Privacy policy
Last updated
This describes what personal information Yenza’iCV collects, why it is collected, and what you can do about it under the Protection of Personal Information Act (POPIA).
Pending legal review
What we collect
The account details you give us: your name, your email address, and a password (stored only as a hash, never as the password itself).
The content you write into a CV, which is the point of the product, and the record of any payment you make — the amount, the date and the order number, not your card details.
Why we collect it
To give you an account, to keep your CVs for you, to let YenzaAI suggest improvements, to take a payment for a download, and to send you the email that confirms your address.
We do not sell your information, and we do not use your CV to train anything.
Cookies
There are two, and neither is there to track you around the internet.
- A refresh cookie, which is httpOnly (no script can read it) and is sent only to the sign-in endpoints. It is what keeps you signed in.
- A session hint, which holds the single character "1" and nothing else. It lets the server send a signed-out visitor to the sign-in page without asking the API first, and it is cleared when you sign out.
Who else is involved
PayFast processes payments, a transactional email provider sends the confirmation and reset emails, and Google handles the optional sign-in — if you use it, Google confirms your address and we never see your Google password.
Those providers receive only what they need for the job they do. They do not receive your CV to advertise anything.
Your rights under POPIA
You may ask what we hold about you, ask us to correct it, ask for a copy of it, or ask us to delete it.
The account screen does most of this directly: your details can be edited, your data can be exported, and your account can be deleted. Deleting it removes your CVs and ends your sessions.
How long we keep it
Your CVs and account are kept while your account exists. Financially, an invoice record has to be kept for the period the tax law requires, and it is kept for that and nothing else.
Short-lived things — a password reset link, a sign-in code, a verification link — expire on their own within minutes or hours.
Keeping it safe
Passwords are hashed, sessions are revocable, and access to production data is limited to the people who need it to run the service.
If something goes wrong in a way that affects your information, we will tell you what happened and what we are doing about it.