MatchAccuracy
IntegrityHow it worksPricingFor candidates
Log inStart free
MatchAccuracymatchaccuracy.com
  • /What the product does and who it is for
  • /transparenciaWhat we measure and what we do not
  • /para-candidatosWhat is asked of you and what rights you have
  • /como-medimosThe method, with a real specimen
  • /aviso-legalProvider, terms and jurisdiction
  • /cookiesThe ones we use and how to refuse them
  • /privacy-policyLawful bases and retention periods
  • /novedadesWhat changed and when

MatchAccuracy Labs S.L. · B-12345678 · Alameda de Mazarredo 47, 48009 Bilbao · legal@matchaccuracy.euart. 10 LSSI · example values

Language of this pageEnglishEspañol
© 2026

On this page

  1. The short version
  2. The cookies we set
  3. What is not a cookie but counts all the same
  4. How we measure usage without cookies
  5. When you pay
  6. Why there is no banner
  7. What you can do

Cookies

Last updated: 2026-08-05

Everything MatchAccuracy leaves on your device, with its name, its purpose and how long it lasts. The list comes from the code itself: there is no second copy that could fall behind.

The short version

If you only read one paragraph, read this one:

  • We use no advertising, tracking or profiling cookies. None.
  • Every cookie we set is technical: without them you cannot sign in or take your assessment.
  • We do measure site usage, but with a tool that writes nothing to your device.
  • That is why you will not see a cookie banner: there is nothing to consent to.

The cookies we set

None of these is shared with third parties or can recognise you outside MatchAccuracy:

NameWhat it doesHow long it lasts
authjs.session-tokenKeeps you signed in once you have identified yourself. Only company accounts get it; a candidate never has one.30 days
authjs.csrf-tokenProtects the sign-in step against forged requests coming from another website.while the browser is open
authjs.callback-urlRemembers which screen to return to once you finish signing in.while the browser is open
candidate-tokenGives you access to your assessment, and only yours, without having to create an account. It is what replaced the link that carried the token in plain sight.1 hour
sessionId_ *Identifies the assessment session in progress so your answers reach the right one.1 day
testLoaded_ *Marks that the assessment was already opened once. It is how a mid-assessment reload is detected.1 day

The two ending in an underscore carry your assessment identifier appended, so you will see one per assessment rather than one for all of them.

Over https, the three sign-in cookies appear with a “__Secure-” prefix before the name. It is the same data carrying the flag that stops it being sent over an unencrypted connection.

What is not a cookie but counts all the same

The law speaks of “cookies and similar technologies”, and this is the similar part: keys living in browser storage that never travel to the server on their own.

NameWhat it doesHow long it lasts
ma:preferencesStores the interface preferences you chose yourself, such as the light or dark theme.until you clear it
recorderStores the identifier of the assessment in progress so reloading the page does not lock you out.until you clear it
notification-storeStores your notifications and their alert settings so the tray does not empty on every load.until you clear it

How we measure usage without cookies

We count page views and loading speed with Vercel Analytics and Vercel Speed Insights. Neither writes a cookie or a key on your device, and neither builds a profile of you:

  • What gets recorded is aggregate: how many visits a page had, how long it took to paint.
  • There is no persistent identifier, so we cannot follow you across visits or across sites.
  • The scripts only load in the deployed environment, never in development.

Verified in the deployed environment, not inferred from the documentation: with storage emptied and after walking the public pages, both scripts load and not one cookie or new key remains.

When you pay

The payment gateway is Stripe and it opens inside our own screen, not on another website. At that point Stripe code loads, which is a third party and uses its own cookies to prevent fraud. It only happens on the payment screen, which belongs to the company account: a candidate never goes through it.

The names and durations of Stripe’s cookies are not in the table above because we have not measured them ourselves. We would rather say so than copy them from their documentation and take them on trust.not measured yet

Why there is no banner

A cookie banner exists to ask your permission for what is not essential. There is none of that here: everything in the tables is technical or something you asked for, and usage measurement works without writing anything. Asking permission for something we do not do would be noise, not transparency.

The banner is built and switched off, not missing. The rule that switches it on is written into the code: the day a single non-essential cookie or key arrives — third-party analytics included — it appears.

What you can do

You do not need to ask us: everything on this page is under your browser’s control.

  • Clear this site’s cookies and storage from your browser settings.
  • Block cookies for this site, or for every site, in your privacy settings.
  • Browse in a private window, where everything is cleared when you close it.

What breaks if you block them, said plainly: without the sign-in cookies you cannot get into your account, and without the candidate one you cannot take your assessment. There is no way for those to work without them, which is why we do not ask your permission to set them.