Privacy Policy

Last Updated:  25-06-25

1. Data We Collect

From Job Seekers:

  • Required: Name, email, phone, resume, work history.
  • Optional: LinkedIn profile, salary expectations.

From Employers:

  • Company name, tax ID (for invoicing), job descriptions.

Automatically:

  • IP address, device type, cookies (see Section 4).

2. How We Use Data

PurposeExamplesLegal Basis
Service DeliveryMatching candidates to jobsContractual
Fraud PreventionDetecting fake job postsLegitimate Interest
Marketing“Top Jobs” emails (opt-out anytime)Consent

3. Data Sharing

  • Employers: Your profile/resume only when you apply.
  • Vendors: Stripe (payments), Google Cloud (hosting), analytics tools.
  • Legal Compliance: If required by law (e.g., subpoenas).

4. Cookies & Tracking

  • Necessary: Login sessions, payment processing.
  • Analytical: Google Analytics (anonymized IPs).
  • Opt-Out: Browser settings or GDPR banner.

5. Your Rights

  • Access/Delete: Request via support@jobflow24.com.
  • Correction: Edit profile anytime in account settings.
  • Portability: Export your data as JSON/PDF.

6. Security Measures

  • Encryption (SSL/TLS) for all data transfers.
  • Regular audits for vulnerabilities.
  • Employee training on GDPR/CCPA.

Data Protection Officer: support@jobflow24.com

Data Collection

  1. Provided by You:
Data TypeExamplesRetention Period
Account ProfileName, email, phone, resumeUntil account deletion + 30 days (backup)
Job ApplicationsCover letters, responses to employers3 years (or per employer’s request)
Payment DataStripe transaction records7 years (tax compliance)
  1. Collected Automatically:
Data TypePurposeRetention
IP/Device InfoFraud prevention12 months
CookiesSession management6 months (opt-out anytime)
Analytics (Google)Traffic trends26 months (anonymized)

2. Data Use & Legal Bases

PurposeLegal BasisExample
Match candidates/jobsContractualSharing resume with employers you apply to
Send marketing emailsConsent“Top Jobs” newsletters (opt-out link in every email)
Improve algorithmsLegitimate InterestAnalyzing application rates to refine AI suggestions

3. Data Sharing

  1. With Employers:
  • Only when you apply—employers see your full profile, resume, and responses.
  • Employers may retain your data per their policies (we require compliance with GDPR/CCPA).
  1. With Service Providers:
VendorPurposeData Shared
StripePaymentsBilling address, last 4 digits of card
AWS (Hosting)Data storageEncrypted user profiles
ZendeskSupport ticketsEmail + issue description
  1. Legal Disclosures:
  • We’ll notify users before sharing data for legal requests (unless prohibited by law).

4. Data Retention & Deletion

  • Active Accounts: Data retained until deletion request.
  • Inactive Accounts: Deleted after 24 months of inactivity (emails will warn you first).
  • Backups: Encrypted and purged every 30 days.

How to Request Deletion:

  1. Email privacy@jobflow24.com with subject “Data Deletion Request.”
  2. We’ll verify your identity (e.g., confirm via account email).
  3. Process within 30 days (excluding legal retention requirements).

5. Security & Compliance

  • Encryption: TLS 1.2+ for all data transfers; AES-256 for storage.
  • Audits: Annual penetration testing + SOC 2 compliance roadmap.
  • Employee Access: Strict role-based permissions; training every 6 months.

6. Your Rights

RightHow to ExerciseTimeline
AccessDownload data in Settings > PrivacyInstant (CSV/PDF)
CorrectionEdit profile anytimeInstant
PortabilityEmail request to privacy@jobflow24.com30 days
Opt-Out of MarketingUnsubscribe link or Settings > Preferences48 hours

CCPA/GDPR Requests:

7. Policy Updates

  • Material changes require 30 days’ notice (email + banner on site).
  • Archive of past versions available [here].

Contact: