Privacy Policy
Last updated 2026-09-03
Owner-approved privacy policy
This English version was approved by the service Owner on September 3, 2026 and is effective from that date. Changes are announced in the service.
Policy version: 2026.09.03-en-v2 · Effective date: 2026-09-03
This translation was approved by the service Owner for public release. If this translation differs from the Korean original, the Korean original controls.
1. Personal Information Collected
- Required for all members: email, hashed password, name, and signup time.
- Individuals: display name, primary field, years of experience, region, preferred work arrangement, and a self-authored story.
- Companies: company name, business registration number, industry, location, short introduction, and a self-authored company story.
- Purpose-specific inputs: job criteria, project scope and deliverables, expert evidence and availability, or fundraising facts and investor-mandate constraints. Capital financial facts retain source, as-of date, unit, confirmation, and visibility.
- Service logs: matching attempts, saves, exclusions, interest, login time, and IP address.
- Optional verification materials: corporate registry, bank balance certificate, and audit report when applicable. These are deleted immediately after verification; only the result is retained.
- Planned carrier identity verification through PASS or NICE may process mobile number, name, date of birth, and gender to prevent bots, duplicate accounts, and false identities. Only the verification result is retained by JobsMatch.
2. Purposes of Processing
- Member identification, account creation, and login.
- Improving AI-assisted connection quality through stories, keywords, contextual signals, structured strengths, and choice signals.
- Projecting confirmed evidence into another purpose only after explicit consent, and recording purpose-specific confirmation or revocation.
- Service operation, improvement, and statistical analysis using non-identifying aggregate data.
- Preventing abuse, detecting false statements, and handling reports.
- Optional verification status review, company payment and tax invoice processing, and essential emails such as verification, expiry, and policy changes.
3. Anonymity in the Matching Pool
An individual’s legal name, contact details, and photo are private in the matching pool. Companies see only an anonymous code and relevant strengths. Direct member email addresses and phone numbers remain private at every stage; mutual acceptance enables platform-managed follow-up rather than direct contact disclosure.
Progressive disclosure applies to all modes. Match reasons exclude legal names and direct contacts. Project source files and Capital IR materials, cap-table or ownership information, customer details, and contact details remain private until the owner grants a bounded scope to a specific recipient.
4. Retention Periods
- Member information is retained until account closure and then deleted. Limited operations logs may be retained for six months to prevent abuse.
- Payment records are retained for five years under Korean e-commerce law.
- Matching, save, exclusion, and interest logs may be anonymized for connection-quality learning; identifiable logs are deleted after one year.
- Verification documents are deleted immediately after review; only the verification outcome remains on the profile.
- Purpose evidence consent, disclosure grants, revocation, and access-audit records are retained only as needed for service integrity, disputes, and applicable law. Revocation blocks future access but does not erase a recipient’s lawful prior actions.
5. Third-Party Disclosure
Personal information is not disclosed to third parties without consent, except for a lawful request from an investigative or supervisory authority, an approved bounded artifact grant, or payment information required by an approved payment and tax-invoice provider. Mutual acceptance enables platform-managed follow-up, not direct member email or phone disclosure. An information request alone never grants access to contact details or IR material.
6. Processing Vendors and International Transfers
- Supabase (Postgres, authentication, storage): member information and content in the Seoul region.
- Anthropic: selected AI response provider processing story content, match reasons, conversations, and attachments in the United States.
- DoubleZero (BillingAI): Korean gateway processing masked text, attachment images, and request metadata, with possible subprocessors and overseas model transfers.
- Voyage AI: creates semantic vectors from stories and AI-manager messages in the United States.
- Vercel: hosting and CDN delivery through a global edge network; United States provider.
- Resend: email delivery using email addresses; United States provider.
- PASS and NICE (planned): Korean mobile identity verification providers.
Transfers to United States providers occur in real time through encrypted HTTPS/TLS API calls under Korean Personal Information Protection Act Article 28-8. Each recipient publishes privacy-contact details in its privacy policy.
6-2. AI Manager Data
- AI-manager conversations, attachment text, extracted facts, and summaries are private to the member’s account.
- They are stored to maintain conversational context and improve that member’s matches and guidance, and are not shared with other members.
- Conversation content is temporarily sent to the selected AI provider—Anthropic or DoubleZero (BillingAI)—and Voyage AI when generating a response.
- Members can immediately edit or delete extracted facts in the Memory panel and may request deletion of messages.
- AI-manager conversations, fit-calculation data, memory, and summaries are permanently deleted within 30 days after account closure, subject to legal retention exceptions.
7. Member Rights
- Members may request access, correction, deletion, suspension, or a portable copy of personal information at any time through in-service settings or the in-product inquiry system.
- An account-closure request immediately de-identifies the account and completes deletion within 30 days, except for the retention periods above.
- JobsMatch does not collect personal information from children under age 14.
8. Security Measures
- Passwords are stored with a one-way hash and never in plaintext.
- All network communication is encrypted with HTTPS/TLS.
- Database Row Level Security isolates access to each member’s own data.
- Operators do not routinely access identifying information and use limited access only for exceptional reasons such as abuse reports.
9. Privacy Rights and Service Inquiries
- Privacy operator: Jobs Ventures, Inc., a Delaware corporation.
- Request channel: in-product inquiry system.
- Registered office: 131 Continental Dr, Suite 305, Newark, Delaware 19713, US.
- Requests are reviewed and receive their status and final outcome in the service according to applicable law and service procedures.