Privacy policy
Last updated: 6 September 2026
This page describes what is actually installed on this site. Not a template: every tool named here is one we run.
1The short version
We collect what we need to sell you a file and to know whether our advertising works. Our own site analytics runs on our own server, in our own database, and it sets no cookie. The only cookie this site sets is the one that remembers your privacy choice.
The ad platforms are a separate thing. They are listed in section 3, they set their own cookies, and one switch turns all of them off at once.
We do not sell personal information for money. Sending events to ad platforms can count as “sharing” under California law, which is why section 5 gives you a switch for it.
2What we collect
Your order. Our database keeps the email address you paid with, the amount, the currency, the payment provider’s session and payment identifiers, and the time. We use it to deliver the file, to answer support email, and to keep the accounting records the tax authorities expect.
What Stripe collects for us. The payment page is Stripe’s. To take the payment and to work out the tax, Stripe collects your card details, your name and your billing address, and it shows us your email address, the amount, and the billing country it used for tax. Card numbers never reach our server, and the billing address stays in our Stripe account rather than in our database. Data a processor collects for us is still data we are responsible for, which is why it is named here.
Download access log. Each time a download link is used we record the time, whether it worked, the browser user agent, and a one-way hash of the IP address. We keep the hash, not the address, so the log can catch a link being passed around without holding a list of who lives where.
Site analytics. Page views, how far down the page you scroll, which questions you open, and which buttons you press. These are recorded on our own server, in our own database. A random visitor id is kept in your browser’s local storage, not in a cookie, so repeat visits join up. In the EU and the UK it is created only after you accept; everywhere else it is created on your first visit and section 5 clears it.
What we never collect. No card number, no phone number, and no account, because there is no account.
3Ad measurement
We advertise on Meta and TikTok and we look at the numbers in Google Analytics. To know which advert produced a sale, three measurement tools are installed:
- Meta Pixel in your browser and the Meta Conversions API from our server
- TikTok Pixel in your browser and the TikTok Events API from our server
- Google Analytics 4
One switch covers all three. In the EU and the UK they stay off until you accept them in the banner. Everywhere else they are on by default and section 5 turns them off.
Each of those destinations can receive:
- Event name
- page_view, view_content, scroll depth, cta_click, begin_checkout, purchase
- Event id
- a random id, sent identically from your browser and our server so one action is counted once
- Page
- the address of the page, without anything after the question mark, and the page you arrived from
- Ad click id
- fbclid, ttclid or gclid, the identifier the advert added to the link you clicked
- Platform cookies
- _fbp, _fbc, _ttp and _ga, set by those platforms in your browser
- On a purchase
- the order value, the order id, and your email address hashed with SHA-256
The email address goes out hashed, never in readable form. We do not put your IP address into anything the browser sends, but those platforms see it themselves the moment your browser contacts them, the way any site you load does. Our server-side calls send it because those APIs require it. We never store it in readable form.
4Cookies and browser storage
One cookie on this site is ours. The rest of what we keep lives in your browser’s own storage, and the platform cookies below are set by the platforms, only while ad measurement is on.
- jk_consent
- cookie, ours. Your choice from the banner or the choices dialog. 365 days. The only cookie we set.
- jk_vid
- local storage, not a cookie. A random visitor id so repeat visits join up. Stays until it is cleared.
- jk_attr
- local storage. Which advert or link brought you here, so the sale can be credited to it.
- jk_sid
- session storage. A session id for the current tab. Gone when you close it.
- _fbp, _fbc
- cookies set by Meta while ad measurement is on.
- _ttp
- cookie set by TikTok while ad measurement is on.
- _ga, _ga_*
- cookies set by Google Analytics while ad measurement is on.
When you switch ad measurement off — by declining the banner, by saving the choices dialog with the switch off, or by sending Global Privacy Control — we stop forwarding events to those platforms immediately, tell Meta and TikTok to revoke the consent they were given, delete _fbp, _fbc, _ttp, _ga and the _ga_* cookies from this domain, clear the visitor id and the attribution record out of local storage, and reload the page so no pixel script is left running in it. Your consent record is what remains.
5Your choices
The consent banner. In the EU and the UK you get a banner before any ad measurement loads. Decline and the site keeps working, with your choice as the only thing stored.
Do not sell or share my personal information. The link sits in the footer of every page, including this one. It opens a switch that turns ad measurement off for this browser and runs the clean-up described in section 4. This is the CCPA opt-out and it applies whether or not you live in California. In the EU and the UK the same link brings the banner back so you can change the answer you gave it.
Global Privacy Control. If your browser sends the GPC signal, ad measurement is off from your first page view and stays off, which covers Meta, TikTok and Google Analytics alike. We read it in the browser and again on our own server. It also overrides a choice you made earlier: if you had turned ad measurement on and then switched GPC on, we run the clean-up in section 4 on your next page load and record the new answer. You do not have to touch the link above. If you do use it to turn ad measurement back on while GPC is running, that later answer is the one we keep.
Your browser. Clearing site data for this domain removes everything listed in section 4, ours and the platforms’ alike.
Email us. Write to hello@jobkit.shop to ask what we hold about you, to correct it, or to have it deleted.
6Who else processes your data
- Stripe
- takes the payment. Card details go straight to Stripe and never touch our server.
- Resend
- sends the email with your download link.
- Vercel
- hosts the site and serves the pages.
- Cloud storage
- holds the product file that your signed download link fetches.
- Meta, TikTok, Google
- receive the ad measurement events described in section 3.
Those companies are in the United States and elsewhere. Where data leaves the EU or the UK, the transfer runs on the standard contractual clauses in their data processing terms.
7How long we keep it
- Orders and receipts
- as long as tax law requires the records to exist.
- Analytics events
- up to 13 months.
- Download access log
- up to 13 months.
- Consent record
- as long as the cookie lasts, up to 365 days.
- Support email
- two years, then deleted.
Those limits are a job, not a promise. The maintenance script npm run db:prune (scripts/db-prune.mjs) deletes analytics events and download-log rows once they pass 13 months, along with download links that expired more than 30 days ago. It runs monthly.
8Why we are allowed to hold it
Under the GDPR and the UK GDPR our legal bases are: performing the contract, for the order and the delivery of the file; legal obligation, for the accounting records; legitimate interests, for our own first-party site analytics and for keeping download links from being passed around; and consent, for everything in section 3 wherever consent is required.
9Your rights
If the GDPR or the UK GDPR applies to you, you can ask for a copy of your data, ask us to correct or delete it, ask us to limit what we do with it, object to processing based on legitimate interests, ask for it in a portable form, and withdraw consent at any time. Withdrawing consent does not undo what was done before.
If California law applies to you, you can ask what we collected, ask for it to be deleted or corrected, and opt out of sharing for advertising. We will not treat you differently for asking.
Email hello@jobkit.shop. We answer within 30 days and it costs nothing. If you are in the EU or the UK and you are not satisfied, you may complain to your local data protection authority.
10Children
Jobkit is sold to people running a business. It is not aimed at anyone under 16, and we do not knowingly collect data from children. If you believe a child sent us data, email us and we will delete it.
11Changes and contact
The date at the top of this page is the date of the current version. If we change something that matters, we change that date and say what changed.
Jobkit · hello@jobkit.shop · see also our terms and our refund policy.