Privacy

Privacy Policy.

Last updated: 2026-07-03

01Who we are

Your Next Seat (“the Service”) is a job-discovery tool for managers and above. We aggregate publicly listed roles, score them against your CV, and help you track applications. Your Next Seat, an unincorporated sole proprietorship based in Pakistan, is the data controller for the personal data described here. For privacy questions, contact [email protected].

02Scope

This policy covers the Your Next Seat web application, the public Score My Fit tool, any browser extension, and the communications we send you. It explains what we collect, why, how long we keep it, who we share it with, and your rights. It does not cover third-party sites you may reach by following a link from our application, including the employer career sites you apply to.

03What we collect

  • Account data. Email address, password (hashed; never stored in plain text), and the role assigned to your account.
  • Profile data. CV or resume content you upload, structured profile fields (work history, education, skills, certifications, language proficiency, cover-letter preferences), search preferences (seniority, function, country, work arrangement), and notification preferences.
  • Usage data. Searches you run, jobs you view, the jobs you save or track, the status you set on each tracked job, apply-clicks, and the scores generated for you.
  • AI Assistant data. If you have given explicit consent to use the in-app AI Assistant, the questions you put to it and the context drawn from your profile to answer them. If you have not enabled the AI Assistant, no data is sent to our AI provider.
  • Score My Fit submissions (without an account). If you use the public Score My Fit tool without creating an account, we receive the job URL and CV text you submit for scoring. This data is not linked to any account.
  • Billing data. Your subscription tier, plan status, and a customer reference used by our payment processor. We do not receive or store your full card number or bank details.
  • Technical data. IP address (used for rate-limiting and abuse prevention; not retained long-term), browser type and version, device identifiers set after you complete two-factor email verification on a new device (so we do not ask you for a code on every sign-in), and cookies (see our Cookie Policy).

We do not collect: full payment-card or bank data, government-ID numbers, health or biometric data, salary or income data, or your browsing history outside the Service.

04Why we collect it and our lawful basis

PurposeLawful basis
Authenticate you and keep you signed in, including two-factor verification on new devicesContract
Score jobs against your CV; track applicationsContract
Process your subscription and paymentsContract
Send transactional email (verification codes, security alerts, billing notices)Contract
Send the optional Weekly Digest, if you have not unsubscribedLegitimate interest (one-click unsubscribe in every message)
Enforce plan limitsLegitimate interest (preventing abuse)
Rate-limit and secure authenticationLegitimate interest (security)
Detect and respond to security incidents; prevent fraud and automated scrapingLegal obligation and legitimate interest
Comply with tax, accounting, and consumer-law obligationsLegal obligation
Power the in-app AI AssistantConsent (explicit opt-in, withdrawable at any time)
Aggregate, non-identifying product analyticsConsent (analytics cookies)

We do not use your data for advertising targeting, and we do not sell or rent your personal data.

05Cookies

Full inventory in our Cookie Policy. Summary:

CookiePurposeDurationType
yns_cookie_consentRemembers your cookie choice90 daysEssential
hp_refreshRefresh token to keep you signed in30 daysEssential
yns_trusted_deviceSet after two-factor email verification so we do not ask you for a code on every sign-in from a trusted device90 daysEssential
Session cookieIn-flight request authenticationSessionEssential
Product-analytics cookiesMeasure how the Service is used. Loaded only if you accept analytics in the cookie banner.Up to 12 monthsConsent-required

06Who we share data with (processors and recipients)

Your data stays inside the Service except for these service providers (processors and sub-processors), who act on our instructions:

