Privacy Policy
Last updated: June 9, 2026
1. What We Collect
When you register and use shipMeThisJob, we collect:
- Account info - email address, display name, and password (hashed, never stored in plain text)
- Usage data - job statuses, bookmarks, notes, pipeline activity, and network contacts you create
- Technical data - IP address, browser type, and page views (for security and debugging only)
We do not collect payment information, location data, or any data from third-party services.
2. How We Use Your Data
- Provide and operate the job tracking dashboard
- Authenticate your account and maintain your session
- Send transactional emails (invite, password reset, email verification)
- Improve the product based on aggregate usage patterns
We never sell, rent, or share your personal data with third parties for marketing purposes.
3. Data Storage
Your data is stored in a PostgreSQL database hosted on Neon (serverless Postgres) with encryption at rest. The application is hosted on Vercel. Both services are based in the United States.
4. Cookies
We use a small number of HTTP-only cookies strictly for authentication and security:
- Session token - a signed JWT that identifies your logged-in session
- CSRF token - prevents cross-site request forgery attacks
- Callback URL - remembers where to redirect after sign-in
We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
5. Data Retention
Your data is retained as long as your account is active. If you delete your account (via Settings), all your personal data is permanently removed immediately.
Job listing lifecycle:
- Jobs are marked inactive shortly after they are removed from a company's career page
- Inactive jobs remain visible in your dashboard but are flagged
- After 120 days inactive, jobs with no user activity are permanently removed
- Jobs you have bookmarked or applied to are never auto-deleted
- Items you manually delete (notes, contacts, history) are kept in trash for 30 days before permanent removal
Sessions expire after 7 days of inactivity. Active daily usage keeps your session alive indefinitely.
6. Your Rights
You can:
- Access and export your data at any time via the dashboard
- Update or correct your profile information in Settings
- Delete your account and all associated data from Settings
- Contact us at privacy@shipmethisjob.dev for any data-related requests
7. Security
We protect your data with:
- HTTPS encryption on all connections
- Bcrypt password hashing
- Rate limiting on authentication endpoints
- HTTP-only, secure session cookies
8. Changes
We may update this policy as the product evolves. Significant changes will be communicated via the changelog or email. Continued use after changes constitutes acceptance.
9. Contact
For questions about this policy, reach us at privacy@shipmethisjob.dev.