Privacy Policy

Last updated: 18 September 2026

1. Who we are

GoInRemote is a job board for remote work, and the data controller for everything described in this policy. We hold the data you add to this platform. We never sell it, and the only companies that receive any of it are the service providers listed in section 7, each acting on our instructions and for that purpose alone.

You can reach us about anything in this policy through our contact page. It reaches the same people an email would, and it tells you straight away that your message arrived.

We are established in Spain, so this policy is governed by the EU General Data Protection Regulation and by Spanish Organic Law 3/2018 on data protection and digital rights (LOPDGDD).

2. What we collect

Everything below is information you type in or upload yourself. We do not buy data about you, and we do not build a profile of you from anywhere other than this site.

Everyone with an account

  • Name, email address, and a password we store only as a bcrypt hash, never in readable form
  • Whether your email has been confirmed, and when
  • A session record so you stay signed in, and the date you were last active
  • Your IP address, for a short time, so we can rate limit sign-ins and form submissions and block abuse. It is not used to profile you
  • Anything you write to us through the contact or help form, with the address you gave, so we can answer

Candidates

  • Profile details: headline, location, about you, years of experience, desired role, desired location and contract type
  • Links you choose to add: LinkedIn, GitHub, X, portfolio
  • The phone number on your profile, if you enter one. That one is never shown to employers
  • Your CV file, your skills, languages, work history, education, awards and publications
  • When you upload a CV, we read it on our own server to suggest entries for your profile — your jobs, education, skills, languages and links — and show them to you before anything is saved. Nothing is added until you confirm it. Your CV is not sent to any AI service or other outside company to do this. What we read is kept with your account so you can see it in your data export, and deleted with it
  • Which jobs you told us you applied to, so your tracker is accurate
  • When you apply through GoInRemote rather than on the employer's own site, what you put on the application form: your name, email address, phone number, country of residence, whether you need visa sponsorship, whether you have the right to work in the job's country, your answer to the gender question, your cover letter, and your answers to any questions that employer added
  • A record of when an employer opened your profile or downloaded your CV. It is kept so we can meter their plan and so you can see it in your data export
  • Whether an employer has saved you to a shortlist, and the score our matching calculates between your profile and one of their roles. The score is worked out from your skills, experience and desired role at the moment they ask for it, and it is a sorting aid for them, not a decision about you
  • Whether your profile is public and whether you are open to work

Employers

  • Company name, website, logo, description, industry, type, size and location
  • A contact email and phone for your company, if you provide them
  • Your job listings, and which candidate profiles or CVs your team has opened
  • Subscription state. Card details go straight to Stripe and never reach our servers

Job alerts

  • Your email address, the categories and job titles you asked for, and how often you want them

3. What we do not collect

  • No advertising or analytics trackers. There is no Google Analytics, no Meta pixel, no Hotjar and no session recording
  • One third-party script, and only one: Google reCAPTCHA, which runs on the signup, contact and application forms to tell a person from a bot. It sees your IP address and how you interact with that page, and Google may set its own cookies. We use it because without it these forms are filled by scripts within days. It runs nowhere else on the site
  • No cross-site tracking by us, and nothing of ours that follows you once you leave
  • No card numbers. Stripe handles payment details end to end
  • No data bought from data brokers or scraped from elsewhere

4. How we use it

  • To run the account you asked for and keep you signed in
  • To show your listings to candidates, or your profile to employers if you made it public
  • To send job alerts you subscribed to, password resets, and email confirmations
  • To take payment for an employer subscription, through Stripe
  • To enforce plan limits, such as how many jobs a company may have live at once
  • To keep the site working: rate limiting, spam prevention and debugging

We do not use your CV or profile to train machine learning models, and we do not use your data to advertise to you.

5. Our lawful basis for each use

The GDPR does not let anyone process personal data simply because it is useful. Every use needs a lawful basis under Article 6, and ours are set out below so you can see which one applies to what.

