Legal

Privacy Policy.

What we collect, why, who touches it, how long we keep it, and how to make us forget you. Written in English, kept as short as we can keep it.

Last modified April 22, 2026 · Governing law State of California · Questions? legal@thecareersprint.com

1. Introduction

The Career Sprint ("TCS," "we," "our") is a human-run resume rewrite and application service. This Privacy Policy explains what personal data we collect when you use thecareersprint.com or our services, how we use it, who we share it with, and the choices you have. This policy is incorporated into and forms part of our Terms of Use.

If any of it is unclear, email legal@thecareersprint.com and a human will reply.

2. What we collect

We collect the minimum we need to do the sprint for you, and nothing else. In plain terms:

  • Account & contact: name, email, and anything you type into the intake form (target role, seniority, location, comp range, links to your LinkedIn / portfolio).
  • Resume uploads: the .pdf, .docx, or .txt you upload — at checkout, at intake, or through the Resume Report Card tool.
  • Payment metadata: the cart you purchased, your billing email, and the last 4 of your card. Full card data is handled by Stripe — we never see it.
  • Site analytics: page views, clicks, referrer, device/browser, coarse region (city-level, not address). Captured via PostHog. No recordings of keystrokes or form inputs.
  • Server logs: IP address, timestamp, and request path, kept for ~30 days for abuse prevention and debugging.

The Resume Report Card is the one thing that's mostly browser-local — parsing runs in your tab and the file never leaves it. We do capture your email + letter grade + category breakdown when you submit, so we can send you a copy.

3. How we use it

We use your personal data to:

  • Deliver the service you paid for (rewrite your resume and LinkedIn, submit applications on your behalf, schedule coaching calls).
  • Send you transactional email about your order — receipts, intake form, weekly trackers, revision drafts.
  • Send you occasional product email (new features, results from other sprinters). You can unsubscribe in one click; we won't resubscribe you.
  • Understand how the site is used so we can make it less annoying.
  • Comply with law, respond to lawful requests, and defend our rights.

We do not sell your personal data. We do not share it with advertisers. We don't train AI models on your resume.

4. Who we share it with

We use a short list of vetted processors to run the service. Each one only sees the slice of data they need:

StripePayments & receipts. Sees: card + billing details. Does not see: your resume.
SupabaseDatabase for orders, intake form answers, Report Card leads. Data lives in US regions.
CloudflareSite hosting + R2 object storage for resume uploads. Sees: everything you send to the site.
PostHogProduct analytics. Sees: page events and coarse device / region. Does not see: resume content or payment data.
ResendTransactional & product email delivery. Sees: your email and the message body we send you.
Google FontsWeb fonts loaded over HTTPS. Sees: your IP and user-agent on first page load.

We will also share data when we genuinely have to: a lawful subpoena, a fraud investigation, or an actual emergency involving risk to a person. We'll narrow the disclosure to what's required and, where the law lets us, tell you.

If TCS is ever acquired or merged, your data transfers with the company under terms at least as protective as this policy; we'll notify you before anything changes.

5. Cookies & analytics

We keep cookies light on purpose:

  • Necessary: session cookies for checkout and (if you sign in) your portal session. Can't be turned off without breaking the site.
  • Analytics: a first-party PostHog cookie for product analytics. You can opt out by setting a __ph_opt_in_out cookie or via any standard privacy extension.

We don't use ad-tracking cookies. We don't run Facebook Pixel, Google Ads, or similar.

6. Retention

How long we hold onto things, by default:

  • Resume uploads (Sprint customers): 90 days after your final deliverable ships, then deleted from Cloudflare R2.
  • Resume uploads (Report Card tool): parsed in your browser and never uploaded. If you email yourself a copy, the file travels through Resend to your inbox and we don't retain it.
  • Report Card lead record (email + grade summary): 12 months, then anonymized.
  • Order records (in Supabase): 7 years. We're required to retain financial records for tax purposes.
  • Server + analytics logs: 30 days (logs), 12 months (PostHog events), then rolled off.
  • Account data (if you signed into a portal): kept as long as the account is active; 30-day grace period after deletion request, then permanently removed.

You can ask us to delete anything sooner, at any time. See your rights below.

7. Your rights

Wherever you're based, you can:

  • Access a copy of the data we hold on you.
  • Correct anything that's wrong or out of date.
  • Delete your data (subject to the tax-retention carve-out above; we'll minimize what stays).
  • Export your intake answers and uploaded files in their original formats.
  • Opt out of product email (there's an unsubscribe link on every one) and of analytics (see cookies).
  • Object to how we use your data, or ask us to restrict that use.

To exercise any of the above, email legal@thecareersprint.com. We respond within 30 days — usually much faster. We don't charge a fee and we don't require a lawyer.

8. GDPR (EU / UK)

If you're in the EU, EEA, or UK, you have rights under the GDPR and UK GDPR. The Career Sprint is the data controller; the processors in section 4 act as processors under our instructions.

Our legal bases for processing:

  • Contract — to deliver the Sprint services you paid for.
  • Legitimate interest — to run and improve the site, prevent fraud, and send product updates you've already engaged with. You can object any time.
  • Consent — for marketing email sent to people who aren't current customers. Withdraw any time.
  • Legal obligation — for tax records and responses to lawful requests.

You have the right to lodge a complaint with your national data-protection authority. We'd appreciate a chance to address it first — email legal@thecareersprint.com.

9. CCPA (California)

California residents have additional rights under the CCPA / CPRA:

  • The right to know the categories of personal information we collect, where we got it, why, and who we share it with (see sections 2–4).
  • The right to delete personal information we've collected.
  • The right to correct inaccurate personal information.
  • The right to limit use of sensitive personal information.
  • The right to opt out of "sale" or "sharing" of personal information. We do neither, so there's nothing to opt out of.
  • The right to non-discrimination — we won't charge you more or give you worse service for exercising these rights.

To exercise any California right, email legal@thecareersprint.com. You can also authorize an agent to act for you; we'll verify the agent's authority before proceeding.

10. Security

We keep your data on servers run by Cloudflare and Supabase, behind TLS in transit and AES-256 at rest. Access inside TCS is limited to the humans who actually need it — the writer on your account, the person who processes payments, and the founder. No ad-hoc database exports; every change is logged.

No system is perfectly secure. If we learn of a breach that affects your personal data, we'll notify you without undue delay — and within 72 hours where the law requires — with what happened, what we've done about it, and what you should do.

11. International transfers

TCS is based in California. Our processors operate in the United States and the European Union. If you're in the EU / EEA / UK, your data may be transferred to the US under Standard Contractual Clauses or equivalent safeguards put in place by each processor.

12. Children

The Career Sprint is built for adult job seekers. You must be at least eighteen (18) to use the site or services. We don't knowingly collect data from anyone under 18. If you believe a child has given us personal data, email legal@thecareersprint.com and we'll delete it.

13. Changes

If we make a material change to this policy, we'll update the "Last modified" date at the top and — for changes that actually affect you — email you or put a banner on the site for at least thirty (30) days. Continued use of the service after the change takes effect means you accept the new version.

14. Contact

Questions, deletion requests, GDPR / CCPA requests, or anything else privacy-related: email legal@thecareersprint.com or write to The Career Sprint, 3753 W Turner Rd., Lodi, CA 95242.

Last modified on April 22, 2026.