Last updated: May 17, 2026

RovoCareer Privacy Policy

This Privacy Policy describes what personal data the RovoCareer site collects, for what purpose and on what legal basis it processes it, how long it retains it, and what rights users have regarding the processing of their data. This document has been prepared in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable data protection laws.

Key Information

  • Controller. The operator of the site and the data controller is the site owner (contact details in section 16).
  • Purpose. We process data solely for the purpose of providing site services — creating an account, generating resumes, handling payments, and ensuring security.
  • Legal Basis. Data processing is based on contract performance, legal obligation, the controller's legitimate interest, or user consent — depending on the purpose.
  • Third Parties. We use the services of Supabase (database), Stripe (payments), and Google (login). Each of these entities processes data based on its own privacy policies.
  • Rights. You have the right to access, rectify, erase, restrict processing, transfer data, and lodge a complaint with the relevant data protection authority.
  • Cookies. Details regarding cookies can be found in the Cookie Policy.
  • Contact. contact@rovocareer.com

1. Definitions

  • GDPRRegulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data.
  • Controllerthe entity determining the purposes and means of processing personal data, i.e. the operator of the RovoCareer service.
  • Userany natural person using the RovoCareer service whose personal data is processed.
  • Personal Dataany information relating to an identified or identifiable natural person.
  • Processingany operation performed on personal data, such as collecting, storing, viewing, modifying, sharing, or deleting.
  • Processora third-party entity processing data on behalf of and for the Controller under a data processing agreement (e.g. Supabase).
  • Consenta freely given, specific, informed, and unambiguous indication that the user agrees to the processing of their personal data.
  • Servicethe RovoCareer online platform available at rovocareer.com.

2. Scope of Data Collected

Depending on how the service is used, the Controller may process the following categories of personal data:

(a) Registration and Account Data

  • email address provided during registration or login,
  • password (stored exclusively in encrypted form by Supabase Auth),
  • Google account identifier and Google email address — in the case of Google login,
  • date and time of registration and last login.

(b) Resume Data and User Content

  • first and last name, home address, phone number, email address — if the user entered them into the resume builder,
  • professional information: employment history, education, skills, achievements, languages, interests,
  • profile photo for the resume — if the user added one,
  • any other content entered by the user into the resume builder.

(c) Technical and Usage Data

  • device IP address,
  • browser type and version,
  • operating system,
  • date and time of visits to individual subpages,
  • data from cookies and similar tracking technologies — in accordance with the Cookie Policy,
  • system logs of the service.

(d) Payment Data

  • transaction data (amount, currency, date, payment identifier) — stored by the Controller only to the extent necessary to handle complaints and tax obligations,
  • full payment card data and bank account numbers — processed exclusively by Stripe; the Controller does not have access to them.

The Controller does not collect or process sensitive data (such as health data, political beliefs, or ethnic origin), unless the user independently includes such data in the content of their resume.

3. Purposes and Legal Bases of Processing

The table below presents the purposes of data processing and their corresponding legal bases.

Purpose of ProcessingLegal Basis
Registration and account managementContract performance
Creating, editing, and storing resumesContract performance
Processing payments for PDF downloadsContract performance
Issuing sales documents and fulfilling tax obligationsLegal obligation
Handling complaints and user inquiriesContract performance and legal obligation
Ensuring site security, detecting abuse and fraudLegitimate interest
Statistical traffic analysis and site optimization (Google Analytics)Legitimate interest or consent
Google login (OAuth)Consent and contract performance
Pursuing or defending against claimsLegitimate interest
Sending emails regarding your account and the serviceContract performance or legitimate interest

Data is not used for automated profiling that produces legal effects or otherwise significantly affects the user in a similar way.

