Privacy Policy
Effective: April 2026 · Last updated: October 2026
DRAFT — pending legal review. This text was updated on 18 Aug 2026 to reflect a change in which hiring criteria the platform permits, and again in September 2026, to correct what it says about where your data is processed, which providers receive it, the cookies we set, the payment data we share and keep, whether a phone number is required, and what we say about children's accounts; each change since 29 September 2026 is dated in the change log in Section 15. It has not yet been reviewed by counsel.
النسخة العربية قادمة قريبًا. The Arabic version is coming soon. In case of conflict, the English version is authoritative.
1. Introduction
Cheghel ("we", "us", "Cheghel") is a Lebanese job platform operating at cheghel.com. We connect job seekers (white-collar professionals, blue-collar workers, freelancers, and Lebanese diaspora) with employers whose companies we verify before they can post a job.
This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It applies to:
- The Cheghel website and Progressive Web App at cheghel.com
- Future Cheghel mobile apps for iOS and Android
- WhatsApp and Telegram alerts and integrations operated by Cheghel
- Transactional and opt-in emails sent from @cheghel.com
English is the authoritative version of this policy. An Arabic translation will follow. If there is any conflict, the English version prevails.
2. Data Controller and Contact
- Data controller: Cheghel (legal entity name to be finalised at launch).
- Privacy contact / DPO: privacy@cheghel.com
- Legal contact: legal@cheghel.com
- Postal address: Beirut, Lebanon (full address to be added at company registration).
- EU representative: Not currently appointed. Cheghel does not target EU residents, but we honour data rights requests from anywhere in the world.
3. Data We Collect
We group the data we collect into the same categories used by Apple's privacy labels and Google Play Data Safety, so you can compare directly.
a) Contact Info
- Email address: required to create an account.
- Full name: required on your profile.
- Phone number / WhatsApp number: required when you create an account with an email address and a password. Signing up with Google does not ask for one; you can add one later in Settings. Employers do not see it.
- Physical address: we do not collect a home address. We only store your Lebanese governorate selection.
b) Identifiers
- A Cheghel user ID (a random UUID generated at signup).
- Google account identifier: only if you sign in with Google OAuth.
- Device identifiers: we do not use Apple's IDFA or IDFV, nor any equivalent cross-app identifier. If a future mobile app ships, it will use Apple's session-only, on-device identifiers only.
c) User Content
- CV / resume file (PDF or DOCX) and extracted text.
- Profile photo, headline, bio.
- Skills, portfolio URLs, LinkedIn URL.
- Salary expectation and availability.
- Job applications you submit and cover messages.
- Reviews you leave about companies. Your review text is public; your identity as the reviewer is never shown publicly and is permanently protected under Law 81/2018 (see Section 5).
- Saved jobs and saved search alerts.
- Messages you send to employers through Cheghel, if any.
d) Usage Data
- Pages you view and links you click on Cheghel.
- Search queries you run on the platform.
- Which jobs you view, save, and apply to.
- Session duration and activity timing.
- Referrer URL (where you came from to reach Cheghel).
e) Diagnostics
- Crash and error reports via Sentry. Personal data is scrubbed before a report leaves your device or our server. What we do send is limited to: the address (URL) and method of the request that failed, a small set of technical headers (browser type, language preference, content type and encoding), the error and its stack trace, and an error code. Account and record identifiers are replaced with a placeholder before a report is sent.
- What we remove before sending: session cookies and authentication tokens, IP addresses and the location derived from them, and any account or record identifier. We do not send the content of your data — your CV, applications, messages, screening answers, and profile fields do not appear in a crash report.
- Performance traces of requests to Cheghel (route name and timing; currently every request is traced). Request and response bodies are not included.
f) Location Data
- Your Lebanese governorate (Beirut, Mount Lebanon, North, Akkar, Bekaa, Baalbek-Hermel, South, Nabatieh) or "Abroad" selection.
- We do not collect precise GPS or device-level location.
- IP addresses are logged with login events for security, abuse detection, and fraud prevention, and retained for 90 days.
g) Sensitive Data: what we do not collect
- We do not collect religion, sect, political views, sexual orientation, or health data.
- We enforce this at the platform level: employer HR queries naming religion or sect, political affiliation, age, marital or family status, physical appearance, sexual orientation or gender identity, or disability are hard-blocked and never reach our AI provider. The attempt is logged as a compliance event for moderation.
