Web Analytics

Privacy Policy

Last updated: 20 March 2026

1. Introduction

BestCV.pro ("the Service"), operated by BestCV ("we", "us", "our"), is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data. By using the Service, you consent to the practices described here.

2. Data We Collect

2.1 Account Data

When you sign in with Google, we receive and store:

  • Your name
  • Your email address
  • Your Google profile picture URL
  • Your Google account ID

We also generate a unique referral code for your account.

2.2 Uploaded Content

When you use the Service, you may upload:

  • Your CV (PDF or Word format)
  • A professional photo (JPEG or PNG)
  • A job description (text)

2.3 Generated Content

We store the AI-generated tailored CV produced from your inputs.

2.4 Payment Data

Payments are processed by Stripe. We store a record of your payment (amount, currency, status, Stripe session ID) but do not store your credit card number or full payment details. Stripe's own privacy policy governs how they handle your payment information.

2.5 Usage Data

We use Google Analytics and Statcounter to collect anonymised usage data such as page views, device type, browser, and approximate location. This data is not linked to your personal identity.

2.6 Cookies

We use the following cookies:

  • Session cookie — to maintain your authentication state.
  • Referral cookie — a temporary HTTP-only cookie (7-day expiry) that stores a referral code if you arrive via a referral link.
  • Analytics cookies — set by Google Analytics and Statcounter for usage tracking.

3. How We Use Your Data

We use your data exclusively for the following purposes:

  • Service delivery — processing your CV through our AI to generate a tailored version.
  • Payment processing — charging for the Service via Stripe.
  • Transactional emails — sending you a welcome email, CV-ready notification, and payment receipt via Mailgun.
  • Referral tracking — attributing new sign-ups to the referring user.
  • Service improvement — understanding usage patterns through anonymised analytics.
  • Abuse prevention — detecting and preventing misuse of the Service.

4. AI Processing

Your uploaded CV and job description are sent to an AI model hosted on DigitalOcean infrastructure for processing. The AI generates a tailored CV based on your inputs. We do not use your data to train AI models. The AI processing is performed solely to deliver the Service to you.

5. Data Storage & Security

Your data is stored on secure infrastructure hosted by DigitalOcean, including:

  • Database — PostgreSQL database for account, payment, and CV records.
  • File storage — DigitalOcean Spaces (S3-compatible) for uploaded CVs, photos, and generated documents. Files are stored with unique keys and accessed via time-limited pre-signed URLs.

We implement industry-standard security measures including encrypted connections (HTTPS/TLS), secure authentication via OAuth 2.0, and access-controlled storage.

6. Data Retention

  • Account data — retained as long as your account exists.
  • Uploaded files and generated CVs — retained for up to 90 days after creation, after which they may be deleted.
  • Payment records — retained for accounting and legal compliance purposes as required by UAE law.

7. Data Sharing

We do not sell your personal data. We share data only with the following third-party services, solely to operate the Service:

  • Google — OAuth authentication.
  • Stripe — payment processing.
  • DigitalOcean — infrastructure hosting and AI inference.
  • Mailgun — transactional email delivery.
  • Google Analytics & Statcounter — anonymised usage analytics.

Each of these services operates under their own privacy policies. We may also disclose data if required by law or to protect our legal rights.

8. Your Rights

You have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request correction of inaccurate data.
  • Deletion — request deletion of your account and associated data.
  • Data portability — request your data in a portable format.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

9. Children

The Service is not intended for individuals under the age of 18. We do not knowingly collect data from minors. If we discover that we have collected data from a minor, we will delete it promptly.

10. International Data Transfers

Your data may be processed and stored in data centres outside your country of residence. By using the Service, you consent to the transfer of your data to jurisdictions that may have different data protection laws than your own.

11. Changes to This Policy

We may update this Privacy Policy at any time. We will update the "Last updated" date at the top of this page. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.

12. Governing Law

This Privacy Policy is governed by the laws of the United Arab Emirates, including the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing regulations.

13. Contact

For questions or requests regarding your privacy and data, contact us at [email protected].