Legal Notice
In accordance with the provisions of French Law No. 2004-575 of June 21, 2004 on Confidence in the Digital Economy (LCEN), we inform you of the identity of the various parties involved in the creation and monitoring of this website.
1. Website Publisher
The MyTrackia website (hereinafter "the Site") accessible at mytrackia.com is published by:
- Name:
- Thirisan Raveendran
- Status:
- Sole trader (Auto-entrepreneur)
- SIRET:
- 10214733700012
- Address:
- 50 avenue des Champs-Élysées, 75008 Paris, France
- Email:
- contact.mytrackia@gmail.com
2. Publication Director
The publication director of the Site is:
Thirisan Raveendran
Contact: contact.mytrackia@gmail.com
3. Hosting
The Site is hosted by:
These providers process personal data on behalf of MyTrackia. Data Processing Agreements (DPAs) are in place in compliance with GDPR.
4. Intellectual Property
All content on the Site (texts, images, graphics, logo, icons, sounds, software, etc.) is the exclusive property of MyTrackia or its partners, and is protected by French and international intellectual property laws.
Any reproduction, distribution, modification, adaptation, retransmission or publication, even partial, of these elements is strictly prohibited without the express written consent of MyTrackia.
The application source code is protected by copyright. Any reverse engineering, decompilation or attempt to extract the source code is prohibited.
Trademarks and logos appearing on the Site are registered trademarks of MyTrackia. Any unauthorized use of these trademarks is strictly prohibited.
5. Personal Data Protection
MyTrackia places great importance on protecting your personal data and is committed to complying with applicable regulations, in particular the General Data Protection Regulation (GDPR — EU Regulation 2016/679).
5.1 Data Controller
The data controller for your personal data is:
- Thirisan Raveendran
- contact.mytrackia@gmail.com
- 50 avenue des Champs-Élysées, 75008 Paris, France
5.2 Processing Purposes
The personal data collected is used for the following purposes:
- •Creating, authenticating and managing your user account
- •Tracking your job applications, job offers and recruitment sites
- •Storing and managing your personal documents (CVs and cover letters)
- •Automated ATS readability analysis of your CVs (text extraction and diagnosis, with no automated decision-making about you within the meaning of Article 22 GDPR)
- •Sending follow-up reminders by email and in-app notifications
- •Processing your messages via the contact form and responding to support requests
- •Managing subscriptions, payments and billing (Pro plan) via Stripe
- •Calculating your personal usage statistics and monthly quotas
- •Improving, measuring audience for and securing the service
- •Detecting and preventing fraud and abuse
- •Complying with our legal obligations (accounting, tax, responses to authorities)
5.3 Data Collected
The following data may be collected and processed:
- •Identity: first name, last name, profile picture (avatar, if you choose to upload one)
- •Contact details: email address
- •Authentication data: hashed password (never stored in plain text), OAuth identifiers if you sign in via Google or GitHub, timestamp of acceptance of the Terms and Privacy Policy
- •Application and tracking data: companies, positions, statuses, dates, notes, salaries, contract types, locations, tags, links
- •Saved job offers: title, company, URL, notes
- •Tracked recruitment sites: name, URL, notes
- •Follow-ups: scheduled reminder dates, delivery status
- •Documents: CV and cover letter files (PDF or DOCX), title, size, MIME type, original filename
- •ATS analysis results: text extracted from your CVs, detected sections, detected contact information (email, phone, LinkedIn), readability score, warnings
- •Connection and technical data: IP address, browser type and version, operating system, session logs, unique identifier
- •Subscription data: plan type (free / Pro), status, start and end date, billing cycle, Stripe customer and subscription identifiers (MyTrackia does not store any payment card details — these are handled exclusively by Stripe)
- •Usage counters (monthly quotas): number of applications, job offers, sites, follow-ups and messages consumed
- •Preferences: interface language, notification preferences, cookie settings
- •In-app notifications: title, message, read status, type
- •Contact messages: name, email, subject, message, processing status and reply from our team
- •Usage data: anonymized statistics and audience data (subject to your consent for analytics cookies)
Important notice: CVs and cover letters you upload may contain special categories of personal data within the meaning of Article 9 GDPR (for example: ethnic origin, opinions, health, trade-union membership, religious beliefs). MyTrackia does not actively process these special categories and does not use them for any purpose other than storing the document and performing ATS analysis at your request. You remain free to remove such information from your documents before uploading them if you wish.
5.4 Retention Period
The retention periods we apply are as follows:
- •Account and profile data: duration of active account + 30 days after deletion
- •Application, job offer, recruitment site, follow-up and notification data: duration of active account + 30 days after deletion
- •Documents (CVs and cover letters): duration of active account + 30 days, files permanently removed from encrypted storage
- •ATS analysis results: automatically deleted when the corresponding CV is deleted or when the account is deleted
- •Contact messages: 3 years from the last exchange
- •Payment data and invoices: 10 years (accounting and tax obligations)
- •Security and technical logs: 90 days maximum
- •Analytics and audience cookies: 13 months maximum
After deleting your account from the settings, all your personal data and files are permanently deleted within a maximum of 30 days, except for data subject to a legal retention obligation.
5.5 Your Rights
Under the GDPR (Articles 15 to 22), you have the following rights:
- •Right of access to your personal data
- •Right to rectification of inaccurate data
- •Right to erasure ("right to be forgotten")
- •Right to restriction of processing
- •Right to data portability
- •Right to object to processing
- •Right not to be subject to automated decision-making
To exercise these rights, contact us at: contact.mytrackia@gmail.com. We commit to responding within one month.
