Draft for legal review. This is not a finished privacy policy. Do not rely on it until a lawyer has reviewed it for the Privacy Act 1988 and the Australian Privacy Principles.

Privacy policy (draft)

FIFOWorks is a job board. Jobs posted here take applications on FIFOWorks. Jobs collected from an employer career page link to that original ad. The operator must insert their legal name, ABN and contact email before launch (see PUBLISHER_LEGAL_NAME and PUBLISHER_ABN).

What we collect

Why

To run the board, review ads, send emails you asked for, take payment for premium ads, and investigate reports. A small business exemption under the Privacy Act can be lost where personal information is collected for a benefit or service. Plan to comply with the APPs from the start.

Who else sees it

Hosting and database: Vercel and Supabase, when those accounts are connected. Resumes are stored in a private Supabase Storage bucket when that is configured, and are opened only with a short-lived signed link. Without Storage they stay in the database and are still opened with a signed link. The recruiter who posted the ad can see that application in their FIFOWorks account. Payments: Stripe, for premium ads only. Email: Resend, including an application confirmation to the worker and a notice to the recruiter who posted the ad. That notice names the job and links to log in. It does not include the applicant’s name, contact details or resume. For an ad that arrived by email, FIFOWorks does not email the recruiter. The worker receives an application pack at their own address, including the recruiter’s apply email, so they can send it themselves. Optional virus scanning uses VIRUS_SCAN_URL. Optional language-model checks of ad text, and a worker’s resume when they ask us to read tickets from it, use the provider in LLM_BASE_URL. Resume text is not written to logs. We do not sell personal information. If analytics are switched on, Plausible records page views and events for applications, alerts, posting and checkout, without advertising cookies.

Email

Alert and weekly emails are sent only after you open a confirmation link. Every commercial email identifies FIFOWorks and includes an unsubscribe link. Add a postal address (POSTAL_ADDRESS) before sending those emails to real people, to meet the Spam Act 2003. The application pack is a transactional email the worker triggers by tapping Apply. It is sent from the business address, with no marketing. Ticket expiry warnings stay in the app and in that pack. FIFOWorks does not send expiry reminder emails.

Access, correction and deletion

Applicants, recruiters and subscribers can email the operator address published at launch to ask for a copy of the personal information FIFOWorks holds, to correct it, or to have it deleted. That includes an application, a resume, a recruiter account, a worker account and an alert subscription. Unsubscribe links stop further email without a login. A recruiter or worker can also delete their own account from the account page. A worker can delete just the resume, which also removes tickets that were read from it.

Overseas disclosure

FIFOWorks is aimed at people in Australia. Some providers that process personal information are based overseas, including in the United States: Vercel (hosting), Resend (email) and the optional language-model provider. Supabase should be created in the Sydney region, and Vercel functions should run in Sydney (syd1), so the database and resume files stay in Australia when those settings are used. By applying, posting or subscribing you acknowledge that some information may be handled by those overseas providers for the purposes above.

Retention

Ads expire on the timetable in the terms. Account and subscription records stay while the account or subscription is active, and for a short period afterwards if needed for a dispute or a legal obligation. Applications on recruiter-posted ads, and those resumes, are deleted after APPLICATION_RETENTION_DAYS (90 days unless the operator sets another number). Setting that value to 0 turns that deletion off and must not be used for a public launch. A worker resume, and the tickets read from it, are deleted after RESUME_INACTIVITY_DAYS without account activity (365 days unless the operator sets another number, or 0 to turn that off). A worker can delete the resume or the account sooner.