4. Data Retention Period

The Controller retains personal data for the period necessary to achieve the purposes for which it was collected, taking into account applicable legal provisions. Specifically:

  • Account and Resume Datauntil the user deletes their account or requests data deletion, plus a short additional period necessary to handle any related complaints.
  • Payment Transaction Datafor a period of 5 years from the end of the tax year in which the transaction took place, in accordance with tax law.
  • Technical Data and System Logsfor the period necessary to ensure site security and detect abuse, no longer than 12 months from generation, unless legal provisions or ongoing proceedings require a longer retention period.
  • Correspondence and Complaint Submissionsfor a period of 3 years from the date the case is closed, in connection with possible claims.
  • Marketing Datauntil the user withdraws consent or files an effective objection.

After the retention period expires, data is permanently deleted or anonymized in a way that prevents identification of the individual.

5. Data Recipients — Third Parties

To ensure the proper functioning of the service, the Controller uses the services of third parties, to whom it entrusts or shares user data to the extent necessary. Data is not sold or shared with entities for marketing purposes.

(a) Supabase

Supabase Inc. acts as a data processor with respect to the site's technical infrastructure — including the account and resume database (Supabase Database), file and photo storage (Supabase Storage), and authentication handling (Supabase Auth). Data may be stored on servers located within or outside the European Union, using standard contractual clauses or other mechanisms compliant with GDPR. More information: supabase.com/privacy.

(b) Stripe

Stripe Inc. or Stripe Payments Europe Limited handles payments made through the service. Stripe processes transaction data, payment method information, and identifying user data to the extent necessary to authorize and settle payments. The Controller does not have access to full payment card data. Stripe acts as an independent data controller with respect to processing data for fraud detection and regulatory compliance purposes. More information: stripe.com/privacy.

(c) Google

Google LLC processes data in two contexts. First, in connection with logging in via a Google account (Google OAuth) — Google shares with the Controller the email address and account identifier to the extent chosen by the user when giving consent in the Google authorization window. Second, in connection with the Google Analytics service — Google processes technical data to generate anonymous traffic statistics for the site. Analytics data may be transferred to Google's servers outside the EEA, using standard contractual clauses. More information: policies.google.com/privacy.

(d) Government Authorities

The Controller may be required to disclose data to law enforcement or other public authorities based on legally binding regulations. In such cases, data is disclosed only to the extent required by applicable law and after verifying the legal basis for the request.

6. International Data Transfers

Some of the third parties used by the Controller (Supabase, Stripe, Google) may process data on servers located outside the European Economic Area (EEA), particularly in the United States. Data transfers to these countries take place using one of the following legal mechanisms:

  • standard contractual clauses adopted by the European Commission;
  • an adequacy decision (e.g. under the EU–US Data Privacy Framework);
  • other legal mechanisms compliant with Chapter V of the GDPR.

Users can obtain a copy of the safeguards applied by contacting the Controller at the email address indicated in section 16.

7. User Rights Regarding Data Protection

Under GDPR, users have the following rights with respect to their personal data processed by the Controller:

Right of Access

Users have the right to obtain confirmation from the Controller as to whether their personal data is being processed, and if so, to access it and receive information about the purposes, categories, recipients, and retention period.

Right to Rectification

Users have the right to request the prompt correction of inaccurate data or completion of incomplete data.

Right to Erasure ("Right to be Forgotten")

Users have the right to request deletion of their data if it is no longer necessary for the purposes it was collected for, consent is withdrawn, or the data was processed unlawfully. This right does not apply when processing is necessary to fulfill a legal obligation or pursue claims.

Right to Restriction of Processing

Users may request restriction of processing in cases specified by GDPR — e.g. when disputing the accuracy of data or having objected to processing.

Right to Data Portability

Users have the right to receive the personal data they provided to the Controller in a structured, commonly used, machine-readable format, and to transmit it to another controller — provided that processing is based on consent or contract and is carried out in an automated manner.

Right to Object

Users have the right, at any time, to object to processing of their data based on the Controller's legitimate interest — particularly regarding profiling and direct marketing purposes.

Right to Withdraw Consent

Where data processing is based on user consent, the user may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Right to Lodge a Complaint with a Supervisory Authority

If a user believes that the processing of their personal data violates GDPR, they have the right to lodge a complaint with the relevant data protection authority.

