Privacy Policy.
01Who we are
Your Next Seat (“the Service”) is a job-discovery tool for managers and above. We aggregate publicly listed roles, score them against your CV, and help you track applications. Your Next Seat, an unincorporated sole proprietorship based in Pakistan, is the data controller for the personal data described here. For privacy questions, contact [email protected].
02Scope
This policy covers the Your Next Seat web application, the public Score My Fit tool, any browser extension, and the communications we send you. It explains what we collect, why, how long we keep it, who we share it with, and your rights. It does not cover third-party sites you may reach by following a link from our application, including the employer career sites you apply to.
03What we collect
- Account data. Email address, password (hashed; never stored in plain text), and the role assigned to your account.
- Profile data. CV or resume content you upload, structured profile fields (work history, education, skills, certifications, language proficiency, cover-letter preferences), search preferences (seniority, function, country, work arrangement), and notification preferences.
- Usage data. Searches you run, jobs you view, the jobs you save or track, the status you set on each tracked job, apply-clicks, and the scores generated for you.
- AI Assistant data. If you have given explicit consent to use the in-app AI Assistant, the questions you put to it and the context drawn from your profile to answer them. If you have not enabled the AI Assistant, no data is sent to our AI provider.
- Score My Fit submissions (without an account). If you use the public Score My Fit tool without creating an account, we receive the job URL and CV text you submit for scoring. This data is not linked to any account.
- Billing data. Your subscription tier, plan status, and a customer reference used by our payment processor. We do not receive or store your full card number or bank details.
- Technical data. IP address (used for rate-limiting and abuse prevention; not retained long-term), browser type and version, device identifiers set after you complete two-factor email verification on a new device (so we do not ask you for a code on every sign-in), and cookies (see our Cookie Policy).
We do not collect: full payment-card or bank data, government-ID numbers, health or biometric data, salary or income data, or your browsing history outside the Service.
04Why we collect it and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Authenticate you and keep you signed in, including two-factor verification on new devices | Contract |
| Score jobs against your CV; track applications | Contract |
| Process your subscription and payments | Contract |
| Send transactional email (verification codes, security alerts, billing notices) | Contract |
| Send the optional Weekly Digest, if you have not unsubscribed | Legitimate interest (one-click unsubscribe in every message) |
| Enforce plan limits | Legitimate interest (preventing abuse) |
| Rate-limit and secure authentication | Legitimate interest (security) |
| Detect and respond to security incidents; prevent fraud and automated scraping | Legal obligation and legitimate interest |
| Comply with tax, accounting, and consumer-law obligations | Legal obligation |
| Power the in-app AI Assistant | Consent (explicit opt-in, withdrawable at any time) |
| Aggregate, non-identifying product analytics | Consent (analytics cookies) |
We do not use your data for advertising targeting, and we do not sell or rent your personal data.
07International transfers
Your information is processed primarily in the United Kingdom and the European Economic Area. Where personal data is transferred outside the UK or the EEA (for example, to a US-based AI provider), we rely on appropriate safeguards, including Standard Contractual Clauses and the UK International Data Transfer Addendum, and/or applicable adequacy decisions.
08How long we keep your data
| Data | Retention |
|---|---|
| Account record (email and auth) | Until you delete your account |
| Profile and CV | Until you delete your account |
| Tracker and application history | While your account is active. You can delete individual entries at any time. |
| Score My Fit submissions (made without an account) | 30 days, after which they are anonymised |
| Login attempts (rate limiting) | 24 hours |
| Billing records and invoices | As required by tax and accounting law (typically 6–10 years) |
| Encrypted backups | 30 days rolling |
| Deletion residue (audit) | 30 days, then permanent purge |
09Your rights
Depending on where you live, you may have rights to: access a copy of your data; correct inaccurate data; delete your account and request erasure; restrict or object to processing; data portability (machine-readable export); and withdraw consent for optional features.
You can exercise the most common of these rights directly inside the Service:
- Export your data as a downloadable archive, at any time, from Account → Data Export.
- Deactivate your account temporarily. Your account is hidden, all email from us stops, and signing back in restores everything with your data intact.
- Delete your account permanently. We require an email one-time-passcode confirmation to prevent accidental deletion. Data is then handled per the retention schedule above.
- Manage trusted devices and active sessions from Account → Sessions.
For any right you cannot exercise inside the Service, email [email protected]; we respond within 30 days (or the period your local law requires).
- EU/EEA and UK. GDPR and UK GDPR apply; you may lodge a complaint with your supervisory authority (e.g. the UK ICO or your national DPA).
- California. CCPA and CPRA rights, including the right to know, delete, correct, and opt out of “sale” and “sharing” (we do neither). We do not discriminate for exercising rights.
- Australia. The Privacy Act 1988 and Australian Privacy Principles apply.
- New Zealand. The Privacy Act 2020 applies.
- UAE and Saudi Arabia. The UAE PDPL and KSA PDPL may apply to residents.
10Children
The Service is for adults (18+). We do not knowingly collect data from children. If you believe a child has provided data, contact [email protected].
11Security
We protect your information with industry-standard measures, including TLS encryption in transit, bcrypt password hashing, httpOnly and Secure cookies for session tokens, two-factor email verification on new devices, per-IP and per-account rate limiting, security headers (HSTS, Content Security Policy, X-Frame-Options, Referrer-Policy), encrypted backups, and server-side audit logging. No service can guarantee absolute security. Where a personal-data breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and notify affected users without undue delay.
12Changes
We may update this policy. Material changes (broadening what we collect or who we share with) trigger email notice and a 30-daynotice period before they take effect. Minor updates will be reflected by changing the “Last updated” date at the top.
13Contact
For privacy questions, data-rights requests, or to report a security concern: [email protected].
This page sits alongside our Privacy, Terms, Cookies, Refund, and Cancellation policies. Questions: [email protected].