1. Introduction
This Cookie Policy explains how EuropeCV ("EuropeCV", "we", "us", or "our") uses cookies and similar technologies on https://www.europecv.io.
It should be read together with our Privacy Policy at /privacy and our Terms of Service at /terms.
This policy is based on the actual EuropeCV application as implemented in our codebase. It does not list cookies or technologies that are not used.
2. Who This Policy Applies To
EuropeCV
Baden-Württemberg, Germany
Germany
Email: [email protected]
Operator: Hamza Ghariani
Effective date: 23 July 2026
4. What We Actually Use
As currently implemented, EuropeCV uses:
- Supabase authentication cookies managed through our Next.js and Supabase SSR integration for sign-in and session management.
- Browser local storage for limited interface and dashboard convenience features.
- Remote loading of Google Fonts stylesheets from Google servers on site pages.
- Google Analytics 4 (when `NEXT_PUBLIC_GA_MEASUREMENT_ID` is configured) via Google tag (`gtag.js`), loaded only after analytics consent through our cookie preference center.
- Vercel Web Analytics (when analytics consent is granted) for privacy-focused usage metrics.
- Google AdSense Auto ads on individual blog article pages only, using publisher ID `ca-pub-9225863648469257`.
- Google Consent Mode v2 default and update signals in the site layout to communicate consent state to Google services.
- Google's certified Consent Management Platform (CMP), delivered through AdSense Privacy & messaging, for advertising consent on blog article pages for users in the EEA, the UK, and Switzerland.
- Third-party pages and domains during Stripe Checkout and OAuth sign-in flows.
We do not currently implement marketing pixels, retargeting trackers, heatmaps, or A/B testing trackers such as Hotjar or Microsoft Clarity in the application codebase.
Google AdSense is not loaded on the homepage, resume examples, tools, dashboard, paid Country Job Search Packs, or other non-blog pages.
5. Categories of Technologies
We distinguish between the following categories:
5.1 Strictly Necessary Technologies
These technologies are used to provide core functionality that you request, such as signing in, maintaining an authenticated session, securing the Service, and operating protected dashboard features.
Where legally permitted, strictly necessary technologies may be used without consent because they are required to provide a service you explicitly request, such as account access.
As currently implemented, this category includes Supabase-managed authentication session cookies used by our authentication flow.
5.2 Functional Browser Storage
EuropeCV currently uses browser local storage for limited convenience features, including:
- Dashboard sidebar collapsed/expanded state (`sidebar_collapsed`).
- A local dashboard document list cache (`europe_cv_documents`) used for UI convenience in parts of the dashboard and cover-letter experience.
These values are used for interface convenience and local UI state. They are not used for advertising or cross-site tracking.
EuropeCV does not currently offer a separate toggle for this browser storage in the cookie preference center because it is used for core interface convenience rather than analytics or marketing.
5.3 Analytics Cookies
When Google Analytics is enabled, EuropeCV uses Google Analytics 4 through Google tag (`gtag.js`) loaded from Google servers.
Google Analytics helps us understand how visitors use the Service, such as pages visited, general usage patterns, and referral information.
Analytics cookies are not strictly necessary for core account functionality. Where required by applicable law, they should be used only with appropriate consent.
Server-side session and feature-usage records may also be created for security, billing, and service operation. Those records are described in the Privacy Policy and are separate from Google Analytics browser cookies.
5.4 Advertising Cookies and Technologies
EuropeCV displays third-party advertising through Google AdSense Auto ads on individual blog article pages at URLs such as `/blog/resume-tips/how-to-write-a-resume`.
AdSense is configured with publisher ID ca-pub-9225863648469257. A site verification meta tag with the same publisher ID is present globally in the site layout head.
AdSense is not enabled on the homepage, resume examples, dashboard, tools, checkout flows, paid Country Job Search Packs, or any page other than single blog article routes matching `/blog/:category/:slug`.
When ads are displayed, Google may set or read advertising cookies and similar identifiers, process device and connection data, and use local storage where permitted, in accordance with your consent choices and Google's policies.
For users in the EEA, the UK, and Switzerland, advertising consent on blog article pages is collected through Google's certified CMP in AdSense Privacy & messaging. EuropeCV does not use its own advertising toggle for those pages.
If you do not consent to advertising through Google's CMP, Google may serve limited or non-personalized ads where supported, or restrict ad personalization, in line with Google's consent requirements.
6. Supabase Authentication
EuropeCV uses Supabase Auth with the Supabase SSR helpers for Next.js. Authentication is handled using HTTP cookies set and refreshed through our server and middleware integration.
These authentication cookies are used to keep you signed in, protect account-only routes, and support secure session handling.
We do not publish specific authentication cookie names or token values in this policy because doing so could create unnecessary security risk.
Exact cookie names, persistence, and expiration are managed by Supabase and our authentication configuration. Those details should be verified against the current Supabase SSR behavior before relying on them for legal analysis.
7. localStorage and sessionStorage
EuropeCV currently uses localStorage in the browser for the items described above.
