CV Manager

Privacy Policy

Last Updated: October 2026

1. Data We Collect

We collect only information necessary to deliver candidate profiling and recruitment workflows:

  • Account Credentials: Name, email address, and securely hashed passwords.
  • Profile Information: Location, optional profile photo, and customizable profile attributes.
  • Work History & Projects: Project titles, date ranges, Markdown descriptions, and technology tags.
  • CVs & Submissions: Generated CV documents, attribute values, and publication states.
  • Community Data: Discussion posts and questions posted on position boards.

2. External Authentication (Google & Facebook)

When you choose to sign in using Google or Facebook OAuth, we receive only your verified email address and basic profile name. We never receive or store your third-party social passwords.

3. Data Access & Visibility

Access to candidate information is strictly scoped by system permissions and publication state:

  • Draft CVs: Strictly private to you. No recruiter can view your draft CVs or unfinished applications.
  • Published CVs: Visible to verified Recruiters and Administrators searching for matching candidates.
  • Administrators: Platform administrators possess access to manage user accounts, assign roles, and maintain system health.

4. Salesforce CRM Integration

CVPlatform includes an optional Salesforce CRM integration. Profile data is transmitted to Salesforce only when you explicitly submit the 'Sync to Salesforce' action. We do not perform background syncs without user initiation.

5. Cookies & Local Storage

We use minimal, strictly necessary cookies and browser storage to power core site features:

  • Authentication Cookie: Secure HTTP-only session cookie to keep you logged in.
  • Theme & Language Cookies: Preferences for light/dark theme and English/Bengali UI.
  • Sidebar State: Local storage flag to remember collapsed or expanded sidebar state.

6. Data Storage & Security

All user credentials and sensitive records are stored in encrypted databases. Passwords use PBKDF2 cryptographic hashing. Uploaded media assets are stored in MinIO object storage with presigned expiring URLs. All web traffic is strictly encrypted over HTTPS/TLS.

7. Your Rights & Retention

You have the right to access, update, correct, or delete your profile and CV records at any time directly through the platform settings. When an account is removed, associated personal CVs and projects are permanently deleted.

For privacy inquiries or data requests, please contact our data protection team at: privacy@cvplatform.local