Skip to main content

Privacy and data handling

Privacy Policy

Last updated: July 14, 2026

ResumeShortList processes personal career information to provide resume and LinkedIn diagnostics, Target Role Matches, Career Positioning Briefs, positioning workspaces, contextual advisor answers, founder-led services, secure account access, and any follow-up support you request. This policy explains the current application behavior, where configuration affects storage or communications, and the choices available to you.

Not sold or automatically circulated

Providing a resume or LinkedIn profile does not authorize sharing it with employers, recruiters, or professional contacts.

Used to operate your requested product

Your career materials and target-role context are used to generate, deliver, protect, and support the diagnostic, brief, workspace, advisor answer, or founder-led service you request.

Deletion requests available

You may request deletion of your career materials and related account, support, feedback, purchase, or service records by email.

Information collected for the resume diagnostic

The current resume diagnostic asks for your first name, email address, target role, career level, resume file, and acceptance of the Privacy Policy and Terms. Your last name, target market, and pasted target job description are optional.

The application may also process technical information such as IP address, browser or user-agent information, timestamps, file name, file type, file size, and upload metadata. These signals support service operation, troubleshooting, security, and the one-complimentary-diagnostic limit.

Information collected for the LinkedIn diagnostic

The LinkedIn Positioning Diagnostic asks for your first name, email address, target role, career level, LinkedIn profile content, and acceptance of the Privacy Policy and Terms. You may provide profile content by pasting visible sections, uploading a text-based LinkedIn PDF or DOCX export, or using both methods.

Target market, target industry, a pasted target job description, and a resume file are optional. When you provide a resume, it is used to compare whether the resume and LinkedIn profile reinforce a consistent role direction, seniority level, evidence base, and career narrative.

The LinkedIn diagnostic may also process limited technical information such as IP address, browser or user-agent information, timestamps, file names, file types, file sizes, and submission metadata. These signals support service operation, troubleshooting, security, and complimentary-use limits.

Information collected for the Career Positioning Brief and Positioning Advisor

The Career Positioning Brief may process the resume, LinkedIn profile content, target role, career level, target market, target industry, target job description, career notes, first name, email address, and consent information you provide. The brief turns those inputs into a structured positioning result containing scores, narrative direction, value proposition, differentiators, proof themes, risks, headline direction, recruiter introduction, interview stories, actions, and limitations.

The contextual Positioning Advisor receives the structured Career Positioning Brief, your current question, and a limited number of recent chat turns so it can answer questions about the score, priorities, recruiter concerns, LinkedIn direction, evidence gaps, and interview preparation. The advisor does not require another copy of the original resume or LinkedIn file and does not independently know experience that was not included in the supplied materials or question.

The current advisor provides up to five complimentary questions per brief. Where the database is configured, the application may store an advisor usage count, last-used timestamp, and general answer category for service operation and usage limits. The current implementation is not designed to store the advisor question text, answer text, or chat transcript in the database.

Information collected for Target Role Match and the 30-Day Positioning Workspace

When secure checkout is configured, ResumeShortList collects the product selected, first name, last name, email address, and an optional originating report ID before redirecting you to Stripe. Stripe processes the payment. ResumeShortList may receive and store the Stripe session identifier, payment status, amount, currency, product code, and limited purchase metadata needed to verify payment and provision access.

A paid Target Role Match or positioning workspace may store a workspace ID, product type, activation and expiry timestamps, entitlement limits, usage counters, progress checklist status, an optional linked report ID, saved role-match outputs, target role, career level, target market, file name, and limited request metadata such as IP address and browser information.

To create a Target Role Match, the application processes the resume file and pasted job description you provide. The current paid-workspace implementation is designed to retain the generated analysis, role context, file name, usage information, and limited metadata rather than the raw extracted resume text, raw pasted job description, or uploaded resume file in the workspace record after the request completes.

Paid workspaces use a private access token. The server stores a one-way hash of the token rather than the raw token. The raw token may appear in the private access link returned after successful payment verification and may be sent by service email when email delivery is configured. The website may store the workspace ID and raw access token in your browser's local storage after you open the workspace so you can return without entering the token again.

Keep the private access link and token confidential. Anyone who obtains both the workspace ID and valid token may be able to access the workspace until it expires or the token changes. You can remove the locally stored access details by clearing site data for ResumeShortList in your browser. Clearing browser storage does not delete the server-side workspace record.

The visible access period may be seven or thirty days depending on the product. Expiry disables normal workspace access, but it does not currently guarantee immediate deletion of the underlying purchase, workspace, usage, or analysis records. You may request deletion using the contact information below.

Customer accounts, secure support requests, and experience feedback

Customer account access uses the email associated with a prior submission or purchase. A requested sign-in link is designed to be one-time, expire after a limited period, and be replaced by a newer successfully delivered link. The server stores token hashes, session records, expiry and revocation timestamps, and limited security or delivery metadata rather than the raw sign-in token.

