How Spark ATS utilizes essential session cookies and manages user preferences with zero third-party advertising trackers.
Cookies are small text files placed on your computer, tablet, or mobile device by websites that you visit. They are widely used across the internet to ensure websites operate correctly, maintain user authentication states across page requests, and remember user-specific choices.
In this policy, "cookies" also encompasses similar client-side storage technologies, such as browser Local Storage and Session Storage, which may store operational state within your web browser.
Spark ATS is enterprise-grade recruitment software designed with a strict privacy-first architecture. Our core commitments regarding browser data include:
SameSite=Lax, HttpOnly (where accessible only to the server), and Secure on encrypted HTTPS connections.We categorize all browser storage technologies into four distinct classifications:
Essential cookies are strictly necessary to deliver the recruitment software services you request. Under applicable data privacy laws (including GDPR Article 6(1)(b) and ePrivacy regulations), essential cookies do not require prior consent because the platform cannot function securely without them.
PHPSESSID: Standard PHP session identifier that maintains your authenticated state, links your requests to your organization's workspace, and protects against unauthorized access. Expires upon browser closure (or after sliding idle timeout).spark_cookie_consent: First-party technical cookie that records your consent decisions so you are not repeatedly presented with the consent banner on every page load. Preserved for 12 months.Spark ATS implements robust defense against Cross-Site Request Forgery (CSRF) attacks. We provide the following clarification regarding CSRF mechanics:
Our CSRF tokens are session-backed cryptographic values stored directly within your encrypted server-side session, keyed to your PHPSESSID. Spark ATS does not emit a separate public tracking cookie for CSRF tokens. Instead, the token is verified server-side during form submissions and state-changing AJAX mutations to confirm that requests originate from legitimate users.
Functional cookies enable enhanced convenience features. These cookies are disabled by default and are only activated if you explicitly opt-in:
spark_ats_remember: Emitted only when an organization administrator or recruiter explicitly checks the "Remember me" option on the sign-in form. Contains a cryptographically random, salted selector token enabling automatic sign-in across browser sessions. Retained for up to 30 days.spark_ats_remember_user: Emitted only when "Remember me" is selected. Remembers your work email address on the login form for faster access. Retained for up to 30 days.If functional cookies are declined or disabled, Spark ATS remains completely functional; you will simply be prompted to enter your credentials upon each new browser session.
Analytics cookies collect aggregated, anonymous information about how visitors navigate web pages, helping developers identify broken links, measure load times, and improve usability.
SparkCookieConsent.has('analytics')) so that if privacy-friendly analytics are introduced in the future, they will remain strictly blocked unless you affirmatively opt-in.
Marketing and targeting cookies are used by third-party advertising networks to track users across websites, create behavioural profiles, and serve personalized commercial advertisements.
The following table provides a complete, truthful disclosure of all cookies emitted or supported by Spark ATS:
| Cookie Name | Provider / Domain | Category | Duration | Security Flags | Exact Purpose |
|---|---|---|---|---|---|
PHPSESSID |
First-Party (Spark ATS) | Essential | Session | HttpOnly, SameSite=Lax, Secure* |
Maintains user authentication, session continuity, and links requests to the authorized tenant context. |
spark_cookie_consent |
First-Party (Spark ATS) | Essential | 12 Months | SameSite=Lax, Secure* |
Stores non-sensitive user cookie preferences (version, category choices) to prevent repetitive banners. |
spark_ats_remember |
First-Party (Spark ATS) | Functional | 30 Days | HttpOnly, SameSite=Lax, Secure* |
Persistent login selector token. Set ONLY upon explicit user opt-in ("Remember me" checkbox). |
spark_ats_remember_user |
First-Party (Spark ATS) | Functional | 30 Days | SameSite=Lax, Secure* |
Prefills username/email on login screen. Set ONLY upon explicit user opt-in ("Remember me"). |
Secure flag is automatically enforced whenever Spark ATS is accessed over an encrypted HTTPS connection.
You have the right to change or revoke your cookie preferences at any time. You can adjust your selections using our built-in preference center:
Additionally, every public page of the Spark ATS website includes an accessible Cookie Settings link in the footer, allowing you to review your active choices whenever you wish.
In addition to our Preference Center, most web browsers allow you to control cookies through their browser settings. You can configure your browser to notify you when you receive a cookie, or to block cookies entirely:
Please note that blocking all cookies (including essential technical cookies) in your browser settings will prevent you from logging in, maintaining a session, or using Spark ATS workspaces.
We may periodically update this Cookie Policy to reflect technical advancements, operational changes, or new legal obligations. When material revisions are made, the Consent Version will be updated, and you will be presented with the Cookie Consent banner upon your next visit to review the revised terms.
This document represents Spark ATS Cookie Consent Version 1.0, effective as of September 19, 2026.
For complete information regarding how Spark ATS collects, processes, and protects personal data, please review our Spark ATS Privacy Policy and Terms & Conditions.