Privacy Policy
How Shortlisted collects, uses, and protects your personal information โ written in plain English.
The short version
We collect what we need to build your CV and nothing more. Your personal and career information is never sold, shared with advertisers, or used to train AI models. You can access, edit, or delete your data at any time. If you have a question, just email us.
1. Overview
Shortlisted ("we", "us", "our") operates the website getshortlisted.com.au and the Shortlisted CV builder application. We are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act.
This Privacy Policy explains what personal information we collect, why we collect it, how we use and disclose it, and the choices you have in relation to your information. By using Shortlisted, you agree to the collection and use of information in accordance with this policy.
If you have any questions about this policy or your personal information, please contact us at privacy@getshortlisted.com.au.
2. What we collect
We collect personal information that you provide directly and information generated through your use of the service.
Information you provide
| Category | Information collected | Why we need it |
|---|---|---|
| Account | First name, last name, email address, password (hashed) | To create and manage your account |
| CV content | Employment history, education, skills, career summary, qualifications, professional memberships | To generate your AI-enhanced CV |
| Contact details | Phone number (optional), suburb/city, state, LinkedIn URL | To include on your CV as you choose |
| Working rights | Australian citizenship/visa status | To include on your CV and tailor AI output |
| Job application data | Job advertisements you paste into the service | To tailor your CV and calculate your ATS score |
| Payment | Payment is processed by Stripe โ we do not store card numbers, expiry dates, or CVCs | To process your purchase |
| Communications | Messages you send to our support team | To respond to your enquiries |
Information collected automatically
When you use Shortlisted, we automatically collect certain technical information including your IP address, browser type, device type, operating system, referring URL, pages visited, and the date and time of your visit. This information is used for security, analytics, and service improvement purposes.
3. How we use your information
We use the information we collect only for the purposes for which it was provided or as otherwise described in this policy:
- To provide the service โ building, enhancing, and generating your CV, cover letter, and LinkedIn rewrite
- To process payments โ via our payment provider, Stripe
- To communicate with you โ transactional emails (receipts, account notifications), and if you've opted in, product tips and updates
- To improve the service โ analysing usage patterns and feature performance (using aggregated, de-identified data only)
- To ensure security โ detecting and preventing fraud, abuse, and unauthorised access
- To comply with legal obligations โ where required by Australian law
Marketing communications
If you opted in to marketing emails during registration, we may send you occasional CV tips, job market updates, and product news. You can unsubscribe at any time by clicking the unsubscribe link in any email or contacting us directly. We comply with the Spam Act 2003 (Cth) โ we will never send unsolicited commercial electronic messages.
4. AI processing of your information
Shortlisted uses artificial intelligence to enhance your CV content. To do this, your CV information (employment history, skills, education, and any job advertisement you provide) is processed through our AI pipeline.
The AI-generated output is always presented to you for review and approval before it is included in your final CV. You remain in full control of your CV content at all times.
We do not make any automated decisions about you as an individual โ AI is used solely to improve the quality of your CV content. No profiling or automated decision-making in relation to your employment, creditworthiness, or any other significant matter occurs as part of this service.
5. Third-party service providers
We work with a small number of trusted third-party service providers to operate Shortlisted. Each provider is bound by a data processing agreement and is required to protect your information in accordance with applicable privacy law.
We do not share your personal information with any other third parties except where required by law or with your explicit consent.
6. Data storage and security
Your personal information is stored on secure servers. Where data is stored or processed outside Australia (for example, by our cloud infrastructure or AI provider), we take steps to ensure that it receives equivalent protections to those required under Australian privacy law, including through contractual data processing agreements.
We implement a range of technical and organisational security measures to protect your information, including:
- Encryption in transit (TLS/HTTPS) and at rest
- Access controls limiting who can view personal data
- Regular security reviews and vulnerability assessments
- Hashed password storage (we never store plain-text passwords)
- Stripe's PCI-compliant infrastructure for all payment processing
No method of electronic transmission or storage is 100% secure. While we take reasonable steps to protect your information, we cannot guarantee absolute security. If you become aware of any security concern, please contact us immediately at security@getshortlisted.com.au.
7. Data retention
We retain your personal information only for as long as necessary to provide the service and meet our legal obligations.
| Data type | Retention period |
|---|---|
| Account and CV data | Until you delete your account, or 24 months of inactivity, whichever comes first |
| Payment records | 7 years (required by Australian tax law) |
| Support communications | 2 years from the date of the last communication |
| Analytics data | Aggregated and de-identified โ no individual retention limit |
When your data is no longer required, it is securely deleted or de-identified in accordance with our data destruction procedures.
8. Your rights
Under the Privacy Act and Australian Privacy Principles, you have the following rights in relation to your personal information:
Access
You have the right to request access to the personal information we hold about you. You can access most of your information directly through your account settings. For a complete data export, contact us at privacy@getshortlisted.com.au.
Correction
If any of your personal information is inaccurate, out of date, incomplete, or misleading, you can correct it at any time through your account settings or by contacting us.
Deletion
You can delete your account and all associated data at any time through your account settings. Upon deletion, your CV data, personal information, and account details will be permanently removed within 30 days, except where retention is required by law (such as payment records).
Opt-out of marketing
You can opt out of marketing emails at any time using the unsubscribe link in any email or by updating your notification preferences in your account settings.
Complaints
If you believe we have interfered with your privacy, you have the right to make a complaint. Please contact us first at privacy@getshortlisted.com.au โ we will respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
9. Cookies and tracking
We use cookies and similar technologies to operate and improve Shortlisted. Cookies are small text files stored on your device.
| Cookie type | Purpose | Duration |
|---|---|---|
| Essential | Session management, authentication, security (CSRF protection) | Session / 30 days |
| Functional | Remembering your preferences and progress through the CV builder | 30 days |
| Analytics | Understanding how users interact with the service (privacy-friendly, no cross-site tracking) | 12 months |
We do not use advertising or tracking cookies. We do not participate in cross-site tracking or behavioural advertising networks.
You can control cookies through your browser settings. Disabling essential cookies may prevent the service from functioning correctly.
10. Children's privacy
Shortlisted is designed for use by adults seeking employment. We do not knowingly collect personal information from individuals under the age of 16. If you believe a person under 16 has provided us with personal information, please contact us at privacy@getshortlisted.com.au and we will delete that information promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify you by email (if you have an account) and by posting a prominent notice on our website at least 14 days before the changes take effect.
The date at the top of this policy indicates when it was last updated. We encourage you to review this policy periodically.
Continued use of Shortlisted after changes take effect constitutes your acceptance of the updated policy.
12. Contact us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us:
Privacy enquiries
๐ง privacy@getshortlisted.com.au
We aim to respond to all privacy enquiries within 30 days. For urgent matters, please indicate "Urgent" in your email subject line.