Controller
TOKEN LABS LIMITED (company number 17372231), trading as HateInterviews, operates the website and dashboard described in our Privacy Policy. Registered office: 98 Lozells Road, Birmingham, England, B19 2TB. Privacy contact: support@hateinterviews.com.
What “cookies” covers
PECR regulates technologies that store or access information on your device. That includes HTTP cookies, local storage, session storage, pixels, and similar tools. Some are set by us; others by processors (for example auth or Stripe Checkout) when you use their flows.
What we use today
Strictly necessary (no PECR consent required). Needed to provide a service you request — for example keeping you signed in, securing the session, CSRF/security protections, and completing Stripe Checkout. Without these, login and billing will not work.
Appearance / preference storage. For example remembering light/dark theme so the UI does not flash on reload. Where this only stores a UI preference you chose, we treat it as low-impact preference storage. You can clear it in browser settings without deleting your account.
Analytics or marketing. We do not currently run third-party advertising pixels or non-essential product-analytics suites on the marketing site. If we add them, we will update this notice and obtain prior opt-in consent where PECR requires it (equal prominence for reject, no pre-ticked boxes, non-essential tags blocked until you accept).
Referral / invite attribution
If you arrive through an invite or affiliate link, we may need to remember a referral code long enough to attribute a later signup. Where that uses device storage that is not strictly necessary for a service you have already requested, we will either:
- ask for consent before storing it; or
- keep the code in the URL until you open signup/login, and only then set a first-party referral cookie tied to that auth flow (or attribute server-side after account creation).
Our production behaviour follows the second approach: landing pages with ?ref= pass the code into register/login links; a referral cookie is set only on those auth routes after the server confirms the code belongs to an active creator affiliate. Unknown or disabled codes are not stored.
Examples tied to our stack
- Auth session cookies or tokens via our authentication provider (Supabase).
- Theme preference keys in local browser storage.
- Cookies on Stripe-hosted Checkout pages (see Stripe’s own notices during payment).
How to control cookies
Use your browser settings to block or delete cookies. Blocking all cookies will break sign-in. Preference-only storage can usually be cleared independently.
When we introduce optional analytics or marketing cookies, we will provide a consent control consistent with ICO PECR guidance (including UK/EU-style opt-in where required). Essential cookies will continue to run without a banner.
Client apps
Native client apps do not use website cookies to run interview sessions. Sign-in still uses our auth provider. Personal data practices are in the Privacy Policy.
Your rights and updates
For personal data rights (access, erasure, ICO complaints, and so on), see the Privacy Policy. We may update this Cookie Notice when our technologies change; check the date at the top.
Contract terms: Terms of Service.