Trust
Privacy and data handling
UNlockit keeps the product useful without treating personal career data casually. This page explains what we collect, why, how long we keep it, and how to control it.
Who we are
UNlockit ("we", "us") operates this job-aggregation and career-matching website. For questions about this policy or to exercise any data right described below, contact [email protected]. This policy applies to the UNlockit website and does not cover the official agency career portals we link out to, which are governed by their own policies.
What we collect
Account details you provide (email address, password hash, display name, language preference); content you create in the product (saved roles, watchlists, source submissions, preferences); CV files you upload and the structured fields extracted from them; and technical data generated by using the site (session cookie, log data, and aggregate analytics events). We do not collect special-category data deliberately — please don't include it in free-text fields beyond what a CV normally contains.
Why we use it and our legal basis
We process account and content data to provide the service you signed up for (contractual necessity); CV data to run AI matching and reviews at your request (your consent, withdrawable by deleting the file/profile); transactional email and security logging to operate and protect the service (legitimate interests and legal obligation); and analytics/advertising to sustain and improve a free product (consent where required, otherwise legitimate interests). You can withdraw consent at any time as described under "Your rights and control".
Account data
We store the email address and profile details needed to provide the service, including saved roles, watchlists, and preferences. You can change your email or delete your account at any time from the Account page; deletion enters a grace window before data is hard-deleted.
CV handling
Uploaded CV files are used for profile extraction and matching. The original PDF is removed after the configured retention window (seven days by default); structured fields extracted by AI (skills, experience, languages, etc.) are kept so matching keeps working. You can delete the file or the entire account from the Account page.
Data retention
Account and profile data is kept for as long as your account is active. When you delete your account it enters a grace window and is then hard-deleted. Uploaded CV files auto-delete after the retention window (seven days by default). Billing records and transactional logs required for accounting, fraud-prevention, or legal compliance may be retained by us or by Stripe for the period those obligations require, after which they are deleted or anonymised.
Cookies and analytics
We use a session cookie (signed, not personal data) to keep you logged in, and a language cookie to remember your locale. We use Google Analytics 4 to understand site usage in aggregate — visit counts, page popularity, traffic sources — so we can prioritise improvements. Analytics data is anonymised and IP-truncated. You can opt out by disabling cookies in your browser or by installing the official Google Analytics opt-out add-on (https://tools.google.com/dlpage/gaoptout).
Advertising
We may serve ads through Google AdSense. AdSense and partner networks use cookies to deliver and personalise ads, and to measure their performance. Third-party vendors, including Google, may use cookies to serve ads based on a user’s prior visits to this and other websites. You can opt out of personalised advertising through Google’s Ads Settings (https://adssettings.google.com/) and via the EDAA opt-out (https://www.youronlinechoices.com/) or DAA opt-out (https://optout.aboutads.info/). Disabling ad cookies still allows ads to be shown, but they will not be personalised.
Transactional emails (verification, password reset, billing receipts, subscription notices) are sent through our SMTP provider. If you opt in, we may send a periodic AI-curated job digest — each digest carries a one-click unsubscribe link as required by RFC 8058.
Payments
Subscription billing is processed by Stripe; we never see or store your card data. Stripe holds payment-related personal data under its own privacy policy (https://stripe.com/privacy).
Third-party services
We rely on infrastructure providers (database hosting, mail delivery, edge / DNS) and a Large Language Model provider for the AI matching and content features. These vendors process data only to perform the service and are bound by their own data-processing terms.
International transfers
Our service providers (hosting, email, Stripe, analytics, and the LLM provider) may process data in countries outside your own, including the United States. Where required, transfers rely on the providers' own safeguards such as Standard Contractual Clauses. By using the service you understand your data may be processed in these locations.
Children
UNlockit is a professional careers tool intended for adults in the workforce. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
Your rights and control
Depending on your jurisdiction you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. You can exercise most of these directly: (1) view and edit your profile and CV-extracted fields on the Profile page; (2) change email or password, sign out other devices, and delete your account from the Account page; (3) unsubscribe from email digests with one click; (4) email [email protected] for any access, correction, portability, or deletion request not covered by the self-service tools. We aim to respond within 30 days and will not discriminate against you for exercising these rights.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by the "Last updated" date above and, where appropriate, announced in-product or by email. Continued use after an update means you accept the revised policy.