Privacy Policy

Last updated:
July 18, 2026
Effective date:
July 18, 2026
Table of contents

1. Introduction

Your privacy matters to us — not as a legal formality, but as a product principle. Zaplied is built on the premise that your professional data is yours, and we only use it to do the one thing you signed up for: help you apply for jobs.

This Privacy Policy explains what data we collect, why we collect it, how we use it, who we share it with, and what rights you have over it. It applies to zaplied.com and all Zaplied services.

Governing law. This policy is designed to comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, as currently in force. Where we serve users in other jurisdictions, we apply the same or higher standards.

If you have any questions about this policy, email us at support@zaplied.com.


2. Who We Are

Zaplied is operated by Velocity1 Tech Labs Pvt Ltd ("Zaplied", "we", "us", "our"), a company registered in India.

Under the DPDP Act, we act as a Data Fiduciary — the entity that determines the purpose and means of processing your personal data.


3. What Data We Collect

We collect data in three ways: data you give us directly, data generated by your use of the Platform, and data from third-party services you connect.

3.1 Data You Provide

Account data

  • Name, email address, password (hashed — never stored in plain text)

Profile data This is the professional information you enter to build your Zaplied profile:

  • Work experience (job titles, employers, dates, responsibilities, achievements)
  • Education (institutions, degrees, graduation dates)
  • Skills, certifications, and languages
  • Contact details you choose to include (phone number, LinkedIn URL, portfolio, GitHub)
  • Any other information you voluntarily add to your profile

Job description data

  • Job descriptions, role URLs, and company information you paste or enter when creating an application

Payment data

  • Transaction reference numbers and amounts
  • We do not store your card number, CVV, or bank account details — these are handled entirely by Razorpay

Communications

  • Messages you send to our support team

3.2 Data We Generate or Collect Automatically

Application outputs

  • Resumes, cover letters, outreach messages, and Q&A generated for your applications
  • ATS scores and match scores calculated for each role

Usage data

  • Pages visited, features used, time spent, button clicks, and in-app actions
  • Device type, browser type and version, operating system
  • IP address and approximate location (country/city level, derived from IP)

Cookies and similar technologies

  • Session cookies (required for you to stay logged in)
  • Analytics cookies (to understand how the Platform is used — see Section 7)

3.3 Data from Third Parties

We do not purchase data about you from third-party data brokers. If you connect a third-party account (e.g. sign in via Google), we receive only the information that service provides — typically your name and email address.


| Purpose | Data Used | Legal Basis | |---|---|---| | Creating and managing your account | Account data | Consent (account creation) | | Generating your application kit | Profile data, job description data | Performance of service you requested | | Processing payments | Payment data | Performance of contract | | Providing customer support | Account data, communications | Legitimate interest / contract | | Improving the Platform | Usage data, anonymised aggregates | Legitimate interest | | Fraud prevention and security | Account data, usage data, IP address | Legitimate interest / legal obligation | | Complying with legal obligations | Any relevant data | Legal obligation | | Sending product updates and announcements (if opted in) | Email address | Consent |

We do not use your data for advertising, profiling for third parties, or selling your information to any party.


5. Our Firm Commitment on AI Training

We will never use your personal data — including your profile, job descriptions, or generated application materials — to train, fine-tune, benchmark, or evaluate any AI or machine learning model, whether operated by us or by a third party, without obtaining your explicit, informed, written consent first.

This commitment exists because we know your resume contains sensitive information about your career, employers, and aspirations. It is yours. We only use it to generate your documents and then store it so you can access and edit it.

If we ever change this policy, we will notify you clearly before doing so and give you the option to delete your data.


6. How We Share Your Data

We do not sell your data. We share it only in the following circumstances:

6.1 Service Providers (Sub-processors)

We work with the following third-party providers who process your data on our behalf, under strict data processing agreements:

| Provider | Purpose | Data Shared | |---|---|---| | Supabase | Database, authentication, file storage | Account data, profile data, application outputs | | OpenAI (via Cloudflare Workers) | AI generation of application materials | Profile data, job description data (sent as prompts) | | Razorpay | Payment processing | Payment transaction data (not card details) | | Cloudflare | Edge computing, DDoS protection, CDN | Request metadata, IP addresses | | Google Analytics | Usage analytics | Anonymised usage data |

All sub-processors are contractually prohibited from using your data for any purpose other than performing their service for us.

Note on OpenAI. When we send your profile and job description data to OpenAI's API to generate your application materials, OpenAI's API usage policies apply. As of this policy's effective date, OpenAI does not use API inputs to train its models by default. We use the API, not ChatGPT's consumer interface.

We may disclose your data if required to do so by a court order, government authority, or applicable law. Where legally permitted, we will notify you of such a request before complying.

6.3 Business Transfers

If Zaplied is acquired by or merges with another company, your data may be transferred to the new entity. We will notify you before this happens and you will have the option to delete your account and data before the transfer takes effect.

