Privacy at a glance
DevProofs is a CV and portfolio platform. We process the information needed to create accounts, build CVs and portfolios, provide secure login, enable LinkedIn sign-in, deliver requested messages, process purchases where applicable, and maintain the security and operation of the service.
Profiles are unlisted: a public CV preview is available only through its permanent, high-entropy tokenized link or QR code. DevProofs does not intend to make these preview links searchable or index them for search engines.
1. Who controls your data
For the purposes of the EU General Data Protection Regulation (GDPR), the data controller for DevProofs is:
Pelea Raul-Daniel
Individual operator and DevProofs founder
Principala, Tureni, Cluj, 407560, Romania, Europe
Administrator contact: [email protected]
The address [email protected] is used only to send automated messages and cannot receive privacy requests. Please use the administrator contact above for questions, rights requests, or concerns.
2. Information we collect
The exact information we process depends on how you use DevProofs and the choices you make in your account.
| Category | Examples | Purpose |
|---|---|---|
| Account data | Full name, email address, password hash, profile picture, email-verification status and timestamps, account creation, update and login timestamps. | Account creation, authentication, communications, fraud prevention and service administration. |
| Profile and CV data | Headline, description, bio, location, phone number, experience history, education, skills and proficiency, projects, project links, GitHub links, certificates, certificate links, and other CV or profile information you add. | Building, displaying, exporting and sharing your CV or portfolio. |
| LinkedIn data | OpenID subject/account identifier, name, email address and profile picture received through LinkedIn OAuth. | LinkedIn sign-in, account verification, account identity and profile population. |
| Preview data | A permanent random preview token and preview-generation timestamp. | Providing unlisted shareable CV links and QR-code access. |
| Technical and security data | Session identifiers, consent preferences, device/browser information, IP-related security logs, CAPTCHA/rate-limit signals and error-monitoring records. | Security, abuse prevention, diagnostics, website operation and compliance. |
| Payment and transaction data | Billing details you enter at checkout (name, address, city, postal code, country, and company name and VAT ID if you buy as a company), your PayPal subscription and transaction IDs, amounts, dates, refunds and subscription status. We never receive your card or bank details - PayPal processes them. Invoice copies may be retained in private business email. | Performing the subscription contract (Art. 6(1)(b) GDPR) and meeting tax and accounting obligations (Art. 6(1)(c)); kept for the periods required by Romanian accounting and tax law. |
| Checkout consent records | When you order Pro: the date and time, the Terms version, the confirmations you ticked, your IP address and browser user-agent, and the withdrawal request if you make one. | Proving that the order and your consents were given as required by consumer law (legitimate interest, Art. 6(1)(f)); kept while the subscription runs and for 3 years after it ends (the general limitation period). |
Do not submit information that you do not want included in a CV, portfolio, project preview, certificate entry, or other profile section. You remain responsible for ensuring that information you publish or share is accurate and appropriate.
3. Why we use your information
We process personal data only where we have a lawful basis under GDPR. Depending on the context, this is performance of a contract, our legitimate interests, consent, or compliance with a legal obligation.
- To provide DevProofs: create and manage your account, produce CVs, portfolios, downloads, tokenized previews and other requested features.
- To authenticate and secure accounts: verify email addresses, support LinkedIn OAuth, prevent duplicate or fraudulent use, detect abuse and protect infrastructure.
- To communicate: send account, security, verification, service, recruiter-message, job-alert, newsletter or product emails according to your account settings and applicable law.
- To process purchases: manage paid plans, payments, invoices, refunds, tax records and related customer support.
- To improve the service: use aggregated or de-identified analytics, diagnostics and performance information where enabled.
- To comply with law: preserve limited information when necessary for accounting, tax, security, dispute resolution or legal claims.
4. Unlisted CV previews and public information
DevProofs CV previews are designed to be unlisted rather than openly searchable. They can be viewed by anyone who has the applicable tokenized link or QR code. Users may share these links with employers, clients, recruiters, companies, or other recipients.
Email address, phone number and location may appear on a shared CV preview when the user has enabled their visibility. Because these fields can be shared in a CV link, download, PDF, PNG, JPG or WebP export, users should review their profile settings and previews before sharing.
Unlisted does not mean confidential or access-controlled. Anyone who receives the link may be able to open it unless the preview is changed, revoked, or the account is deleted.
5. LinkedIn and OAuth sign-in
You may register or sign in through LinkedIn OAuth. When you choose this method, LinkedIn may provide DevProofs with your OpenID subject identifier, name, email address and profile picture, subject to the permissions you grant and LinkedIn's own policies.
The LinkedIn identifier is used to support account identity and verification. LinkedIn OAuth tokens may be stored and used only while valid and operational under LinkedIn's rules, which may range from approximately one to twelve months depending on the token and LinkedIn configuration. Tokens are not intended to be retained longer than necessary for the connected functionality.
LinkedIn-linked accounts generally cannot be “unlinked” while retaining the same account identity because the LinkedIn identifier is part of the account verification and uniqueness process. You may request deletion of your DevProofs account and, if desired, create a new account without LinkedIn afterward.
8. Retention and account deletion
We keep account and CV data while your account remains active or while it is needed to provide the service. When you request deletion, we aim to remove or anonymize account and profile data within 30 days, subject to technical limitations and lawful retention requirements.
We may retain limited information beyond this period where necessary for tax, accounting, invoicing, fraud prevention, security, dispute resolution, legal claims, or compliance with a legal obligation. Invoice and transaction records may be kept for the period required by applicable accounting and tax laws.
9. Your rights under GDPR
Subject to applicable law, you may request:
- Access to your personal data.
- Correction of inaccurate or incomplete data.
- Deletion of your data.
- Export/portability of data you provided to us.
- Restriction of processing in certain situations.
- Objection to processing based on legitimate interests.
- Withdrawal of consent at any time where processing is based on consent.
- Changes to email preferences through account settings, where available.
To exercise these rights, email [email protected]. We may request reasonable information to verify your identity before acting on a request. You also have the right to lodge a complaint with the Romanian data-protection authority, Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), or with the supervisory authority in your country of residence or work.
10. How we protect information
No internet service can guarantee absolute security. However, DevProofs uses reasonable technical and organizational measures intended to protect data from unauthorized access, alteration, loss and misuse, including:
- HTTPS and SSL/TLS encryption in transit.
- Password hashing rather than storing readable passwords.
- Email verification and session controls.
- Sanitized inputs and prepared database queries.
- Cloudflare security features, CAPTCHA, bot mitigation and rate limiting.
- Server access protections, including SSH two-factor authentication, strong passwords and authenticator-app controls.
- Fail2ban, server-side and Cloudflare rate limiting, monitoring and anti-abuse behavior.
- Backups and recovery procedures.
11. Children and minimum age
You must be at least 16 years old to create a DevProofs account. A person under 16 may use the service only with the consent of a parent or legal guardian.
We cannot reliably determine a person's age from information submitted to the service, and users may provide inaccurate information. If you believe a child has created an account without appropriate consent, please contact us so we can review the situation.
12. Changes to this policy
We may update this Privacy Policy when DevProofs changes, legal requirements change, or our practices evolve. We will post the revised policy on this page and update the effective date. For material changes, we may provide additional notice through the website or email where appropriate.
13. Contact us
Privacy requests and questions
Email [email protected]
DevProofs · Pelea Raul-Daniel · Tureni, Cluj, Romania