Privacy Policy
- Last updated:
- 20 August 2026
- Effective:
- 6 August 2026
1. Who we are#
ReqHunt ("ReqHunt", "we", "us") operates the website and application at https://reqhunt.com (the "Service"). ReqHunt monitors companies' public careers pages and shows users job openings matching their stated preferences.
Data controller: ReqHunt.com, Italy
Contact for privacy matters: privacy@reqhunt.com
2. What personal data we collect#
2.1 Data you give us
Account data. Your email address, and your name and profile picture if you sign in with Google. We do not store passwords when you use Google sign-in.
Job preferences. The job titles, keywords, locations and exclusions you configure; how many email alerts you want; your timezone.
Your CV and profile details. If you upload a CV or fill in your profile, we store the file and the employment and education history you enter.
Application activity. Which roles you saved, hid, opened, or marked as applied to.
This reveals that you are looking for work and where. It is not a GDPR special category, but disclosure could cause real harm — for example to your relationship with a current employer. We treat it accordingly and never share it.
Support correspondence. Anything you send us by email.
2.2 Data we generate
Match records. Which job listings matched your filters, when we first saw them, and whether you have viewed them.
Service records. Your subscription and trial status, when your matches were last refreshed, and how many alert emails you have been sent.
2.3 Data collected automatically
Technical data. IP address, browser and device type, pages viewed, referring page, and approximate location derived from IP.
Abuse-prevention signal (at signup only). When you create an account we store two derived values: a one-way salted hash of your IP address (we never store the IP itself) and a normalised form of your email address (lower-cased, with dots and any +suffix removed). We use these only to detect the same person opening multiple accounts to obtain pricing they are not entitled to. They are not used to profile you, to target advertising, or for any other purpose, and they are deleted after 90 days.
2.4 Data about companies, not about you
We read publicly available job listings from companies' own careers pages and applicant tracking systems. These listings describe roles, not people. Where a listing incidentally names an individual (for example a hiring manager), we process that under our legitimate interest in operating a job-discovery service, and you may object under section 7.
3. Why we process it, and our legal basis (GDPR Article 6)#
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account | To provide the Service you signed up for | Contract — Art. 6(1)(b) |
| Match job listings to your filters | Core function of the Service | Contract — Art. 6(1)(b) |
| Store your CV and profile | To let you keep application materials in one place | Consent — Art. 6(1)(a), plus explicit consent under Art. 9(2)(a) where the file contains special-category data |
| Send alert emails about new matches | You asked to be notified | Consent — Art. 6(1)(a); withdrawable at any time |
| Send service emails (security, account) | Necessary to administer the contract | Contract — Art. 6(1)(b) |
| Keep the Service secure, prevent abuse, debug | We have a genuine interest in a working, non-abused service | Legitimate interests — Art. 6(1)(f) |
| Store a hashed IP and normalised email at signup | To detect duplicate accounts created to obtain pricing not available to that person | Legitimate interests — Art. 6(1)(f) |
| Comply with legal obligations | Tax, accounting, lawful requests | Legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interests we have assessed that our interest does not override your rights. You may ask for that assessment, and you may object (section 7).
4. Who we share it with#
We do not sell your personal data. We do not share it with third parties for their own marketing.
We use the following processors, who handle data only on our instructions:
| Provider | What it does | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage, backend functions | All account, preference, match, application and CV data |
| Lovable | Application hosting and development platform | Application data in transit; possibly logs |
| Sign-in via Google OAuth | Your email, name, profile picture | |
| Resend | Sending alert and service emails — alert emails are currently disabled, so no alert data is sent to this provider today | Your email address and the contents of the email |
We may also disclose data where legally required — to comply with a valid legal request, enforce our terms, or protect rights and safety — and in a merger or acquisition, in which case we will notify you before your data becomes subject to a different policy.
