Privacy Policy
Last updated: March 2026
Your privacy matters to us. This policy explains what data we collect, why, and how we protect it. EZCV is committed to complying with the General Data Protection Regulation (GDPR) and respecting your rights over your personal data.
Data We Collect
We collect the minimum data necessary to provide the Service:
- Account information: Your name, email address, and profile picture (if using Google OAuth). We do not store your passwords.
- CV and cover letter data: The content you enter into your CVs and cover letters (personal details, work experience, education, etc.). This data is stored in our database to enable the Service.
- Public CV data: If you choose to make a CV public, the CV content and a customizable link slug are stored to enable public access. Public CVs are viewable by anyone with the link.
- Public CV view counts: We track how many times your public CV is viewed. This is an aggregate count and does not store information about who viewed your CV.
- Payment information: If you make a payment, Stripe processes the transaction. We store only the Stripe payment ID and payment date — never your card details.
- System activity & error logs: We record your activities within the app (e.g., logins, PDF exports, payments, public link changes) and any technical errors you encounter. This diagnostic data is linked to your account to help us debug issues, provide customer support, and maintain platform security.
- Usage data: We use Plausible Analytics, a privacy-focused, cookie-less analytics tool, to understand website traffic. It does not track individual users or collect personal data.
Public CV Sharing
When you enable public sharing for a CV:
- Your CV becomes accessible via a unique link (e.g., EZCV/p/slug)
- Free users get one public CV with a randomly generated link
- Paid supporters can customize their main public CV link with a memorable slug of their choice
- Anyone with the link can view your CV without logging in
- We track the number of views but not who viewed it
- You can disable public sharing or change your link at any time for the custom slug
- Deleting your CV or account immediately removes public access
You are responsible for the personal information you choose to make public. Consider carefully what details to include in publicly shared CVs.
Legal Basis for Processing (GDPR)
We process your data under the following legal bases:
- Contract performance: Processing your CV and cover letter data is necessary to provide the Service you signed up for.
- Legitimate interest: Account management, security, and service improvements.
- Consent: You consent to data processing when you create an account and use the Service.
Your Rights (GDPR)
Under GDPR, you have the right to:
- Access: Request a copy of all personal data we hold about you.
- Rectification: Correct any inaccurate personal data.
- Erasure: Request deletion of your personal data ("right to be forgotten"). Deleting your account removes all your CVs, cover letters, and personal information.
- Data portability: Export your CV data in a standard format.
- Restriction: Request restriction of processing in certain circumstances.
- Objection: Object to processing based on legitimate interest.
To exercise any of these rights, please contact us at the email address listed below.
Data Storage & Security
Your data is stored in a PostgreSQL database on our secure server infrastructure. We use encrypted connections (HTTPS/TLS) for all data transmission. Access to the database is restricted and protected by authentication. Our designated administrators have access to your account data, activity logs, and CV content solely for the purposes of providing customer support, resolving technical issues, and ensuring platform security. We do not share, sell, or provide your personal data to third parties, except as required by law or as necessary to provide the Service (e.g., Stripe for payment processing).
Data Retention
We retain your data for as long as your account is active. If you delete your account, all associated personal data, CVs, and cover letters are permanently removed from our systems. Payment records may be retained for legal and accounting purposes as required by applicable law.
Cookies
We use only essential cookies required for authentication and session management. We do not use advertising cookies, tracking cookies, or third-party analytics cookies.
Contact
For any privacy-related questions or to exercise your GDPR rights, please contact us at contact@ezcv.app.