HouseEdge

Legal

Privacy

Ultimo aggiornamento: 12 August 2026

Questo documento è pubblicato solo in inglese. La versione inglese è quella che vincola, e tradurlo creerebbe un secondo testo autorevole. Se qualcosa non è chiaro, scrivi all'assistenza e una persona te lo spiegherà nella tua lingua.

What HouseEdge collects, who can see it, and what you can do about it. Written to be checked against the service rather than to cover us — if something below is not true of how the site behaves, treat that as a bug and tell us.

Operatore

Operatore
VELORA GRUPP LLS, TOO
Sede legale
36 Abylai Khan Avenue, apt. 43, Almaty district, Astana 010001, Republic of Kazakhstan
Numero di registrazione
BIN 260540009816
Contatto
support@houseedge.gold

HouseEdge is operated by this company, which is responsible for the personal data described on these pages. JunketClub is run by the same company as a separate service, with its own accounts and its own database — the two do not share user data.

01HouseEdge is separate from JunketClub

HouseEdge is a casino-industry job board. It shares infrastructure with JunketClub, a separate service run by the same operator, but it is a separate product with its own database, its own accounts and its own sign-in.

A HouseEdge account is not a JunketClub account. Nothing you enter here appears there, and no JunketClub user can see a HouseEdge profile, CV or application. JunketClub's privacy policy does not describe this service and does not apply to it — this page does.

02What we collect

When you create an account:

  • your email address and your first and last name
  • your password, stored only as a bcrypt hash — we never hold the password itself and cannot recover it
  • whether your email has been verified, and when you last signed in

If you use HouseEdge as a candidate, your profile may also hold whatever you choose to add: a headline, a summary, country and city, a phone number, years of experience, skills, languages, a desired salary range, a LinkedIn URL, and a CV file with its original filename and upload date. All of these are optional. The account itself needs only an email and a name.

When you apply to a listing we store the application: which listing, when, its status, your cover letter if you wrote one, and a reference to the CV that was on your profile at the time. It is a reference, not a second copy — replacing or deleting your CV replaces or removes the file the employer can open, including for applications you already sent. The employer may also attach a private note to your application — a comment written by them, about you. You can ask us for a copy of those notes.

If you use HouseEdge as an employer, we store your company profile and your listings. These are business details, not personal data, apart from your own account.

Our servers keep request logs that include IP addresses. We use them to operate the service, to enforce the sign-in and registration rate limits, and to investigate abuse. We are not going to claim a retention period we do not yet enforce automatically: today they are removed when we rotate them, and putting a fixed limit in place is outstanding work.

03Who can see your CV

Your CV is treated as the most sensitive thing on this service, and it is handled accordingly.

  • It is stored in a private bucket. It has no public URL, and guessing one is not possible — files are addressed by an internal key that is never sent to a browser.
  • It is released only as a signed link valid for five minutes, and only after we have checked that the person asking is entitled to it.
  • An employer can reach it only for a listing you applied to yourself. Browsing CVs is not something an employer can do.
  • It never appears in any list of applicants. Only opening a single application can produce a link to it.

A candidate profile is not searchable by default. Being discoverable by employers is a setting you turn on, not one you turn off.

While it is on, employers can find you in candidate search and see what you put on your profile: your headline, summary, location, years of experience, skills, languages and the salary you are looking for. They do not see your CV, your email address, your phone number or your LinkedIn — search results carry none of them, and the CV rules above are unchanged.

An employer who finds you can send you one invitation per listing, asking you to apply. It reaches you by email, it names the listing, and it may carry a short note from them. It is not an application and it changes nothing about your account — you read it and decide. Turning discovery off stops you appearing in search, and stops invitations with it.

When you apply, the employer sees your name, your profile, your cover letter and your CV. They do not get your email address. Replies happen in a conversation inside HouseEdge, attached to the application it is about, and that conversation is the only channel we give them.