- The applicant tools do not use gender or nationality. When an employer searches across their applicants with the applicant search (“Ask about your applicants”), or asks the per-job applicant assistant, a Cheghel Pro tool, about the applicants to one job, a question that asks for gender or nationality is refused, and the refusal is logged. Such a question is refused by our AI assistant and its checker rather than blocked before them, so its text does reach our AI provider. A question about the right to work in Lebanon or a work permit is not a question about nationality and is not refused: the applicant search answers that its list does not show it, and the per-job assistant is instructed to answer it only from what each applicant wrote in answer to the employer’s own screening questions — never by inference, and without repeating a nationality an applicant gave as the reason. We hold no gender field about you, and the optional nationality you may add to your own CV appears only on that CV: it is never used for matching, ranking or employer search, and both applicant tools are instructed never to infer your gender or nationality from your name, languages or location.
h) Financial Info
- Purchases of Cheghel Plus and credit packs are processed by Tap Payments, listed in section 7. Payments currently run in test mode; section 8 of our Terms of Service sets out what that means.
- When you start a purchase, we send Tap the first word of the name on your account (if you have given one), your email address, the amount and currency, a description of what you are buying (the plan and its length, or the number of credits), and your Cheghel account ID, part of which also makes up the payment’s reference. You enter your card details on Tap’s own payment page, and Tap collects them there under its own privacy policy.
- Your full card number, expiry date and CVV are typed into Tap’s own payment page, never into a Cheghel page, so they do not pass through our site on their way to Tap. What Tap sends back to us afterwards is set out in the next point.
- We keep your paid plan’s status and period, with Tap’s identifier for you as its customer. For each payment notification Tap sends us, we keep only the charge’s references, its status and outcome codes, the amount, currency and timestamps, and the description of what the payment was for. Before a notification is stored, we remove any name, email address and phone number and every card detail: the card’s brand and network, any digits of the card number, the 3-D Secure data, and card and device identifiers. We do this for payment notifications we reject as well as for those we accept.
i) Data Linked to You vs. Not Linked to You
| Linked to your identity | Not linked to your identity |
|---|---|
| Account data, CV, applications, saved jobs, job alerts, plan status, payment history, review content. | Pseudonymous product analytics, only if you accept analytics cookies: usage events tied to a random browser ID that we never link to your account, which we look at in aggregate. |
Reviewer identity on company reviews is stored internally but is never returned by any API, UI, or admin screen. See Section 5.
4. How We Use Your Data
a) App Functionality
- Match seekers with jobs using profile data and search filters.
- Process applications (CV + profile + the job you applied to).
- Manage reviews, including moderation and employer replies.
- Administer paid plans and payment status.
b) Communications
- Transactional emails: welcome, application received, application status changes, review published, password reset.
- Weekly "Top Jobs for You" digest: opt-in only, with a one-click unsubscribe link in every email.
- WhatsApp messages via Twilio: used only for phone-verification codes, and not currently sent at all. We do not send job alerts over WhatsApp.
- We do not send marketing or promotional emails without your explicit consent.
c) Analytics
- We use PostHog for product analytics. It is pseudonymous, not anonymous: PostHog gives this browser a random ID, which we never link to your account.
- With each event it records the page you are on and the page you came from — with anything after the “?” or “#” removed before it is sent — which links and buttons you click (the kind of element, its design class names and where it sits on the page, and for a link the page it leads to, again without anything after the “?”; never the words on it or any label attached to it), how far down the page you scroll, and your browser, device, language, time zone and screen size. PostHog also receives your IP address, as any site you connect to does, and may use it to estimate your approximate location.
- In your browser, PostHog keeps that ID in a cookie that expires a year after your last visit, and in local storage, where it has no expiry. Local storage also holds the address of the first page of each visit — which can include what follows the “?” — and the page that sent you there. See the Cookie Policy.
- Analytics only load if you accept analytics cookies in the consent banner. If you choose "Essential only" — at first, or at any time later — PostHog does not start, or stops straight away in every Cheghel tab you have open and deletes what it stored in this browser. Anything it had already sent is not deleted from PostHog, and events from the moments just before you chose may still arrive.
- We use analytics to understand feature usage in aggregate, not to profile individuals.
d) Product Personalisation
- AI job recommendations based on your extracted profile and activity.
- Search result ranking tailored to your history.
- All personalisation happens server-side. The results are visible only to you.
e) Fraud Prevention and Security
- Detecting spam accounts, fake jobs, and abusive behaviour.
- Rate limiting to prevent automated abuse.
- Login anomaly detection based on IP and session patterns.
f) Legal Compliance
- Retaining financial records for 7 years as required by Lebanese tax law.
- Responding to valid legal requests from Lebanese authorities where there is a lawful basis.
