← Back to app
Privacy Policy
Last updated: 22 March 2026  ·  CVShortlist  ·  Effective immediately

Plain English summary: We process your CV and job descriptions through Claude AI in real time — we never store them. Your account and billing are handled by Outseta and Stripe. We collect anonymised, cookie-free analytics to understand how the site is used. If you arrived via an affiliate link, we record that for attribution. No advertising. No data selling. No cookie banner needed.

Contents
  1. Who We Are
  2. What Data We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing
  5. Third-Party Processors
  6. Data Retention
  7. International Transfers
  8. Your Rights
  9. Cookies and Local Storage
  10. Analytics
  11. Affiliate Tracking
  12. Children's Privacy
  13. Changes to This Policy
  14. Contact Us

1. Who We Are

CVShortlist ("we", "us", "our") is an AI-powered CV tailoring service operated as a sole trader business based in the United Kingdom. We can be contacted at support@cvshortlist.com.

For the purposes of UK GDPR and the Data Protection Act 2018, we are the data controller for the personal data described in this policy.

2. What Data We Collect

Data you provide directly

DataWhy we collect itStored where
Name and email addressAccount creation and loginOutseta (our auth and billing provider)
Payment informationProcessing your subscriptionStripe via Outseta — we never see card details
CV / resume contentAI tailoring — processed in real timeNot stored — sent to AI and discarded immediately
Job descriptionsAI tailoring — processed in real timeNot stored — sent to AI and discarded immediately
Target country and preferencesTailoring settings for your sessionNot stored beyond the session

Data collected automatically

DataWhyWhere
IP address (hashed)Rate limiting and abuse preventionHashed with a rotating daily salt on our server; original IP never stored; deleted after 1 hour
Anonymised analytics dataUnderstanding how the site is usedOur server (Hostinger) — see Section 10
Affiliate referral sourceAttributing signups to affiliate partnersYour browser localStorage (60 days) and Outseta account record — see Section 11
Credit usage countEnforcing your monthly plan limitYour browser's localStorage only — we cannot access this
Session tokenKeeping you logged inYour browser's sessionStorage — cleared when you close the tab

3. How We Use Your Data

We use your data only for the following purposes:

We do not use your data for advertising, profiling, automated decision-making with legal effects, or any purpose not listed above.

4. Legal Basis for Processing

Processing activityLegal basis (UK GDPR)
Account creation and managementContract — necessary to provide the service you signed up for
Payment processingContract — necessary to fulfil your subscription
Processing your CV through AIContract — the core service you requested
Security and abuse prevention (rate limiting)Legitimate interests — preventing abuse and protecting service availability for all users
Anonymised analyticsLegitimate interests — understanding usage patterns to improve the service; no personal data is stored
Affiliate attribution (UTM fields)Legitimate interests — fairly attributing referrals to affiliate partners; data is limited to campaign name only
Customer support emailsLegitimate interests — responding to your queries and resolving issues

5. Third-Party Processors

We use the following third-party services that may process personal data on our behalf:

ProviderPurposeLocationPrivacy policy
OutsetaAuthentication, account management, and billingUnited Statesoutseta.com/legal/privacy
StripePayment processing (via Outseta)United Statesstripe.com/gb/privacy
Anthropic, Inc.AI processing of CV and job description textUnited Statesanthropic.com/privacy
HostingerWeb hosting and server infrastructureEuropean Unionhostinger.com/privacy-policy
Google FontsServing web fonts (your IP is sent to Google on page load)United Statespolicies.google.com/privacy

We do not sell, rent, or share your personal data with any other third parties for their own purposes.

6. Data Retention

DataRetention period
Account data (name, email)Until you delete your account, then 30 days before permanent deletion
Payment records7 years — required by UK tax and accounting law
CV and job description contentNot retained — discarded immediately after AI processing
Hashed IP (rate limiting)Maximum 1 hour, then automatically deleted
Anonymised analytics dataAggregated monthly data retained for 24 months; no individual records
Affiliate referral data (UTM fields)Retained on your Outseta account record for the duration of your account
Support email correspondence2 years from last contact

7. International Transfers

Some of our third-party processors are based in the United States. Transfers to the US are protected by Standard Contractual Clauses (SCCs) or equivalent mechanisms under UK GDPR. Specifically:

Your CV content is transmitted to Anthropic's US servers for processing and is not retained there after the response is generated.

8. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

To exercise any of these rights, email us at support@cvshortlist.com. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

9. Cookies and Local Storage

We do not use advertising or tracking cookies. We do not display a cookie banner because no consent-requiring cookies are set. We use the following browser storage for functional purposes only:

Storage keyPurposeExpiry
cvb_used_v2_{uid}Counting your monthly credit usageResets each calendar month automatically
cvb_tokenKeeping you logged in during your sessionCleared when you close your browser tab
cvb_cookie_okRemembering that you dismissed the notice bannerPersistent until you clear browser data
cvb_tip_dismissedRemembering that you dismissed the onboarding tipPersistent until you clear browser data
cvs_refStoring affiliate referral source for attribution (see Section 11)60 days, then automatically removed
o-snippet.utmStoring UTM parameters at first visit for signup attributionPersistent until you clear browser data or sign up
cvs_click_logged_{ref}Preventing duplicate affiliate click counts within the same browser sessionCleared when you close your browser tab
cvs_restoreTemporarily saving your CV session before a payment redirect so it can be restoredCleared immediately after restore or on logout

You can clear any of these at any time through your browser's developer tools or by clearing your browser data. Doing so will not affect your account but may reset your usage counter display.

10. Analytics

We operate our own privacy-first analytics system to understand how the site is used. This system is designed to comply with UK GDPR without requiring a cookie banner or user consent.

What we collect

What we do not collect

How we anonymise data

Where a temporary identifier is needed to count unique visitors within a single day, we create a one-way hash using your IP address combined with a secret salt that rotates every 24 hours. This hash cannot be reversed to identify you, and it cannot be linked to you on any subsequent day. All analytics data is stored in aggregated form only — we store counts, not individual records.

Our legal basis for this processing is legitimate interests (Article 6(1)(f) UK GDPR). We have assessed that this interest is not overridden by your privacy rights because: (a) no personal data is retained; (b) no cookies are used; (c) the data cannot identify you; and (d) the processing is limited to understanding aggregate usage patterns to improve the service.

11. Affiliate Tracking

CVShortlist works with affiliate partners who refer visitors to our site using unique links (for example, cvshortlist.com?ref=partner). When you arrive via one of these links, we record the referral for attribution purposes.

What we record

What we do not record

Our legal basis for affiliate attribution is legitimate interests (Article 6(1)(f) UK GDPR) — specifically, the fair operation of our affiliate programme and correctly attributing referrals to partners.

12. Children's Privacy

CVShortlist is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us at support@cvshortlist.com and we will delete it promptly.

13. Changes to This Policy

We may update this policy from time to time to reflect changes in our practices or in applicable law. When we make material changes, we will update the "last updated" date at the top of this page. We encourage you to review this policy periodically.

Continued use of CVShortlist after a policy update constitutes your acknowledgement of the updated terms.

14. Contact Us

If you have any questions about this privacy policy or how we handle your data, please contact us: