Privacy Policy

How we collect, use, and protect your information

Privacy Policy

Last Updated: November 11, 2025

1. Introduction

Laravel ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

2. Information We Collect

2.1 Account Information

  • Personal Information: Name, email address, company name
  • Authentication Data: Password (encrypted), login sessions
  • Billing Information: Payment details processed through Stripe (we do not store full credit card numbers)

2.2 Resume Data

  • Uploaded Documents: PDF resumes you upload for processing
  • Extracted Information: Names, emails, phone numbers, addresses, skills, education, and work experience extracted from resumes
  • Batch Information: Job positions, batch names, and organizational data

2.3 Usage Information

  • Service Usage: Credits consumed, batches processed, features used
  • Technical Data: IP addresses, browser type, device information, timestamps
  • Logs: System logs for debugging and security purposes

2.4 Cookies and Tracking

  • Essential Cookies: Required for authentication and service functionality
  • Analytics: We may use analytics to improve our Service
  • Preferences: Storing your settings and preferences

3. How We Use Your Information

3.1 Service Delivery

  • Process resumes using AI to extract candidate information
  • Manage your account and subscriptions
  • Process payments and manage credits
  • Provide customer support

3.2 Service Improvement

  • Analyze usage patterns to improve features
  • Develop new features and functionality
  • Train and improve our AI models (using anonymized data only)

3.3 Communication

  • Send transactional emails (receipts, notifications, password resets)
  • Provide important service updates
  • Respond to your inquiries
  • Send marketing communications (with your consent - you can opt out anytime)

3.4 Security and Legal

  • Detect and prevent fraud and abuse
  • Enforce our Terms of Service
  • Comply with legal obligations
  • Protect our rights and property

4. Legal Basis for Processing (GDPR)

We process personal data based on:

  • Contract Performance: To provide the Service you signed up for
  • Legitimate Interest: To improve our Service and prevent fraud
  • Legal Obligation: To comply with laws and regulations
  • Consent: For marketing communications (you can withdraw anytime)

5. Data Sharing and Disclosure

5.1 We DO NOT Sell Your Data

We never sell your personal information or resume data to third parties.

5.2 Service Providers

We share data with trusted service providers who help us operate:

  • Stripe: Payment processing
  • OpenAI/Anthropic: AI processing (with data protection agreements)
  • AWS/Cloud Providers: Hosting and storage
  • Email Service: Transactional email delivery

5.3 Legal Requirements

We may disclose data when required by law, court order, or to:

  • Comply with legal processes
  • Protect rights, property, or safety
  • Prevent fraud or security issues

5.4 Business Transfers

In case of merger, acquisition, or asset sale, your information may be transferred (you will be notified).

6. Data Security

6.1 Security Measures

  • Encryption: Data encrypted in transit (HTTPS/TLS) and at rest
  • Access Control: Role-based access, secure authentication
  • Infrastructure: Secure cloud hosting with regular backups
  • Monitoring: Security monitoring and incident response
  • Multi-tenancy: Your data is isolated from other tenants

6.2 Your Responsibility

  • Keep your password secure and confidential
  • Use strong, unique passwords
  • Notify us immediately of any suspected unauthorized access

6.3 No Absolute Security

While we implement strong security measures, no system is 100% secure. Use the Service at your own risk.

7. Data Retention

7.1 Account Data

  • Retained while your account is active
  • Retained for a reasonable period after account closure for legal and backup purposes

7.2 Resume Data

  • Stored according to your account settings
  • You can delete resumes and batches at any time
  • Deleted data is removed from active systems within 30 days
  • Backups may retain data for up to 90 days

7.3 Logs and Metadata

  • System logs retained for up to 12 months for security and debugging
  • Anonymized analytics may be retained longer

8. Your Rights

8.1 Access and Portability

  • Access: Request a copy of your personal data
  • Export: Download your data in standard formats (CSV, JSON)

8.2 Correction and Deletion

  • Correct: Update inaccurate information in your account settings
  • Delete: Request deletion of your account and data (subject to legal retention requirements)

8.3 Control

  • Object: Object to certain processing of your data
  • Restrict: Request restriction of processing
  • Withdraw Consent: Unsubscribe from marketing emails anytime

8.4 Complaints

  • You have the right to lodge a complaint with your local data protection authority

8.5 Exercising Rights

Contact us at [email protected] to exercise your rights.

9. International Data Transfers

  • Our servers may be located in various countries
  • We ensure adequate protection through standard contractual clauses
  • By using the Service, you consent to international data transfers

10. Children's Privacy

  • Our Service is not intended for users under 18
  • We do not knowingly collect data from children
  • If you believe we have collected data from a child, contact us immediately

11. Third-Party Links

  • Our Service may contain links to third-party websites
  • We are not responsible for the privacy practices of other sites
  • Review their privacy policies before providing information

12. Data Controller and Processor

12.1 Our Role

  • Your Account Data: We are the data controller
  • Resume Data: You are the data controller; we are the data processor

12.2 Your Responsibilities

As the data controller for resume data, you must:

  • Have legal basis to collect and process candidate data
  • Obtain necessary consents from candidates
  • Comply with applicable data protection laws (GDPR, PDPA, etc.)
  • Inform candidates about data processing and their rights

13. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights:

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed
  • Right to opt out of sale (we do not sell data)
  • Right to deletion
  • Right to non-discrimination

14. Changes to This Privacy Policy

  • We may update this Privacy Policy from time to time
  • Changes are effective immediately upon posting
  • Material changes will be communicated via email
  • Continued use of the Service constitutes acceptance

15. Contact Us

For privacy-related questions or requests:

Email: [email protected]
Website: https://resume.longmobile.my
Address: [Your Company Address]

For data protection officer inquiries:
Email: [email protected]

16. Consent

By using Laravel, you consent to this Privacy Policy and our Terms of Service.