Privacy Policy

LAST_UPDATED: September 26, 2026 • VERSION 2.0 • GDPR_COMPLIANT

Welcome to Remoto (remoto.fyi). We respect your privacy and are committed to protecting your personal data in strict compliance with Regulation (EU) 2016/679 (General Data Protection Regulation or GDPR) and applicable European privacy legislation.

01. Data Controller Identity

For the purposes of the GDPR and European data protection laws, the Data Controller responsible for your personal data is:

PLATFORM_SERVICE: Remoto (remoto.fyi)
DATA_PROTECTION_EMAIL: support@remoto.fyi

02. Personal Data We Collect

We adhere strictly to the principle of data minimization. We only collect personal data required to deliver customized job matching, alert pipelines, and developer market analytics:

A. Identity & Auth (Google OAuth)

Google primary email, display name, profile avatar URL, and internal session ID. We never process or store your Google password.

B. User Preference Configurations

Selected programming languages, framework tags, target work countries, compensation minimums, and notification cadence.

C. Telegram Job Alert Integration

Unique numeric Telegram Chat ID and username handle (provided by the Telegram Bot API) to dispatch instant match notifications.

D. Billing & Subscriptions (Stripe)

Stripe Customer ID, subscription status, and billing renewal dates. Payment card details are ingested directly by Stripe on PCI-DSS Level 1 infrastructure.

E. Technical, Security & Usage Logs: IP address, browser user-agent, timestamped request URLs, and security telemetry for rate-limiting and anti-scraping trap detection.

03. Legal Bases for Processing (GDPR Article 6)

Under Article 6 of the GDPR, every processing activity must rest on a valid legal ground:

Processing PurposeData CategoryLegal Basis (GDPR Art. 6)
User Account & AuthGoogle OAuth profile, emailArt. 6(1)(b) - Contract
Job Digest & Telegram AlertsEmail, Telegram Chat ID, filtersArt. 6(1)(b) - Contract
Premium SubscriptionsStripe customer ID, subscription statusArt. 6(1)(b) - Contract
Tax & Financial InvoicingTransaction invoices, VAT recordsArt. 6(1)(c) - Legal Obligation
Security & Anti-ScrapingIP addresses, request logs, crawler trapsArt. 6(1)(f) - Legitimate Interests

04. Data Sharing & Third-Party Processors

NOTICE: We never sell, rent, lease, or monetize your personal data, nor do we disclose candidate contact info to third-party recruiters.

We rely strictly on vetted Data Processors operating under compliant Data Processing Agreements (DPAs):

  • Stripe (Stripe Payments Europe, Ltd.): Processes payments, recurring subscriptions, and tax compliance.
  • Google Identity Services: Facilitates secure, federated OAuth authentication.
  • Telegram Bot API: Transmits instant job notifications to users who deliberately link their Telegram accounts.
  • Transactional Email Providers: Delivers authentication links, digest emails, and security notices.
  • Cloud & Edge Infrastructure: Encrypted databases and edge distribution hosted in EU data center zones.

05. International Data Transfers

When communicating with infrastructure providers operated by US-headquartered entities (Google, Stripe, Telegram), we ensure personal data benefits from an adequate level of protection under Chapter V of the GDPR by relying on the EU-U.S. Data Privacy Framework (DPF) and European Commission Standard Contractual Clauses (SCCs) supplemented by strict encryption in transit.

06. Cookies & Local Storage Controls

Strictly Necessary Storage: We use local storage tokens and session cookies essential for maintaining your authenticated session, CSRF security, and basic interface state.

Optional Analytics & Preferences: Telemetry regarding site performance and UI custom configurations are opt-in and require your explicit consent before activation. We do not use third-party advertising cookies or cross-site tracking pixels.

You can review, modify, or revoke your cookie choices at any time by clicking the “Cookie Settings” link in our website footer.

07. Data Retention & Erasure Schedules

  • Active User Data: Retained for as long as your account remains open.
  • Account Deletion: Upon deletion, your profile, filters, and alert records are purged immediately from production databases.
  • Financial & Invoicing Records: Retained for up to 10 years to comply with statutory EU tax auditing requirements.
  • Security Logs: Server access records and crawler tripwire telemetry are rotated and permanently purged after 90 days.

08. Your Statutory Rights Under GDPR

As an EU/EEA data subject, you hold statutory rights under Articles 15–22 of the GDPR:

Art. 15 Right of Access: Obtain a readable export of your personal information.
Art. 16 Right to Rectification: Update your profile and job filters anytime in /preferences.
Art. 17 Right to Erasure: Request complete deletion of your account and personal records.
Art. 20 Data Portability: Receive your stored data in machine-readable JSON format.
Art. 21 Right to Object: Object to processing based on legitimate interests.
Alert Opt-Out: Unsubscribe from job alerts with 1 click in email footers or account settings.

To exercise any statutory right, contact support@remoto.fyi. We respond to all verified requests within 30 days.

09. Right to Lodge a Supervisory Complaint

Under Article 77 of the GDPR, you have the right to lodge a complaint with an EU data protection supervisory authority in your Member State of residence or workplace.

10. Security Protocols

In-Transit Encryption: All traffic is served over HTTPS with mandatory TLS 1.3 protocol encryption and HSTS headers.

At-Rest Encryption: Database records, encrypted tokens, and daily backups are secured using AES-256 encryption.

Least Privilege: Production environment credentials and database access are strictly restricted to authenticated personnel on a need-to-know basis.

11. Privacy Contact & Inquiries

To submit privacy questions or exercise your statutory data rights, email our team at support@remoto.fyi.