We will share your data with any other party only with your explicit consent.


7. Cookies

We use a small number of cookies:

| Cookie Type | Purpose | Can You Opt Out? | |---|---|---| | Essential / session | Keeps you logged in, maintains your session | No — required for the Platform to function | | Analytics | Understands which features are used (anonymised) | Yes — via cookie preferences in your account settings | | Payment | Razorpay's payment flow cookies | No — required for payment processing |

We do not use advertising cookies or tracking cookies for third-party marketing.


8. Data Retention

| Data Category | Retention Period | |---|---| | Account and profile data | Until you delete your account, then 30 days | | Application outputs | Until you delete them or close your account, then 30 days | | Payment records | 7 years (required by Indian tax and accounting law) | | Usage logs | 12 months, then deleted or anonymised | | Support communications | 2 years from last communication | | Anonymised analytics | Indefinitely (no personal data attached) |

When you delete your account, we initiate deletion within 30 days. Some data (e.g. payment records) may be retained longer solely to comply with legal obligations.


9. Data Security

We take the following measures to protect your data:

  • All data in transit is encrypted using TLS 1.2 or higher
  • All data at rest is encrypted using AES-256
  • Passwords are hashed using bcrypt and are never stored in plain text
  • Access to production systems is restricted to authorised personnel only, with multi-factor authentication required
  • We conduct regular security reviews
  • Our sub-processors (Supabase, Cloudflare, etc.) maintain their own industry-standard security certifications

No method of transmission over the internet is 100% secure. In the event of a personal data breach that poses a risk to your rights, we will notify you and the relevant authority within 72 hours of becoming aware, as required by the DPDP Act.


10. Your Rights

Under the DPDP Act and applicable law, you have the following rights regarding your personal data:

10.1 Right to Access

You can request a copy of the personal data we hold about you.

10.2 Right to Correction

You can update most of your profile data directly from your account settings. For data you cannot update yourself, contact us and we will correct it.

10.3 Right to Erasure (Deletion)

You can delete your account from account settings, which initiates deletion of your profile and application data within 30 days. You can also request deletion of specific data by emailing support@zaplied.com.

Where we rely on your consent to process your data (e.g. marketing emails), you can withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.

10.5 Right to Grievance Redressal

If you believe we have mishandled your data, you can raise a grievance with our Grievance Officer (see Section 13). We will respond within 30 days.

10.6 Right to Nominate

Under the DPDP Act, you may nominate another person to exercise your rights on your behalf in the event of your death or incapacity. Contact us to make such a nomination.

To exercise any of these rights, email support@zaplied.com with the subject line "Data Rights Request." We will verify your identity before acting on your request and respond within 30 days.


11. Children's Privacy

Zaplied is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from someone under 18, we will delete it promptly. If you believe a minor has used Zaplied, please contact us at support@zaplied.com.


12. International Data Transfers

Our primary infrastructure is hosted in regions selected for reliability and compliance. When your data is processed by OpenAI (for AI generation), it may be processed on servers outside India. We take steps to ensure such transfers are covered by appropriate safeguards, consistent with applicable Indian law.

The DPDP Act's cross-border transfer provisions (including the whitelist of permitted countries) will become enforceable by May 2027. We are monitoring the regulatory rollout and will update our practices and this policy accordingly.


13. Grievance Officer

In accordance with the Information Technology Act, 2000 and the DPDP Act, we have appointed a Grievance Officer:

Name: Prashant Chourasia Email: support@zaplied.com Response time: Within 30 days of receiving your complaint

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India once it is operational.


14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Send you an email notification at least 14 days before the change takes effect
  • Display a prominent notice in the Platform

Your continued use of Zaplied after the effective date of a change constitutes your acceptance of the updated policy. If you do not accept the changes, you may delete your account before the changes take effect.


15. Contact Us

For any privacy-related questions, concerns, or requests:

Email: support@zaplied.com Grievance Officer: support@zaplied.com General support: support@zaplied.com Website: zaplied.com

Velocity1 Tech Labs Pvt Ltd 14, C. I. Enclave, Chunabhatti, Kolar Rd, Bhopal India


Quick Summary (Plain English)

We know legal documents are long. Here is the short version — the full policy above is the binding version, but we want you to actually understand it:

| What | Our position | |---|---| | Do we sell your data? | No. Never. | | Do we use your data to train AI? | No — not without your explicit consent, which we will never ask for silently | | Who can see your profile? | Only you and the Zaplied systems that generate your documents | | What do we share? | Only what's needed to run the service (database, AI API, payments) | | Can you delete your data? | Yes, anytime — from account settings or by emailing us | | Do we track you for ads? | No advertising cookies or third-party tracking | | How long do we keep your data? | Until you delete it, then 30 days — except payment records (legal requirement) | | What if there's a breach? | We notify you and the regulator within 72 hours |


This Privacy Policy was last reviewed on July 18, 2026.