  • Running your account, your profile, CV, applications, saved jobs and the job postings employers publish. Basis: performance of a contract, Article 6(1)(b). This is the service you signed up for, and we cannot provide it without this data
  • Taking payment for employer subscriptions, billing details, VAT number and invoice records. Basis: performance of a contract, Article 6(1)(b), and legal obligation, Article 6(1)(c), for the years that Spanish tax and accounting law requires us to keep invoices
  • Job alerts and the newsletter, your email address and the searches you asked to be alerted about. Basis: consent, Article 6(1)(a). You gave it by subscribing and you can withdraw it from the unsubscribe link in every message, without logging in. Spanish law (LSSI-CE Article 21) requires that consent for commercial email, which is why we will not add you to a list you did not ask for
  • Keeping the service secure and working, rate limiting, blocking abuse and fraudulent postings, diagnosing faults. Basis: legitimate interests, Article 6(1)(f). Our interest is in a job board that is not overrun by fraud, and we judge that this does not override your rights because the data involved is minimal and is never used to profile you
  • Answering messages you send us through the contact form. Basis: legitimate interests, Article 6(1)(f), you wrote to us and expect a reply
  • Complying with the law, including a valid order from a court or authority. Basis: legal obligation, Article 6(1)(c)

Withdrawing consent stops the processing that relied on it from that point onwards. It does not make what happened before unlawful, and it does not affect the data we hold on a different basis, such as your account itself.

Special category data. We do not ask for, and have no lawful basis to process, the special categories in Article 9, health, religion, ethnicity, trade union membership, sexual orientation, political views. A CV is free-form and you may include such details yourself, but we do not seek them, do not index them and do not use them to rank or filter candidates. Please leave them out.

We do not make decisions about you by automated means alone, and we do not profile you in any way that produces legal or similarly significant effects. Matching a candidate to a job is a suggestion shown to a human, who decides.

6. Who can see your data

  • Employers can search candidate profiles only if you set yours to public. A new profile is private, so that is a switch you have to turn on yourself, and turning it off again takes you out of their search immediately. The phone number on your profile is never shown. Your profile email address is shown only to Enterprise subscribers, and only if you switch that on too
  • Your CV is downloadable only by a subscribed employer whose plan includes CV downloads, and every download is recorded. You can see those records in your data export
  • An employer you apply to sees the application you sent them, whatever your profile settings say: that is the point of applying. The CV, cover letter and screening answers go to every employer who receives an application; the email address and phone number you typed on the form reach Enterprise subscribers
  • Colleagues on an employer team share one company record, so they see the same listings and the same candidate activity
  • Nobody else. Your profile is not indexed for sale, syndicated to other job boards, or passed to recruitment agencies

7. Service providers we rely on

These, and each one only receives what it needs to do its job:

  • Stripe (Stripe Payments Europe, Ltd., Ireland), for employer subscriptions. Card and billing details go to them directly and never reach us
  • Supabase, which hosts the database and the private file storage where your profile and your CV live. Our project is in the EU (Ireland)
  • Railway, which runs the site itself, in its EU West region
  • Zoho (Zoho Corporation B.V., Netherlands, on its EU servers), which sends our email: confirmations, password resets, job alerts and the notification an employer gets when you apply. It receives the address and the message
  • Google (Google Ireland Ltd.), for the reCAPTCHA check on the signup, contact and application forms. It receives your IP address and how you interacted with that form, and nothing about your profile
  • Adzuna, a job-advertising partner whose listings we import. Data flows the other way here: we receive listings from them and send them nothing about you

None of them is permitted to use your data for their own purposes. We will also disclose data where the law requires it, and we would tell you unless legally barred from doing so.

8. Sending data outside Europe

We are based in the EU and we keep your data in the European Economic Area wherever the provider offers it. Some of the providers above are American companies, so a transfer out of the EEA can still happen, most obviously with payments, where Stripe operates globally.

Where that happens, the transfer rests on one of the safeguards Chapter V of the GDPR allows, and never on nothing at all:

  • An adequacy decision from the European Commission, where one covers the country in question, which means the Commission has judged its protection to be equivalent to the EU's
  • The European Commission's Standard Contractual Clauses (the 2021 modules), signed with the provider, together with a transfer impact assessment and whatever additional technical measures that assessment calls for, encryption in transit and at rest, and minimising what is sent in the first place
  • The provider's certification under the EU–US Data Privacy Framework, where it holds a current one

You are entitled to see which safeguard applies to a given provider and to obtain a copy of the clauses. Ask through our contact page and we will send them.

9. We do not sell your data

We do not sell, rent, licence or trade your personal data to third parties. Not to advertisers, not to data brokers, not to recruitment agencies, and not to anyone else, for money or for anything else of value. There is no arrangement under which your profile, CV, email address or browsing on this site is passed to a third party for their own commercial use. If that ever changed we would have to say so here first, and ask you before it applied to data we already hold.