To exercise the above rights, please contact the Controller at the email address provided in section 16. The Controller will respond without undue delay, no later than one month from the date the request is received. If necessary, this period may be extended by a further two months due to the complexity or number of requests — of which the Controller will inform the user.

8. Cookies and Tracking Technologies

The service uses cookies and similar technologies to ensure proper functioning, analyze traffic, and optimize content. Detailed information about the cookies used, their types, retention periods, and how to manage cookie settings has been described in a separate document: Cookie Policy.

With respect to analytics cookies (Google Analytics), the basis for processing is the Controller's legitimate interest in improving the quality and functionality of the service, or possibly the user's consent — depending on the site's configuration and applicable regulations. Users can manage their cookie preferences at any time from their browser settings or by clicking the appropriate link in the site's footer.

9. Google Login (OAuth)

The service allows login via a Google account. Using this option means Google shares with the Controller only the data the user consented to in the Google authorization window — typically an email address and account identifier. The Controller does not gain access to the user's Google account password.

The user's relationship with Google in connection with their Google account is governed solely by Google's terms of service and privacy policy, for which the Controller is not responsible. Users can revoke permissions granted to the Controller at any time in their Google account settings.

10. Dynamic Suggestions (AI Features)

The service provides a dynamic suggestions feature — automatically generated content suggestions for a resume (job descriptions, skills, achievements, etc.) based on data entered by the user in the builder. Data entered by the user may be processed to generate these suggestions.

Suggestions are purely auxiliary in nature. The Controller does not guarantee their accuracy or usefulness in any specific recruitment process. Suggestions do not constitute automated decision-making that produces legal effects within the meaning of GDPR Art. 22.

11. Data Security

The Controller implements appropriate technical and organizational measures to ensure a level of data security corresponding to the risk, in particular:

  • encryption of data transmission using the HTTPS (TLS) protocol,
  • password hashing — passwords are stored exclusively in one-way cryptographic hash form by Supabase Auth,
  • database-level access control (Row Level Security),
  • regular software and library updates,
  • monitoring of suspicious activity on the site.

Despite implementing the above measures, the Controller cannot guarantee complete security of data transmission over the internet. Users are required to keep their login credentials confidential and to promptly inform the Controller of any suspected unauthorized access to their account.

12. Children's Data

The service is intended for adults. The Controller does not knowingly collect personal data from individuals under the age of 16 without parental or legal guardian consent. If the Controller learns that it has collected data from a child under this age without the required consent, it will promptly take steps to delete it.

13. Links to External Services

The service may contain links to third-party websites. This Privacy Policy applies solely to the RovoCareer service. The Controller is not responsible for the privacy practices used by external sites and encourages users to review those sites' privacy policies before providing them with any personal data.

14. Changes to the Privacy Policy

The Controller reserves the right to change this Privacy Policy in the event of changes to applicable law, changes to how the service operates, changes to third-party services, or for other justified reasons. Users will be informed of any significant change with reasonable advance notice — via a notice on the site or an email to the address associated with their account.

The date of the last update of this document is indicated at the top of the page. Continued use of the service after the publication of an amended Privacy Policy constitutes acceptance of it. If a user does not accept the changes, they should stop using the service and may request account deletion.

15. Final Provisions

This Privacy Policy is subject to applicable law and should be interpreted in accordance with GDPR and applicable national data protection regulations. Matters not covered by this Policy are governed by relevant applicable law.

If any provision of this Privacy Policy is found to be invalid or ineffective, it does not affect the validity of the remaining provisions.

16. Data Controller — Contact Details

The controller of personal data processed within the RovoCareer service is:

Hubert Frątczak
RovoCareer
[registered business address]
email: contact@rovocareer.com

For matters concerning the processing of personal data, exercising data subject rights, or any questions related to this Privacy Policy, please contact us at the email address above. The Controller will respond without undue delay, generally within 30 days of receiving the message.