Privacy Policy
This page explains what personal data we collect when you use jobs.myquantpartner.com, why we collect it, how long we keep it, and what rights you have under the General Data Protection Regulation (GDPR).
Who we are
The data controller is MyQuantPartner, LLC, a Delaware Limited Liability Company. Full company details are on our Legal Notice page.
For any question, request or complaint relating to your personal data, contact us at [email protected]. We respond within one month, as required by GDPR.
One account across our sites
jobs.myquantpartner.com and myquantpartner.com share a single account system. Signing in on either one signs you in on both, and there is one record of you rather than two.
In practice this means data you create on the main site, such as practice history, is not created by browsing jobs, but it belongs to the same account. Deleting your account deletes it everywhere.
What we collect
We only collect what the job board needs to work. Concretely:
- Account information: your email address, and, if you sign in with Google, the name and avatar URL Google returns. We never receive your Google password.
- Technical data: IP address, browser and device information visible from standard HTTP requests, and authentication cookies. We use these to keep your account secure and the service reliable.
We do not collect a CV, a cover letter, or an application of any kind. Applying happens on the employer's own site, and nothing you type there passes through us.
Why we process it
For each purpose below we identify the legal basis under Article 6 of the GDPR.
- To provide and maintain your account. Legal basis: performance of a contract (Art 6(1)(b)).
- To keep the service secure and detect abuse. Legal basis: our legitimate interests in protecting the service and its users (Art 6(1)(f)).
Who we share data with
We do not sell your data, and we do not share it with the companies whose roles are listed here. An employer does not learn that you viewed their posting.
We rely on a small number of processors to run the service:
- Supabase, for authentication and database hosting.
- Railway, for application hosting.
- Google, if and only if you choose to sign in with Google. Google tells us your email, name and avatar; we tell Google nothing about what you do here.
We may disclose data where required by law, or to establish, exercise or defend a legal claim.
Clicking through to an employer
Every listing's Apply button is an ordinary external link. When you follow it you leave this site, and the employer's own privacy policy governs everything that happens next, including whatever they record when you apply.
We do not append tracking parameters to those links and receive no notification that you followed one.
International data transfers
Our infrastructure providers are established in the United States, so data may be processed there. Where the GDPR applies, these transfers rely on Standard Contractual Clauses approved by the European Commission, or on an adequacy decision where one exists.
How long we keep your data
- Account data: for as long as the account exists. Deleting your account removes it.
- Authentication cookies: the session cookie expires after 30 minutes and the refresh cookie after 30 days. Signing out clears both immediately.
- Server logs: kept for a short period for security and debugging, then discarded.
Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase your data, by deleting your account.
- Restrict or object to processing carried out on the basis of our legitimate interests.
- Port your data, receiving it in a structured, commonly used, machine-readable format.
- Complain to your local data protection authority.
To exercise any of these, write to [email protected] from the address on your account.
Cookies
We use cookies for authentication only. There is no advertising cookie, no analytics cookie and no third-party tracker on this site.
- Session and refresh cookies: these keep you signed in. They are HttpOnly, so JavaScript on the page cannot read them.
- A CSRF token cookie: this protects your account from requests forged by another site.
Because these are strictly necessary to deliver a service you asked for, they do not require consent under the ePrivacy Directive. Blocking them in your browser will prevent you from signing in.
Security
Passwords, where used, are hashed by our authentication provider and never visible to us in plain text. All traffic is served over HTTPS. Authentication tokens are held in HttpOnly cookies so that a cross-site scripting flaw cannot read them off the page.
No system is perfectly secure. If you believe your account has been compromised, write to [email protected] and we will act on it.
Children
This service is not directed at children. You must be at least 16 to create an account. If we learn that we hold data belonging to someone younger, we delete it.
Changes to this policy
If we change this policy we update the date at the foot of this page. Where a change materially affects your rights, we will tell you by email before it takes effect.