Back to Home

Privacy Policy

Last updated: March 2, 2026

1. Introduction

CareerOnTrack (“we,” “us,” or “our”) is an AI-powered career intelligence platform that helps job seekers transition from cold-applying to network-powered job campaigns. This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our website, applications, and services (collectively, the “Service”).

We are committed to protecting your privacy and handling your data responsibly. This policy is written in plain language to help you understand your rights and our practices. If anything is unclear, please contact us at privacy@careerontrack.com.

2. Who We Are

CareerOnTrack is operated by PotentiaOS Inc. For privacy inquiries, contact our Privacy Officer at privacy@careerontrack.com. We will respond to all privacy requests within 30 days.

3. What Data We Collect

We collect the following categories of personal information:

CategoryDetails
Account & IdentityEmail address, full name, hashed password (never stored in plain text)
Profile & Career DataWork history, education, certifications, skills, target roles, salary range, preferences, residency status (if provided), languages
Resume & DocumentsUploaded resume (PDF), extracted resume text, AI-tailored resume versions, cover letters
Assessment DataCareer Readiness Score (CRS) responses, dimension scores, gap analysis results, skill gaps
Job Activity DataApplications tracked, job postings saved, match scores, follow-up dates, application status
Network DataLinkedIn connection CSV uploads (name, company, title), outreach messages drafted, referral tracking
AI Conversation DataARIA chat transcripts, voice session transcripts, session summaries, coaching notes, interview scores
Billing & PaymentSubscription tier, billing dates. Payment card details are handled entirely by our PCI-DSS compliant payment processor — we never see or store card numbers.
Usage & Technical DataPages visited, features used, session duration, IP address (not logged in plain text), device type, browser
Marketing EngagementEmail open/click events, marketing interaction tracking via our CRM provider

What we do NOT collect: We never collect identity documents (such as visas or work permits), Social Insurance Numbers (SIN), Social Security Numbers (SSN), financial data beyond salary ranges, or any government-issued identification numbers.

4. Why We Collect Your Data

CategoryDetails
Account creation & authenticationTo create and secure your account (Legal basis: contract performance)
Readiness assessment & scoringTo calculate your Career Readiness Score and provide personalized gap analysis (Legal basis: contract performance)
AI-powered featuresResume tailoring, ARIA coaching, outreach drafting, skill gap analysis (Legal basis: contract performance)
Job discovery & matchingTo find and score relevant job opportunities (Legal basis: contract performance)
Network activationTo identify warm paths and draft outreach messages (Legal basis: contract performance)
Payment processingTo process subscriptions and payments via our payment processor (Legal basis: contractual necessity)
Marketing communicationsMarket Pulse briefings and nurture emails (Legal basis: explicit consent)
Security & fraud preventionBot protection, rate limiting, anomaly detection (Legal basis: legitimate interests)
Product improvementAnonymized usage analytics to improve features (Legal basis: legitimate interests)

5. AI-Powered Features: How Your Data Is Used

We may use third-party AI services to power our AI features. When you interact with CareerOnTrack’s AI-powered features:

  • Your conversation data is sent to our AI service providers for processing via secure API connections
  • Our AI service providers do not use your data to train their models (per our data processing agreements)
  • We implement prompt caching to reduce redundant API calls and improve response times
  • AI outputs are validated against strict schemas before storage or display
  • All AI-generated content is presented as suggestions. You review and approve all resumes, outreach messages, and action plans before use

Features that use AI:

  • Resume tailoring (generates customized resumes for specific job postings)
  • ARIA chat coaching (text-based career coaching sessions)
  • ARIA voice sessions (voice-based mock interviews and coaching)
  • Outreach message drafting (personalized networking messages)
  • Skill gap analysis (strategic insights about your skills vs. market demand)
  • Course prescriptions (learning recommendations with ROI scoring)
  • Market Pulse briefings (personalized market intelligence)
  • LinkedIn post drafting (thought leadership content suggestions)

Voice sessions:

We use a third-party voice AI provider to power ARIA voice sessions (mock interviews and coaching calls). Voice audio is processed in real time and is not stored by the voice provider after the session ends. Transcripts are stored securely in our database under your account. The voice provider operates under a data processing agreement that prohibits training use of your audio.

Automated decision-making:

CareerOnTrack uses automated systems to calculate your Career Readiness Score (CRS) and generate your daily action queue. These are guidance tools, not binding decisions. They do not affect your employment prospects, creditworthiness, or any legal status. You can retake the readiness assessment at any time and request human review of any automated recommendation.

AI output accuracy:

AI-generated content (resumes, outreach messages, coaching advice) may contain errors or require editing. CareerOnTrack is not responsible for outcomes resulting from AI-generated content you choose to use. Always review AI outputs before submission or use.

6. Third-Party Services

We work with carefully selected third-party service providers to operate CareerOnTrack. These providers are bound by data processing agreements and are only permitted to process your data as necessary to provide their services to us.

