PRIVACY

Privacy Policy

EXPHIRST is designed around data minimization. We collect and process only the information needed to provide account, job-analysis, subscription and security features.

Data we process

  • Account and authentication data such as email address, display name and authentication references.
  • Professional profile and CV-derived data such as role, seniority, skills, location and work preferences. If a user uploads a CV, EXPHIRST stores only structured professional signals and metadata needed for the feature; the raw CV file is not persistently stored.
  • Job-analysis data submitted from supported job-listing pages and the scores or signals generated by EXPHIRST.
  • Usage and security data required for quotas, audit trails, subscription status and abuse prevention.
  • Limited first-party anonymous analytics. EXPHIRST does not store IP addresses, User-Agent strings, email addresses or persistent browser identifiers in its analytics table.

Data minimization

EXPHIRST does not fabricate missing salary or employer-history data. The same principle applies to personal data: information that is not necessary for the service is not collected by default.

Free-text employer reviews are not collected in the current product scope.

Payments

Paid subscriptions are processed through Paddle. Card details are entered into Paddle's secure checkout and do not pass through EXPHIRST servers.

EXPHIRST stores only the payment-provider references and subscription state required to manage account entitlements.

Retention and deletion

  • Raw anonymous analytics have a technical target retention period of 90 days.
  • Short-lived rate-limit records and expired pairing codes are subject to cleanup policies.
  • Users can export their EXPHIRST data and request deletion of EXPHIRST account data from the product.
  • Some billing, audit or legal records may need to be retained where required by applicable law.

Third parties and international processing

Authentication is handled through a shared SuperTokens infrastructure operated on WebRising systems.

Payments are processed by Paddle. Hosting, security and infrastructure providers may process limited data where necessary to operate the service.

User controls

  • Update profile information.
  • Export EXPHIRST data.
  • Delete EXPHIRST user data.
  • Manage optional analytics and marketing preferences separately.
  • Submit privacy-related requests through the Privacy Center.