close the tab. |
Firebase Authentication’s own storage
When you sign in, Google’s Firebase Authentication library stores its own session state in IndexedDB and local storage so you are not asked to sign in again on every visit. We do not read or write it ourselves, and its contents are Google’s format rather than ours.
What We Do Not Use
Stated as a list because its absence is the point, and because “we may use cookies for analytics” is the sentence most job sites hide behind:
- No third-party analytics. No Google Analytics, no tag manager, no product-analytics SDK. Nothing on this site reports what you do to anyone but us, and §7 is the complete list of who is contacted.
- No profile of you, and no behavioural targeting. We count openings of a job posting. We do not build a picture of you from them, we do not use them to decide what you are shown, and they reach the employer as numbers on their own job — never as a list of what you read.
- No advertising cookies, no advertising pixels and no conversion tags.
- No session recording or heatmap tool. Nobody replays your screen.
- No fingerprinting by us — we do not profile your device, fonts, canvas or hardware, and nothing we run examines them. On the four sign-in pages only, Google’s reCAPTCHA does look at device and interaction signals; that is how it tells a person from a script, it happens nowhere else on this site, and neither we nor Google use it here to profile you or to decide what you are shown. See §7.
- No cross-site or cross-context tracking, and no data sold or shared for it. Nothing you do here follows you to another site. An employer sees the count on their own posting and nothing else — no employer learns which other jobs you viewed, on this site or anywhere.
- No IP address and no user-agent recorded against your session, your consent, or a job view — including the view signal in §5, which is why declining costs you nothing in privacy that we were collecting anyway. This is unusual and it is deliberate.
We do not respond differently to a Do Not Track header. It is unenforced and ambiguous, and §6 asks you the question directly instead — which is a worse excuse than the one this sentence used to give, and a more honest one.
The One Thing We Ask You
Consent rules exist for storage that is not needed to deliver the service you asked for. Everything in §2 and the first three rows of §3 is either strictly necessary to run the site or a preference you set yourself. Exactly one entry is neither: ros-visitor-id, the random number that lets a job’s view count tell a returning reader from a new one. So we ask about that one, and only that one.
The banner appears once, on your first visit, with Accept and Decline the same size and the same prominence. Declining is not hidden behind a second screen and does not have to be repeated per purpose, because there is only one purpose. Your answer is remembered in ros-analytics-consent and you are not asked again unless this policy substantially changes.
Changing your mind
The link in the site footer reopens the choice, and so does the Privacy section of your profile if you have an account. Choosing Decline after having accepted deletes ros-visitor-id rather than merely stopping its use — the number is gone from your browser, and accepting again produces a new one that cannot be joined to the old.
Third-Party Requests From This Site
| Request | What it discloses | Storage set |
|---|---|---|
| Google Fonts — the Inter typeface, on every page load | Your IP address and browser user-agent, to Google | None |
| Firebase Authentication (Google) — when you sign in | Your email address or Google account, to Google | IndexedDB and local storage — see §3 |
| Google reCAPTCHA Enterprise — on the sign-in, registration and password-reset pages only | Your IP address, browser user-agent and how you interacted with the page, to Google. It is what stops scripts creating accounts in bulk and using our signup form to send mail to addresses that never asked for it. | A _GRECAPTCHA cookie, set by google.com — not by us, and not readable by us |
| Our own API — every data request the site makes | Your session cookie, to us | See §2 |
No advertising network, analytics provider, social widget or embedded tracker is loaded on any page of this site. reCAPTCHA is the one third-party script that examines how you use a page, and it is loaded on four pages — sign-in, registration, forgot-password and reset-password — and on none of the job pages. It is there to keep automated abuse off the sign-up form, which is a security measure rather than a choice about advertising, so it is not covered by the question in §6; if you would rather not be assessed by it, you can browse and search every job on this site without ever loading it.