CategoryDetails
Cloud Database & AuthenticationWe use a SOC 2 Type II certified cloud database provider for data storage, user authentication, and file storage. Data is encrypted at rest and in transit.
Payment ProcessingWe use a PCI-DSS Level 1 compliant payment processor for subscription billing. We never see, access, or store your raw card numbers.
AI Text GenerationWe use third-party AI services for resume tailoring, coaching, and analysis. Your data is sent via secure API and is not used for model training under our agreements.
Voice AIWe use a third-party voice AI provider for ARIA voice sessions. Audio is processed in real time under a data processing agreement that prohibits training use.
Job Market DataWe use licensed job aggregator APIs for skills-market fit scoring and job discovery. No personal identifiers are sent to these providers.
CRM & CommunicationsWe use a SOC 2 Type II certified CRM platform for email and SMS delivery (Market Pulse, nurture communications, and notifications).
Application HostingOur application is hosted on a cloud platform that processes IP addresses, request metadata, and serves static assets.

Cross-border transfers: Your data may be processed in the United States or other jurisdictions by our service providers. Transfers are protected by Standard Contractual Clauses (SCCs) with each processor where required by applicable law.

We do not sell your data. We do not sell, rent, or share your personal information with third parties for their marketing purposes. Data shared with our processors is used solely to operate the Service.

Provider changes: We may change our third-party service providers from time to time to improve security, performance, or cost-effectiveness. Any new providers will be held to the same data protection standards described in this policy.

7. Cookies & Tracking

CategoryDetails
Strictly NecessaryAuthentication session cookies, CSRF protection tokens. Cannot be disabled.
FunctionalUser preferences (theme, onboarding step). Can be disabled.
AnalyticsAnonymized usage patterns for product improvement. Requires consent in EU/UK/Canada.
MarketingEmail open/click tracking via our CRM provider. Requires explicit consent.

We respect Do Not Track signals and Global Privacy Control (GPC) preferences. If your browser sends these signals, we will not set non-essential cookies or tracking.

8. Data Retention

CategoryDetails
Account & profile dataRetained for the duration of your account plus 30 days after deletion request.
CRS scores & assessment historyRetained for the duration of your account. Available for export at any time.
AI conversation transcripts12 months from session date, or account deletion, whichever is sooner. You can request earlier deletion.
Resume & job application dataRetained for the duration of your account. User-owned data, available for export.
Billing & transaction records7 years (legal/tax requirement). This overrides deletion requests for this category only.
Usage logs24 months from collection.
Deleted account residualData may persist in encrypted backups for up to 30 days after deletion, then purged.

9. Your Rights

All Users

  • Export all your data at any time (JSON format from Settings)
  • Delete your account and all associated data
  • Correct inaccurate information in your profile
  • Opt out of marketing communications

Canadian Users (PIPEDA)

  • Right to access your personal information (we respond within 30 days)
  • Right to correct inaccurate information
  • Right to withdraw consent at any time (you may lose access to features requiring that data)
  • Right to know if your data has been transferred outside Canada
  • Right to file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca)

UK/EU Users (GDPR)

  • Right of access (Subject Access Request, we respond within 30 days)
  • Right to rectification
  • Right to erasure (“right to be forgotten”)
  • Right to restriction of processing
  • Right to data portability (machine-readable format)
  • Right to object to processing based on legitimate interests
  • Right not to be subject to solely automated decision-making with legal effects
  • Right to lodge a complaint with your supervisory authority (ICO for UK; relevant DPA for EU)

California Users (CCPA/CPRA)

  • Right to know what personal information is collected
  • Right to know if personal information is sold or shared (we do not sell data)
  • Right to delete personal information
  • Right to opt out of sale or sharing
  • Right to correct inaccurate personal information
  • Right to limit use of sensitive personal information (including residency status)
  • Right to non-discrimination for exercising your rights

Sensitive data: Residency status, collected for international professionals to enable personalized career guidance, is classified as sensitive personal information under CPRA. You can limit our use of this data at any time through your account settings.

10. Data Security

  • All connections encrypted in transit (TLS/HTTPS)
  • Data encrypted at rest (AES-256)
  • Sensitive tokens encrypted with AES-256-CBC before database storage
  • Row-Level Security enforced at database level. Each user can only access their own data
  • No plaintext personally identifiable information in application logs
  • Production database access restricted to service accounts with least privilege
  • Security headers applied on every response (CSP, HSTS, X-Frame-Options, and more)
  • Bot protection on account creation (honeypot, timing analysis, rate limiting)
  • Regular security reviews and dependency auditing

In the event of a data breach affecting your information, we will notify you and relevant authorities within 72 hours of becoming aware, as required by GDPR, or as soon as reasonably possible under PIPEDA.

11. Children’s Privacy

CareerOnTrack is not intended for users under 18 years of age (or 16 for GDPR purposes). We do not knowingly collect personal information from minors. If we discover that a minor’s data has been collected, it will be deleted immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email (if you have an account) and by updating the “Last Updated” date above. For GDPR users, material changes to processing purposes will require fresh consent.

13. How to Contact Us

To exercise any of your rights or ask questions about this policy:

  • Email: privacy@careerontrack.com
  • Response timeframe: 30 days (GDPR/PIPEDA), 45 days (CCPA)

Supervisory authorities:

  • Canada: Office of the Privacy Commissioner (priv.gc.ca)
  • UK: Information Commissioner’s Office (ICO) at ico.org.uk
  • EU: Your local data protection authority
  • California: California Privacy Protection Agency (cppa.ca.gov)