We did not identify current use of sessionStorage in the reviewed application codebase.
We did not identify use of IndexedDB, service workers, or Cache Storage APIs for tracking in the reviewed application codebase.
The local dashboard document cache may contain document names, timestamps, preview lines, and related UI metadata. It should not be treated as a secure place to store sensitive information. Core resume and account data is stored server-side subject to the Privacy Policy.
8. Stripe Payments
EuropeCV uses Stripe Checkout through a redirect flow. When you purchase Credits, you are redirected to Stripe-hosted checkout pages.
EuropeCV does not embed Stripe Elements or Stripe Payment Element on the main site in the reviewed implementation.
Stripe may use cookies or similar technologies on Stripe-hosted pages under Stripe's own cookie and privacy policies. EuropeCV does not control Stripe's cookies on stripe.com or related Stripe domains.
9. Google and LinkedIn Sign-In
If you choose Google or LinkedIn sign-in, you are redirected to the relevant provider to authenticate.
Those providers may set or use cookies on their own domains during the authentication flow. EuropeCV does not control provider cookies on google.com, linkedin.com, or related provider domains.
EuropeCV receives authentication information through Supabase after successful sign-in, such as email, name, profile picture URL, and provider identifiers, as described in the Privacy Policy.
10. Google Fonts
EuropeCV currently loads the Google Sans font remotely from Google Fonts services (`fonts.googleapis.com` and `fonts.gstatic.com`) in the site layout.
This creates network requests from your browser to Google servers. Even if no cookie is set, Google may receive connection information such as your IP address, browser type, and referrer.
We have not verified that Google Fonts sets cookies in this specific implementation. Do not assume that no personal data is processed merely because the resource is a font stylesheet.
Whether this remote font loading requires consent in your jurisdiction should be reviewed with legal counsel.
11. Google Analytics
EuropeCV may use Google Analytics 4 when a measurement ID is configured through the `NEXT_PUBLIC_GA_MEASUREMENT_ID` environment variable.
In that case, the site loads `gtag.js` from `www.googletagmanager.com` and sends usage information to Google.
Google may set or read analytics cookies and process connection data such as IP address, browser information, pages visited, and referral information according to Google's analytics configuration and policies.
EuropeCV does not control all processing performed by Google. For more information, see Google's documentation and privacy materials: https://policies.google.com/privacy
Google Analytics is used for website analytics only. It is not used by EuropeCV for employment decisions.
12. Google AdSense
EuropeCV uses Google AdSense with publisher ID ca-pub-9225863648469257 to monetize individual blog article pages through Auto ads.
The AdSense script (`adsbygoogle.js`) is loaded only on single blog article pages through the blog article layout. Google chooses ad placement automatically through Auto ads.
EuropeCV does not manually insert individual AdSense ad unit elements on pages. Ad formats and positions are determined by Google.
On blog article pages, the AdSense script loads so that Google's Privacy & messaging CMP can collect advertising consent from users in the EEA, the UK, and Switzerland. The script is not blocked behind EuropeCV's analytics consent choice.
Advertising cookies and identifiers, if set, are controlled by Google according to the consent choices collected through Google's CMP or applicable default consent settings.
For more information about Google's advertising technologies and your choices, see Google's privacy materials at https://policies.google.com/privacy and Google AdSense Help at https://support.google.com/adsense.
13. Google Consent Mode and Consent Management
EuropeCV implements Google Consent Mode v2 in the global site layout before Google tags load.
For users in the EEA, the UK, and Switzerland, default consent signals for `ad_storage`, `ad_user_data`, `ad_personalization`, and `analytics_storage` are set to `denied` until updated. `ads_data_redaction` and `url_passthrough` are enabled in the default configuration.
For users outside those regions, advertising-related consent signals default to `granted` where AdSense may serve ads on blog article pages, while `analytics_storage` remains `denied` until you make a choice in EuropeCV's cookie preference center.
EuropeCV uses two coordinated consent mechanisms:
- On most site pages, EuropeCV shows its own cookie banner with "Accept All", "Reject Non-Essential", and "Manage Preferences". This banner controls analytics consent for Google Analytics 4 and Vercel Web Analytics through the `analytics` category stored in the `ecv_cookie_consent` cookie.
- On single blog article pages (`/blog/:category/:slug`), EuropeCV suppresses its own initial cookie banner so that users in the EEA, the UK, and Switzerland are not shown two competing consent dialogs. Advertising consent on those pages is handled by Google's certified CMP through AdSense Privacy & messaging.
- When you change analytics preferences through EuropeCV's cookie preference center, EuropeCV updates the `analytics_storage` consent signal. Advertising consent signals on blog article pages are updated by Google's CMP when you interact with its consent, do not consent, or manage options dialogs.
You can reopen EuropeCV cookie settings at any time through the "Cookie Settings" link in the website footer on pages where the EuropeCV preference center is used.
On blog article pages, you can change advertising choices through Google's CMP manage-options interface when it is shown, or through browser controls and Google account ad settings where applicable.
