Resumes Coach

Privacy Policy

Last updated: May 2026

1. Controller

The controller responsible for data processing on this website is:

Keya Kashem
[YOUR ADDRESS]
Email: contact@resumes.coach

2. Data We Collect and Why

We process your personal data only where we have a legal basis under Art. 6 GDPR.

Account registration and authentication

  • Data: name, email address, password (hashed) or Google account details
  • Purpose: to create and manage your user account
  • Legal basis: performance of a contract (Art. 6(1)(b) GDPR)

Resume and CV content

  • Data: CV text, job descriptions, and other content you submit for optimization
  • Purpose: to provide AI-powered CV analysis and optimization
  • Legal basis: performance of a contract (Art. 6(1)(b) GDPR)

Profile photo

  • Data: profile image you upload
  • Purpose: to include your photo in generated resume documents
  • Legal basis: performance of a contract (Art. 6(1)(b) GDPR)

Payment data

  • Data: transaction amount, payment status, credit balance (card details are processed exclusively by Stripe and never stored by us)
  • Purpose: to process purchases of credits and manage your balance
  • Legal basis: performance of a contract (Art. 6(1)(b) GDPR)

Technical log data

  • Data: IP address, browser type, pages visited, timestamps, error data
  • Purpose: to ensure the security and stability of the platform; error tracking via Sentry
  • Legal basis: legitimate interests (Art. 6(1)(f) GDPR)

3. Data Retention

We retain your data for as long as your account is active or as needed to provide the service. Upon account deletion:

  • Account data is deleted within 30 days
  • Payment records are retained for 10 years to comply with German commercial and tax law (§ 257 HGB, § 147 AO)

4. Third-Party Processors

We share data with the following processors under data processing agreements:

Processor Purpose Location Safeguard
Anthropic AI processing of CV content USA Standard Contractual Clauses (SCC)
Stripe Payment processing USA SCC + Stripe DPA
Cloudflare R2 File storage (profile photos) EU (Netherlands) EU hosting
Google OAuth login, email delivery USA SCC + Google DPA
Mailtrap Transactional email delivery USA SCC + Mailtrap DPA
Railway Application hosting EU (Netherlands) EU hosting
Sentry Error tracking and monitoring USA SCC + Sentry DPA

Transfers to the USA and other third countries are based on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR).

5. Your Rights

Under GDPR, you have the following rights:

  • Right of access (Art. 15): request a copy of your personal data
  • Right to rectification (Art. 16): correct inaccurate data
  • Right to erasure (Art. 17): request deletion of your data ("right to be forgotten")
  • Right to restriction (Art. 18): restrict processing of your data
  • Right to data portability (Art. 20): receive your data in a machine-readable format
  • Right to object (Art. 21): object to processing based on legitimate interests

To exercise any of these rights, contact us at: contact@resumes.coach

6. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. The competent authority for North Rhine-Westphalia is:

Landesbeauftragte für Datenschutz und Informationsfreiheit NRW (LDI NRW)
Postfach 20 04 44, 40102 Düsseldorf
www.ldi.nrw.de

7. Cookies

We currently use only technically necessary session cookies required for authentication and security. No tracking or advertising cookies are used.

8. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be available at resumes.coach/privacy. We will notify you of significant changes by email.