Privacy Policy for Track376 Chrome Extension
Last Updated: February 3, 2026
Introduction
Track376 ("we", "our", or "the extension") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Chrome extension.
Data We Collect
Personal Information
- Account Information: Email address, name, password (hashed with bcrypt)
- Profile Data: Phone number, address, LinkedIn URL, GitHub URL, portfolio website
- Resume Files: PDF/DOC/DOCX files uploaded for autofill functionality
Job Application Data
- Job Details: Company name, job title, location, salary, work type, job description
- Application Tracking: Status, dates applied, interview dates, notes, tags, priority levels
- Resume Attachments: Resume files associated with specific job applications
Group Collaboration Data
- Group Information: Group names, descriptions, member lists, roles
- Chat Messages: Text messages, timestamps, reactions, typing indicators
- Shared Jobs: Job opportunities shared within groups
Usage Data
- Analytics: Error logs, performance metrics (via Sentry - anonymized)
- Activity: Login times, feature usage patterns
How We Use Your Data
We use your data to:
- Provide Core Functionality: Track job applications, autofill forms, sync across devices
- Enable Collaboration: Facilitate group chat and job sharing features
- Improve Service: Analyze errors and performance to fix bugs and optimize features
- Authenticate Users: Secure access to your account with JWT tokens
- Store Files: Save resumes on AWS S3 for autofill functionality
Data Storage
Storage Locations
- User Accounts & Personal Jobs: MongoDB Atlas (cloud database, encrypted at rest)
- Group Features & Chat: Local MongoDB instance (for collaborative features)
- Resume Files: AWS S3 (private bucket, encrypted, signed URLs with 1-hour expiry)
- Cache: Upstash Redis (temporary cache, 24-hour TTL for chat, 5-minute TTL for jobs)
- Local Storage: Chrome Storage API (offline access, synced across your devices)
Security Measures
- Passwords hashed with bcrypt (industry-standard encryption)
- JWT tokens for secure authentication
- HTTPS/TLS encryption for all data transmission
- AWS S3 private buckets with signed URLs (1-hour expiry)
- Input sanitization to prevent XSS and injection attacks
- Rate limiting to prevent abuse
- Helmet.js security headers (CSP, HSTS, etc.)
Data Sharing
We DO NOT sell, rent, or trade your personal information to third parties.
Limited Sharing
- Group Members: Jobs you share in groups are visible to group members only
- Service Providers: AWS (file storage), MongoDB Atlas (database), Upstash (cache), Sentry (error monitoring)
- Legal Requirements: We may disclose data if required by law or to protect our rights
Your Rights
You have the right to:
- Access: View all your personal data stored in the extension
- Export: Download your job application data as CSV
- Delete: Remove individual jobs, groups, or your entire account
- Modify: Edit your profile, job details, and settings at any time
- Opt-Out: Disable analytics or error reporting in settings
Data Retention
- Active Accounts: Data retained as long as your account is active
- Deleted Jobs: Permanently removed from database immediately
- Deleted Accounts: All data permanently deleted within 30 days
- Cache: Automatically expires (24 hours for chat, 5 minutes for jobs)
- Resume Files: Deleted from S3 when you remove them or delete your account
Third-Party Services
Track376 uses the following third-party services:
Cookies and Tracking
Track376 uses:
- JWT Tokens: Stored in Chrome Storage for authentication (not cookies)
- Local Storage: For offline functionality and sync
- No Third-Party Tracking: We do not use Google Analytics or advertising trackers
Children's Privacy
Track376 is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13.
International Users
Your data may be stored and processed in the United States or other countries where our service providers operate. By using Track376, you consent to the transfer of your data to these locations.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Updating the "Last Updated" date at the top of this policy
- Displaying a notification in the extension
- Sending an email to your registered email address (for major changes)
Contact Us
If you have questions about this Privacy Policy or your data, please contact us:
Consent
By using Track376, you consent to this Privacy Policy and agree to its terms.