JobsInCrypto Privacy Policy
Version 1.0. Effective date: 25 September 2026.
This Privacy Policy explains how personal data is processed when the JobsInCrypto website at jobsincrypto.net is used. Terms defined in the Terms of Service have the same meaning here.
1. Controller
1.1. The controller of personal data processed through the Service is Pavlo Nadakhovskyi, a private individual residing in the European Union (the "Operator").
1.2. Questions and requests concerning personal data may be sent to pablo@jobsincrypto.net or through the contact form at jobsincrypto.net/contact.
2. Personal data processed
2.1. Account data: name, email address, password (stored only in hashed form), account type and settings.
2.2. Candidate profile data: data the Candidate chooses to provide, such as headline, location, experience, skills, languages, work history, education, portfolio, salary expectations, contact details and social profiles, photo, intro video, resumes and the X username confirmed through "Verify with X".
2.3. Employer data: company name and profile, logo, details of team members, Listings, and the name and email address of the Owner and Teammates.
2.4. Application data: the Candidate's name, email address, resume, answers and salary expectations submitted with an application, and the application's status.
2.5. Messages: the content of conversations between Users and their attachments.
2.6. Payment data: the amount, time and reference of each Credits purchase. Payment details entered on the Payment Processor's page are collected by the Payment Processor, not by the Operator.
2.7. Technical and security data: IP address at registration, IP addresses and records of sign-in and other attempts used for rate limiting and fraud checks (for example on sign-in, the contact form and reports), fraud indicators, session cookies, error logs, and the browser and device signals that the Service's bot-detection provider (Cloudflare Turnstile) checks on sign-up, password reset, code resend and the contact form to tell people from automated scripts.
2.8. Communications: messages sent to the Operator through the contact form or by email, and reports submitted about Content.
3. Purposes and legal bases
3.1. The Operator processes personal data for the following purposes:
(a) to create and run Accounts, publish Listings and profiles, process applications and messages, and provide the other features of the Service, on the basis of the contract with the User;
(b) to process purchases of Credits and keep payment records, on the basis of the contract and of legal obligations;
(c) to prevent and investigate fraud, scams, spam and abuse, keep the Service secure, enforce the Terms and retain evidence, on the basis of the Operator's legitimate interest in protecting the Service and its Users;
(d) to send service emails and, where the User has not switched them off, optional notifications, on the basis of the contract and the Operator's legitimate interest;
(e) to send marketing emails, only on the basis of the User's consent, which may be withdrawn at any time;
(f) to answer requests and complaints and handle reports, on the basis of the Operator's legitimate interest and legal obligations;
(g) to establish, exercise or defend legal claims, on the basis of the Operator's legitimate interest.
3.2. Providing personal data is voluntary, but without the data required for an Account the Service cannot be used.
4. Automated processing
4.1. The Operator reviews Accounts, Listings and activity to detect fraud and abuse, using both automated checks (for example, several registrations from the same IP address or scam wording in a Listing) and its own judgement. On that basis the Operator may restrict or ban an Account at its discretion, with the consequences set out in the Terms of Service, including for Credits.
4.2. Automated checks only flag items for the Operator, with three exceptions: registration with an address from a disposable (temporary) email service is refused automatically, and the person may register with a regular address instead; a sign-up, password reset, code resend or contact attempt that the bot check classifies as automated is refused automatically, and a person may try again; and rate limits temporarily block repeated attempts, for example at sign-in, registration, the contact form and reports. No decision producing legal or similarly significant effects is taken solely by automated means.
5. Recipients
5.1. Employers. When a Candidate applies to a Listing or chooses to reveal their details, the relevant Employer receives the Candidate's data. From that moment the Employer processes that data as an independent controller and is responsible for it under its own privacy policy.
5.2. Other Users. Published Listings and company pages are public. Candidate profiles are visible to signed-in Employers according to the Candidate's settings.
5.3. Service providers. The Operator uses providers of hosting, file storage, database, email delivery, real-time messaging infrastructure and bot detection, which process personal data on the Operator's behalf and under its instructions.
5.4. Independent third parties. The Payment Processor processes payment data as an independent controller under its own terms. X processes data under its own terms when a User uses "Verify with X".
5.5. Authorities. Personal data may be disclosed to public authorities where required by law or where necessary to protect the rights of the Operator or of Users.
5.6. The Operator does not sell personal data.
6. International transfers
6.1. Some service providers may process personal data outside the European Economic Area, subject to the safeguards required by law.
7. Retention
7.1. Account, profile and Employer data are kept until the Account is deleted.
7.2. Applications and conversations are kept until either party deletes its Account.
7.3. Accounts whose email address was never confirmed and which show no activity may be deleted automatically.
7.4. Data of a banned Account is kept as evidence for at least 1 year from the ban, and for longer while a legal claim or an official investigation concerning it is pending or while it is needed to protect the Service and its Users. The Operator deletes it when it is no longer needed.
7.5. Payment records are kept for as long as required by accounting and tax law.
7.6. Security records are kept for short periods, as long as needed for their purpose.
7.7. Reports and messages sent to the Operator are kept for as long as needed to handle them and to defend legal claims. Reports filed by a User whose Account is deleted are kept without identifying that User.
7.8. Backups and technical copies are kept for a limited time and deleted or overwritten over time. A data subject may request erasure at any time under Section 8.
7.9. Copies of emails sent by the Service are kept for 30 days after sending, including after the Account is deleted.
8. Rights of the data subject
8.1. Subject to the conditions set by law, every data subject has the right to:
(a) access their personal data and receive a copy;
(b) rectify inaccurate data, which Users can mostly do themselves in their Account;
(c) have their data erased, including by deleting their Account;
(d) restrict processing;
(e) receive their data in a portable format; Candidates can download their data from the Account settings;
(f) object to processing based on legitimate interest;
(g) withdraw consent at any time, without affecting processing carried out before withdrawal;
(h) lodge a complaint with a data protection supervisory authority, in particular in the country of their residence, place of work or of the alleged infringement.
8.2. Requests are sent to pablo@jobsincrypto.net. The Operator may ask for information needed to confirm the requester's identity and responds within the time limits set by law.
8.3. Some rights do not apply where data must be kept for legal reasons or for establishing, exercising or defending legal claims, including evidence retained under Section 7.4, payment records under Section 7.5 and reports under Section 7.7. Copies of emails under Section 7.9 are deleted within 30 days of sending.
9. Cookies and similar technologies
9.1. The Service uses only cookies strictly necessary for its operation, such as cookies that keep the User signed in and protect the sign-in process, and local browser storage for preferences such as search filters and the cookie notice. The bot check on sign-up, password reset, code resend and the contact form reads technical signals from the browser for security only, not for tracking. These do not require consent.
9.2. The Service does not use analytics, advertising or tracking cookies. If this changes, consent will be requested first.
10. Security
10.1. The Operator applies appropriate technical and organisational measures to protect personal data. No method of transmission or storage is completely secure, and absolute security cannot be guaranteed.
11. Age
11.1. The Service is intended for persons aged 18 or over. The Operator does not knowingly process data of persons under 18.
12. Changes
12.1. The Operator may update this Privacy Policy at any time. Material changes are notified in advance by email or on the Service. The version and effective date are stated at the top.