Effective: February 25, 2026
β’Version 1.1.0
Effective Date: February 25, 2026
Last Updated: February 25, 2026
Version: 1.1.0
Welcome to YourNiceCv ("Service", "we", "us", "our"). Your privacy is critically important to us. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website and services.
Who we are:
Scope: This Privacy Policy applies to all users of YourNiceCv, regardless of location. It complies with:
By using the Service, you consent to the data practices described in this policy.
YourNiceCv is the data controller responsible for your personal data under UK GDPR (Data Protection Act 2018) and EU GDPR.
Contact details:
UK Supervisory Authority: If you have concerns about how we handle your personal data, you can contact the UK Information Commissioner's Office (ICO):
ICO Registration: We are committed to registering with the ICO as required under UK data protection law for organisations processing personal data.
We collect the following types of personal data:
When you register an account, we collect:
Legal Basis (GDPR): Performance of contract (Art. 6(1)(b)) β necessary to provide the Service.
When you use the Service, we collect:
Legal Basis (UK GDPR/GDPR): Performance of contract (Art. 6(1)(b)) β necessary to provide resume creation/editing services
Your resume may contain special category data under UK GDPR/GDPR Article 9, including:
We do NOT intentionally collect special category data, but it may be present in your uploaded resume content.
Legal Basis (UK GDPR/GDPR): Explicit consent (Art. 9(2)(a)) β by uploading a resume, you explicitly consent to processing any special category data it may contain. You may withdraw consent at any time by deleting your resume or account.
When you subscribe, we collect:
We do NOT store credit card numbers or payment credentials. Paddle handles all payment processing (PCI DSS compliant).
Legal Basis (UK GDPR/GDPR): Performance of contract (Art. 6(1)(b)) + Legal obligation (Art. 6(1)(c)) for tax records.
We automatically collect:
This data is collected via PostHog (analytics platform) using cookies and tracking technologies.
Legal Basis (UK GDPR/GDPR):
If you contact us (email, support ticket), we collect:
Legal Basis (UK GDPR/GDPR): Legitimate interests (Art. 6(1)(f)) β to respond to enquiries and provide customer support.
We use your personal data for the following purposes:
| Purpose | Data Used | Legal Basis (UK GDPR/GDPR) |
|---|---|---|
| Provide the Service (resume creation, editing, AI features) | Account info, resume content, files | Performance of contract (Art. 6(1)(b)) |
| AI processing (parse resumes, generate content) | Resume text, job descriptions | Performance of contract + Consent (special categories) |
| Process payments (subscriptions, refunds) | Payment info, email | Performance of contract (Art. 6(1)(b)) |
| Send transactional emails (password reset, receipts) | Email, name | Performance of contract (Art. 6(1)(b)) |
| Send marketing emails (product updates, offers) | Consent (Art. 6(1)(a)) β opt-in required | |
| Analytics and improvement (product optimization) | Usage data, IP, device info | Legitimate interests (Art. 6(1)(f)) |
| Security and fraud prevention (abuse detection) | IP, device fingerprint, usage patterns | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance (tax records, legal holds) | Payment records, account info | Legal obligation (Art. 6(1)(c)) |
We do NOT:
We retain your data as follows:
| Data Type | Retention Period | Reason |
|---|---|---|
| Active account data | Until account deletion | Service provision |
| Deleted accounts (soft delete) | 30 days | Allow recovery, legal hold |
| Resume files (uploaded) | Until deleted by user or account closure | User-requested storage |
| Payment records | As required by UK tax and accounting laws | UK tax compliance |
| Analytics logs (PostHog) | 12 months | Business intelligence |
| Error logs and backups | 90 days | Debugging and recovery |
| Support emails | 3 years | Customer service records |
Permanent deletion: After the retention period, data is irreversibly deleted from our systems (except where required by law, e.g., tax records).
We share your data with the following trusted third-party service providers:
What they do: Host our PostgreSQL database, store uploaded files (resumes), manage user authentication (including Google OAuth).
Data shared:
Location: EU and/or US data centres (depending on Supabase region configuration)
Privacy & Security:
Their policies:
Legal Basis: Data processing agreement (DPA) in place as required by UK GDPR/GDPR Art. 28.
What they do: Process subscription payments, handle billing, issue invoices, manage refunds.
Data shared:
Location: Global (Paddle operates in US, EU, UK)
Privacy & Security:
Their policies:
Important: Paddle acts as merchant of record (they collect payment on our behalf). You are also subject to Paddle's terms and privacy policy.
Legal Basis: Data processing agreement (DPA) in place.
What they do: Provide artificial intelligence services to parse resumes, generate cover letters, and tailor content.
Data shared:
Location: Google Cloud global infrastructure (US, EU, Asia)
Privacy & Security:
Important:
Their policies:
Legal Basis: Data processing agreement (DPA) via Google Cloud terms.
What they do: Track user interactions, page views, feature usage, and product analytics.
Data shared:
Location: US and EU (depending on configuration)
Privacy & Security:
Their policies:
Legal Basis: Consent (for EU/UK users via cookie banner) + Legitimate interests (Art. 6(1)(f)) for essential analytics.
We may share data with:
We will update this policy if we add new third-party services.
