FiFoDiDo

Privacy at FiFoDiDo

Job seeking involves some of your most sensitive information. Here is exactly how we handle it, in plain language. This summary complements our full policy and applies globally, including under GDPR (EU/UK), CCPA (California), and the Australian Privacy Act.

What we collect

Account details (name, email), the profile information you choose to add (resume, work history, certifications, location and work preferences), your applications and messages on the platform, and consent records. For employers, we also collect business verification documents. We collect only what the product needs: no data brokering, no selling of personal information, ever.

Who can see your profile

  • Private (default): only companies you apply to can see your details, and only in the context of that application.
  • Open to verified employers (opt-in): signed-in, identity-verified employers can find you in the resume database. Your profile is never shown to anonymous visitors, and all candidate pages carry a noindex header so search engines cannot index them.

Switching visibility is recorded in an auditable consent log you can view any time, and you can switch back whenever you like.

Your rights & self-service controls

  • Access & portability: download a complete JSON export of your data from your privacy dashboard, instantly.
  • Erasure: delete your account yourself: profile, files, applications and bookmarks are permanently removed, and your messages to others are redacted.
  • Rectification: edit any profile field at any time.
  • Consent withdrawal: marketing emails and profile visibility are opt-in and reversible, with every change logged.

Data retention & destruction

When you delete your account, your profile, files and applications are anonymised or removed immediately. Backups and system logs that may still reference your data are purged on a rolling basis and fully cleared within one month of your deletion request.

Storage & security

Files (resumes, photos, documents) are stored in private object storage and served only through short-lived signed links after an authorization check; there are no public file URLs. Passwords are hashed with bcrypt. Payment card details never touch our servers; billing is handled by Stripe.

Overseas data transfers

Some personal information is sent overseas as part of running the platform: payment processing through Stripe (based in the United States), and hosting/infrastructure providers that may store or process data outside Australia. We take reasonable steps to ensure these providers protect your data to a standard consistent with the Australian Privacy Principles, though overseas recipients aren’t always subject to the same privacy laws as those in Australia.

Cookies

Essential cookies keep you signed in. Analytics cookies are used only if you accept them in the consent banner, and you can decline with one tap without losing any functionality.

Contact

Questions or requests we haven’t automated yet? Email privacy@fifodido.com. We respond to all data-rights requests within 30 days as required by law, usually much faster.

If you’re not satisfied with how we’ve handled a privacy request or complaint, you can escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.