Cookie Policy
Effective date: 2 September 2026 · WeavHR Limited, Aotearoa New Zealand
In short
- Our public website sets no cookies. Browsing www.weavhr.com, reading about the platform, using the savings calculator or sending an enquiry does not place any cookie on your device, and we do not use analytics, advertising or social-media tracking on the website.
- The WeavHR application uses strictly necessary cookies and browser storage to sign you in securely, keep you signed in, remember which organisation you are working in and remember your interface preferences. It cannot work without them.
- We do not sell or share cookie data, and no cookie set by WeavHR is used to profile you or to advertise to you.
- Because we use only strictly necessary and functional cookies, we do not show a cookie banner. If that ever changes, we will update this policy and ask for your consent where the law requires it.
1. Who we are and what this policy covers
This Cookie Policy is issued by WeavHR Limited, a company registered in New Zealand (‘WeavHR’, ‘we’, ‘us’). It explains how cookies and similar technologies are used on our public website at www.weavhr.com (the ‘Website’) and in the WeavHR workforce operations platform that you reach after signing in, including the client portal and the worker web experience (together, the ‘Application’).
It should be read together with our Privacy Policy, which explains how we handle personal information under the New Zealand Privacy Act 2020, and our Terms of Use. The WeavHR mobile app for workers does not use browser cookies; the information it stores on your device is described in the Privacy Policy.
2. What cookies and similar technologies are
A cookie is a small text file that a website asks your browser to store on your device and send back on later requests. Cookies let a site recognise your browser, keep you signed in and remember choices you have made. A cookie is ‘first-party’ when it is set by the site you are visiting and ‘third-party’ when it is set by a different domain.
Modern browsers also provide other storage that behaves in a similar way, and we describe it here so this policy is complete:
- Local storage: information kept in your browser until it is deliberately removed. Unlike a cookie it is not sent to our servers with every request.
- Session storage: the same idea, but cleared when you close the browser tab.
- Service workers: small scripts your browser runs in the background for a site you have visited, for example to receive notifications you have opted in to.
3. Cookies on the public website
The Website does not set cookies. Specifically, it does not use analytics services, advertising or remarketing pixels, session-recording tools, A/B-testing tools, embedded social-media widgets or third-party fonts loaded from another domain. Links to LinkedIn on our About page are ordinary links; nothing is loaded from LinkedIn until you choose to follow them.
The contact form and the savings calculator run without cookies. The calculator keeps your inputs only in the page you are viewing and sends nothing to us. The contact form sends what you type to us only when you press the button to send it.
We may in future measure how the Website is used in an aggregated, privacy-respecting way. If we introduce any tool that sets cookies for that purpose, we will update this policy first and, where the law of your location requires it, ask for your consent before those cookies are set.
4. Cookies and storage in the WeavHR application
When you sign in to the Application we use a small number of first-party cookies and browser storage items. All of them exist to make the Application work securely for you; none is used for advertising, profiling or tracking you across other sites.
4.1 Signing in and staying signed in
WeavHR uses Kinde, a specialist authentication service, to handle sign-in. When you sign in, the following cookies are set on the weavhr.com domain by our Application through Kinde’s software:
| Name | Set by | Purpose | Type | Duration |
|---|---|---|---|---|
| access_token, id_token, refresh_token | WeavHR (via our sign-in provider, Kinde) | Prove who you are after you sign in, keep you signed in as you move between pages, and renew your session without asking you to sign in again. | Strictly necessary | For your sign-in session. Tokens expire and are renewed automatically; all are removed when you sign out. |
| user | WeavHR (via Kinde) | Holds your basic profile (name, email, identifier) so the application can show it without another request. | Strictly necessary | For your sign-in session; removed when you sign out. |
| ac-state-key | WeavHR (via Kinde) | Protects the sign-in hand-off against forgery by matching the request that started sign-in with the one that completes it. | Strictly necessary (security) | Only during the sign-in hand-off. |
| post_login_redirect_url | WeavHR (via Kinde) | Remembers the page you asked for so we can return you to it after you sign in. | Strictly necessary | Only during the sign-in hand-off. |
During the sign-in step itself your browser also visits Kinde’s own domain (weavhr.kinde.com), where Kinde sets cookies needed to complete a secure sign-in, for example to deliver and verify the one-time code sent to your email address. Those cookies are governed by Kinde’s privacy policy (opens in a new tab).
