Privacy Policy
At TezApply, your privacy, data sovereignty, and security are foundational. This Privacy Policy details the types of personal data we collect, how it is processed and protected, and our retention policies, including identity preservation for platform safety and abuse prevention.
Transparent Notice on Identity Data & Post-Account Deletion Retention:
When you delete your account, your uploaded resumes, cover letters, and connected email tokens are deleted from active databases. However, to prevent cyclic abuse, free-tier/trial exploitation, fraud, and circumvented suspensions, TezApply permanently retains your verified email address, mobile phone number, account creation/deletion timestamps, and security audit logs in an isolated anti-abuse ledger.
Table of Contents
- 1. Overview & Controller
- 2. Information We Collect
- 3. How We Use Personal Data
- 4. Google API User Data Disclosure
- 5. Post-Deletion Anti-Abuse Retention
- 6. Third-Party Subprocessors
- 7. Security & Encryption
- 8. Your Data Protection Rights
- 9. Cookies & Tracking
- 10. Children's Privacy
- 11. Contact & Grievance Officer
1Overview & Data Controller
This Privacy Policy applies to all personal data collected through the TezApply platform, website, mobile-responsive interfaces, and related software tools.
TezApply operates as the Data Controller for your account information, billing records, and platform security logs. In connection with the content of your job application emails and resume documents dispatched to prospective employers, TezApply operates as a service provider and technical processor acting strictly on your instructions.
2Information We Collect
We collect information necessary to provide, protect, and optimize our automated career services:
A. Identity & Contact Information
When you register, we collect your full name, verified email address, country calling code, and verified mobile phone number. These data points are mandatory to authenticate your identity, prevent spamming, and secure your account.
B. Connected Email & OAuth Tokens
When you connect your email account (such as Gmail or Outlook), we receive and securely store encrypted OAuth access and refresh tokens. These tokens enable the platform to send outbound application emails and track delivery message IDs on your behalf.
C. Career & Application Content
We store PDF resumes you upload, parsed resume metadata, AI-generated cover letters, job description text you input, recruiter contact email addresses, and your job application status history.
D. Billing & Transaction Records
When you purchase a subscription, our payment processor (Razorpay) handles payment details. We store transaction IDs, subscription status, plan tier, amount paid, and invoice numbers. We do not store credit card numbers or banking PINs on our servers.
E. Technical, Audit & Usage Logs
We automatically log IP addresses, browser user agent strings, device identifiers, login timestamps, error logs, and transactional email dispatch records to safeguard platform stability and audit system integrity.
3How We Use Personal Data & Legal Grounds
We process your personal information under the following legal bases:
- Contractual Performance: To create your account, generate AI drafts, connect your email, scan resumes for malware, dispatch job outreach emails, and fulfill subscription entitlements.
- Legitimate Interests: To detect and prevent fraud, block spamming, prevent multiple account exploitation, safeguard server stability, and maintain anti-abuse ledgers.
- Legal & Regulatory Compliance: To maintain financial accounting books, verify billing transactions, comply with tax laws (e.g. GST in India), and cooperate with authorized legal requests.
- User Consent: For specific optional features, such as opting into product update digests and onboarding tips.
4Google API Services User Data Policy Compliance
Strict Adherence to Google Limited Use Policy:
TezApply's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We do NOT read, scrape, or store your personal incoming inbox emails.
- We do NOT sell your Google user data to advertisers or data brokers.
- We do NOT use or transfer Google user data to train generalized AI models or large language models without your express opt-in.
- We access Gmail API strictly under the
https://www.googleapis.com/auth/gmail.sendscope to transmit outgoing job applications that you review and trigger.
5Data Retention & Post-Deletion Anti-Abuse Ledger
We maintain transparent and strict policies regarding the retention and deletion of your data:
What Is Purged Upon Account Deletion:
When you delete your account, your uploaded resume files, parsed resume text, AI cover letter drafts, application tracker history, and connected OAuth refresh tokens are permanently purged from active operational tables within thirty (30) days.
What Is Retained for Platform Safety & Anti-Abuse:
To safeguard the platform, prevent bad actors from evading administrative bans, block the cyclic recreation of accounts to exploit free daily quotas or promotional offers, and fulfill mandatory statutory tax and accounting retention rules:
- Primary Identity Markers: We permanently retain your verified email address and mobile phone number in our restricted security registry.
- Security & Abuse Logs: We retain account creation/deletion timestamps, referral fraud markers, and anti-abuse verification hashes.
- Financial Records: Transaction logs and invoice records are preserved for the statutory period required under applicable tax and financial legislation (up to 7 years in India).
Retained identity markers in the security ledger are isolated from operational marketing workflows and are strictly used for identity deduplication, anti-fraud enforcement, rate limiting, and legal defense.
6Third-Party Subprocessors
We engage vetted third-party service providers to support our operations under strict confidentiality and data protection agreements:
| Partner / Subprocessor | Purpose | Data Handled |
|---|---|---|
| Clerk | Authentication & User Session Management | Email, Phone Number, Password Hashes, Session IDs |
| Razorpay | Payment Gateway & Recurring Subscriptions | Payment Tokens, Billing Address, Transaction Status |
| PostgreSQL / Cloud DB | Core Application & Security Database | Encrypted Application Records, User Identity |
| AWS S3 / Cloud Storage | Encrypted Resume Document Storage | User-Uploaded PDF Resumes |
| OpenAI / AI Engine | AI Resume Parsing & Cover Letter Generation | User-provided job descriptions, resume snippets |
7Data Security & Encryption Safeguards
We employ defense-in-depth technical and organizational measures to safeguard your personal data:
- AES-256-GCM Token Encryption: All third-party OAuth access and refresh tokens are encrypted at rest using industry-standard AES-256-GCM algorithms with isolated master encryption keys.
- TLS 1.3 in Transit: All data transmitted between your browser and our servers is secured with HTTPS and modern TLS encryption.
- Automated Malware & Virus Scanning: Uploaded resumes undergo automated security checks to prevent malware distribution.
- Access Controls: Database access is restricted to authorized personnel under least-privilege principles and multi-factor authentication.
8Your Data Protection Rights
Subject to applicable data protection laws (including the Digital Personal Data Protection Act / DPDP and GDPR), you possess the following rights:
- Right to Access & Portability: Request a copy of the personal data we hold about you in a structured format.
- Right to Rectification: Request correction of inaccurate or incomplete personal details.
- Right to Erasure: Request deletion of your active account data, resumes, and connected tokens (subject to our anti-abuse and statutory retention exceptions outlined in Section 5).
- Right to Revoke Consent: Disconnect your Google or Outlook account at any time through your account settings, which immediately revokes our access to external mail servers.
10Children's Privacy
TezApply is intended solely for adult job seekers (18 years of age or older). We do not knowingly collect personal data from minors. If you believe a minor has registered for an account, please contact us immediately for removal.
11Contact & Grievance Officer
For questions regarding this Privacy Policy, data subject access requests, or grievance redressal under the DPDP Act, please contact our Data Protection Officer:
Grievance Officer: Data Protection Officer, TezApply
Email: [email protected]
Jurisdiction: Ahmedabad, Gujarat, India
Related: Review our Terms of Service or learn more on our About Page.