Legal
Cookie Policy
Last Updated: April 2026
Data Controller: Vetoropiparo Unipessoal LDA (Lisbon, Portugal)
1. What Cookies Are
Cookies are small data files stored on your device when you visit a website. We also use comparable technologies (e.g. localStorage, pixels). This page lists every such technology Lvlup actually uses, what it does, and how long it lasts.
2. The Two Categories We Use
- Essential:
- Required for the site to work — authentication, security, the cookie-consent mechanism itself, and the guest-upload flow. These cannot be turned off, and they are exempt from consent under the ePrivacy Directive (strictly necessary).
- Optional:
- Analytics and marketing — helps us understand how Lvlup is used and how to improve it. We only load these after you grant consent (EU/UK), or after you have been notified and not opted out (US/RoW). You can change your decision at any time.
3. Essential Cookies (always on)
| Name | Party | Purpose | Retention |
|---|---|---|---|
| access_token | Lvlup (first-party) | Keeps you signed in (JWT access token). | 1 hour |
| refresh_token | Lvlup (first-party) | Renews your session without re-entering credentials. | 7 days |
| pending_2fa_token | Lvlup (first-party) | Carries the two-factor verification step. | 5 minutes |
| guest_cv_token_* | Lvlup (first-party) | Holds your guest CV upload before account creation. | 1 hour |
| guest_cv_terms_* | Lvlup (first-party) | Audit trail of your terms acceptance at the upload step. | 1 hour |
| guest_cv_basics_* | Lvlup (first-party) | Carries your name and email extracted from the CV so the signup form can be pre-filled. Never exposed to client-side JavaScript. | 1 hour |
| lvlup_visitor_id | Lvlup (first-party) | Anchors your cookie-consent record so it can be linked to your account when you sign up. | 12 months |
4. Optional Cookies (consent required in EU/UK)
| Name | Party | Purpose | Retention |
|---|---|---|---|
| _ga, _ga_*, _gid (and other GTM-injected identifiers) | Google (third-party, via Google Tag Manager) | Anonymized analytics — pages viewed, features used, conversion funnels. Helps us improve the product. | up to 14 months |
| __hstc, __hssc, __hssrc, hubspotutk | HubSpot (third-party) | Engagement analytics + onboarding-flow optimization. Linked to your account when you sign up so we know which improvements helped. | up to 13 months |
5. Your Choices
You can change your decision at any time. We do not load analytics or marketing scripts before you have decided in the EU/UK, and we honor the Global Privacy Control (GPC) signal as a clear opt-out everywhere it is broadcast by your browser.
6. Region-Specific Rights
- EU / UK / EEA / Switzerland (GDPR + ePrivacy):
- Optional cookies are loaded only after you give explicit consent. Withdrawal is as easy as giving consent — use "Manage cookies" in the footer at any time.
- California / US (CCPA & CPRA):
- You have the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising. Use the "Do Not Sell or Share" link in the footer or visit our dedicated Do Not Sell or Share page.
7. Disabling Cookies in Your Browser
Modern browsers let you block or delete cookies. Disabling essential cookies will break authentication and core features. For analytics-only blocking we recommend using our preferences center instead, since it covers comparable technologies (e.g. localStorage) that browser settings may not.