Our operations involve international data transfers outside the United Kingdom:
| Service | Data Location | Transfer Mechanism (UK Users) |
|---|---|---|
| Supabase | EU / US | UK International Data Transfer Agreement (IDTA) or UK-approved Standard Contractual Clauses (SCCs) |
| Paddle | Global | UK IDTA + Adequacy Decisions (where applicable) |
| Google Gemini | Global (US, EU, Asia) | Google Cloud DPA + UK-approved SCCs |
| PostHog | US / EU | UK IDTA or UK-approved SCCs |
For UK users: When we transfer your personal data outside the United Kingdom, we ensure appropriate safeguards are in place:
For EU/EEA users: Data transferred outside the EU/EEA is protected by:
You have the right to:
To request information about transfers: Contact privacy@yournicecv.com with subject "International Transfer Inquiry"
Depending on your location, you have the following rights:
You have the right to:
β
Access (Art. 15): Request a copy of your personal data
β
Rectification (Art. 16): Correct inaccurate or incomplete data
β
Erasure (Art. 17 β "Right to be Forgotten"): Delete your data (subject to legal retention requirements)
β
Restrict Processing (Art. 18): Limit how we use your data
β
Data Portability (Art. 20): Export your data in a machine-readable format (JSON)
β
Object (Art. 21): Object to processing based on legitimate interests
β
Withdraw Consent: Revoke consent for marketing, analytics, or special category data processing
β
Lodge a Complaint: File a complaint with your national Data Protection Authority (DPA)
How to exercise rights:
Response time: We will respond within 30 days (may extend to 60 days for complex requests).
California residents have the right to:
β
Know: What personal information we collect, use, and share (see Sections 1-4)
β
Access: Request a copy of your data (last 12 months)
β
Delete: Request deletion of your data (subject to exceptions)
β
Opt-Out of Sale: We do NOT sell personal data, so no opt-out needed
β
Non-Discrimination: We will not discriminate for exercising your rights
How to exercise rights: Email support@yournicecv.com or use in-app data export/deletion tools.
Verification: We may ask for proof of identity (email confirmation) to prevent fraud.
We use cookies and similar tracking technologies for analytics and functionality.
| Cookie Type | Purpose | Duration | Provider |
|---|---|---|---|
| Essential | Authentication, session management | Session / 30 days | Supabase |
| Analytics | Track page views, feature usage | 12 months | PostHog |
| Preferences | Remember settings (theme, language) | 12 months | First-party |
Essential cookies are necessary for the Service to function and cannot be disabled.
Non-essential cookies (analytics) require your consent (EU users).
When you first visit our site, you will see a cookie banner:
You can change preferences at any time via the footer link: [Cookie Settings].
You can block cookies via browser settings:
Note: Disabling essential cookies may break functionality (e.g., login).
For more details, see our Cookie Policy.
We implement industry-standard security measures to protect your data:
To protect your account:
In the event of a data breach:
No system is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
YourNiceCv is not intended for children under 13 years old (or under 16 in the UK/EU for certain processing).
We do NOT knowingly collect personal data from children. If you are under the minimum age:
If we discover that we have collected data from a child without parental consent, we will delete it immediately.
Parents: If you believe your child has provided us with personal data, contact support@yournicecv.com to request deletion.
You can opt out of marketing communications:
Note: You will still receive transactional emails (e.g., password resets, receipts) β these are necessary for the Service.
You can opt out of PostHog analytics:
You can permanently delete your account:
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date.
Material changes (e.g., new data collection, third-party sharing) will be communicated via:
Continued use of the Service after changes take effect constitutes acceptance.
If you do not agree, you may delete your account before changes take effect.
For privacy questions, data requests, or concerns:
General Contact: support@yournicecv.com
Data Protection Contact: privacy@yournicecv.com
Website: https://yournicecv.com
Data Protection Enquiries (UK GDPR/GDPR):
Mailing Address (for formal notices): Available upon request via support@yournicecv.com
UK Representative (if required under UK GDPR): [To be appointed if processing large volumes of UK data from outside UK]
If you are unhappy with how we handle your data, you have the right to lodge a complaint with your national Data Protection Authority (DPA):
π¬π§ UK: Information Commissioner's Office (ICO)
πͺπΊ EU: Find your DPA at https://edpb.europa.eu/about-edpb/board/members_en
| Processing Activity | Legal Basis |
|---|---|
| Account management, service provision | Performance of contract (Art. 6(1)(b)) |
| Payment processing | Performance of contract (Art. 6(1)(b)) + Legal obligation (Art. 6(1)(c)) |
| Resume content processing | Performance of contract + Consent (for special categories, Art. 9(2)(a)) |
| AI processing (Gemini) | Performance of contract + Consent |
| Analytics (PostHog) | Consent (Art. 6(1)(a)) + Legitimate interests (Art. 6(1)(f)) |
| Marketing emails | Consent (Art. 6(1)(a)) |
| Security and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance (tax records) | Legal obligation (Art. 6(1)(c)) |
California residents may request information about disclosure of personal information to third parties for direct marketing purposes (Cal. Civ. Code Β§ 1798.83).
We do NOT share personal data with third parties for their marketing purposes.
By using YourNiceCv, you acknowledge that you have read and understood this Privacy Policy.
Document Version: 1.1.0
Effective Date: February 25, 2026
Next Review: August 25, 2026 (6 months)