Privacy Policy
LAST_UPDATED: September 26, 2026 • VERSION 2.0 • GDPR_COMPLIANT
Welcome to Remoto (remoto.fyi). We respect your privacy and are committed to protecting your personal data in strict compliance with Regulation (EU) 2016/679 (General Data Protection Regulation or GDPR) and applicable European privacy legislation.
01. Data Controller Identity
For the purposes of the GDPR and European data protection laws, the Data Controller responsible for your personal data is:
02. Personal Data We Collect
We adhere strictly to the principle of data minimization. We only collect personal data required to deliver customized job matching, alert pipelines, and developer market analytics:
Google primary email, display name, profile avatar URL, and internal session ID. We never process or store your Google password.
Selected programming languages, framework tags, target work countries, compensation minimums, and notification cadence.
Unique numeric Telegram Chat ID and username handle (provided by the Telegram Bot API) to dispatch instant match notifications.
Stripe Customer ID, subscription status, and billing renewal dates. Payment card details are ingested directly by Stripe on PCI-DSS Level 1 infrastructure.
03. Legal Bases for Processing (GDPR Article 6)
Under Article 6 of the GDPR, every processing activity must rest on a valid legal ground:
| Processing Purpose | Data Category | Legal Basis (GDPR Art. 6) |
|---|---|---|
| User Account & Auth | Google OAuth profile, email | Art. 6(1)(b) - Contract |
| Job Digest & Telegram Alerts | Email, Telegram Chat ID, filters | Art. 6(1)(b) - Contract |
| Premium Subscriptions | Stripe customer ID, subscription status | Art. 6(1)(b) - Contract |
| Tax & Financial Invoicing | Transaction invoices, VAT records | Art. 6(1)(c) - Legal Obligation |
| Security & Anti-Scraping | IP addresses, request logs, crawler traps | Art. 6(1)(f) - Legitimate Interests |
04. Data Sharing & Third-Party Processors
We rely strictly on vetted Data Processors operating under compliant Data Processing Agreements (DPAs):
- Stripe (Stripe Payments Europe, Ltd.): Processes payments, recurring subscriptions, and tax compliance.
- Google Identity Services: Facilitates secure, federated OAuth authentication.
- Telegram Bot API: Transmits instant job notifications to users who deliberately link their Telegram accounts.
- Transactional Email Providers: Delivers authentication links, digest emails, and security notices.
- Cloud & Edge Infrastructure: Encrypted databases and edge distribution hosted in EU data center zones.
05. International Data Transfers
When communicating with infrastructure providers operated by US-headquartered entities (Google, Stripe, Telegram), we ensure personal data benefits from an adequate level of protection under Chapter V of the GDPR by relying on the EU-U.S. Data Privacy Framework (DPF) and European Commission Standard Contractual Clauses (SCCs) supplemented by strict encryption in transit.
06. Cookies & Local Storage Controls
Strictly Necessary Storage: We use local storage tokens and session cookies essential for maintaining your authenticated session, CSRF security, and basic interface state.
Optional Analytics & Preferences: Telemetry regarding site performance and UI custom configurations are opt-in and require your explicit consent before activation. We do not use third-party advertising cookies or cross-site tracking pixels.
You can review, modify, or revoke your cookie choices at any time by clicking the “Cookie Settings” link in our website footer.
07. Data Retention & Erasure Schedules
- Active User Data: Retained for as long as your account remains open.
- Account Deletion: Upon deletion, your profile, filters, and alert records are purged immediately from production databases.
- Financial & Invoicing Records: Retained for up to 10 years to comply with statutory EU tax auditing requirements.
- Security Logs: Server access records and crawler tripwire telemetry are rotated and permanently purged after 90 days.
08. Your Statutory Rights Under GDPR
As an EU/EEA data subject, you hold statutory rights under Articles 15–22 of the GDPR:
To exercise any statutory right, contact support@remoto.fyi. We respond to all verified requests within 30 days.
09. Right to Lodge a Supervisory Complaint
Under Article 77 of the GDPR, you have the right to lodge a complaint with an EU data protection supervisory authority in your Member State of residence or workplace.
10. Security Protocols
In-Transit Encryption: All traffic is served over HTTPS with mandatory TLS 1.3 protocol encryption and HSTS headers.
At-Rest Encryption: Database records, encrypted tokens, and daily backups are secured using AES-256 encryption.
Least Privilege: Production environment credentials and database access are strictly restricted to authenticated personnel on a need-to-know basis.
11. Privacy Contact & Inquiries
To submit privacy questions or exercise your statutory data rights, email our team at support@remoto.fyi.