When you submit a support request from a signed-in account, ResumeShortList stores the verified account email, allowlisted support category, subject, message, priority, status, timestamps, and an optional reference to a workspace or founder-led service that the server confirms belongs to the same account. Customer-facing support responses use a human-readable product label rather than exposing the internal related record identifier.

Support requests may be visible in your account history and in the protected ResumeShortList operations dashboard. When transactional email is configured, a new support request may be emailed to the service owner using the verified account email and the support information you submitted so the request can be reviewed. Do not include passwords, sign-in links, account sessions, workspace access credentials, payment-card details, government identifiers, health information, or other information that is unnecessary to resolve the request.

When you submit experience feedback, ResumeShortList may store the verified account email, selected experience area, rating from one to five, optional comment, optional allowlisted product code, and timestamp. The protected operations dashboard presents aggregate response counts and average ratings by area. Customer email and comment text are not included in those aggregate insight summaries.

Support and feedback submission rates may be limited to protect service availability and reduce abuse. These limits do not prevent you from using the contact email below for an urgent privacy, security, billing, or deletion concern.

How the information is used

Resume, LinkedIn, brief, advisor, workspace, payment-verification, intake, account, support, and feedback information is used to extract readable text, evaluate supplied career material, generate a diagnostic score or positioning output, answer contextual questions, provision and protect paid access, enforce product limits, save permitted results, deliver the requested service, prevent repeated complimentary use, respond to support requests, operate service workflows, understand aggregate customer friction, and improve the product.

When you provide both a resume and LinkedIn profile, the application may compare the documents for alignment in role direction, seniority, dates, titles, major achievements, capabilities, and professional narrative. A difference is not automatically treated as an error because LinkedIn may appropriately be broader or more conversational than a resume.

Your submission, purchase, account, support request, or feedback is not treated as permission to send unrelated marketing communications. Service-related messages may include your diagnostic or brief confirmation, workspace access link, payment or purchase information, requested consultation information, support responses, or delivery updates. Any broader marketing program should use a separate consent mechanism.

AI-assisted processing

When the production AI integration is configured, extracted resume text, supplied LinkedIn profile content, optional resume-comparison content, career notes, role context, pasted job descriptions, structured brief content, current advisor question, and limited recent advisor conversation may be sent to the OpenAI API to support the product or answer you request. The application also uses built-in scoring rubrics and deterministic signals to improve consistency and explainability. If the AI integration is unavailable, the relevant built-in rubric or deterministic advisor response may be used to provide a limited fallback result.

Support requests and experience-feedback comments are not intentionally sent to the OpenAI API as part of the current support and aggregate-insight implementation.

ResumeShortList does not train its own general-purpose AI model on uploaded resumes, LinkedIn profiles, briefs, workspaces, advisor questions, support requests, or feedback. Third-party providers process information under their own service terms, privacy commitments, and data controls. Do not provide information that is unnecessary for career positioning or support, or that you are not comfortable having processed for the requested purpose.

Database records and file storage

When the production database is configured, ResumeShortList stores diagnostic, brief, workspace, purchase, account, founder-service, support, feedback, or version records containing the customer details provided, product context, generated result, status, timestamps, entitlement or usage information, limited request metadata, and file names associated with the submission. These records support service operation, troubleshooting, follow-up, complimentary-use controls, paid access, product limits, customer support, aggregate experience review, and contextual advisor usage.

For the complimentary resume diagnostic, the original resume file is stored in private object storage only when that storage integration is configured. If file storage is not configured, the file may still be processed temporarily in memory to extract text and generate the report. Diagnostic records and extracted results may still be retained in the configured database.

The current LinkedIn diagnostic processes pasted profile content and uploaded LinkedIn or resume files to generate the report. The implementation is designed to retain the diagnostic result and limited submission metadata rather than the raw profile text, extracted resume text, or uploaded files. This statement describes the current application behavior and will be updated if storage practices change.

Current LinkedIn diagnostic behavior: the LinkedIn diagnostic stores the analysis result, contact and intake details, file names, timestamps, and limited request metadata when the database is configured. The current LinkedIn diagnostic implementation does not intentionally store the raw pasted profile text, extracted LinkedIn profile text, extracted comparison-resume text, or uploaded LinkedIn/resume files after the request completes.

Current Career Positioning Brief behavior: when the database is configured, the brief stores the generated structured result, contact and intake details, file names, timestamps, and limited request metadata. The current advisor may update the brief record with usage count, last-used timestamp, and general answer category. It is not designed to store advisor question or answer content.

Current workspace behavior: paid workspaces store entitlement, progress, usage, purchase-verification, access-hash, and generated role-match records as described above. The current implementation is not designed to retain the raw workspace resume file, extracted resume text, or raw job-description text in those workspace records after analysis completes.

Current support and feedback behavior: secure support records store the customer-written subject and message so the request can be resolved. Feedback records may store an optional comment. Protected operational-health and aggregate experience-insight responses are designed to expose minimum operational status, counts, ratings, and allowlisted labels rather than tokens, Stripe identifiers, resume text, job-description text, request IPs, or provider payloads.

