Last updated: March 2025
Privacy Policy
This policy explains how cvdrops.com collects, uses, and protects your personal data.
1. Data We Collect
We collect only the data necessary to provide our service: • Account data: email address and name, provided during registration. • CV content: the text, dates, and other information you enter into the wizard. • Profile photo: uploaded voluntarily to Supabase Storage. • Payment data: processed exclusively by Lemon Squeezy. We do not store card numbers or payment details. • Usage data: anonymous analytics (page views, feature usage) to improve the product. No personal identifiers are attached.
2. How We Use Your Data
Your data is used solely to: • Provide and improve the cvdrops.com service. • Generate and display your CV. • Send transactional emails (account confirmation, purchase receipts) via Resend. • Comply with legal obligations. We never sell your data. We never share it with advertisers or third-party marketers.
3. Data Storage & Security
All data is stored in Supabase (EU-West region by default). Data is encrypted at rest using AES-256 and in transit using TLS 1.3. Supabase is SOC 2 Type II certified. Access to production data is restricted to essential personnel only.
4. Cookies
We use only strictly necessary cookies: • Supabase session cookie: keeps you logged in. Expires when you sign out or after 7 days of inactivity. We do not use tracking, advertising, or analytics cookies.
5. Your Rights (GDPR)
Under the General Data Protection Regulation (EU) 2016/679, you have the right to: • Access your data (export all CV data from your dashboard). • Rectify inaccurate data. • Erase your data ("right to be forgotten") — delete your account at any time from settings. • Portability — download your CV data as JSON. • Object to processing. To exercise any right, email: privacy@cvdrops.com
6. Data Retention
We retain your data for as long as your account is active. When you delete your account, all associated data (profile, CVs, uploads) is permanently deleted within 30 days. Purchase records may be retained for up to 7 years for tax and legal compliance.
7. Third-Party Processors
We use the following sub-processors: • Supabase Inc. — database, authentication, and file storage • Lemon Squeezy — payment processing (PCI DSS Level 1) • Resend — transactional email delivery • Anthropic — AI content generation (your CV content may be sent to Claude API; it is not used to train models) • Vercel — application hosting All processors are under contractual data protection agreements.
8. Children
cvdrops.com is not directed at children under 16. We do not knowingly collect data from minors. If you believe a child has provided us with personal data, contact us at privacy@cvdrops.com and we will delete it promptly.
9. Changes to This Policy
We may update this policy. We will notify you by email and display a banner on the site at least 14 days before significant changes take effect.
10. Contact
Data controller: cvdrops.com Email: privacy@cvdrops.com