What Cavuno Analytics collects

The events, fields, and cookie behind your built-in dashboard analytics, and how they follow your cookie consent setting. A reference for writing your privacy policy.

Cavuno Analytics is the built-in tracker behind your dashboard analytics. This page lists what it collects so you can describe it accurately in your board's privacy policy and cookie notice.

This page describes how Cavuno works. It is not legal advice. Have your privacy policy reviewed by someone who knows the rules that apply to your audience.

When it runs

On hosted boards, Cavuno Analytics follows the Require cookie consent setting in Settings → Features:

  • Require cookie consent on: the tracker waits for the visitor to select Accept on the cookie banner. Before a choice, and after Reject, it does not load, does not set its cookie, and sends no events. If a visitor reopens the banner from the cookie preferences link after accepting, Cavuno deletes the session-id cookie and reloads the page without the tracker.
  • Require cookie consent off: the tracker runs for every visitor.

On builder and SDK boards, the board's own code loads Cavuno Analytics. The current starter template waits for Accept when Require cookie consent is on. If your board runs on your own code, call analytics.install() only after the visitor accepts (see Boards built with the SDK).

Visitors who are not tracked do not appear in your dashboard, so totals are lower when consent is required.

NameTypeContentsLifetime
session-idFirst-party cookie on your board's domainA random identifier generated in the browser30 minutes, renewed with each event

The identifier groups one visit's page views into a session. It is not derived from the visitor's device or personal data, and Cavuno does not link it to visitor accounts or email addresses. A visitor who returns after 30 minutes of inactivity gets a new identifier.

Events

Each event records its name, a timestamp, the session identifier, and your board.

  • page_hit: one per page view, including navigation within the board.
  • engagement: at most once per page view, on the visitor's first real interaction: a click or tap, a key press, or a scroll of more than 50 pixels.
  • web_vital: page performance measurements from the browser: Cumulative Layout Shift (CLS), First Contentful Paint (FCP), Largest Contentful Paint (LCP), Time to First Byte (TTFB), and Interaction to Next Paint (INP).
  • job_apply_click: when a visitor clicks a job's apply button. It records the job's ID and, when known, the company and job slugs.

Fields sent by the browser

Page view events include:

  • The browser's user agent string
  • The browser's preferred language
  • A country derived from the browser's timezone setting, and the IANA timezone itself (for example, Europe/Berlin)
  • The referrer (the page the visitor came from)
  • The page path and full URL, including any query string such as UTM parameters
  • A small set of automation hints used to filter bots, such as whether the browser window has zero size

Performance events include the measurement's name, value, and rating, with the same path, URL, user agent, language, timezone-derived country, and referrer.

Before sending, the tracker masks values under keys that commonly hold personal data, such as email, phone, password, and address.

Fields added by Cavuno's servers

When a page view event arrives, Cavuno adds:

  • The visitor's country, read from a header set by Cavuno's CDN
  • The results of header consistency checks used to filter bots, for example whether the user agent agrees with the browser's other request headers

For boards served through Cavuno's board-hosting gateway, such as AI Builder boards that Cavuno hosts, page view events can also include the visitor's network: the autonomous system number (ASN) and the network operator's name. Hosted boards, and SDK boards running on your own hosting, do not include it.

IP addresses

Analytics events are stored without the visitor's IP address. When an event arrives, the address is used as a short-lived rate-limiting key to protect the endpoint from floods, and is not added to the event.

Server-side counts

Some counts are recorded on Cavuno's servers rather than by the tracker, so they do not depend on the banner:

  • Submitted applications: the job ID.
  • Redirects through Cavuno's apply links to an external application page: the job ID and slug.
  • Apply attempt decisions, when Cavuno checks an apply attempt against the job's location rules: the job slug, where the attempt came from, how it was checked, the decision and its reason, and, when known, the country on the applicant's candidate profile and the countries the job accepts.

These records carry no session identifier and do not read or set cookies in the visitor's browser.

Third-party tags

Google Analytics 4, Google Tag Manager, Meta Pixel, and the LinkedIn Insight Tag are separate from Cavuno Analytics. They collect data under their providers' own terms. When Require cookie consent is on, Cavuno loads them only after the visitor accepts, the same as Cavuno Analytics. See Customize the cookie consent banner.

Boards built with the SDK

If you build your own frontend with @cavuno/board, analytics.install() loads the same tracker, which sets the session-id cookie and sends page view, engagement, and performance events. When analytics.cookieConsentRequired from board.context() is true, call install() only after the visitor accepts your cookie banner. Custom events sent with analytics.track() carry the action and payload you pass, with no session identifier, and nothing is sent before install() runs.

Frequently asked questions