  • Payment processor (Merchant of Record). Handles checkout, billing, taxes, and refunds. Receives the data needed to bill you (email, billing country, payment instrument); we do not receive your full card details.
  • Email delivery provider. Sends transactional email (verification codes, security alerts, billing notices) and the optional Weekly Digest. Receives your email address, display name, and the email body. Does not receive your CV or tracked jobs.
  • Hosting and database provider. Runs the application and stores your account data within the European Economic Area.
  • File-storage provider. Stores your uploaded CV files in encrypted form.
  • Product analytics provider. Measures how the Service is used in aggregate. Loaded only if you accept analytics in the cookie banner. Does not receive your CV or tracked jobs.
  • AI provider. Used only after you have given explicit consent via the AI Assistant opt-in. Processes CV text and job descriptions to generate answers. Under their commercial terms, your data is not used to train their models. If you have not enabled the AI Assistant, no data is sent.
  • Job-listing aggregation provider. Fetches publicly listed job postings. Receives only the search parameters needed to fetch listings; does not receive your CV or profile.
  • Encrypted off-site backup provider. Used for disaster recovery (operator access only).
  • Legal compliance. We may disclose data where compelled by valid legal process; we will notify you unless legally prohibited.

We do not transfer your data to third parties for their own marketing or advertising purposes.

07International transfers

Your information is processed primarily in the United Kingdom and the European Economic Area. Where personal data is transferred outside the UK or the EEA (for example, to a US-based AI provider), we rely on appropriate safeguards, including Standard Contractual Clauses and the UK International Data Transfer Addendum, and/or applicable adequacy decisions.

08How long we keep your data

DataRetention
Account record (email and auth)Until you delete your account
Profile and CVUntil you delete your account
Tracker and application historyWhile your account is active. You can delete individual entries at any time.
Score My Fit submissions (made without an account)30 days, after which they are anonymised
Login attempts (rate limiting)24 hours
Billing records and invoicesAs required by tax and accounting law (typically 6–10 years)
Encrypted backups30 days rolling
Deletion residue (audit)30 days, then permanent purge

09Your rights

Depending on where you live, you may have rights to: access a copy of your data; correct inaccurate data; delete your account and request erasure; restrict or object to processing; data portability (machine-readable export); and withdraw consent for optional features.

You can exercise the most common of these rights directly inside the Service:

  • Export your data as a downloadable archive, at any time, from Account → Data Export.
  • Deactivate your account temporarily. Your account is hidden, all email from us stops, and signing back in restores everything with your data intact.
  • Delete your account permanently. We require an email one-time-passcode confirmation to prevent accidental deletion. Data is then handled per the retention schedule above.
  • Manage trusted devices and active sessions from Account → Sessions.

For any right you cannot exercise inside the Service, email [email protected]; we respond within 30 days (or the period your local law requires).

  • EU/EEA and UK. GDPR and UK GDPR apply; you may lodge a complaint with your supervisory authority (e.g. the UK ICO or your national DPA).
  • California. CCPA and CPRA rights, including the right to know, delete, correct, and opt out of “sale” and “sharing” (we do neither). We do not discriminate for exercising rights.
  • Australia. The Privacy Act 1988 and Australian Privacy Principles apply.
  • New Zealand. The Privacy Act 2020 applies.
  • UAE and Saudi Arabia. The UAE PDPL and KSA PDPL may apply to residents.

10Children

The Service is for adults (18+). We do not knowingly collect data from children. If you believe a child has provided data, contact [email protected].

11Security

We protect your information with industry-standard measures, including TLS encryption in transit, bcrypt password hashing, httpOnly and Secure cookies for session tokens, two-factor email verification on new devices, per-IP and per-account rate limiting, security headers (HSTS, Content Security Policy, X-Frame-Options, Referrer-Policy), encrypted backups, and server-side audit logging. No service can guarantee absolute security. Where a personal-data breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and notify affected users without undue delay.

12Changes

We may update this policy. Material changes (broadening what we collect or who we share with) trigger email notice and a 30-daynotice period before they take effect. Minor updates will be reflected by changing the “Last updated” date at the top.

13Contact

For privacy questions, data-rights requests, or to report a security concern: [email protected].

This page sits alongside our Privacy, Terms, Cookies, Refund, and Cancellation policies. Questions: [email protected].