Legal

Privacy Policy — OnlyRemoteJobs

Learn how OnlyRemoteJobs collects, uses, stores, and shares personal data under Brazil's LGPD and the EU GDPR.

Last updated:

Who we are

OnlyRemoteJobs is operated from Brazil by the OnlyRemoteJobs team. The operator is the controller responsible for the personal data practices described in this policy, and is reachable at reativatecnologia@gmail.com.

Personal data we collect

  • Account and profile data: email address, name, avatar, public account metadata, and authentication session information managed through Clerk.
  • Subscription data: subscription status and customer email used by the website and API to provide paid access. Payment-card entry is hosted by Stripe Checkout; our website and API do not receive raw card numbers.
  • Marketing and attribution data: event names, non-PII commerce or page context, advertising click identifiers, campaign parameters, and provider-created browser identifiers only after the relevant optional consent.
  • Technical and observability data: page and referrer origin and pathname only, a pseudonymous session identifier, and browser user agent. URL query strings and fragments are removed before browser telemetry is recorded.

Why we use data and the legal bases

Depending on the processing and the law that applies, we rely on:

  • Contract: to create accounts, authenticate users, manage subscriptions, and provide the paid job platform.
  • Legal obligations: to keep records or respond to lawful requests where the law requires us to do so.
  • Legitimate interests: to secure, operate, troubleshoot, and understand the service, provided those interests are not overridden by your rights.
  • Consent: for optional Analytics and Marketing technologies. They remain off unless you affirmatively choose them, and you may withdraw that choice as described below.

Where tracking runs today

Optional analytics and marketing technologies are available only on /subscribe, /subscribe/cancel, /subscribe/success, /account/billing, /account/api, /docs/developers/jobs-api, and /docs/developers/jobs-mcp. They are not mounted on the home page or individual job-detail pages.

Necessary processing is always available. Analytics and Marketing independently default to off on these routes, and their scripts, requests, attribution state, and events remain disabled until you make an affirmative category choice. The first layer offers equally accessible accept and reject actions. You can reopen Cookie settings and withdraw your choice at any time; withdrawal stops future optional events and clears known first-party tracking state.

Service providers and data recipients

We use the following verified services for the stated purposes:

Verified services that process OnlyRemoteJobs data
ServicePurpose and data
ClerkAuthentication, account profiles, sessions, and public metadata.
ClarityConsent-controlled behavioral analytics using session playback and heatmaps derived from page structure, clicks, scrolling, and pointer movement. Sensitive content is masked. Analytics storage is enabled only with Analytics consent, and advertising storage remains denied unless Marketing is granted.
MetaConsent-controlled advertising measurement using event and commerce context plus provider browser and click identifiers. Browser tracking does not send contact or profile fields, raw or hashed, and Automatic Advanced Matching is disabled.
GoogleConsent-controlled analytics and advertising measurement using event and commerce context, click identifiers, and campaign parameters. Enhanced conversions are disabled; browser tracking does not send contact or profile fields.
SigNozOpenTelemetry observability using page and referrer origin and pathname only, pseudonymous session identifiers, and user agents; query strings and fragments are removed before emission.
StripePayment processing, hosted subscription checkout, and subscription support. Our API sends the customer email; raw card numbers are entered in Stripe-hosted checkout and are not received by our servers.
DragonflySubscription lookup and caching in the API, including email in plaintext keys and stored values.

Cookies and browser storage

The necessary reativa_consent cookie stores your category decision for up to 180 days. Reativa-created attribution cookies exist only with Marketing consent, use SameSite=Lax, are scoped to the current root domain, and expire after at most 180 days. Provider-managed and session storage have the separate lifetimes shown below.

Cookies and browser storage used by OnlyRemoteJobs
KeyUseStorage and lifetime
reativa_consentNecessary record of the independent Analytics and Marketing choices.Cookie, up to 180 days.
_fbcMeta click attribution.Marketing cookie, up to 180 days.
_fbpMeta browser identifier.Provider-controlled Marketing cookie.
_gclidGoogle click attribution.Marketing cookie, up to 180 days.
_wbraidGoogle web-to-app attribution.Marketing cookie, up to 180 days.
_gbraidGoogle app-to-web attribution.Marketing cookie, up to 180 days.
_msclkidAdvertising click attribution.Marketing cookie, up to 180 days.
_ttclidAdvertising click attribution.Marketing cookie, up to 180 days.
_utmCampaign source, medium, name, term, and content.Marketing cookie, up to 180 days.
_gaGoogle Analytics client identifier read by the attribution flow.First-party cookie with a provider-controlled lifetime.
_clckMicrosoft Clarity pseudonymous visitor and consent preferences.First-party Analytics cookie with a provider-controlled lifetime.
_clskMicrosoft Clarity page views grouped into a session recording.First-party Analytics cookie with a provider-controlled lifetime.
onlyremotejobs.observability.session_idPseudonymous observability session correlation.sessionStorage for the browser session.
Clerk session cookieStrictly necessary authentication and session continuity.First-party cookie with a provider-controlled lifetime.

Retention

We retain personal data only for as long as needed for the purposes described here, to provide subscriptions and account access, maintain security and operational records, resolve disputes, and meet legal obligations. Exact periods depend on the category and provider. Attribution cookies and the consent decision created by our code expire after at most 180 days, while sessionStorage ends with the browser session. Provider-managed records follow the applicable provider settings and contractual or legal requirements. Rejecting or withdrawing optional consent triggers cleanup of known first-party provider and attribution state.

International transfers

The services listed above may process data in countries other than the one where you live. Where transfer rules apply, we require the transfer mechanism and safeguards mandated by applicable law and consider the destination, recipient, and purpose of the transfer.

Your privacy rights

Subject to the conditions and exceptions in applicable law, you may request confirmation of processing, access, correction, anonymization, blocking or deletion, portability, information about sharing, restriction, objection, consent withdrawal, and review of qualifying automated decisions. You may also complain to the competent data-protection authority.

These rights include those in Brazil's LGPD Article 18 and EU GDPR Articles 15–22. The cited official texts govern if this summary differs from the law.

How to exercise your rights

Email reativatecnologia@gmail.com with enough detail to identify the account and request. We may ask for proportionate verification before acting so that we do not disclose or delete another person's data. We will respond within the period required by applicable law.

Children

OnlyRemoteJobs is a paid employment-search service and is not designed for children. If you believe a child supplied personal data through the service, contact us so we can investigate and take the action required by law.

Changes to this policy

We may update this policy when our practices, providers, or legal obligations change. We will revise the “Last updated” date and provide any additional notice required by applicable law.

Contact

Privacy requests: reativatecnologia@gmail.com
General support: reativatecnologia@gmail.com