5. The 3-Tier Information Wall
Cheghel uses a tiered disclosure model for job listings:
| Tier | Sees |
|---|---|
| Visitors (logged out) | Job title, category, governorate, type. |
| Registered free users | Everything above, plus the company name. |
| People on Cheghel Plus ($3.99/month tier) | Everything above, plus the full salary and the Apply button. |
Reviewer identities are never disclosed: not to other seekers, not to employers, not through the admin UI, and not via any API. This is a permanent protection under Law 81/2018 and is enforced at the database row-level security layer.
6. Legal Bases for Processing
| Purpose | Legal basis |
|---|---|
| Account, applications, plans | Contract performance |
| Fraud prevention, security, abuse detection | Legitimate interest |
| Marketing, analytics cookies, WhatsApp alerts | Consent (opt-in) |
| Financial record retention, law enforcement cooperation | Legal obligation |
7. Third-Party Service Providers
We rely on the following providers. Each one processes data only for the purpose listed below, under a written contract.
| Provider | Purpose | Data shared | Location | Policy |
|---|---|---|---|---|
| Supabase | Database, authentication, file storage | All user data | Japan (AWS ap-northeast-1, Tokyo) | link |
| Upstash (Redis) | Rate limiting on every request | Client IP address; Supabase user id when signed in | Not stated by us — the region is set per deployment | link |
| Tap Payments | Payment processing (currently in test mode) | First name, email address, amount and currency, a description of what is bought, and your Cheghel account ID. Your card details are entered on Tap’s own page, not on Cheghel; section 3(h) lists what Tap sends back. | Kuwait / regional | link |
| Cloudflare (Turnstile) | Bot protection on sign-in, sign-up and password reset | IP address, user agent, browser challenge signal | Global edge network | link |
| Resend | Transactional email delivery | Email address, email contents | United States | link |
| Sentry | Error and crash reporting, and performance tracing of requests | Scrubbed error reports and performance traces: request URL and method, technical headers, stack trace, error code, route timing. No cookies, authentication tokens, IP addresses, or user identifiers. | Germany (EU region) | link |
| PostHog | Product analytics (opt-in only) | Pseudonymous usage events: a random browser ID we never link to your account; the pages you view and the page you came from, with anything after the “?” removed; which links and buttons you click, by kind, design class name and position, never their text; how far you scroll; browser, device, language, time zone and screen size; and your IP address. | EU | link |
| Anthropic (Claude) | AI screening, CV extraction, HR queries | CV text and job text submitted by our servers. Anthropic does not train on API data. | United States | link |
| OAuth sign-in (optional) | Email, name, avatar (only if you choose Google sign-in) | United States | link | |
| Twilio | Phone verification codes (not currently sent) | Phone number, message content | United States | link |
| Vercel | Hosting: runs our pages and features and delivers the site through its global network | Request logs (IP, user agent, path) | Japan (Tokyo), where our pages and features run. Each request is first handled at the Vercel location nearest you, which may be in another country. Vercel may also transfer data to the United States and other countries where it or its providers operate. | link |
What we do NOT do:
- We do not sell your personal data.
- We do not share your data with advertisers.
- We do not use data brokers.
- We do not transfer your data to any third party outside the providers listed above.
8. Data Retention
| Data | Retention |
|---|---|
| Account data (profile, applications, saved jobs) | While your account is active |
| Deleted account data | Removed within 30 days |
| Reviews written by a deleted user | Review text remains published; reviewer link is set to NULL permanently |
| Payment and billing records | 7 years (Lebanese tax law) |
| IP address logs | 90 days |
| Email delivery logs | 90 days |
| Crash / error logs (Sentry) | 30 days |
| Database backups | 35-day rolling window |
| Email unsubscribe suppression list | Kept indefinitely, so we never email you again after you opt out |
9. Your Rights
Under Lebanon Law 81/2018 and GDPR-equivalent principles, you have the following rights:
- Right of access: request a copy of the personal data we hold about you. Self-serve at /data-request.
- Right of deletion: request deletion of your account. Self-serve at /data-request.
- Right of correction: edit your profile, or email privacy@cheghel.com.
- Right of portability: get a JSON export of your data via /data-request.
- Right to withdraw consent: unsubscribe links in emails, WhatsApp STOP, your profile settings, and — for analytics cookies — the Cookie preferences link in the site footer or on the Cookie Policy page, which stops analytics straight away.
- Right to object to a specific processing activity: email privacy@cheghel.com.
- Right to lodge a complaint with the relevant Lebanese data protection authority.
We respond to all rights requests within 30 days, as required by Law 81/2018. Self-serve actions are immediate.
10. Children's Privacy
- Cheghel is not intended for users under 18.
- We do not knowingly collect data from minors.
- Parents or guardians can email privacy@cheghel.com to report a minor's account or request its deletion.