4.2 Remembering where you are working
| Name | Set by | Purpose | Type | Duration |
|---|---|---|---|---|
| weavhr_selected_org | WeavHR | Remembers which organisation you chose to work in, so every request and download is served from the right organisation's data. Your access to that organisation is verified on the server on every request. | Strictly necessary | 7 days, refreshed while you use the application; cleared when you sign out. |
| weavhr_selected_client | WeavHR | For client portal users with access to more than one client organisation, remembers which one you selected. | Strictly necessary | 7 days, refreshed while you use the application; cleared when you sign out. |
4.3 Browser storage and notifications
| Name | Set by | Purpose | Type | Duration |
|---|---|---|---|---|
| persist:root (local storage) | WeavHR | Keeps your signed-in profile and organisation context in your browser so the application can load without refetching it on every visit. | Strictly necessary | Until you sign out or clear your browser's site data. |
| Interface preferences (local storage) | WeavHR | Remembers choices such as your preferred job-board and calendar views. | Functional | Until you clear your browser's site data. |
| calendar.filters.* (session storage) | WeavHR | Keeps the calendar filters you set for the current browser tab. | Functional | Until you close the tab. |
| weavhr.staleBuildReloadedAt (session storage) | WeavHR | A short-lived marker that stops the application reloading repeatedly if a tab was left open across a software update. | Strictly necessary | 30 seconds, or until you close the tab. |
| Push notification service worker | WeavHR, only if you turn on browser notifications | Lets the application deliver notifications about your work (for example a new invitation) when you have chosen to receive them in your browser. | Functional, opt-in | Until you turn notifications off in your browser or the application. |
5. Third parties
We keep the number of third parties involved in delivering the Website and Application deliberately small:
- Kinde provides sign-in for the Application, as described in section 4.1. Kinde does not receive information about your browsing of the Website.
- Microsoft Azure hosts the Website and Application. Our hosting configuration does not set cookies on your device. Standard web server logs (such as IP address, requested page, browser type and time) are kept for security and reliability, as described in the Privacy Policy.
We do not use advertising networks, data brokers or cross-site tracking of any kind, and we do not allow third parties to set cookies through the Website or Application for their own purposes.
6. Your choices
Because the Website sets no cookies, there is nothing to accept or refuse when you browse it. For the Application:
- Signing out removes the sign-in and workspace cookies and the signed-in profile held in local storage.
- Browser settings let you view, block or delete cookies and site data for any site, including weavhr.com. Every major browser explains how in its help pages (look for ‘cookies and site data’). If you block strictly necessary cookies for weavhr.com you will not be able to sign in to the Application.
- Notifications are only ever set up if you turn them on. You can turn them off at any time in your browser’s site permissions or in the Application, which also removes the associated service worker registration.
- Private or incognito windows discard all cookies and storage when the window is closed.
7. Cookies and your personal information
Some of the cookies and storage described above contain or point to personal information, for example your name and email address in the sign-in profile. We handle that information in accordance with the New Zealand Privacy Act 2020 and our Privacy Policy, which also explains how to access or correct your information and how to complain. If you are visiting from a country whose law treats cookies differently, please note that we set only cookies that are strictly necessary to provide a service you have asked for, plus the functional storage described above.
8. Changes to this policy
We review this policy whenever we change how the Website or Application uses cookies and at least once a year. Changes take effect when the updated policy is published here, and the effective date at the top of the page will change. If a change means we would start setting cookies that are not strictly necessary, we will tell you before it takes effect and seek your consent where required.
9. Contact us
Questions about this policy or about cookies on weavhr.com can be sent to our Privacy Officer at WeavHR Limited: