Cookie policy
Last updated: 21 August 2026
In short
This public website sets no analytics or advertising cookies. We use cookieless, aggregate website statistics to improve the site, and you can object to that measurement below without affecting your access.
Inside the HollyHR application we set a small number of strictly necessary cookies, and we run product analytics only if you explicitly allow it.
If you arrive through one of our paid Google or Microsoft Search ads and continue to signup, the application asks separately before loading any advertising measurement. Declining does not affect signup or the service.
1. This website (hollyhr.com)
We use Vercel Web Analytics and Vercel Speed Insights to count page views and measure page performance. Per Vercel's published documentation, these:
- set no analytics cookies;
- count visitors using a hash derived from the incoming request, which is discarded within 24 hours and cannot be used to follow you across sites;
- do not store your IP address;
- record aggregate page and performance data plus a fixed interaction event for public signup-link clicks. It never includes your name, email, free text, full referrer URL, query string, or an advertising click identifier.
- report standard campaign parameters such as source, medium, campaign, term, and content when a link to HollyHR contains them; our convention forbids personal information or free text in those fields.
We use these tools solely to create aggregate statistics for improving the website, under the statistical-purpose exception in the UK Privacy and Electronic Communications Regulations. The resulting data cannot be linked back to you. We give you a simple way to object below and list Vercel in our sub-processor register.
If you object, this browser stores one local preference named hhr_public_analytics_preference so the site can suppress both Web Analytics and Speed Insights events on later pages and visits. The preference is used only to remember your objection and is removed if you resume aggregate analytics.
Aggregate website analytics
Checking analytics preference
This choice applies only to cookieless Vercel Web Analytics and Speed Insights on this website in this browser. It does not enable advertising measurement or signed-in product analytics.
We do not use advertising cookies, tracking pixels, or third-party marketing trackers on this website. For a canonical paid-search visit, a signup link may carry the fixed campaign source and a validated provider click identifier to the application in the URL fragment after the #. A fragment is not sent in the application's document request. The HollyHR marketing application does not write that identifier to browser storage or include it in the custom signup-link event, and it does not load Google or Microsoft advertising code.
2. The HollyHR application
Strictly necessary cookies. These keep you signed in and cannot be turned off without breaking the service: your session, the organisation you have selected, and your theme preference. They are set only after you sign in.
Product analytics (consent required). We use PostHog Cloud EU to understand how the app is used. It runs only for signed-in users, only in production, and only after you choose "Allow analytics". Until you do, no analytics script captures anything. You can change your choice at any time.
We never send HR record contents, free-text fields, employee names, or email addresses to PostHog, and we do not sell personal data. Beyond the consented internal account context described above, performance event data is limited to scalar Web Vitals and sanitized page families; it excludes browser/device metadata, performance entries, DOM attribution, raw URLs, query strings, and browser metric identifiers.
Paid-search measurement (separate consent required). A visitor who continues from a canonical Google or Microsoft Search ad is shown an advertising-measurement choice on the application host. Before an allow choice, HollyHR loads no advertising provider, sends no advertising request, and writes no advertising identifier to cookies or browser storage.
If you allow, the application loads only the provider that matches the paid source. It initialises limited conversion measurement and, if you create a new organisation, sends one organisation_created conversion. Those events contain no name, email, employee data, HR record, free text, search term, or internal HollyHR identifier. We do not use the launch setup for remarketing or personalised ads.
hhr_ad_measurement_consentis a signed, host-only, HttpOnly cookie recording allow or decline for up to 180 days. It contains no identity or provider identifier.hhr_paid_attributionis a signed, host-only, HttpOnly cookie containing only the fixed source,cpcmedium and canonical campaign for up to 30 days. It is consumed after the first successful organisation creation and never contains a provider click identifier.hhr_paid_click_id_v1is exact-origin application browser storage for one validated Google or Microsoft click identifier, expiring after 30 days. It is removed on decline, withdrawal, expiry, source mismatch, or after the primary conversion dispatch.- Google Ads may set host-only
_gcl_*measurement cookies onapp.hollyhr.com, limited to 30 days by our configuration. Microsoft UET is configured not to store its own conversion-tracking cookies.
3. Managing cookies
You can block or delete cookies in your browser settings. Blocking strictly necessary cookies will prevent you from signing in. You can use the aggregate analytics control above at any time; clearing browser site data also removes the saved objection, returning this browser to the default aggregate-measurement setting. A consented paid visitor can use the application's Ad measurement choices control to withdraw. Withdrawal sends a denied signal to an already loaded provider, suppresses future HollyHR conversion calls, and removes the advertising state HollyHR can reach on the application host. You can also clear site data in your browser.
4. Questions
See our privacy policy for how we handle personal data more broadly, or contact us at info@hollyhr.com.