GhostedBy
What Leaves Your Browser

Privacy Notice

This Site Measures Which Pages Work. Once You Sign In It Records Which Account Is Using Them, and Never What You Applied To or Which Companies You Looked Up. Those Are Separate Promises, and the Last One Is the Reason the First Is Kept Deliberately Small.

What Is Measured

Which pages are opened, and a small number of named events on the landing page — which surface a button was pressed on, whether the visitor was signed in, and which confidence band a rating fell into.

Query strings are removed before anything is sent to the provider that records what happens on the site. The search box on the company directory puts what you typed into the address bar, and that is stripped rather than transmitted.

A company’s own page carries that company’s name in its address, so the address is reduced before it is sent. The provider that records what happens on the site is told that a company page was opened, never which company it was.

The provider that measures what brought you here is the exception, and only if you accept. It reads the address of the page itself, unreduced, and on the company directory that address contains what you typed into the search box. Nothing else reaches it: no company you have tracked, no role title, and no field of any application.

Device Identification

Separately from analytics, and separately from your answer to the cookie notice, this site identifies the device you are using on every visit. It is provided by a specialist third party, on European infrastructure.

It works chiefly by reading characteristics your browser exposes, and it also keeps a cookie and a local storage entry as a cache. Clearing those does not reset who it takes you to be, because the identifier is recomputed from the characteristics rather than recalled from the store. A private window does not reset it either.

It is served from edge.ghostedby.xyz — a subdomain of this site pointed at that provider’s servers. Its requests are therefore first-party, and so is what it stores, which means it is not swept away by blocking third-party cookies.

This runs whether you accept or decline. Declining the notice stops the analytics cookie; it does not stop this.

It is here so that the ratings can be defended: a public record built from anonymous reports is only worth reading if the same person cannot file the same outcome fifty times, and a company cannot quietly vote its own rating down.

Cookies

No analytics cookie is written until you accept. If you decline, or simply ignore the notice, the visit is still counted — through a hash derived on the analytics provider’s servers rather than an identifier stored in your browser.

The provider that measures what brought you here sets no cookie at any point. It runs cookieless, keeping a short-lived entry in your browser instead and forgetting who you are roughly every day. That is less precise for us and less durable for you, which is the trade we chose.

Device identification is the exception, and it is described above: it keeps a cookie and a storage entry of its own whatever you answer here.

If you accept, one first-party analytics cookie is set, which is what allows a return visit to be recognised as the same visit rather than a new one.

Your answer itself is recorded either way, because remembering that you declined is the only way to avoid asking again.

Who Processes It

Two providers. The first records what happens on the site, on European infrastructure — what it receives is sent to and held in the EU.

The second measures what brings people here and which of those visits end in an account. It receives the address of each page you open, and nothing else.

The second one is not in the EU. Its own agreement says most of its infrastructure sits outside it, including in the United States, and that transfers there rely on the standard contractual clauses. That is a real difference from the line above, which is why it is written out rather than folded into it.

Each is configured separately. If no key is set for a provider on a deployment, that provider’s code is never downloaded at all and none of this applies to it.

Being Signed In

Until you sign in you are a number the provider generated, and nothing more. From the moment you sign in, what is recorded carries the identifier your account already has in our database, and your email address is stored alongside it so the account is recognisable to us in that tool. Nothing else about you is sent: not your name, not what you have applied for, not the companies you looked up.

Nothing you did before signing in is joined to it. The anonymous number is thrown away at the moment you sign in rather than being tied to your account, so the pages you read while deciding whether to sign up stay separate from the account you went on to create. Joining the two is the single thing that would attach the companies you had looked up to you by name, and it is the reason this is done in this order.

Signing out throws the identifier away again, so the next person to use that browser begins as a new anonymous visitor rather than as you.

The provider that measures what brought you here is never told any of this. It receives addresses and nothing else, and it is never given an account identifier.

What Is Deliberately Switched Off

Automatic click capture is off. It records the text of whatever was clicked, and on your tracker that text is company names and role titles.

Neither provider is ever given your name or your email address. The one that knows which account is signed in is told that a company page was opened and not which company; the one that receives the address in full is never told which account is reading it.

Session Recording

If you accept, your session is recorded and can be replayed later as video — the pages you moved through and how you interacted with them.

If you decline, it is not, and it cannot be: recording needs an identifier kept in your browser, which is the thing declining refuses. You are still counted, just never recorded.

Both what you type and the text already on the page are masked before anything leaves your browser. A recording shows the shape of a visit — what was clicked, in what order, how far you scrolled, where you stopped — and not a word of what any of it said. Your tracker is unreadable in a recording of it.

Cookie Settings withdraws consent and stops it from that point.

Your Applications

None of it is public. What you have applied to is readable by you alone, and that is enforced by the database rather than by the application.

No event ever carries a company name, a role or a search term, and no session recording does either — the page text is masked before a recording leaves your browser. There is no route by which what you applied to reaches anyone but you.

Changing Your Mind

Cookie Settings, at the foot of any page, reopens the notice. Declining after having accepted stops the cookie being used from that point.

Withdrawing consent reloads the page. A script that has already started running cannot be called off in place, so the page is rebuilt without it — that reload is the thing that actually stops it, rather than a promise that it will behave.

How company ratings themselves are kept — what counts, what is never published, and how to ask for a correction — is set out in the Moderation Policy.

Privacy Notice · GhostedBy