This Privacy Policy describes how JobLoom ("we," "us," or "our") collects, uses, and shares information when you use JobLoom websites, applications, and related services (the "Service").
1. Information we collect
Account and authentication
We use third-party authentication providers to manage sign-in (currently Clerk). They may process your email address, identifiers, and session data under their own policies. We receive the information we need to create and secure your account.
Profile and resume data
If you upload a resume or enter profile information, we store and process that content to provide search, optional matching, and application-assistance features. This may include extracted text, structured fields, and derived data (such as features used to compare your materials with job descriptions). We do not use this to guarantee employment or financial outcomes.
Usage and device data
We may collect technical information such as IP address, browser type, approximate location derived from IP, timestamps, and diagnostic logs to secure the Service, enforce plan limits, and troubleshoot issues.
Communications
If you contact support or enable emails such as job alerts, we process your messages, preferences, and delivery metadata.
Payments
We do not store your full card number or other complete payment method details on our systems. Payments for subscriptions are processed by PayPal and Dodo Payments, either of which may act as the Merchant of Record. The provider handles payment data, charge authorization, and related records in line with its own terms and privacy policy. We receive limited billing metadata (such as subscription status, product or plan identifier, and transaction or customer references) needed to provide access to paid features. How the provider uses payment data is described in the provider's privacy policy and checkout materials. For subscription management, tax lines, and some refund or billing questions, the provider may be your first point of contact under its policies.
2. How we use information
- Provide, maintain, and improve the Service.
- Authenticate users and enforce free and paid plan limits.
- Provide resume- and job-related insights and optional AI-assisted text when you use those features.
- Send transactional messages, job alerts you configure, and service announcements.
- Detect abuse, fraud, and security incidents.
- Comply with legal obligations.
3. Smart Apply browser extension
The optional Smart Apply extension may request permission to access pages you visit so it can detect application forms and help fill fields using your JobLoom profile. You choose when to use it and what to submit. Data needed for autofill may be read from the page context and sent to our servers to generate suggestions; we design flows to limit what is transmitted. Review the extension permissions in your browser and our Terms of Service for acceptable use.
4. Cookies, storage, and measurement
Essential cookies and sessions
We use first-party cookies and similar technologies that are needed for authentication (including Clerk sessions), security, CSRF protection where applicable, and basic site functionality.
Attribution cookie (jl_attr)
When you land on JobLoom with campaign parameters (for example UTM tags or fbclid), we may store a first-party cookie to remember that attribution for a limited time (currently up to about 180 days). We use it to understand how marketing campaigns perform and to attach coarse attribution metadata to product analytics on our systems. It is not used to sell your data to third parties.
Local storage
We may store small values in browser localStorage, for example to remember marketing attribution between visits and to record an optional analytics preference (see Analytics & advertising choices).
Meta (Facebook) Pixel and Conversions API
When enabled for our deployment, we use Meta's Pixel (browser) and the Meta Conversions API (server-to-Meta) to measure activity such as page views, searches, and certain product events (for example when you view a job or start checkout). These tools help us understand usage and improve our marketing. Meta processes data under its own terms and policies. We configure server events to send hashed identifiers where appropriate (for example email) rather than raw personal details in URLs.
You can learn more about Meta's practices in Meta's Data Policy. If you want to limit Meta measurement in your browser, you can use controls Meta provides (for example ad preferences) and you may also enable Do Not Track in your browser—our site treats common DNT signals as a request not to load optional marketing measurement scripts where that logic is implemented.
You can also opt out of our optional marketing measurement storage by using the Analytics preferences link in the site footer, which sets a JobLoom preference in localStorage and may require a page refresh to apply fully.
Future changes
If we add new advertising or analytics partners beyond what is described here, we will update this policy and provide choices where required by law.
5. Sharing of information
We may share information with:
- Service providers who host infrastructure, send email, process payments, or support sign-in, subject to contractual obligations.
- Legal and safety recipients when required by law or to protect rights, safety, and integrity of users and the Service.
- Business transfers in connection with a merger, acquisition, or sale of assets, with notice where required.
We do not sell your personal information for money in the way that term is commonly understood in U.S. state laws.
6. Retention; deletion
We retain information for as long as your account is active and as needed to provide the Service, comply with law, resolve disputes, and enforce our agreements. You may request deletion of your account or your personal data by following the options in your account (including profile or sign-in account settings) or by contacting us at the address below, subject to legal exceptions. Some residual data may remain in encrypted backups for a limited period, or where we have a valid legal or security reason to retain it.
7. Security
We implement technical and organizational measures designed to protect information. No method of transmission or storage is completely secure.
8. International users
If you access the Service from outside the country where we or our providers process data, your information may be processed in other countries with different privacy laws. Where required, we provide appropriate safeguards or choices.
Residents of the European Economic Area, United Kingdom, and certain other regions may have additional rights (such as access, correction, deletion, restriction, portability, and objection). Contact us to exercise those rights where applicable.
9. Children
The Service is not directed to children under 16 (or the age required in your jurisdiction). We do not knowingly collect their personal information.
10. Changes to this policy
We may update this Privacy Policy. We will post the revised version and update the "Last updated" date.
11. Contact
Privacy and data rights requests: hello@jobloom.tech