What we collect
When you request the CV or a call, we collect:
- The details you provide: name, company, job role, LinkedIn URL, company email.
- Verification signals: results of free-mail / disposable-domain checks, DNS MX lookup, WHOIS domain age, LinkedIn URL HEAD response, and a search for the company's LinkedIn page.
- Browser & device characteristics: User-Agent, language preferences, referrer, screen resolution, timezone, platform, memory, hardware concurrency, and a stable fingerprint hash plus raw fingerprint components.
- Approximate location: your IP resolved to country, region, city, postal code, and lat/long (city-level), plus ASN (your network provider) and VPN/proxy/Tor/hosting flags. We store the IP itself.
- Activity log: which actions you clicked (Download CV / Schedule a Call), timing of form fills, whether you pasted, and timestamps.
Why we collect it
To verify that the people requesting the CV or a call are who they say they are, to recognise you on return visits so you don't have to re-verify, and to keep an audit trail.
Who else sees it
- Google — receives the company name when we look up its LinkedIn page via search.
- Resend — receives your email address to deliver the verification code.
- Supabase — stores all the data above on our behalf.
- proxycheck.io — receives your IP to flag VPN/proxy/Tor.
- Amazon Web Services (AWS) — hosts the application (Amazon S3 and CloudFront for the site; AWS Lambda for the verification API).
- MaxMind GeoLite2 IP→geo lookups happen on the server and do not transmit your IP to a third party.
Retention
Verified records and visit events are retained indefinitely. Pending verification codes are deleted within 10 minutes. Trusted-device records are revoked when they expire (90 days after creation).
Your choices
If you'd like your data deleted, email info@hassanhashmi.com. Manual deletion will be performed promptly.
← Back to home