14. Connection Data
Even when no cookie is set, web servers and third-party resources may process connection information such as IP address, browser type, device information, request timestamps, and referrer data.
This is described in more detail in our Privacy Policy.
15. Legal Basis
Strictly necessary authentication and security technologies may be used where legally permitted without consent because they are necessary to provide requested sign-in and account functionality.
Non-essential technologies, such as analytics, advertising on blog article pages, or remote font loading, require consent where applicable under ePrivacy and GDPR rules.
Google Analytics is a non-essential analytics technology and is activated only after analytics consent through EuropeCV's cookie preference center.
Google AdSense advertising on blog article pages relies on consent collected through Google's certified CMP for users in the EEA, the UK, and Switzerland.
Because EuropeCV currently loads Google Fonts remotely on site pages, legal review is also required to determine whether additional consent or a self-hosting change is needed.
16. EuropeCV Cookie Banner and Preference Center
EuropeCV provides its own cookie consent banner and cookie preference center on most site pages.
On your first visit to pages where the EuropeCV banner is shown, you can accept all optional cookies, reject non-essential cookies, or manage your preferences by category.
Rejecting non-essential cookies is as easy as accepting them. No optional analytics category is enabled before you choose.
Your analytics choices are stored in a first-party consent cookie named `ecv_cookie_consent`. That cookie stores only the consent version, timestamp, and selected category preferences. It does not store resume content, passwords, payment information, or other sensitive personal data.
The current EuropeCV preference center includes one optional category: Analytics (Google Analytics 4 and Vercel Web Analytics). Necessary cookies remain always active.
Google Analytics and Vercel Web Analytics are activated only after you grant analytics consent where those services are configured.
On single blog article pages (`/blog/:category/:slug`), EuropeCV does not show its initial cookie banner. Advertising consent on those pages is handled separately by Google's certified CMP through AdSense Privacy & messaging for users in the EEA, the UK, and Switzerland.
You can reopen EuropeCV cookie settings at any time through the "Cookie Settings" link in the website footer.
17. Managing Cookies and Browser Storage
You can delete or block cookies through your browser settings.
You can also clear browser local storage through your browser settings or developer tools.
Blocking or deleting strictly necessary authentication cookies may prevent you from signing in or staying signed in.
Blocking functional browser storage may reset interface preferences or local dashboard list caches.
Blocking analytics cookies may limit our ability to measure site usage but should not prevent core account functionality if authentication cookies remain allowed.
Blocking advertising cookies or identifiers on blog article pages may affect whether ads are shown or personalized, but should not prevent core account functionality.
18. Withdrawing Consent
Where processing is based on consent, you may withdraw consent at any time.
You can reopen the EuropeCV cookie preference center through the "Cookie Settings" link in the website footer and disable analytics cookies.
If you disable analytics cookies in EuropeCV's preference center, EuropeCV stops loading Google Analytics and Vercel Web Analytics on future visits and attempts to clear common Google Analytics browser cookies already stored on your device.
On blog article pages, you can change or withdraw advertising consent through Google's CMP manage-options interface when available, or through browser controls and Google account ad settings.
You can also clear cookies and browser storage through your browser settings, subject to the limitations described above.
19. Retention
Authentication cookie duration is determined by Supabase and our authentication configuration. We do not publish fixed expiration periods here because they may be session-based, refreshed on activity, or otherwise provider-managed.
According to Google's documentation for Google Analytics, common analytics cookies include `_ga` (often up to 2 years), `_gid` (often up to 24 hours), and `_ga_<container-id>` (often up to 2 years). Actual duration may vary based on Google settings and browser behavior.
The consent preference cookie `ecv_cookie_consent` is stored for up to 12 months so EuropeCV can remember your analytics choices between visits.
Google AdSense and Google CMP consent records are managed by Google according to Google's retention practices for Privacy & messaging and TCF consent strings.
Local storage values remain on your device until you clear them or the application removes them.
We do not use generic statements such as "all session cookies are deleted when you close your browser" because actual behavior depends on browser and provider settings.
21. Advertising Scope and Limitations
Google AdSense advertising is limited to single blog article pages on europecv.io.
EuropeCV does not serve AdSense ads on the homepage, resume examples, dashboard, tools, authentication pages, pricing or checkout pages, paid Country Job Search Packs, or blog listing pages such as `/blog` or `/blog/:category`.
Google Analytics is used for website usage analytics, not for employment decisions or hiring choices by EuropeCV.
EuropeCV does not run separate retargeting pixels, affiliate trackers, or social advertising pixels in the current application codebase.
This section describes the current implementation and should be reassessed if advertising scope or providers change.
22. Changes to This Cookie Policy
This Cookie Policy is effective as of 23 July 2026 and was last updated on 28 July 2026.
We may update this Cookie Policy if our use of cookies or similar technologies changes.
23. Contact
EuropeCV
Baden-Württemberg, Germany
Germany
Email: [email protected]