Privacy Policy
1. Who We Are
Belixar LLC (doing business as “Jobpaq,” “we,” “us,” or “our”) operates the Jobpaq platform (the “Platform”), an online hiring marketplace that connects job seekers (“Candidates”) with companies looking to hire (“Employers”).
2. What Data We Collect
We collect only what is necessary to operate the Platform. The categories below reflect what is actually collected.
Account data — your email address, used as your login identifier.
Candidate profile data — your display name and any resumes you create (title and description).
Employer profile data — your organization name and description, and the name of any managers you add to your account.
Job postings and vacancies — job titles, locations, descriptions, compensation details, and posting status submitted by Employers.
Application data — when a Candidate applies to a posting, we associate the submitted resume with the posting and track the application's status.
Messages — text content and timestamps of in-platform messages exchanged between Candidates and Employers, as well as support ticket messages you send to us.
Notification preferences — your choices about receiving platform updates, news, application status alerts, and new posting alerts via email.
Billing contact data — the name and email address associated with your Employer billing profile, used for payment receipts and invoices.
Payment data — processed by Paddle.com Market Ltd (“Paddle”), our payment provider and merchant of record. We do not store your card number, CVV, or full card details. For saved payment methods, Paddle shares the card brand, last 4 digits, and expiration date with us so we can display and manage them on your behalf.
Technical and diagnostic data — error events, stack traces, and basic device/browser context collected automatically by Sentry when you encounter an error on the Platform.
Analytics data — aggregated, non-identifying page view and usage metrics collected automatically by Vercel Analytics to understand how the Platform is used.
Session data — a session cookie stored in your browser to keep you logged in across page loads.
IP address and request logs — our hosting and network providers (Cloudflare, Vercel, and Render) automatically log your IP address, browser type, and request timestamps for every request, as is standard for operating a web service.
Feedback — any free-text feedback you voluntarily submit about an application, posting, or user interaction.
3. How We Collect It
Directly from you — when you create an account, build a resume or profile, apply to a posting, send a message, submit a support ticket, or adjust your notification preferences.
Automatically — a session cookie is set when you log in. If an error occurs, Sentry automatically captures diagnostic context from your browser session. Vercel Analytics automatically collects aggregated page view metrics as you navigate the Platform. Our hosting and network providers (Cloudflare, Vercel, and Render) automatically log your IP address and basic request metadata for every request to the Platform.
From third parties — Paddle sends us transaction and payment method details after you complete a payment or save a card. We receive no raw card data from Paddle.
4. Why We Use It
We use your data only for the purposes described below, each with a stated legal basis.
To provide the Platform (contract performance) — authenticating your account, displaying your profile and resumes, processing job applications, facilitating messaging, and managing payments.
To send transactional email notifications (contract performance) — one-time login codes, application status updates, new message alerts, and payment receipts.
To send platform news and updates by email (consent) — only when you have opted in via your notification preferences. You can withdraw consent at any time in your profile settings.
To monitor and fix errors (legitimate interest) — Sentry error data helps us identify and resolve bugs to keep the Platform stable and secure.
To handle support requests (contract performance / legitimate interest) — support ticket content is used to respond to and resolve your issue.
To personalize job matching (legitimate interest) — feedback you submit about an application or posting helps our matching logic surface postings you're more likely to want to apply to, and application signals hiring managers are more likely to act on. This feedback is never shown to other Members.
To comply with legal obligations — we may retain or disclose data where required by law, court order, or regulatory authority.
To operate and secure the Platform (legitimate interest) — IP address and request logs help us keep the Platform available, diagnose outages, and protect against abuse.
To prevent fraud and abuse (legitimate interest) — account activity may be reviewed to detect and prevent violations of our Terms of Service.
5. Who We Share It With
We do not sell your personal data. We share it only with the service providers listed below, strictly for the stated purpose.
Paddle.com Market Ltd — payment processing and merchant of record. When you complete a purchase, you interact directly with Paddle's hosted checkout, and Paddle is the seller of record for the transaction. Paddle's use of your data is governed by the Paddle Privacy Policy. Sentry (Functional Software, Inc.) — error monitoring. Sentry receives error events and diagnostic context when exceptions occur on the Platform. Data is processed under Sentry's data processing agreement.
Vercel Inc. — application hosting and website analytics. As our hosting provider, Vercel automatically logs request data, including IP addresses, for every request to the Platform. Vercel Analytics separately collects aggregated, non-identifying usage metrics to help us understand Platform traffic.
