Privacy Policy
Last updated: 2026-02-24
This Privacy Policy explains how CV Career ("we", "us") collects, uses, and shares information when you use our website and services (the "Service").
If you have questions, contact us at: support@cv-career.de
1) Who we are
Controller: CV Career
Contact: support@cv-career.de
(If you have an official company name/address, add it here.)
2) What data we collect
A) Account data
When you create an account or sign in, we may collect:
- Name (if provided)
- Email address
- Password (stored as a secure hash, not in plain text)
- Authentication provider identifiers (e.g., Google/LinkedIn provider ID)
B) Resume and profile content you provide
The Service lets you create and store resume-related content, which may include:
- Work experience, education, skills
- Links (e.g., portfolio, LinkedIn)
- Any personal data you choose to include (phone, address, etc.)
C) Newsletter data (optional)
If you subscribe to our newsletter:
- Email address
- Preferred language (if available)
- Subscription status and delivery history (for compliance and operations)
You can unsubscribe at any time using the link in our emails.
D) Billing and subscription data (if you purchase)
If you start a paid plan, we store:
- Stripe customer and subscription identifiers
- Subscription status and billing lifecycle fields (e.g., trial end)
We do not store full payment card details. Payments are handled by Stripe.
E) Technical data
We may process standard technical data to operate and secure the Service:
- Device and browser information
- Approximate location (derived from IP)
- Logs related to security, reliability, and debugging
3) How we use your data
We use your information to:
- Provide the Service (create accounts, save resumes, show your dashboard)
- Authenticate users (including OAuth sign-in via Google and LinkedIn)
- Send essential service messages (security, account, transactional communications)
- Send newsletters if you opted in
- Provide and manage subscriptions and billing
- Maintain security, prevent abuse, and troubleshoot issues
- Comply with legal obligations
4) Legal bases (EEA/UK)
Depending on your location, we rely on:
- Contract: to provide the Service you request
- Consent: for optional features like newsletter marketing (where required)
- Legitimate interests: to secure, improve, and operate the Service
- Legal obligation: accounting, fraud prevention, and other legal requirements
5) Authentication providers (Google / LinkedIn)
You can sign in using third-party providers such as Google and LinkedIn. When you use these providers, we receive information like:
- Your email address
- Your name (if provided by the provider)
- A provider user identifier (so we can link your account)
We use this data only to authenticate you and link you to your CV Career account.
6) Payments (Stripe)
If you subscribe to a paid plan, payment processing is handled by Stripe. Stripe may collect and process payment details according to its own privacy policy. We typically store only Stripe identifiers and subscription status needed to manage your plan.
7) Cookies and similar storage
We use limited cookies / browser storage for core features. For example:
- Theme preference (light/dark) may be stored in a cookie.
- Language preference may be stored in a cookie.
- Some flows may use sessionStorage/local storage for temporary UI state.
We do not use these storage items to sell personal data.
(If you add analytics/ads later, update this section with full details and consent handling.)
8) Sharing and disclosure
We may share information:
- With service providers who help us run the Service (hosting, email delivery, payment processing)
- When required by law or to protect rights, safety, and security
- In a business transfer (merger/acquisition), with appropriate safeguards
We do not sell your personal data.
9) Data retention
We keep data as long as needed to provide the Service and for legitimate business/legal purposes. Examples:
- Account data: retained while your account is active
- Resume content: retained while your account is active (unless you delete it)
- Billing records: retained as required by law/accounting rules
- Newsletter logs: retained for compliance and operational needs
You can request deletion of your account data (see Section 11).
10) Security
We use appropriate technical and organizational measures to protect your data. No system is 100% secure, but we work to prevent unauthorized access, loss, or misuse.
11) Your rights
Depending on your jurisdiction, you may have rights including:
- Access to your personal data
- Correction of inaccurate data
- Deletion of your data
- Objection or restriction of certain processing
- Data portability
To exercise your rights, contact: support@cv-career.de
12) International transfers
Your data may be processed in countries where we or our service providers operate. Where required, we use appropriate safeguards (e.g., contractual protections).
13) Children
The Service is not intended for children under the age required by local law to consent to online services. Do not use the Service if you do not meet the minimum age requirement.
14) Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page.
15) Contact
Email: support@cv-career.de