1. Introduction & Scope
JidoQ (Pty) Ltd ("we", "us", "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our CV website builder and hosting service ("Service"). It applies to all users, including visitors, free-tier users, and paid subscribers. This Policy is drafted to comply with the Protection of Personal Information Act 4 of 2013 ("POPIA") and should be read alongside our Terms of Service and End User License Agreement.
2. Information We Collect
2.1 Account & Profile Data
When you create an account, we collect: email address, name, password hash (via bcrypt), and optional profile photo. If you sign in via LinkedIn OAuth, we receive: public profile URL, name, headline, email address, profile photo, and any other data you consent to share via LinkedIn's permission screen.
2.2 CV Website Content
You voluntarily provide the content for Your Site: work history, education, skills, projects, publications, contact details, and uploaded media (images, PDFs). This content is published at your direction and may be publicly accessible.
2.3 Usage & Analytics Data
We automatically collect: IP address, browser type, device information, pages visited, timestamps, referral source, and interaction events (clicks, scroll depth). This is collected via first-party analytics (no third-party trackers by default) and our hosting provider Cloudflare.
2.4 Billing & Payment Data
Subscription payments are processed by PayFast. We receive: transaction ID, amount, currency, status, and last 4 digits of payment method. We do not store full card numbers or bank credentials.
2.5 Communications
If you contact support, we retain your email, message content, and any attachments you provide.
3. Legal Bases for Processing (POPIA)
We process personal information on the following grounds:
- Contract performance: Providing the Service, billing, account management
- Legitimate interest: Security, fraud prevention, analytics, service improvement
- Consent: Analytics cookies, marketing communications, LinkedIn data import
- Legal obligation: Tax records, compliance with court orders
4. How We Use Your Information
- Create and manage your account
- Provision, host, and publish Your Site
- Process subscription payments via PayFast
- Send service-related emails (invoices, renewal notices, security alerts)
- With consent: send product updates, tips, and promotional emails
- Analyze usage to improve templates, performance, and UX
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations and respond to lawful requests
5. Sharing & Disclosure
We do not sell personal information. We share data only as follows:
- Service providers: Cloudflare (hosting, CDN, DDoS protection, analytics), PayFast (payments), email delivery (transactional). All processors sign DPAs with appropriate safeguards.
- LinkedIn: Only when you initiate OAuth sign-in/import; we send no data to LinkedIn.
- Legal requirements: Courts, regulators, law enforcement where required by law.
- Business transfers: In a merger, acquisition, or asset sale, your data may transfer subject to this Policy.
6. Cross-Border Transfers
Our Service runs on Cloudflare's global network. Your data may be processed in countries outside South Africa (including the USA, EU, Singapore, and others). Cloudflare is certified under the EU-US Data Privacy Framework and provides Standard Contractual Clauses for transfers. Where no adequacy decision exists, we rely on contractual safeguards and Cloudflare's security certifications (SOC 2 Type II, ISO 27001). You consent to these transfers by using the Service.
7. Data Retention
- Account data: Retained while your account is active, plus 30 days after closure for recovery, then deleted.
- CV content: Retained while published; deleted within 30 days of account closure or manual deletion.
- Billing records: Retained for 5 years per SARS tax requirements.
- Analytics logs: Aggregated after 13 months; raw logs deleted after 24 months.
- Support tickets: Retained for 2 years after resolution.
- LinkedIn import data: Deleted within 30 days of disconnection or account closure.
8. Your Rights (POPIA Section 23–25)
You have the right to:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion where data is no longer necessary, consent is withdrawn, or processing is unlawful (subject to legal retention obligations).
- Restriction: Request restriction of processing in certain circumstances.
- Portability: Receive your data in a structured, commonly used format (JSON/CSV).
- Object: Object to processing based on legitimate interest, including direct marketing.
- Complaint: Lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za.
To exercise any right, email privacy@webprofile.app. We respond within 30 days (extendable by 30 days for complex requests).
9. Cookies & Similar Technologies
9.1 Essential Cookies (Always Active)
session_id— Authentication session, expires on browser closecsrf_token— CSRF protection, expires on browser closecookie_consent— Remembers your cookie preferences, 1 year
9.2 Analytics Cookies (Require Consent)
_ga,_ga_*— Google Analytics (if enabled), 13 monthscf_clearance— Cloudflare bot management, session
You can manage preferences via the cookie banner (bottom-left on first visit) or your browser settings. Disabling essential cookies will break authentication.
10. Security Measures
We implement appropriate technical and organizational measures per POPIA Section 19:
- TLS 1.3 encryption in transit; AES-256 at rest on Cloudflare R2/D1
- Passwords hashed with bcrypt (cost factor 12)
- Rate limiting, WAF rules, and DDoS protection via Cloudflare
- Principle of least privilege for staff access; MFA enforced
- Annual penetration testing and vulnerability scanning
- Incident response plan with 72-hour breach notification to the Information Regulator where required
11. Children's Privacy
The Service is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided data, contact us and we will delete it.
12. Marketing Communications
With your consent, we may send product updates, CV tips, and occasional promotions. You can unsubscribe anytime via the link in each email or in Account Settings. Service-related emails (billing, security, legal) are not marketing and cannot be opted out.
13. Third-Party Links
Your Site may contain links to external websites (LinkedIn, GitHub, personal domains). We are not responsible for the privacy practices of third parties. Review their policies before providing information.
14. Changes to This Policy
We may update this Policy. Material changes will be notified via email and in-app banner 30 days before effectiveness. The "Last updated" date above reflects the latest revision. Continued use constitutes acceptance.
15. Data Protection Officer & Contact
Our designated Information Officer under POPIA can be reached at:
JidoQ (Pty) Ltd
Attention: Information Officer
Email: privacy@webprofile.app
Post: South Africa, South Africa
For general support: support@webprofile.app