Privacy Policy
Effective: August 6, 2026
1. Overview
EvoResume is an online résumé builder. This policy explains what we collect, why we collect it, who processes it on our behalf, and what you can ask us to do with it. It covers evoresume.com and the builder application.
For data-protection purposes EvoResume is the controller of the personal data described below. Reach us about anything in this policy at support@evoresume.com.
2. Information We Collect
Account data: your email address when you sign up. If you use Google Sign-In we also receive your name and profile picture from Google.
Résumé content:while you are editing, your résumé is held in your browser’s localStorage. When you save a résumé to your account, that content is also stored on our servers so it is there when you sign in again from another device. Saved résumés are held against your email address in our database (see “Where your data is processed” below).
Payment data: purchases are handled by Stripe. We never see or store your card number. We keep the identifiers Stripe gives us — a customer id, the plan you bought and when it expires — so we know what your account has access to.
Usage and analytics data: we use Google Analytics 4, which sets cookies and collects page views, approximate location, device and browser information, and a randomly generated identifier, and the Meta (Facebook) Pixel, which records the pages you visit here and reports them to Meta so we can measure and target advertising. Both load only once you accept cookies — see section 5.
Live chat:we run chat ourselves rather than embedding someone else’s widget. If you open it, we store what you write, your email address and WhatsApp number if you give them, the page you started from and your browser’s user-agent on our own infrastructure (Upstash) for 30 days, after which the conversation is deleted automatically. We ask for a number only when a chat has gone unanswered longer than we promised, and we use it to answer that conversation, nothing else. Sending a message emails us so that someone answers. No third party receives any of it, and no chat cookie is set: your browser keeps a conversation id in local storage, which is what lets the thread still be there when you come back.
Server logs and error reports:IP address, request path and timestamp, kept for security and abuse prevention. If a page in the app throws an error, we record the error message, the page it happened on and your browser’s user-agent so we can fix it.
3. How We Use Your Data, and Our Legal Basis
- Email — to authenticate you and send one-time sign-in codes. Necessary to perform our contract with you.
- Name and picture (Google sign-in only) — to show who is signed in. Contract.
- Saved résumés — to provide cloud storage and sync, which is part of what a paid plan buys. Contract.
- Payment identifiers — to grant the access you paid for, handle refunds and meet tax and accounting obligations. Contract and legal obligation.
- Analytics, live chat and advertising measurement — to understand how the site is used, answer questions, and measure which ads bring people here. Your consent, which you can withdraw at any time.
- Server logs and error reports — to keep the service running and prevent abuse. Our legitimate interest in a secure, working product.
We do not sell or rent your personal data, and we do not share it with third parties for their own marketing.
4. Third Parties Who Process Data For Us
Google (OAuth): handles sign-in if you choose Google. See Google’s Privacy Policy.
Google (Gemini API):when you use an AI feature — the AI coach, a bullet rewrite, a CV import, job tailoring, a cover letter, or an ATS scan against a job description — the relevant text from your résumé and any job description you paste is sent to Google’s Gemini API to generate the response. Do not paste anything into those fields you would not want processed by Google.
Google Analytics: site analytics, loaded only with your consent.
Meta (Facebook): the Meta Pixel, loaded only with your consent. It tells Meta which pages of ours you viewed, which Meta may combine with an account you hold with them. See Meta’s Privacy Policy.
Stripe: payment processing, including card details, which go to Stripe directly and never through our servers.
Resend: delivers sign-in codes and template download emails, alerts us that a chat is waiting, and carries the message you send from the chat widget if chat storage is down. Receives your email address, and in those last two cases what you wrote, for those purposes only.
Supabase and Upstash:the databases that hold account records, saved résumés, purchase grants, live-chat conversations and recent error reports.
Vercel / our hosting provider and Cloudflare: serve the site and see request metadata including your IP address.
5. Cookies
Strictly necessary. One HTTP-only session cookie keeps you signed in. It holds a signed token with your email, name and plan — no advertising identifiers. A small cookie also records your cookie choice itself. These are set without consent because the site cannot work without them.
Analytics and advertising.Google Analytics and the Meta Pixel set their cookies only after you accept them in the cookie banner. Decline, and neither script loads at all. You can change your mind at any time from the “Cookie settings” link in the footer; withdrawing consent stops them loading on your next page view. Live chat is not in this group: it is ours, sets no cookie, and works whichever way you answer.
Local storage.Your working résumé, design preferences and panel layout are kept in your browser under keys prefixed with bdr_, and live chat keeps its conversation id and your address under evo_chat_. This is not a cookie and is not sent anywhere by itself, but clearing your browser data will delete anything you have not saved to your account, and will detach you from an open chat.
6. Where Your Data Is Processed
We are a small operation using US-based infrastructure providers, so your data — including saved résumé content — is processed in the United States and potentially in other countries where our providers operate. Where data is transferred out of the UK or European Economic Area, our providers rely on the standard contractual clauses approved for that purpose. You can ask us for details of any specific transfer.
7. Data Retention
Session cookies expire after 7 days. Account records and saved résumés are kept until you delete the résumé or ask us to close your account. Purchase records are kept for as long as tax and accounting rules require, typically six years. Error reports are capped at the 200 most recent and roll off after that. Anything in your browser’s local storage stays until you clear it or use the in-app “Reset”.
8. Your Rights
Wherever you live, you can ask us to give you a copy of the personal data we hold about you, correct it, delete it, or send it to you in a portable format. If you are in the UK or EEA you can also object to or ask us to restrict processing, and withdraw consent for analytics and chat at any time without affecting what came before. If you are in California, you have the right to know what we collect and to ask us to delete it, and we do not sell or share personal information as those terms are defined there.
Email support@evoresume.comand we will respond within 30 days. You can delete individual résumés yourself from your dashboard, and clear local data at any time by clearing your browser storage.
If you think we have handled your data badly, you can complain to your local data-protection authority — in the UK, the Information Commissioner’s Office at ico.org.uk. We would rather you told us first.
9. Security
Data in transit is encrypted with HTTPS. Session tokens are signed and stored in HTTP-only cookies that JavaScript cannot read. We do not store passwords — sign-in is by one-time code or Google. Paid template files are served through expiring signed links rather than public URLs.
10. Children
The Service is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has given us data, email us and we will delete it.
11. Changes to This Policy
We may update this policy. The effective date at the top reflects the latest revision, and material changes will be flagged on the site rather than made quietly.
12. Contact
Privacy questions or data requests: support@evoresume.com or Live Chat