← Back to open roles

Privacy Notice

Draft — not yet finalized.

This page is a draft. It describes what the application actually does with your data, generated from the codebase for transparency while a finished, legally-reviewed policy is prepared. It has not been reviewed by Oneremit's legal counsel and should not yet be relied on as a complete or binding statement of Oneremit's data practices. Retention periods, lawful basis, and international-transfer safeguards below are described in plain terms and still need to be confirmed and formalized by Oneremit.

What we collect

When you apply: your name, email, phone number (optional), portfolio/LinkedIn link (optional), a short note (optional), and your CV (as a file, or pasted text). If you use the optional "check your fit" tool before applying, the CV text or file you provide there is used only for that one-time check and is not stored or linked to your application.

How we use it

Your CV text is sent to a third-party AI service (via OpenRouter, which may route the request to a provider such as Google) to score how well it matches the role's stated requirements. A reviewer at Oneremit sees that score alongside your application to help decide whether to move forward with you. We do not use your data to train any AI model.

Where it's stored

Application data is stored in a Postgres database (hosted via Supabase) and your CV file, if uploaded, in Supabase's file storage — both currently provisioned in the EU (eu-west-2). The AI scoring step may involve your CV text being processed outside the EU, depending on which provider handles the request; the exact data-location and transfer safeguards for that step still need to be documented here.

How long we keep it

We don't yet have a formal retention schedule. In practice, your application is kept until you withdraw it (see below) or until Oneremit's hiring process for that role concludes. This needs a concrete retention period set by Oneremit.

Your choices

Cookies

This site only sets cookies strictly necessary to run it — a session cookie for reviewer logins and a CSRF-protection cookie. It doesn't use analytics, advertising, or tracking cookies, so there's nothing here requiring a cookie-consent banner.

Still to be added

This draft is missing pieces a finished notice needs: the specific lawful basis relied on (GDPR Art. 6), a named contact/DPO if Oneremit designates one, a firm retention schedule, and confirmed international-transfer safeguards for the AI scoring step. Oneremit should complete these before treating this as final.