11. International Data Transfers
Your data is processed in Japan: our database, authentication and file storage, and the servers that run Cheghel’s pages and features, are in Tokyo. Each request is first handled at the location of our hosting provider’s (Vercel’s) network nearest to you, which may be in another country. Your data may also be processed in the United States or the European Union by the other providers listed in Section 7, including by Vercel, which may transfer data to the United States, and, when you make a purchase, in Kuwait and the wider region by our payment provider, Tap Payments. Where available, we rely on standard contractual clauses or equivalent safeguards. By using Cheghel from Lebanon, you consent to this transfer for the purposes described in this policy.
12. Security Measures
- Encryption in transit using TLS 1.2 or higher.
- Encryption at rest at the database level.
- Row-level security on every database table.
- Regular security reviews and dependency audits.
- Documented incident response plan. Any confirmed breach is notified within 72 hours, as required by Law 81/2018.
13. Cookies and Tracking
- Essential cookies (cannot be disabled): authentication session, language preference, the mode you chose (job seeker, employer or freelancer), and your cookie consent choice itself.
- Optional cookies (require consent via the banner): PostHog analytics — pseudonymous, not anonymous (see section 4c and the Cookie Policy). Withdrawing consent stops it straight away and deletes its cookie and browser storage.
- Bot-protection storage (cannot be disabled, auth screens only): Cloudflare Turnstile may keep short-lived data in its own frame while it runs its challenge on sign-up, sign-in and password reset. It is not analytics and is not used to track you between visits.
- Storage on your device: some features keep working data in your browser — your progress through the welcome steps, a job post you are still writing, the jobs you have previewed, and a display choice. Our servers do not read these entries. They are removed whenever someone signs in or out on this browser or deletes their account, and if a session ends another way, the next time Cheghel loads a page; only the display choice is kept. If you accept analytics, PostHog keeps its identifiers there too, and they are different: they go to PostHog with every analytics event, together with the address your visit began on and the page that sent you there (each without anything after the “?”). They are replaced with new random ones when you sign out, and removed if you withdraw consent.
- Cookies set by other companies: Google sign-in, Tap's payment page and your bank's security check, and Cloudflare in front of our database provider (the
__cf_bmcookie on supabase.co) set their own cookies under their own policies; Cloudflare Turnstile may keep data in its own frame, as described above. We cannot read or remove them. - No third-party advertising trackers.
- No Meta / Facebook pixels.
- No cross-site tracking.
- No fingerprinting for advertising or identity. We run no script that profiles your device to build a marketing or cross-site identity. Cloudflare Turnstile, on the sign-up, sign-in and password-reset screens (and on the resend-confirmation action inside sign-up), does inspect browser signals — that is how it distinguishes a person from a bot — and it is listed in the processor table above. It runs before any account exists and is not used to identify you.
See our Cookie Policy for details and controls.
14. Mobile App Privacy (Future iOS and Android Apps)
Cheghel is currently a web and Progressive Web App. When native iOS and Android apps launch, the following additional rules will apply, consistent with this policy:
- App Tracking Transparency (ATT): We do not track you across apps or websites owned by other companies. Our ATT answer is "not tracking".
- No IDFA or IDFV collected or used.
- Push notifications: opt-in only, with system-level and in-app toggles.
- Background location: not collected.
- Contacts, photos, microphone, camera: accessed only with your explicit permission, and only when you use the feature that needs it (for example, uploading a profile photo).
- Face ID / Touch ID: used on-device only to unlock the app if you enable it. We never see biometric data.
15. Changes to This Policy
- We notify users of material changes by email and an in-app banner, at least 30 days before they take effect.
- Non-material changes (typo fixes, clarifications, broken links) may be posted without notification.
- Previous versions are available on request.
- Each change in the change log below was judged non-material: it reduces what we process, or moves processing to a country the European Union recognises as protecting personal data adequately (Japan). It took effect when it was posted.
Change log
- 29 September 2026: the servers that run Cheghel’s pages and features moved from the United States to Japan (Tokyo), beside our database. Each request is still first handled at the location of our hosting provider’s network nearest to you. See Sections 7 and 11.
- 29 September 2026: the applicant search stopped running searches by gender or nationality, and a refused search is logged. See Section 3(g).
- 1 October 2026: the per-job applicant assistant stopped answering questions by gender or nationality, as the applicant search had; a question about the right to work in Lebanon is still answered, from applicants’ own screening answers. See Section 3(g).
16. Contact Us
- Privacy questions: privacy@cheghel.com
- Data access, export, or deletion requests (fastest route): /data-request
- Legal notices: legal@cheghel.com
- Postal: Beirut, Lebanon (full address at company registration).