Skip to content

Privacy Policy

What we collect, why, who sees it, and what you can ask us to do.

1. What we collect

To run your job search we collect:

  • Identifiers — name, preferred name, email, phone, city, time zone.
  • Career information — resumé, employment history, education, skills, licences, portfolio links.
  • Job-search preferences — target roles, seniority, industries, locations, salary floor, exclusions.
  • Application data — what we submitted, the answers and documents used, and submission evidence.
  • Correspondence — recruiter and employer messages in your dedicated job-search account.
  • Account credentials — passwords for the dedicated job-search account and job-site accounts created for your search, stored encrypted.
  • Sensitive data — work-authorization status, and optionally demographic or disability self-identification.
  • Billing — payment status and history. Card details are held by our payment processor, not by us.
  • Technical — sign-in records, IP address, device and browser information, audit events.

2. What we never collect

We do not collect Social Security numbers, driver's licence or passport images, bank account numbers, medical records, or background-check reports. Where an employer needs those, we direct you to provide them to the employer yourself.

3. Sensitive data and your control over it

Some of what we handle is sensitive — in particular your work-authorization or citizenship status, and any demographic or disability information you record.

We ask for your separate opt-in consent before processing any sensitive category and record that consent with a timestamp and version. You may withdraw it at any time.

Demographic and disability self-identification is optional, defaults to decline-to-answer, is stored separately with tighter access controls, is never used to decide which roles to show you or how to present your application, and is never inferred from anything else you give us.

4. Why we use it

We do not sell your personal data. We do not share it for advertising. We do not use it to train machine-learning models without your separate opt-in consent, which you may withdraw.

  • To provide the service: matching roles, preparing applications, submitting them, tracking responses.
  • To communicate with you about your search and your account.
  • To keep the records our quality standards and the law require, including an audit trail of what was submitted, by whom, and when.
  • To take payment and manage your subscription.
  • To secure the service and investigate misuse.

5. Who we share it with

Our staff see only the clients assigned to them. Access to stored credentials and sensitive answers is restricted further, and every access is logged.

  • Employers and job platforms, when we submit an application you authorized.
  • Service providers processing data on our instructions under written contract: hosting and database, file storage, email delivery, payment processing, error monitoring.
  • Professional advisers, and authorities where the law requires it or to protect someone's safety.
  • A successor in a merger or sale of assets, on notice to you.

6. How long we keep it

  • Active account data — for the life of your account.
  • Application and submission records — 3 years after the application, for dispute and audit purposes.
  • Raw email and attachments — 12 months, then deleted; parsed metadata stays with the application.
  • Stored credentials — deleted when service ends or on your request, whichever comes first.
  • Demographic and disability self-identification — deleted on request; not retained after your account closes.
  • Audit events — 3 years. These are append-only and cannot be altered.
  • Billing records — as long as tax and accounting law requires.

7. Your rights

Wherever you live, we offer all of these:

  • Know what we hold about you and why.
  • Get a copy in a portable, machine-readable format.
  • Correct anything inaccurate.
  • Delete your data, subject to records we must keep.
  • Withdraw consent to any sensitive-data processing.
  • Opt out of any sale, sharing, targeted advertising, or profiling — none of which we do.
  • Appeal if we refuse, then complain to your state attorney general.

8. Making a request

Ask through your account or at privacy@jaloapply.com. We respond within 45 days, extendable once by another 45 days if we tell you why. Up to two requests in any twelve months are free. We honour recognised universal opt-out signals including Global Privacy Control.

9. Security

We encrypt data in transit and at rest. Access is role-based and least-privilege, enforced by the database itself rather than only the application. Stored credentials are encrypted with AES-256-GCM and every decryption writes an entry to an append-only audit log. Documents live in private storage reachable only through short-lived signed links. Multi-factor authentication is required for staff and administrators. We maintain a written incident-response plan and test restores from backup.

No system is perfectly secure. If a breach affects your data we will notify you as required by law — within 30 days of discovery, sooner where a state requires it.

10. Children

The service is not for anyone under 18. We do not knowingly collect data from children and will delete it if we learn we have.

11. Changes and contact

We post changes here with a new date and notify you by email before any material change takes effect. Where a change affects data already collected we ask for fresh consent rather than applying it retroactively.

privacy@jaloapply.com · Gretchen & Hunter LLC, 8305 Greensboro Drive, 1504, McLean, VA 22102.

Privacy Policy — JaloApply