Legal
Privacy Policy — OnlyRemoteJobs
Learn how OnlyRemoteJobs collects, uses, stores, and shares personal data under Brazil's LGPD and the EU GDPR.
Last updated:
Who we are
OnlyRemoteJobs is operated from Brazil by the OnlyRemoteJobs team. The operator is the controller responsible for the personal data practices described in this policy, and is reachable at reativatecnologia@gmail.com.
Personal data we collect
- Account and profile data: email address, name, avatar, public account metadata, and authentication session information managed through Clerk.
- Subscription data: subscription status and customer email used by the website and API to provide paid access. Payment-card entry is hosted by Stripe Checkout; our website and API do not receive raw card numbers.
- Marketing and attribution data: event names, non-PII commerce or page context, advertising click identifiers, campaign parameters, and provider-created browser identifiers only after the relevant optional consent.
- Technical and observability data: page and referrer origin and pathname only, a pseudonymous session identifier, and browser user agent. URL query strings and fragments are removed before browser telemetry is recorded.
Why we use data and the legal bases
Depending on the processing and the law that applies, we rely on:
- Contract: to create accounts, authenticate users, manage subscriptions, and provide the paid job platform.
- Legal obligations: to keep records or respond to lawful requests where the law requires us to do so.
- Legitimate interests: to secure, operate, troubleshoot, and understand the service, provided those interests are not overridden by your rights.
- Consent: for optional Analytics and Marketing technologies. They remain off unless you affirmatively choose them, and you may withdraw that choice as described below.
Where tracking runs today
Optional analytics and marketing technologies are available only on /subscribe, /subscribe/cancel, /subscribe/success, /account/billing, /account/api, /docs/developers/jobs-api, and /docs/developers/jobs-mcp. They are not mounted on the home page or individual job-detail pages.
Necessary processing is always available. Analytics and Marketing independently default to off on these routes, and their scripts, requests, attribution state, and events remain disabled until you make an affirmative category choice. The first layer offers equally accessible accept and reject actions. You can reopen Cookie settings and withdraw your choice at any time; withdrawal stops future optional events and clears known first-party tracking state.
Service providers and data recipients
We use the following verified services for the stated purposes:
| Service | Purpose and data |
|---|---|
| Clerk | Authentication, account profiles, sessions, and public metadata. |
| Clarity | Consent-controlled behavioral analytics using session playback and heatmaps derived from page structure, clicks, scrolling, and pointer movement. Sensitive content is masked. Analytics storage is enabled only with Analytics consent, and advertising storage remains denied unless Marketing is granted. |
| Meta | Consent-controlled advertising measurement using event and commerce context plus provider browser and click identifiers. Browser tracking does not send contact or profile fields, raw or hashed, and Automatic Advanced Matching is disabled. |
| Consent-controlled analytics and advertising measurement using event and commerce context, click identifiers, and campaign parameters. Enhanced conversions are disabled; browser tracking does not send contact or profile fields. | |
| SigNoz | OpenTelemetry observability using page and referrer origin and pathname only, pseudonymous session identifiers, and user agents; query strings and fragments are removed before emission. |
| Stripe | Payment processing, hosted subscription checkout, and subscription support. Our API sends the customer email; raw card numbers are entered in Stripe-hosted checkout and are not received by our servers. |
| Dragonfly | Subscription lookup and caching in the API, including email in plaintext keys and stored values. |
Cookies and browser storage
The necessary reativa_consent cookie stores your category decision for up to 180 days. Reativa-created attribution cookies exist only with Marketing consent, use SameSite=Lax, are scoped to the current root domain, and expire after at most 180 days. Provider-managed and session storage have the separate lifetimes shown below.
| Key | Use | Storage and lifetime |
|---|---|---|
reativa_consent | Necessary record of the independent Analytics and Marketing choices. | Cookie, up to 180 days. |
_fbc | Meta click attribution. | Marketing cookie, up to 180 days. |
_fbp | Meta browser identifier. | Provider-controlled Marketing cookie. |
_gclid | Google click attribution. | Marketing cookie, up to 180 days. |
_wbraid | Google web-to-app attribution. | Marketing cookie, up to 180 days. |
_gbraid | Google app-to-web attribution. | Marketing cookie, up to 180 days. |
_msclkid | Advertising click attribution. | Marketing cookie, up to 180 days. |
_ttclid | Advertising click attribution. | Marketing cookie, up to 180 days. |
_utm | Campaign source, medium, name, term, and content. | Marketing cookie, up to 180 days. |
_ga | Google Analytics client identifier read by the attribution flow. | First-party cookie with a provider-controlled lifetime. |
_clck | Microsoft Clarity pseudonymous visitor and consent preferences. | First-party Analytics cookie with a provider-controlled lifetime. |
_clsk | Microsoft Clarity page views grouped into a session recording. | First-party Analytics cookie with a provider-controlled lifetime. |
onlyremotejobs.observability.session_id | Pseudonymous observability session correlation. | sessionStorage for the browser session. |
| Clerk session cookie | Strictly necessary authentication and session continuity. | First-party cookie with a provider-controlled lifetime. |
Retention
We retain personal data only for as long as needed for the purposes described here, to provide subscriptions and account access, maintain security and operational records, resolve disputes, and meet legal obligations. Exact periods depend on the category and provider. Attribution cookies and the consent decision created by our code expire after at most 180 days, while sessionStorage ends with the browser session. Provider-managed records follow the applicable provider settings and contractual or legal requirements. Rejecting or withdrawing optional consent triggers cleanup of known first-party provider and attribution state.
International transfers
The services listed above may process data in countries other than the one where you live. Where transfer rules apply, we require the transfer mechanism and safeguards mandated by applicable law and consider the destination, recipient, and purpose of the transfer.
Your privacy rights
Subject to the conditions and exceptions in applicable law, you may request confirmation of processing, access, correction, anonymization, blocking or deletion, portability, information about sharing, restriction, objection, consent withdrawal, and review of qualifying automated decisions. You may also complain to the competent data-protection authority.
These rights include those in Brazil's LGPD Article 18 and EU GDPR Articles 15–22. The cited official texts govern if this summary differs from the law.
How to exercise your rights
Email reativatecnologia@gmail.com with enough detail to identify the account and request. We may ask for proportionate verification before acting so that we do not disclose or delete another person's data. We will respond within the period required by applicable law.
Children
OnlyRemoteJobs is a paid employment-search service and is not designed for children. If you believe a child supplied personal data through the service, contact us so we can investigate and take the action required by law.
Changes to this policy
We may update this policy when our practices, providers, or legal obligations change. We will revise the “Last updated” date and provide any additional notice required by applicable law.
Contact
Privacy requests: reativatecnologia@gmail.com
General support: reativatecnologia@gmail.com