Privacy Policy
Last updated: August 23, 2026
PitchPage ("we", "us") turns your résumé into a shareable pitch page. That means you trust us with personal information, and we keep that simple: we collect what the product needs to work, we don't sell your data, and you can ask us to delete everything at any time.
What we collect
Account data: your email address and a password (stored as a secure hash — we never see the password itself).
Content you upload: your résumé, portrait photo, intro video, supporting documents, and the text on your pitch page. This is the product — it exists so you can publish and share it.
Page analytics (your visitors): when someone opens your published page, we record what that visitor did so you can see how your page landed. Specifically: an anonymous visitor ID (a random value kept in their browser's local storage — not a cookie, and not linked to a name or email), their browser's user agent string, an approximate country and city derived from the network request, each page view and repeat visit, when they were first and last seen, which tracked link they used, how far they watched your intro video (25% / 50% / 75% / finished), roughly how long the page was open in a visible tab, how far down the page they scrolled, and any document downloads or button clicks. This is per-visitor detail, not just aggregate counts — you see individual anonymous visitors and their activity.
We do not store raw IP addresses. An IP is used momentarily in memory to derive the approximate location and to limit abuse, then discarded. Time on page measures "tab open and visible", not reading, which is why we only ever show it as a range. Forwarding is not detectable: if a tracked link shows more than one device, we say exactly that and nothing more.
Do Not Track: if a visitor's browser sends a Do Not Track signal, we record nothing about that visit to your published page. No view, no video milestones, no time-on-page, no scroll depth. Our product analytics on the rest of the site respect the same signal in PostHog. Google Analytics does not act on Do Not Track, which is one reason we keep it off published pages.
Product analytics (you, in the app): we use two tools to understand how the marketing site and the signed-in app get used, so we can fix what is broken. PostHog, served first-party from our own domain, records page loads, feature usage and session replay inside the app, with form inputs masked and Do Not Track respected. Google Analytics measures traffic to our marketing pages and sets its own cookies to recognise a returning browser. Neither one runs on published pitch pages. Someone opening your page picks up no Google cookie from us and is never session-recorded.
How your content is processed
When you upload a résumé, AI models read its text to compose your page sections. Your content is processed for that purpose only — it is not used to advertise to you, and we do not sell it to anyone.
Where it's stored
Your data is stored with Supabase (database, authentication, and file storage). Published pages are public by design — that's their purpose — but only the content you chose to put on them. Unpublished drafts are private to your account.
Who else handles your data
We keep the list of companies that touch your data short. These are the ones that do, and what each one is for:
- Supabase: our database, sign-in, and file storage.
- Stripe: payments. Card details go straight to Stripe and never reach us.
- Cloudflare: serves the site, and supplies the approximate country and city on a page view.
- PostHog: product analytics and session replay inside the signed-in app.
- Google Analytics: traffic measurement on our marketing pages and inside the app.
- Resend and n8n: sending you the email that tells you your page was opened.
- Google Gemini, reached through the Lovable AI gateway: reading your resume text so we can compose your page sections.
Payments
Payments are processed by Stripe. Your card number goes directly to Stripe — it never touches our servers. We receive only a confirmation that the payment succeeded, along with the credits you purchased.
What we don't do
We don't sell your personal data. We don't run third-party advertising. We don't share your résumé or page content with anyone except the service providers above, and only so the product can function.
Your rights
You can unpublish or delete your pitch pages from your dashboard at any time. To delete your account and all associated data (résumé, media, analytics), email support@pitchpage.co and we'll complete the deletion within 30 days. You can also ask us what data we hold about you.
Cookies & local storage
Google Analytics sets cookies on our marketing pages and inside the signed-in app, so it can tell a returning browser from a new one. It does not run on published pitch pages. We use your browser's local storage to keep you signed in, and a published page stores one random anonymous visitor ID in the visitor's local storage so repeat visits are not counted as new people. Our own page analytics are served first-party from our own domain. We do not use Google Analytics for advertising and ad personalisation is turned off.
Who we are
PitchPage is operated by a Canadian sole proprietor and handles personal information in line with Canada's PIPEDA. If you're in the EU/EEA or UK, we honor equivalent rights (access, correction, deletion, portability) under the GDPR.
Changes
If this policy changes in a way that matters, we'll update this page and the date at the top. Questions? Email support@pitchpage.co.