Privacy Policy
Last updated: April 2026
1. Data Controller
2. What Data We Collect and Why
2.1 Account Registration
When you create an account we collect your name, email address, and password (stored as a bcrypt hash). For organisation accounts we additionally collect the organisation name, city, country, phone, website, and a logo image.
Legal basis: GDPR Art. 6(1)(b) — processing is necessary to perform the contract (providing the platform service).
Legal basis: GDPR Art. 6(1)(b) — processing is necessary to perform the contract (providing the platform service).
2.2 Job Applications
When you apply for a job we collect the information you voluntarily submit: cover letter, CV file, and any other fields required by the posting organisation. This data is shared with the organisation that posted the job and stored until the application is resolved or you delete your account.
Legal basis: GDPR Art. 6(1)(b) — necessary to perform the application process you initiated.
Legal basis: GDPR Art. 6(1)(b) — necessary to perform the application process you initiated.
2.3 User Profile
Your public profile may include your name, city, bio, phone number, and a profile photo you choose to upload. You can edit or remove this information at any time from your profile settings.
2.4 Authentication Cookies
We use a single httpOnly, Secure cookie (
Legal basis: GDPR Art. 6(1)(f) — legitimate interest in providing a functional, secure login session. No consent required for strictly necessary cookies under ePrivacy Directive Recital 66.
ngo-jobs-token) to keep you logged in. This cookie is strictly necessary for the service to work and does not track you across other websites. It expires after 30 days or when you log out.Legal basis: GDPR Art. 6(1)(f) — legitimate interest in providing a functional, secure login session. No consent required for strictly necessary cookies under ePrivacy Directive Recital 66.
2.5 Analytics
We use Plausible Analytics — a privacy-first, cookie-free analytics tool. Plausible does not use cookies, does not collect personal data, and does not track visitors across websites or devices. All data is aggregated and anonymised. No consent banner is needed.
For more information see Plausible's privacy policy.
For more information see Plausible's privacy policy.
2.6 Server Logs
Our hosting provider may automatically log IP addresses, browser type, and pages visited for security and debugging purposes. These logs are retained for a maximum of 30 days and are not used for profiling.
3. File Uploads
Uploaded files (CV documents, profile photos, organisation logos) are stored securely on cloud storage. CVs submitted through a job application are only accessible to you and the relevant organisation. You can request deletion of your files by contacting us.
4. Data Sharing
We do not sell your personal data. We share it only in these limited cases:
- With organisations: your application data is shared with the NGO you applied to.
- Service providers: cloud hosting and file storage providers under data processing agreements.
- Legal requirement: if required by law or to protect the safety and rights of users.
5. Data Retention
- Account data — retained until you delete your account.
- Job applications — retained for 12 months after submission, then automatically deleted unless the organisation retains them under their own policy.
- Auth cookies — expire after 30 days or on logout.
- Server logs — retained for a maximum of 30 days.
6. Your Rights (GDPR)
If you are located in the EU/EEA or the UK, you have the following rights:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data.
- Erasure — request deletion of your data ("right to be forgotten").
- Portability — receive your data in a machine-readable format.
- Restriction — ask us to limit how we use your data.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — where processing is based on consent, you can withdraw at any time.
To exercise any of these rights, email us at hello@ngo-jobs.com. We will respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority.
7. Security
We protect your data using HTTPS encryption, httpOnly cookies, bcrypt password hashing, and access controls. No method of transmission over the internet is 100% secure, but we take reasonable measures to protect your information.
8. Changes to This Policy
We may update this policy occasionally. We will post the updated version on this page with a new "last updated" date. Continued use of the platform after changes constitutes acceptance of the updated policy.
9. Contact
For any privacy-related questions or requests:
Email: hello@ngo-jobs.com