Render — backend/API hosting. Render hosts the backend service that powers the Platform, including job postings, applications, messages, and the other Platform data described in Section 2.
Cloudflare, Inc. — network and content delivery. Cloudflare sits in front of our servers to route traffic and improve reliability, and logs the same request-level data described in Section 2 for every request to the Platform.
Platform participants — when a Candidate applies to a posting, their resume and name are visible to the Employer. Messages you send are visible to the recipient. This sharing is inherent to the purpose of the Platform.
Law enforcement or regulatory authorities — we may disclose personal data when required by law, valid legal process, or to protect the rights, property, or safety of Jobpaq, its users, or the public.
Business successors — in the event of a merger, acquisition, or sale of substantially all of our assets, your data may be transferred to the acquiring entity, subject to the same privacy commitments described here.
Some Job Postings link out to an application process on the Employer's own website or a third-party service instead of the Platform, as described in our Terms of Service. This Privacy Policy does not apply once you leave the Platform through such a link, and any data you provide there is subject to that site's own privacy practices.
6. International Transfers
Belixar LLC is based in the United States. Sentry and our hosting and network providers (Cloudflare, Vercel, and Render) also operate in the United States and process data on servers located there. Paddle, our payment provider, is a global company with entities in the United States, United Kingdom, and Ireland, and may process payment data outside the United States as part of running its checkout and billing infrastructure. If you access the Platform from outside the United States, your data will be transferred to and processed in the US. We rely on our service providers' own transfer mechanisms (such as Standard Contractual Clauses where applicable) to safeguard cross-border transfers.
7. Retention
Account and profile data — retained for as long as your account is active. When you close your account, your personal profile data is deleted immediately, except where retention is required by law or for legitimate business need (e.g., fraud prevention, financial records).
Messages and support tickets — retained for the duration of your account. After account closure, messages may be retained in anonymized form.
Payment records — Paddle retains payment data per its own policies. We retain transaction and saved payment method records for as long as required by tax and accounting obligations (typically 7 years in the US), or until you remove a saved payment method.
Error logs (Sentry) — retained for up to 90 days within Sentry's platform per its default retention settings.
Session cookies — expire at the end of your browser session or when you log out, whichever comes first.
IP address and request logs — retained by our hosting and network providers per their standard log retention periods, and used only for operating and securing the Platform.
8. Your Rights
Depending on where you live, you may have rights over your personal data. We honor the following rights for all users, regardless of jurisdiction:
Access — request a copy of the personal data we hold about you.
Rectification — update or correct inaccurate data directly in your profile settings, or by request.
Deletion — request deletion of your account and personal data. Deletion is immediate except where retention is required by law.
Portability — request an export of your personal data in a structured, machine-readable format.
Objection / withdrawal of consent — opt out of marketing and news notifications at any time via your profile notification settings. You may also object to other processing by request.
California residents (CCPA/CPRA) — you have the right to know what categories of personal information we collect and disclose, the right to delete, the right to correct, and the right to opt out of the sale or sharing of personal information (we do not sell personal information).
Non-discrimination — we will not deny you service, charge you a different price, or provide a lower level of quality because you exercised any of these rights.
To exercise the Access, Rectification, Portability, or Objection rights, submit a support ticket. We will respond to requests within 30 days and may ask you to verify your identity before fulfilling one.
9. Cookies and Tracking
We use a minimal set of cookies and do not use advertising or cross-site tracking technologies.
Session cookie (strictly necessary) — set when you log in to keep you authenticated across pages. This cookie is required for the Platform to function and cannot be disabled while using the service.
Sentry SDK (functional) — the Sentry client library may set identifiers in browser storage to correlate error events from the same session. This data is used solely for error diagnostics and is not used for advertising.
Vercel Analytics (analytics) — collects aggregated page view and usage metrics without setting a tracking cookie or using cross-site identifiers. This data is not used for advertising.
Paddle Checkout (necessary for checkout) — when you publish a Job Posting, the embedded Paddle checkout may set cookies or similar identifiers to process your payment and prevent fraud. Not used for advertising.
You can control cookies through your browser settings. Blocking the session cookie will prevent you from logging in. For more detail, see our Cookie Policy.
10. Children's Privacy
The Platform is intended for users who are at least 18 years old. We do not knowingly collect personal information from anyone under 18.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Continued use of the Platform after a change takes effect constitutes acceptance of the revised policy.