CV Smart Sender Back to home
LEGAL · PRIVACY

Privacy Policy

This policy explains how CV Smart Sender handles account information, campaign data, and information received through Google APIs.

Effective July 31, 2026Controller CV Smart Sender SRLContact info@cvsmartsender.com
ControllerData we processHow we use dataGoogle user dataSharingRetentionYour rightsContact

1. Controller and scope

CV Smart Sender SRL, with its public contact location in Rome, Italy, operates CV Smart Sender at cvsmartsender.com and is the controller of personal information described in this policy. This policy applies to visitors, registered users, connected Gmail senders, support users, and recipients whose details a registered user enters into a campaign.

For privacy questions, rights requests, or account deletion requests, contact info@cvsmartsender.com. CV Smart Sender has not appointed a separate Data Protection Officer; privacy requests are handled through this address.

2. Information we process

Account and preference data

When you sign in with Google, we receive the Google account identifier, name, email address, profile image, and the authentication information needed to establish your platform session. We also store interface language, timezone, account role and status, signup date, and credit balance.

Gmail connection data

If you separately connect a Gmail sender, we process the connected Gmail address, the permissions granted, connection timestamps, and an encrypted OAuth refresh token. We never receive or store your Google password. The Gmail connection requests the gmail.send permission only for sending, together with basic identity permissions (openid, email, and profile). We do not request general Gmail inbox-reading permission.

Campaign and recipient data

We process campaign names, subjects, message bodies, schedules, timezones, recipient email addresses, optional recipient names and companies, uploaded CVs and attachments, delivery state, provider message identifiers, retry information, and failure categories. Each recipient receives an independent message; recipient lists are not exposed through CC or BCC.

Support, credit, and operational data

We process support conversations, credit requests, credit ledger entries, administrative actions, security and audit events, IP address, request identifiers, timestamps, and sanitized application errors. Private message bodies, OAuth tokens, request bodies, and full stack traces are not displayed in the administrative diagnostics interface.

Website and device data

We use essential session and security cookies. The browser may also store interface language, sidebar state, onboarding state, and a draft reference locally on your device. We do not use this information for behavioural advertising.

3. Purposes and legal bases

We use personal information to:

  • create and secure accounts, maintain sessions, and provide requested platform features;
  • connect the Gmail sender selected by the user and send or schedule messages the user has prepared;
  • store reusable attachments and campaign drafts, show delivery progress, and maintain accurate credit balances;
  • prevent spam, fraud, misuse, unauthorized access, and threats to recipients or the service;
  • respond to support and credit requests and maintain an accountable record of administrative actions;
  • diagnose failures, maintain availability, comply with law, and establish or defend legal claims.

Depending on the context, these activities rely on performance of our agreement with the user, our legitimate interests in operating and securing the service, compliance with legal obligations, and consent where consent is required. A campaign user is responsible for having an appropriate lawful basis to enter recipient data and contact each recipient.

4. Google user data and Limited Use

Google API Limited Use disclosure

CV Smart Sender's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google identity data is used to sign you in and identify your account. Gmail authorization is used only to send messages that you explicitly create, review, and send or schedule through visible platform features. We do not use Google user data for advertising, retargeting, creditworthiness decisions, sale to data brokers, or training general-purpose artificial intelligence or machine-learning models.

Human access to Google user data is prohibited except when you give specific consent for support, when access is necessary to investigate abuse or a security incident, when required by law, or when data has been aggregated and anonymized for permitted internal operations. Access is limited to authorized personnel with a need to know.

You can disconnect Gmail in Account settings. Disconnecting revokes the platform connection, removes the stored token, cancels campaigns that have not begun sending, and releases unused reserved credits. You can also review or revoke access from your Google Account permissions page.

5. Service providers, disclosures, and transfers

We do not sell personal information or recipient lists. We do not share Google user data with advertising networks or data brokers. Information may be processed by vendors that provide infrastructure strictly as needed to operate the service, currently including Google services for identity, Gmail delivery, cloud hosting, database infrastructure, and object storage. Our current vendor list is available on the Subprocessors page.

We may disclose limited information when reasonably necessary to comply with a binding legal request, protect the rights and safety of users or recipients, investigate fraud or abuse, or complete a corporate transaction subject to appropriate confidentiality and user notice where required.

Information may be processed outside the country where a user lives. Where European data protection law requires safeguards for an international transfer, we rely on an adequacy decision, approved contractual safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism made available by the relevant provider.

6. Security

We use encryption in transit, encrypted OAuth refresh tokens, access controls, tenant-scoped database queries, CSRF protection, secure sessions, rate limits, audit records, sanitized operational logging, and restricted administrative access. No service can guarantee absolute security. If you believe your account or data is at risk, contact us promptly at info@cvsmartsender.com.

7. Retention and deletion

Google OAuth tokenUntil Gmail is disconnected or the account is deleted.
Account, campaigns, recipients, and filesWhile the account remains active; deleted within 30 days after a verified account deletion request, unless a legal exception applies.
Support conversations24 months after the conversation is closed.
Security, audit, and credit records12 months, or longer when required for an unresolved dispute, abuse investigation, or legal obligation.
Sanitized application errors30 days.
BackupsRemoved through the backup rotation within 30 additional days.

To request account and data deletion, use Contact support inside the platform or email info@cvsmartsender.com from the address associated with your account. We may verify the request before acting. Deletion does not require continued Gmail access.

8. Your choices and rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent where processing relies on consent; and complain to the competent data protection authority. These rights may be limited by lawful exceptions. We normally respond within the period required by applicable law.

If you are a campaign recipient, the user who entered your details is normally responsible for the decision to contact you. You may contact that sender directly and may also report misuse to info@cvsmartsender.com.

9. Age requirement

CV Smart Sender is intended for people aged 18 or older. We do not knowingly offer accounts to children.

10. Changes to this policy

We may update this policy when the service, providers, or legal requirements change. We will publish the updated version with a new effective date and provide additional notice when a change materially affects how Google user data or other personal information is used.

11. Contact

CV Smart Sender SRL
Public contact location: Rome, Italy
Website: cvsmartsender.com
Email: info@cvsmartsender.com
© 2026 CV Smart Sender SRL
PrivacyTermsAcceptable useSubprocessors