10. California residents (CCPA and CPRA)

If you live in California, the CCPA as amended by the CPRA gives you a specific set of rights. Two of its central questions have short answers here:

  • We do not sell your personal information, and we have not sold any in the preceding twelve months. Not for money, and not for any other thing of value, which is the broader test the CPRA applies
  • We do not share it for cross-context behavioural advertising, which is what “sharing” means under the CPRA. There are no advertising trackers on this site, no Google Analytics, no Meta pixel, no session recording and no third-party script following you between sites. There is one cookie and it keeps you signed in
  • We do not use sensitive personal information to infer characteristics about you, so the right to limit its use has nothing to bite on here
  • We have not sold or shared the personal information of anyone we know to be under 16

Because there is no selling or sharing to opt out of, we do not show a “Do Not Sell or Share My Personal Information” link. A Global Privacy Control signal from your browser needs no special handling for the same reason: there is nothing for it to switch off. If that ever changed, the link would appear here and the signal would be honoured before it did.

Your other rights, and how to use them:

  • Know and access. The categories we collect, why, and where they go are set out in the sections above. Settings has a Download my data button that gives you the actual contents immediately
  • Correct. Every profile field is editable from your dashboard
  • Delete. Deleting your account removes your profile, CV, applications and sessions. We may keep what a law obliges us to keep, such as an invoice, and nothing else
  • Non-discrimination. Using any of these rights costs you nothing and changes nothing about the service you get. We run no financial incentive programme tied to your data

Use the self-serve tools above, or ask through our contact page. We will verify a request against the email on the account before acting on it. An authorised agent may act for you if they provide your signed permission, and we may still verify with you directly.

11. Cookies and local storage

We use one cookie. It is a session cookie that keeps you signed in. It is httpOnly, so scripts cannot read it, it is sent only over HTTPS in production, it is restricted with SameSite, and it expires after 24 hours or when you sign out.

We set no advertising cookies and no analytics cookies. One other party can set one: Google reCAPTCHA, on the signup, contact and application forms, where it is there to keep automated submissions out. That is a security measure rather than an optional extra, which is why the notice at the bottom of the site tells you about it instead of offering a switch: there is nothing here you could turn off and still have a working form. Google's own terms describe what it collects, and if we ever add a cookie that is genuinely optional, you will be asked first.

A few preferences are kept in your browser's local storage rather than sent to us. They never leave your device:

  • Whether you chose light or dark
  • Your language choice
  • Whether you dismissed a notice
  • Jobs you opened to apply for, so we can ask whether you finished. This is why an application is only recorded once you confirm it

Clearing your browser data removes all of it, and nothing is lost but the preferences themselves.

12. Your rights

  • See it. Settings has a Download my data button that exports everything we hold about you as a JSON file, immediately
  • Correct it. Every profile field is editable from your dashboard
  • Delete it. Deleting your account removes your profile, CV, applications and sessions
  • Stop the email. Every alert carries a one-click unsubscribe that needs no login
  • Hide yourself. Turning your profile private removes it from employer search straight away
  • Object or restrict. You may object to processing we base on legitimate interests, and ask us to restrict processing while a dispute about it is resolved
  • Take it with you. The same export is machine-readable JSON, so you can move it to another service
  • Complain. Contact us first if you can, but you may go straight to your national data protection authority, which for anyone in the EEA is the one in the country where you live or work

13. How long we keep it

  • Account and profile data: until you delete the account
  • CV files: until you replace or remove them, or delete the account. A replaced CV is removed from storage shortly afterwards by a scheduled sweep, not kept as an old copy
  • Applications, and the records of who opened your profile or downloaded your CV: until you delete the account. They go with it
  • Job alert subscriptions: until you unsubscribe
  • Messages you send through the contact or help form: they arrive as email in our support inbox and are kept while the matter is open and for a reasonable period afterwards
  • Payment records, including the events Stripe sends us about your subscription: as long as tax and accounting law requires, typically several years
  • Sessions: 24 hours, and immediately on sign-out. Expired ones are deleted by a daily clean-up, along with the short-lived records behind rate limiting
  • Imported listings from our job-advertising partner: removed once they expire at the source. They contain no data about you

14. Security

  • Passwords are stored as bcrypt hashes and cannot be read back, by us or anyone else
  • CV files are held in private storage and served only through an authorised, time-limited link, never from a public URL anyone could guess
  • Sign-in, signup and other sensitive endpoints are rate limited
  • Traffic is encrypted in transit

No system is perfect. If a breach ever affected your data we would tell you and the relevant authority within the time the law allows.

15. Children

This is a service for people old enough to work. It is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will remove it.

16. Changes and contact

If this policy changes we will update the date at the top, and tell account holders by email before anything material takes effect. Questions about your data, or a request to exercise any right above, go through our contact page.