Privacy Policy
Effective date: 15 July 2026
This policy explains how the operator of FIFO Ready (“we”, “us”) handles personal information. The privacy contact and data-request channel is support@fiforesumes.com.
1. Information we collect
- Account data: email address, authentication identifiers, account events and password-recovery status. We do not receive your password in readable form.
- Application data: resume contact details, employment history, tickets, licences, education, skills, job descriptions, target roles, locations, and generated documents.
- Transaction data: Stripe customer/payment identifiers, tier, amount, currency, fulfilment status, receipt/support references, and refund records. We do not store full card details.
- Support and marketing data: messages, launch-list email, source and consent status.
- Technical and analytics data: page, device/browser information supplied by analytics providers, anonymous session ID, attribution, role/region/tier selections, funnel events, errors and consent choice. Resume text and direct identifiers are denied from our analytics payloads.
Do not submit government identifiers, medical information, criminal-history information, references’ private details, or other sensitive data unless genuinely required and lawful.
2. Why we use information
- Provide authentication, resume generation, editing, scoring, storage, paid fulfilment and downloads.
- Process payment, prevent fraud, reconcile entitlements, provide support and issue refunds.
- Secure, debug, measure and improve the service.
- Send transactional messages and marketing only where requested or permitted.
- Comply with tax, accounting, consumer, legal and dispute obligations.
Depending on applicable law, processing is based on performance of our contract, your consent, compliance with law, and legitimate interests in security and service improvement. You may withdraw consent for optional analytics at any time through Cookie settings.
3. AI processing and factual safeguards
Application content may be processed by configured AI/model providers to parse, draft, enhance or compare documents. We automatically mask common names, email addresses, phone numbers, URLs and address patterns before supported AI calls, then restore placeholders in the response. Masking reduces exposure but is not infallible; avoid unnecessary sensitive information.
AI output is not used by FIFO Ready to make an employment decision about you. Employers and job platforms make their own decisions. We do not sell resume data or use it to build a separate candidate-profile marketplace.
4. Providers and disclosures
We disclose only what is reasonably necessary to service providers such as Cloudflare (hosting/security), Supabase (authentication/database), Stripe (payments), configured OpenAI-compatible/model providers (AI processing), and configured email providers. With consent, we may use Google Analytics for aggregate usage measurement and Microsoft Clarity for public marketing-page heatmaps and masked session replay; our own privacy-filtered first-party analytics may also record consented funnel events.
Clarity does not initialize when a sensitive route is opened directly. If a consented visitor moves from a public page to a builder, editor, account, checkout, paid-fulfilment, password-recovery, contact-support or unsubscribe route, the page is masked and reloaded without Clarity before sensitive interaction continues. We do not send resume text or direct account identifiers to Clarity.
We may disclose information where required by law, to protect users or the service, during a genuine business transfer subject to confidentiality, or with your direction. We do not sell personal information.
5. Overseas processing
Providers may process information in the United States, Australia, New Zealand, Europe, or other locations. Where required, we rely on provider contractual protections and other lawful transfer mechanisms. Provider privacy terms also apply.
6. Cookies, local storage and consent
Essential storage supports authentication, security, theme and service preferences. Optional analytics and public-page session-replay tags load only after acceptance. Clarity receives analytics-storage consent but not advertising-storage consent. Declining optional analytics does not prevent core use. Use the Cookie settings control in the footer to change your choice; withdrawal revokes optional analytics consent and reloads the page without the replay tag.
7. Retention
- Resume/account content: while the account is active and until deletion or a valid deletion request, subject to backups and legal holds.
- Transaction, tax, fraud and refund records: generally up to seven years where required for accounting or legal compliance.
- Support records: normally up to two years after closure unless needed for a dispute.
- Privacy-filtered analytics: targeted for no more than 14 months unless aggregated or lawfully required longer.
- Launch-list details: until unsubscribe, invalid address, or deletion request.
Deleted records may remain in secured backups for a limited recovery cycle before final overwrite.
8. Security and incidents
Controls include HTTPS, provider access controls, row-level account policies, signed Stripe webhooks, paid-record checks, rate limits, PII masking, and restricted service credentials. No service can promise absolute security. We will assess and notify affected people and regulators of eligible privacy breaches as required by applicable law.
9. Your choices and rights
Depending on location, you may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent. You can delete individual saved resumes in the product. For account deletion, export, correction, marketing opt-out or a privacy complaint, email support from the account address. We may verify identity and retain information where legally required.
If unresolved, you may complain to the privacy regulator available in your jurisdiction, such as the Office of the Privacy Commissioner in New Zealand, the Office of the Australian Information Commissioner, a Canadian privacy commissioner, the UK Information Commissioner, or an EU supervisory authority.
10. Children
FIFO Ready is for adults aged 18 and over. We do not knowingly collect children’s personal information. Contact us to request removal if you believe a child supplied information.
11. Changes and contact
We may update this policy prospectively and will change the effective date. Material changes will be highlighted where reasonably practicable. Privacy requests and complaints: support@fiforesumes.com.