Privacy Policy.
01Who we are
Your Next Seat (“the Service”) is a job-discovery tool for managers and above. We aggregate publicly listed roles, score them against your CV, and help you track applications. [Legal entity to be confirmed before billing launches 01 July 2026] is the data controller for the personal data described here. For privacy questions, contact [email protected].
02Scope
This policy covers the Your Next Seat web application, any browser extension, and the communications we send you. It explains what we collect, why, how long we keep it, who we share it with, and your rights.
03What we collect
- Account data. Email address, password (hashed; never stored in plain text), display name, the role you are assigned (user, manager, or admin).
- Profile data. CV or resume content you upload, structured profile fields (work history, education, skills, languages, cover-letter preferences), notification preferences.
- Usage data. Searches you run, jobs you track, the status you set on each tracked job, Apply clicks. Used to enforce plan limits and show your application history.
- Billing data. Your subscription tier, plan status, and a Paddle order/customer reference. We do not receive or store your full card number or bank details — these are handled by Paddle (see Section 6).
- Technical data. IP address at the time of a request (rate-limiting and abuse prevention; not retained long-term), browser user-agent, session and refresh cookies (httpOnly, scoped to our domain).
We do not collect: full payment-card or bank data, government-ID numbers, health or biometric data, or your browsing history outside the Service.
04Why we collect it and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Authenticate you and keep you signed in | Contract |
| Score jobs against your CV; track applications | Contract |
| Process your subscription and payments | Contract (with Paddle as Merchant of Record) |
| Send transactional email (registration, approval, password reset, billing) | Contract |
| Enforce plan limits | Legitimate interest (preventing abuse) |
| Rate-limit and secure authentication | Legitimate interest (security) |
| Detect and respond to security incidents | Legal obligation and legitimate interest |
| Comply with tax, accounting, and consumer-law obligations | Legal obligation |
| Aggregate, non-identifying product analytics | Consent (analytics cookies) |
We do not use your data for advertising targeting, and we do not sell your personal data.
07International transfers
Where personal data is transferred outside the UK or the EEA (for example, to a US-based AI provider or US-based Paddle affiliates), we rely on appropriate safeguards such as Standard Contractual Clauses and the UK International Data Transfer Addendum, and/or applicable adequacy decisions.
08How long we keep your data
| Data | Retention |
|---|---|
| Account record (email and auth) | Until you delete your account |
| Profile and CV | Until you delete your account |
| Tracker and search history | 90 days, rolling |
| Login attempts (rate limiting) | 24 hours |
| Billing records and invoices | As required by tax and accounting law (typically 6–10 years) |
| Encrypted backups | 30 days rolling |
| Deletion residue (audit) | 30 days, then permanent purge |
09Your rights
Depending on where you live, you may have rights to: access a copy of your data; correct inaccurate data; delete your account and request erasure; restrict or object to processing; data portability (machine-readable export); and withdraw consent for optional features. To exercise any right, email [email protected]; we respond within 30 days (or the period your local law requires).
- EU/EEA and UK. GDPR and UK GDPR apply; you may lodge a complaint with your supervisory authority (e.g. the UK ICO or your national DPA).
- California. CCPA and CPRA rights, including the right to know, delete, correct, and opt out of “sale” and “sharing” (we do neither). We do not discriminate for exercising rights.
- Australia. The Privacy Act 1988 and Australian Privacy Principles apply.
- New Zealand. The Privacy Act 2020 applies.
- UAE and Saudi Arabia. The UAE PDPL and KSA PDPL may apply to residents.
10Children
The Service is for adults (18+). We do not knowingly collect data from children. If you believe a child has provided data, contact [email protected].
11Security
We use TLS in transit, bcrypt password hashing, httpOnly session cookies, authentication rate limiting, encrypted backups, and admin audit logging. No system is perfectly secure. If we discover a breach affecting your personal data, we will notify the relevant authority and, where required, you, in line with applicable law (e.g. GDPR Art. 33/34 — without undue delay and, to the supervisory authority, within 72 hours of becoming aware where feasible).
12Changes
We may update this policy. Material changes (broadening what we collect or who we share with) trigger email notice and a 30-daynotice period. Minor changes update the “Last updated” date at the top.
13Contact
[email protected]— privacy questions, data requests, breach reports.
This page sits alongside our Privacy, Terms, Cookies, Refund, and Cancellation policies. Questions: [email protected].