Four cookies, all first party
Three keep you signed in and protect the sign-in round trip. One is a first-party analytics identifier. There is no advertising or cross-site tracking cookie.
This is the complete list — not a category summary. Each entry names the cookie, says who sets it, what it is for, whether it is strictly necessary or analytics, and how long it lasts.
Three keep you signed in and protect the sign-in round trip. One is a first-party analytics identifier. There is no advertising or cross-site tracking cookie.
Serproz marks its cookies HttpOnly, so ordinary page scripts cannot read their values. Browser storage used for drafts is separate and can be read by page scripts.
Half-finished bookings and recent searches live in your browser's own storage on your device, not on a Serproz server.
Last updated 7 September 2026. Policy version cookie-policy-2026-09-07-v2. This policy covers the Serproz website and marketplace.
A cookie is a small value your browser stores for a site and sends back on later requests. Serproz uses them for two things only: keeping you signed in safely, and counting how the product is used.
Strictly necessary: The marketplace cannot provide a signed-in session without it. Turning it off means you cannot log in.
Analytics: Used to understand how the product is performing. It is first party, it is not shared with an advertising network, and it does not follow you to other sites.
Four cookies, all first party and all HttpOnly, which means no script running in the page can read them.
| Name | Class | Purpose | Lifetime |
|---|---|---|---|
access_tokenSerproz (first party)HttpOnly, SameSite=Lax, Secure outside local development, Path=/ | Strictly necessary | Carries your signed-in session. Every dashboard request is authorised from it, and the route guard checks for it before showing a signed-in page. | 1 hour |
refresh_tokenSerproz (first party)HttpOnly, SameSite=Lax, Secure outside local development, Path=/api/auth | Strictly necessary | Issues a fresh access token when the short one expires, so you are not asked for your password every hour. It is deliberately scoped to the authentication endpoints and is never sent to an ordinary page. | 7 days |
oauth_stateSerproz (first party)HttpOnly, SameSite=Lax, Secure outside local development, Path=/api/auth | Strictly necessary | A single-use value that proves a returning Google sign-in is the one you started, which is what stops a cross-site request forgery on the sign-in round trip. Set only when you choose Google sign-in. | 10 minutes |
spz_anonymous_idSerproz (first party)HttpOnly, SameSite=Lax, Secure outside local development, Path=/ | Analytics | A random identifier that lets the stages of one journey be counted as one journey — for example, a search followed by a booking — without knowing who you are. It carries no name, email, phone number, search text or job notes, and it is written first when a page interaction is recorded, not on a passive page view. | 365 days |
Signing out expires the session cookies immediately. Both are re-issued only when you sign in again.
Serproz embeds as little third-party code as the product allows, so this list is short.
Stripe, on payment screens only: When a card form loads, the payment provider's script loads with it and sets its own cookies for fraud detection and to keep that payment session together. Serproz cannot read them, and they are not set on pages without a card form. The current list is published by Stripe in its own privacy documentation.
Google, only inside Google sign-in: If you choose Google sign-in, Google sets cookies on its own domain while you are on its sign-in screen. That is Google's own session, governed by Google's policies, not by this page.
What is deliberately absent: No advertising network, no cross-site tracking pixel, no social embed, and no third-party font or script loaded on ordinary pages. Web fonts are self-hosted, so viewing a page makes no request to a font provider.
Google Maps content: Ratings, reviews and photos shown on a profile are fetched by the Serproz server, not by your browser, so viewing a profile does not set a Google cookie on your device.
Stripe describes its own cookies in the Stripe privacy policy. Google describes its own in the Google Privacy Policy.
Some things are kept in your browser's own storage rather than in a cookie. They stay on your device and are not transmitted with every request.
| Key | Purpose | Lifetime |
|---|---|---|
serproz:book-draftsessionStorage | Keeps a partly completed booking so a refresh or a back button does not lose it. A password is never written to it. | Cleared when the booking is submitted, or when the browser tab closes |
serproz:post-job-draftsessionStorage | The same protection for a partly completed Post a Job wizard. | Cleared when the job is posted, or when the browser tab closes |
serproz:post-job-draft:call:*sessionStorage | Keeps the customer's editable, call-derived job draft separate from their ordinary job form while it is reviewed. | Cleared when the job is posted, or when the browser clears the tab session |
serproz.ai-post-job.v3sessionStorage | Keeps the description, AI suggestion, answers and site address you are reviewing in the assisted Post a Job flow. | Cleared when the job is posted, or when the browser clears the tab session |
serproz:assistant-job-draft-reviewsessionStorage | Transfers job wording only after you choose Review job draft. It does not publish a job or put private descriptions in the page URL. | Usable for 30 minutes; removed when applied or dismissed, or when the browser clears the tab session |
serproz:analytics:journey:*sessionStorage | One random journey identifier per funnel — direct booking, quote post, Find a Provider — so the steps of a single visit line up in product analytics. | Until the browser tab closes |
serproz.find-a-pro.journey.v2sessionStorage | Holds the Find a Provider answers you have given so far while you move between steps. | Until the browser tab closes |
serproz:support-location-transfersessionStorage | Carries the location you typed into search across to the support form so you do not retype it. | Read once and removed immediately |
serproz.find-a-pro.recent-jobs.v1localStorage | Your own recently viewed jobs, shown back to you on this device. It stays in your browser and is never sent to Serproz. | Until you clear it, or clear your browser data |
New Zealand has no cookie-consent statute equivalent to the European rules, so this site does not show a consent banner. The Privacy Act 2020 still governs the personal information involved, and these are the controls that genuinely exist.
Browser controls: Every major browser lets you block or delete cookies for a site, and clear its stored data. Blocking the Serproz cookies blocks the analytics identifier as well, at the cost of not being able to stay signed in.
Browse without signing in: Directory, Popular Services and profile pages are readable without an account. No session cookie is set until you sign in.
Ask what is held about you: The analytics identifier is personal information while it can be connected to you. You can ask for the information held against it, and ask for it to be corrected or removed, through the privacy policy's access and correction route.
There is no per-cookie opt-out switch on this site today, and this page will not pretend otherwise. The analytics cookie is written by the server, so a page-level toggle would not be truthful about what it controls. If a genuine opt-out is published it will be described here, in this section.
A new cookie is added to the table above on the same change that introduces it, and the version string at the top of this page moves with it. The current version is cookie-policy-2026-09-07-v2. If you believe a cookie is being set that is not listed here, report it through the support page and it will be either removed or documented.
Read the privacy policy for how the information behind these cookies is used, kept and corrected.
Search and compare local providers, or post the job and invite relevant providers to respond.