Privacy policy
Updated: 18 September 2026 · © 2026 findjobs.ge
1 Who is responsible
findjobs.ge is the data controller. Contact: info@findjobs.ge. This policy covers the website, our Telegram bot and channels, our mobile apps, and our emails.
2 What we collect
Job seekers and candidates: name, email, phone (optional), cover letters, CV files; for seeker listings also your age (never shown publicly) and an optional photo (shown publicly).
Sign-in: your email; if you use Sign in with Apple or Google, the email and account identifier they hand us; the public half of every passkey you register and the name of the device it lives on; an authenticator secret if you enrol one; hashed recovery codes. We never hold the private half of a passkey or any password of yours.
Identity verification (optional): if you choose to verify, the document image you upload is encrypted and kept for 365 days; after that only the outcome and a one-way hash that prevents duplicate verifications remain.
Employers: email, company name, phone, website, and activity on your own listings.
Messages and reviews: your conversation text; review text together with the employment record that makes it verified.
Telegram: your Telegram ID, username, language, and the alerts and account links you set up with the bot.
Payments: none. Nothing on the platform is sold, so we hold no card or payment data of any kind.
Employer contacts from aggregated listings: when a publicly published listing shows a contact address, we store it to attribute the listing, to deliver applications to it, and to send the one-time notice described below. We remove it on request. For every application forwarded to such an address we keep a delivery record: the address, the time, the mail provider's message id, and whether the message was accepted, delivered, delayed or bounced, plus any reply that comes back through us.
The CV builder runs entirely in your browser: what you type is saved on your own device and the PDF is made there too. Nothing you enter in it is uploaded to us.
Automated processing: the assistant, translation and screening run on AI models. What you type to the assistant, listing text, message text sent for translation, and the text of listings, applications and messages screened for fraud may be processed by Cloudflare Workers AI and, for the fraud and abuse screen only, by OpenAI. CV files and identity documents are never sent to any AI provider, and a person reviews anything the screen holds back.
The iPhone app: if you allow notifications, the app registers a push token with Apple so alerts can reach that device. The rating prompt sends us nothing.
Technical: privacy-first traffic counting with no cookies and no per-person profile; a visitor counts once a day via a hash deleted the same day, and known bots are excluded. Standard server logs exist for security. We also publish aggregate traffic figures measured by Cloudflare (visitors and page views per day); they say nothing about any individual.
3 Payments
If you buy Pro, a promoted listing, a banner or a bump pack, the payment is taken by Stripe, Inc., which acts as our payment processor. Stripe receives your email address, the amount and the card details you type on its page; card numbers never reach our servers. We keep what we need to run the service and our books: Stripe customer, subscription, session and invoice identifiers, the product bought, the amount and currency, the dates, and refunds or disputes. Banner images you upload are stored with the order and shown publicly while the banner runs. Payment records are kept for as long as accounting law requires, then deleted.
4 What we use it for
Running the board; delivering applications and messages; moderation and fraud prevention; transactional notifications by email and Telegram (application alerts, hire congratulations, unread-application reminders, one review invitation after a hire, at most one reminder for a quiet listing, push notifications in the app if you allow them); the "For you" pick on the board; aggregate statistics; answering support.
We send our users no marketing newsletters. Separately, when an employer's publicly posted listing shows their own contact address, we may send that employer one short notice that their listing appears here, with removal and opt-out one click away. An opt-out is permanent: an address that asks us to stop is never emailed or listed again, and we delete it entirely on request.
5 Who sees your data
Your application goes only to the employer whose vacancy you applied to. Public listing content is public, including on our Telegram channels and in machine translations. Reviews appear without your name.
Providers that process data for us: Cloudflare (hosting, storage, email routing, AI models), Apple and Google (only if you sign in with them; Apple also delivers the app's notifications), Telegram (bot and channels), Resend and our own mail server in the EU (email delivery), and OpenAI (automated screening of text for fraud and abuse). We never sell personal data and run no advertising networks.
6 Cookies
Sign-in cookies keep you signed in: one for job seekers (90 days) and one for employers (30 days); our staff panel uses additional security cookies. Three small functional cookies remember your language, which side of your account you last used, and the fields of the listings you opened on this device (at most six, for 90 days) so the "For you" pick on the board can show similar work; that last one is read only by our server and holds no listing ids and no name. Analytics run entirely without cookies.
Your browser also keeps a few things locally and never sends them to us: your light or dark theme, which listings you already opened, unsent drafts of a posting, and the CV builder's contents.
If you arrive from one of our Google ads, Google sets its conversion cookie so we can count that the ad led to an application or a posting; we send Google no name, no CV and no email, ad personalization signals are disabled, and visitors who do not come from an ad get no Google requests at all. Visitors in the European Economic Area, the United Kingdom and Switzerland are never served that tag, ad click or not, so there is nothing there to consent to.
7 Security
Everything travels over TLS. CV files are encrypted at rest (AES-256). Access to personal data is restricted and logged: moderation staff never see candidate documents, and staff accounts require a passkey or one-time code on top of their sign-in. Job seeker accounts are protected by a passkey or an authenticator app on top of the email step, employers can add the same, and sessions expire on their own.
8 How long we keep it
Applications and CVs: deleted no later than 6 months after the listing closes, and the delivery record of a forwarded application is cleared with it. Identity documents: 365 days. Sign-in sessions: 90 days for job seekers, 30 days for employers. Accounts: kept until you delete them. Employment records and reviews: kept while the review is published. Support mail and security logs: kept as long as needed for security and legal obligations. Aggregate traffic counts contain no personal data and are kept.
9 Your rights
Ask for a copy of your data, correct it, delete it, or object to a use: info@findjobs.ge. A person answers. Deleting your account removes your personal data except what the law requires us to keep.
You can also complain to the Personal Data Protection Service of Georgia (personaldata.ge). Visitors from the EEA have the equivalent GDPR rights, including data portability.
10 Children
The platform is for people aged 16 and over.
11 Where data lives
Our infrastructure runs on Cloudflare's global network and a mail server in the EU, so data may be processed outside Georgia with contractual safeguards in place.
12 Changes
The date above always shows the current version; meaningful changes are announced on the site.
13 Contact
info@findjobs.ge. A person reads every email.