5. How long we keep it#
| Data | Retention |
|---|---|
| Account data | While your account is active |
| Job preferences | While your account is active |
| CV and profile | Until you delete it, or your account is deleted |
| Match and application history | While your account is active |
| Abuse-prevention signal (hashed IP, normalised email) | 90 days from signup, then deleted automatically |
| Payment records and invoices | 10 years (Italian tax and accounting law) |
| Refund records | 10 years, kept after account deletion as a financial record identified only by an internal reference — no name, no email |
| Deletion record (date, internal identifier, whether the subscription was cancelled, a one-way hash of the email address) | 10 years |
When you delete your account we erase your personal data from our live systems immediately. Copies inside our encrypted backups are overwritten within 30 days, after which no copy remains anywhere.
Three things deliberately survive deletion, and you should know exactly what they are:
- Payment records and invoices. Tax and accounting law requires us to keep them for 10 years. This legal obligation overrides the erasure right (GDPR Art. 17(3)(b)).
- Refunds we processed, kept for the same reason and for the same period, identified only by an internal reference that is no longer linked to your name or email.
- A minimal deletion record — the date, an internal identifier, whether your subscription was cancelled, and a one-way hash of your email address. The record is our evidence that we honoured your request; the hash lets us count how often deleted addresses sign up again, to detect abuse of free-trial pricing. A hash cannot be turned back into an address, and no pricing or access decision is made from it. Legal basis: legitimate interests (fraud and abuse prevention), and legal obligation for the record itself.
Anonymised, non-identifying aggregate statistics may be retained indefinitely.
6. Cookies#
We use cookies that are strictly necessary to run the Service — keeping you signed in and maintaining your session. These do not require consent.
7. Your rights under GDPR#
If you are in the EEA or UK you have the right to:
- access the personal data we hold about you, and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten");
- restrict processing in certain circumstances;
- data portability — receive your data in a structured, machine-readable format, and have it transmitted to another controller where technically feasible;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- not be subject to decisions based solely on automated processing producing legal or similarly significant effects.
Note on automated processing: ReqHunt matches job listings against filters you set. This is automated, but it produces no legal or similarly significant effect — it shows you listings; it does not decide anything about you. We do not profile you, score you, or share any assessment of you with employers.
To exercise any right, contact privacy@reqhunt.com. We respond within one month, extendable by two further months for complex requests, and we will tell you if we extend. We may ask you to verify your identity.
You have the right to lodge a complaint with a supervisory authority. In Italy this is the Garante per la protezione dei dati personali (www.garanteprivacy.it). You may also complain to the authority in your country of residence or workplace.
8. Your rights in the United States#
These rights apply to residents of states with comprehensive privacy laws, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota and Maryland.
You have the right to:
- know what personal information we collect, use, and disclose;
- access and receive a copy of it;
- delete it, subject to legal exceptions;
- correct inaccuracies;
- opt out of sale, of sharing for cross-context behavioural advertising, and of targeted advertising;
- limit use of sensitive personal information;
- non-discrimination — we will not deny service, charge different prices, or provide a lesser service because you exercised a right;
- appeal a refused request, where your state provides for it.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Sensitive personal information. Depending on what a user uploads, a CV may contain information some US laws classify as sensitive. We use it only to provide the Service and never for inferring characteristics about you.
To exercise these rights, contact privacy@reqhunt.com. You may use an authorised agent; we will ask for proof of authorisation. California residents may also request details under the "Shine the Light" law (Cal. Civ. Code § 1798.83).
9. Security#
We protect your data with:
- encryption in transit (TLS) and at rest;
- row-level access controls in our database, so one user's data is not readable by another;
- restricted administrative access;
- private file storage, with time-limited signed links for CV downloads.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by GDPR Article 33, and notify you directly where the risk is high.
10. Children#
The Service is not directed to children and we do not knowingly collect data from anyone under 16. If we learn that we have, we delete it. If you believe a child has provided us data, contact privacy@reqhunt.com.
11. Changes#
We may update this policy. The "Last updated" date reflects the current version. We keep prior versions available on request.
12. Contact#
privacy@reqhunt.com
ReqHunt.com, Italy