Current retention limitation: ResumeShortList has not yet published a fixed automatic deletion period for diagnostic records, briefs, workspace records, purchase records, account records, support requests, feedback, analysis results, or resume files stored through configured services. Product access may expire before the underlying records are deleted. Until a formal retention schedule is implemented and verified, users should request deletion when they no longer want their information retained. This policy will be updated when a defined retention period is operational.

LinkedIn platform limitations

The LinkedIn Positioning Diagnostic reviews only the profile content and career context you provide. It does not log in to LinkedIn, access private profile data, view recruiter activity, retrieve profile views or search impressions, or access LinkedIn's private search or ranking algorithms.

Any discussion of relevant role, capability, industry, or leadership language is directional positioning guidance. It is not a prediction of ranking, profile visibility, recruiter discovery, outreach, interview probability, or employment outcomes.

Email notifications and follow-up

When email delivery is configured, ResumeShortList may send a diagnostic or brief confirmation, payment or purchase update, one-time account sign-in link, private workspace access link, expiry-related service message, requested support communication, or founder-service delivery update to the address you provide. It may also notify the service owner of a new submission, purchase, or secure support request so requested service or support can be provided. Those owner notifications may include the verified customer email, product or support category, customer-written subject or message, priority, human-readable related purchase label, and relevant intake details. The resume or LinkedIn file itself is not intentionally included in standard confirmation or support-notification email.

Network, recruiter, and employer sharing

ResumeShortList does not intentionally circulate your resume or profile to third-party contacts solely because you completed a diagnostic, purchased a workspace, created a brief, opened an account, submitted feedback, or requested support. Any resume circulation, referral outreach, recruiter introduction, or opportunity sharing is a separate activity and requires explicit permission for the relevant context.

Permission to discuss outreach does not guarantee an introduction, recruiter response, interview, job offer, or employment outcome.

Analytics and error monitoring

When analytics are configured, ResumeShortList may collect page views and product events such as diagnostic starts, file selection, successful completion, generated score, workspace product selection, checkout start, payment-verification outcome, workspace access, role-match completion, progress updates, report linking, advisor question starts and completions, general answer category, remaining advisor usage, scheduling clicks, and error events. These events are intended to improve the service and understand where users encounter friction.

Resume contents, LinkedIn profile contents, pasted job descriptions, career notes, support-request messages, feedback comments, workspace access tokens, workspace IDs, report IDs, advisor question or answer text, names, emails, phone numbers, payment-card details, and uploaded files should not be intentionally included in frontend analytics events. Microsoft Clarity may be used for session insights, with sensitive form fields, support inputs, chat inputs, access credentials, and uploaded content intended to remain masked.

Technical error monitoring may include page path, browser information, timestamp, status, product code, and error details. Resume, LinkedIn, brief, workspace access credential, payment-card, support-message, feedback-comment, or advisor conversation content is not intentionally sent as part of frontend error reports.

Service providers and cross-border processing

ResumeShortList relies on service providers for functions such as hosting, database operation, private object storage, AI-assisted analysis, analytics, email, scheduling, error monitoring, and payment processing. Stripe processes payment-card information through its own checkout service. Depending on the provider and configuration, information may be processed or stored outside Canada.

ResumeShortList remains responsible for selecting and managing service providers appropriate to the service. This policy does not claim that any website or transmission method is completely secure.

Security and information you should remove

Administrative access controls, private access tokens, one-way token hashes, product limits, file validation, rate limits, exact-origin controls, and private storage controls are used where configured. No service can guarantee absolute security.

Before providing a resume, LinkedIn profile, job description, career note, advisor question, support request, or feedback comment, remove information that is not needed for career positioning or the requested support, including SIN or social-insurance numbers, passport numbers, financial account details, private health information, passwords, sign-in links, account sessions, workspace access credentials, security answers, or other highly sensitive identifiers. Payment-card details should be entered only on the secure Stripe checkout page when available.

Deletion, access, correction, and questions

You may request deletion of your resume, LinkedIn diagnostic record, Career Positioning Brief, workspace, saved role matches, purchase-associated service record, customer account record, support request, feedback record, advisor usage record, and related records, ask what information is associated with your submission, or request correction of inaccurate contact information by .

Include enough information to identify the relevant submission, such as the email address used, the type of product, report, workspace, service, or support request when available, and the approximate submission or purchase date. Do not send a copy of sensitive identification documents, sign-in links, account sessions, or workspace access credentials unless specifically required through a secure process.

No guarantee of employment outcomes

Resume and LinkedIn diagnostics, Target Role Matches, Career Positioning Briefs, positioning workspaces, founder-led services, Positioning Advisor answers, support, and experience feedback provide or improve directional career-material and service guidance. They do not guarantee ATS passage, LinkedIn ranking, recruiter discovery, recruiter responses, interviews, job offers, application success, compensation outcomes, or employment.

Contact

Privacy questions, concerns, or deletion requests can be sent to .

Return to the Resume Diagnostic, explore the Positioning Workspace, start the LinkedIn Diagnostic, create a Career Positioning Brief, review the scoring methodology, or read the Terms of Service.