Legal

Privacy Policy

Last updated: 22 August 2026

This Privacy Policy explains how Rolvue ("Rolvue", "we", "us") collects, uses, and protects personal data when you use our website, application and Rolvue Apply browser extension (the "Service"). We process data in line with the EU General Data Protection Regulation (GDPR) and applicable local law.

1. Who we are

The data controller is to be published, registered at to be published, VAT/company number to be published. Privacy requests can be sent to contact to be published or submitted through the Support page.

2. Data we collect

  • Account & identity: email address, canonicalised email used for anti-abuse checks, name, verification events and account status. We use password-free magic links and store only hashed, expiring tokens.
  • Profile you build: university, programme, target sectors, Milano preferences, seniority, languages, and preferences you enter during onboarding.
  • Usage data: roles you track, contacts you unlock, filters, and in-app activity needed to run your tracker and alerts.
  • Alert channels: verified email, Telegram chat identifier, WhatsApp (Coming soon) number and push token only when you connect those channels. Availability depends on your plan.
  • Contact Database: business contact records returned by Hunter, the bank and role, records you unlock, token balance and token ledger. Personal contact fields remain withheld from your account until you unlock that record. If you are one of the professionals in that database, the Contact Database Notice explains what we hold and how to have it removed.
  • Payments: plan and purchase records. Card details are handled directly by our payment processor; we never see or store full card numbers.
  • Support & communications: messages you send us (including via WhatsApp (Coming soon) or email) and their content.
  • Technical data: device, browser, and cookies as described in our Cookie Policy.

2A. Rolvue Apply Chrome extension

Rolvue Apply has one purpose: filling job-application forms with a profile you save. Your profile and CV are stored exclusively in chrome.storage.local on your device. The extension handles the visible application-form fields locally so it can fill them after your action, but it does not submit applications or tick consent boxes.

The extension does not transmit your profile, CV or form content to Rolvue or to third parties. Its fonts, icons and other assets are bundled in the extension. You can export your profile or erase it, including the saved CV, with Clear all in the extension settings; uninstalling the extension also removes its local storage.

The extension is unlocked with your Rolvue account, so it does contact api.rolvue.com — from its background worker only, never from inside an application page — in three cases:

  • When you unlock it: your unlock code and a random device identifier generated in your browser are sent, and a signed device token comes back. The identifier is random; it is not a fingerprint of your device and it is not shared with anyone. Your email address is not required to unlock.
  • Once a day: the token is sent to confirm your plan and how many profiles it includes.
  • When they change: the per-ATS filling rules are downloaded, all of them at once.

The rules are downloaded as a single bundle rather than per site, so Rolvue never receives the addresses of the job pages you visit. Nothing is sent while a form is being filled. You can unlink a device at any time from your account area, which stops that installation at its next check.

The storage permission stores that local profile. activeTab and scripting let the extension fill the page only when you invoke it. alarms schedules the daily plan check. Explicit host permissions allow the fill panel on the listed applicant-tracking systems, plus api.rolvue.com for the three calls above; the extension does not request access to every website.

3. How we use your data

  • Provide, personalise, and secure the Service (database access, tracker, alerts).
  • Match live roles to your profile and deliver notifications you request.
  • Process payments and manage your plan.
  • Respond to support requests.
  • Maintain, improve, and analyse the Service in aggregate.
  • Meet legal, accounting, and security obligations.

We do not sell your personal data.

4. Legal bases (GDPR Art. 6)

  • Performance of a contract: to provide the Service you sign up for.
  • Consent: for optional analytics cookies and, where applicable, marketing. You can withdraw consent at any time.
  • Legitimate interests: to secure, maintain, and improve the Service, balanced against your rights.
  • Legal obligation: for tax, accounting, and compliance.

5. Who we share data with

We share only what is necessary with providers acting for the Service: Stripe (checkout, subscriptions, invoices and payment retries), Hunter (business-contact search by monitored bank/domain), Render (hosting and database infrastructure), Resend (delivery of sign-in links, alerts and digests), Skipsend (a one-off check of the email domain at sign-up, to block disposable mailboxes; the full address is not sent for this check), Telegram, our WhatsApp (Coming soon) gateway and push delivery. Optional analytics runs only after consent. We may also disclose data where required by law or to protect rights and security.

6. International transfers

Some providers may process data outside the European Economic Area. Where this happens, we rely on adequacy decisions or Standard Contractual Clauses to protect your data.

7. How long we keep data

We keep account and product data while the account is active, billing records for the statutory tax/accounting period, security and audit logs only as long as necessary for abuse prevention, and cached Hunter records while the related bank remains monitored or until refreshed/deleted. Unlocked-contact history is retained to preserve the purchased entitlement. You can request deletion, subject to legal retention duties.

8. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your data, to object to certain processing, and to withdraw consent. Submit requests through Support. You may also complain to your local supervisory authority (in Italy, the Garante per la protezione dei dati personali).

9. Security

We use encryption in transit, access controls, signed Stripe webhooks, expiring password-free email links, hashed verification tokens, server-side Hunter credentials and minimised API responses for locked contacts. No transmission method is completely secure.

10. Age

The Service is intended for university students and professionals aged 18 or over. We do not knowingly collect data from children under 16.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated in-app.

12. Contact

Questions or privacy requests can be sent to contact to be published or submitted through the Support page.