Skip to content

Legal

Privacy policy

Last updated

This policy explains what CVKaar collects when you use cvkaar.com, why, how long we keep it, and what you can ask us to do with it. CVKaar is the Data Fiduciary for your personal data under India's Digital Personal Data Protection Act, 2023.

What we collect

We only collect what we need to run your account and build your resumes.

  • Account details. Your email address and name. If you sign up with a password, we store only a one-way hash of it (argon2), never the password itself.
  • Google sign-in, if you choose it. Your Google account ID, name, email address, whether Google has verified that email, your profile picture link, and the sign-in tokens Google returns.
  • Your resume content. Everything you type into the builder, such as your contact details, work history, education and skills.
  • A session cookie. One cookie that keeps you signed in, for up to 30 days. It is strictly necessary, so we don't ask for consent for it. We don't use advertising or tracking cookies.
  • Security counters. To stop password guessing and abuse, we count attempts per IP address and per email address. The address is stored as a one-way hash, and each counter only covers a short time window.
  • Account activity days. A record of which days you used CVKaar while signed in (the date only, not what you did). We use it to understand how many people actively use the service. It is kept for 400 days.
  • Product events. Records such as “signed up”, “signed in”, “created a resume” or “downloaded a PDF”, linked to your account, with details like the template used. They never contain your email, password or resume text.

Page-view statistics

We count visits to our pages to see which ones are useful. We built this ourselves so that it does not identify you:

  • It uses no cookies and nothing stored in your browser.
  • We never store your IP address or your browser's full user-agent string. We keep the kind of page (for example “editor”, never a resume ID), the referring website's domain, campaign tags in the link, a broad device, browser and operating system type, and whether a sign-in cookie was present. It is not linked to your account.
  • To count unique visitors, we combine your IP address and user-agent with a random value that changes every day and keep only the resulting hash. The daily value is deleted, so a visitor can't be recognised from one day to the next.
  • If your browser sends a Global Privacy Control signal, we don't create that visitor hash at all; the page view is only counted.
  • Individual page-view records are deleted after 90 days. Daily totals are kept for 25 months.

How we use it

  • To create your account, sign you in and keep it secure.
  • To save your resumes and turn them into PDFs when you ask.
  • To apply your plan, such as the launch offer and its limits.
  • To understand, in aggregate, how the service is used so we can improve it.
  • To answer you when you contact us.

We don't sell your data and we don't show ads.

PDF downloads

When you download a resume, the PDF is created on our own server and sent straight to you. We don't keep a copy of the file.

Leaked-password check

When you choose a password, we may check whether it has appeared in a known data breach using the Have I Been Pwned service. Only the first five characters of a one-way hash of the password are sent. Your password and your email address are never sent.

Payments

We don't take payments during the launch, so we don't collect any card, UPI or bank details. We will update this policy before paid plans start.

Who processes your data, and where

  • Railway hosts our servers and database in its Singapore region. Your data is therefore stored and processed outside India. This transfer is permitted under the DPDP Act, and we will follow any restrictions the Government of India notifies.
  • Google receives and shares data with us only if you choose to sign in with Google. Google's own privacy policy applies to your Google account.

We don't use an email delivery provider yet. If we add one, or any other service that handles your personal data, we will list it here first.

Operator access

Only the operator of CVKaar can use our admin tools. Signing in to them, opening an admin page, viewing an account, revealing contact details or exporting data each writes an entry to an audit log that cannot be edited. Entries record which account was looked at (by an internal ID, not your email) and are kept for 400 days, then deleted. Only the operator can see this log.

How long we keep it

  • Your account and resumes: until you delete your account.
  • Account activity days: 400 days, or until you delete your account, whichever comes first.
  • Page-view records: 90 days. Daily totals: 25 months.
  • Admin audit log: 400 days.

When you delete your account, we delete in one step your account details, password hash, linked Google sign-in and its tokens, sessions, resumes and everything in them, pending email-change and password-reset requests, and your activity days. Two things remain, without your email, name or resume content: product events stay as anonymous counts no longer linked to you, and audit-log entries keep the internal account ID until their 400 days are up.

Your rights

Under the DPDP Act you can:

  • Access a summary of the personal data we hold about you and how we use it.
  • Correct or update it. You can change your name, email and password in Settings, and edit your resumes at any time.
  • Erase it. Delete your account from Settings, or email us and we will do it for you.
  • Nominate someone to exercise these rights for you if you die or become unable to.
  • Have a grievance addressed. Contact us first and we will respond within a reasonable time.

Email support@cvkaar.com from the address on your account. Our contact page lists what to include. If you are not satisfied with our response, you can complain to the Data Protection Board of India.

Children

CVKaar is not intended for anyone under 18 without the consent of a parent or lawful guardian. If you are under 18, please use it only with that consent. If you believe a child has created an account without it, contact us and we will delete it.

How we protect it

  • All traffic to cvkaar.com is encrypted with HTTPS.
  • Passwords are stored only as strong one-way hashes.
  • Sign-in cookies can't be read by scripts, and every request for a resume checks that it belongs to you.
  • Sign-in, password reset and other sensitive actions are rate-limited.
  • Admin access needs a second password check and is recorded in the audit log.

No system is perfectly secure, but we work to keep your data safe.

Changes to this policy

If we change how we handle your data, we will update this page and the “Last updated” date at the top.

Contact

Questions, requests and grievances: support@cvkaar.com.