You may also lodge a complaint with the French data protection authority (CNIL) at: www.cnil.fr — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
5.6 Data Security
MyTrackia implements appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, destruction or disclosure.
- ✓Encryption of data in transit (HTTPS/TLS)
- ✓Encryption of data at rest (AES-256) in the database
- ✓Files (CVs, cover letters) stored in private, encrypted buckets (AES-256), not publicly accessible
- ✓Downloads only via temporary signed URLs valid for 60 seconds — no permanent URL
- ✓Row-Level Security (RLS): each user only accesses their own data and files
- ✓Passwords hashed and never stored in plain text
- ✓Secure authentication via JWT (httpOnly tokens)
- ✓Bot protection via Cloudflare Turnstile on all sensitive forms
- ✓Rate limiting on sensitive actions (sign-in, sign-up, contact, etc.)
- ✓Production data access strictly restricted to authorized personnel and logged
In the event of a data breach likely to pose a risk to your rights and freedoms, MyTrackia commits to notifying the CNIL within 72 hours and informing you as soon as possible, in accordance with Articles 33 and 34 GDPR.
5.7 Sub-processors
MyTrackia uses the following sub-processors to deliver its services:
| Provider | Role | Location | DPA |
|---|---|---|---|
| Supabase Inc. | Database (PostgreSQL), authentication and encrypted file storage (CVs, cover letters) | Singapore / EU | DPA in place |
| Vercel Inc. | Hosting, deployment and edge functions | United States (SCCs) | DPA in place |
| Resend Inc. | Transactional email delivery (welcome, follow-ups, contact) | United States (SCCs) | DPA in place |
| Stripe Payments Europe Ltd. | Payment processing and subscription management (Pro plan) | Ireland / EU and United States (SCCs) | DPA in place |
| Cloudflare Inc. | Bot protection (Turnstile CAPTCHA) | United States (SCCs) | DPA in place |
| Sentry Inc. | Error and performance monitoring | United States (SCCs) | DPA in place |
| Google LLC | OAuth authentication and Google Analytics audience measurement (subject to your consent) | United States (SCCs) | DPA in place |
| GitHub Inc. | OAuth authentication (if you choose to sign in via GitHub) | United States (SCCs) | DPA in place |
| Trustpilot A/S | Customer reviews widget and post-onboarding email invitations | Denmark / EU | DPA in place |
Data transfers outside the European Union are governed by Standard Contractual Clauses (SCCs) adopted by the European Commission in accordance with Article 46 GDPR. The list of sub-processors may change; any material change will be reflected on this page.
For more information on how we collect and use your data, please see our Privacy Policy. Privacy Policy
6. Cookies
The Site uses cookies and similar technologies to ensure its proper functioning and to improve your experience.
Types of cookies used:
- •Strictly necessary cookies: essential for the Site to function (authentication session, security). They cannot be disabled.
- •Performance cookies: allow us to measure the Site's audience and performance (anonymized data).
- •Functionality cookies: remember your preferences (language, theme) to improve your experience.
- •Security cookies: bot protection via Cloudflare Turnstile.
On your first visit, a banner informs you of the use of cookies and allows you to manage your preferences. You can change your choices at any time via the "Cookie Settings" button on the Site.
Cookies have a maximum lifespan of 13 months in accordance with CNIL recommendations.
For more information about cookies, please visit: www.cnil.fr/fr/cookies-et-autres-traceurs.
7. Hyperlinks
The Site may contain links to third-party websites. MyTrackia has no control over these sites and cannot be held responsible for their content, privacy policy or practices. We recommend that you consult the legal notices of each site you visit.
Any hyperlink pointing to the Site must be subject to prior written authorization from MyTrackia. For any request, contact: contact.mytrackia@gmail.com.
8. Limitation of Liability
MyTrackia strives to ensure the accuracy and currency of information published on the Site. However, MyTrackia cannot guarantee the accuracy, completeness or timeliness of information on the Site.
MyTrackia shall not be liable for any direct or indirect damages resulting from the use of the Site or the inability to access it, including data loss, loss of revenue, business interruption or any other damage.
The user is solely responsible for their use of the Site and the information they publish on it. MyTrackia reserves the right to suspend or delete any account in the event of misuse or conduct contrary to the Terms of Service.
MyTrackia does not guarantee uninterrupted availability of the Site and reserves the right to interrupt it at any time for maintenance, updates or any other reason deemed necessary.
Regarding the ATS readability checker: it is an overview tool developed by MyTrackia based on public heuristic rules. It does not replicate the exact behaviour of commercial ATS used by recruiters (Workday, Taleo, Greenhouse, Lever, iCIMS, etc.), which apply their own proprietary algorithms. A favourable score improves your chances but does not guarantee passing the ATS filter of any given company. MyTrackia cannot be held liable for the rejection of an application linked to the analysis, the absence of analysis, or an analysis error by a third-party ATS.
9. Changes to Legal Notice
MyTrackia reserves the right to modify this legal notice at any time. Changes take effect upon publication on the Site. You are advised to check this page regularly. The last update date is shown at the top of this document.
10. Applicable Law and Jurisdiction
This legal notice is governed by French law. In the event of a dispute relating to the interpretation or performance hereof, the parties will endeavor to resolve their disagreement amicably. Failing that, French courts shall have exclusive jurisdiction, even in the event of multiple defendants or third-party proceedings.
11. Contact
For any questions relating to this legal notice, or to exercise your rights regarding personal data, you may contact us:
Email: contact.mytrackia@gmail.com
We commit to responding to your request as soon as possible, and no later than one month as required by GDPR.