Either side can attach a file to a message — a PDF, a Word document or an image, up to 10 MB. Those files are handled exactly like a CV: stored in the private bucket, addressed by an internal key that never reaches a browser, and opened only through a link that expires after five minutes, issued only to the two people in that conversation. We check what a file really is by reading its first bytes rather than trusting its name. We do not scan attachments for malware, so treat a file from someone you do not know the way you would treat one that arrived by email.

We would rather be exact than reassuring about what that buys you: it stops addresses being collected in bulk, one per application, by anyone who can post a listing. It does not make you uncontactable — most people put a phone number or an address on the CV they attach, and an employer you applied to can legitimately open it.

Applying starts a conversation, which means the employer can write to you first. Anything either of you writes is stored until the application is deleted.

04Why we hold it, and on what basis

  • To run the service you asked for — an account, a profile, applications you send, listings you post. This is performance of a contract with you.
  • To keep the service usable and safe: rate limits, abuse prevention, and the logs that make both possible. This is our legitimate interest.
  • Optional profile details and your CV are there because you chose to add them, and you can remove them at any time.

One precision about the second of those: sign-in and registration rate limits are counted per visitor, using the address your request arrives from. That address is the only thing they use — it is not tied to your account and nothing else is derived from it.

We do not profile you, we do not make automated decisions about you, and we do not sell or share your data with anyone for advertising.

05Paying for a plan

Paid plans are sold through Paddle, which is the merchant of record — the seller in the transaction, not a payment gateway we operate. The purchase is a contract between you and Paddle, and Paddle is responsible as a controller in its own right for the payment data it collects. It publishes its own privacy policy for that part, at paddle.com.

We never receive your card details. The checkout is Paddle's, it runs inside Paddle's own frame, and no card number, expiry date or security code passes through our servers or is stored by us at any point. The same is true of the billing address and tax identifiers Paddle asks for — you give those to Paddle, not to us.

What we store about a purchase is what the service needs to know which plan is in force:

  • which plan you are on, monthly or yearly, when the current period started and ends, its status, and whether a cancellation or a change of plan is scheduled
  • the identifiers Paddle gives us for your customer record and your subscription, which are how the two systems recognise the same subscription
  • if you ask for a refund: what you wrote as the reason, the amounts involved, our decision and the reason for it, who decided and when, and what the provider answered

The reason you write on a refund request is read by the person deciding it, and it is kept with the request as the record of why the decision went the way it did.

The legal basis for all of this is performance of the contract with you, and, for keeping the record of what was charged and refunded, our legal obligation under accounting and tax law. That last one is why billing records outlive an account: if you ask us to delete your account we can remove the profile and the files, but a record that a payment happened has to be kept for as long as the law requires.

06Where it is stored, and who else touches it

The database and uploaded files live on our own servers in Germany. File storage is self-hosted on the same infrastructure rather than handed to a storage provider.

Five third parties are involved, each for one job and each getting only what that job needs:

  • Cloudflare — nightly backups are copied to R2 object storage: the database and a mirror of uploaded files, CVs included. It is the only third party that holds a copy of the whole dataset. Those copies are encrypted at rest by Cloudflare; we do not add a layer of our own on top, and we would rather say so than let the word carry more weight than it earns.
  • Resend — sends the notification email described below. It receives the address the message goes to and the message itself.
  • Paddle — sells the plans, as described above. It receives what you type into its own checkout; from us it receives only the plan being bought and the identifiers tying it to your subscription.
  • Sentry — receives a report when something breaks: the error, the page or endpoint it happened on, and the kind of browser or server it happened in. What it is deliberately not given is the content you were working with. Request bodies are dropped, the values in a web address are replaced before the report is sent, and an email address appearing in an error message is redacted. There is no session recording: nothing reconstructs what was on your screen. It never receives a CV, an attachment or the text of a message.
  • Google — our support mailbox, support@houseedge.gold, is hosted by Google Workspace. It therefore holds the messages our own staff receive about an account: the notice that a new company has signed up, which names the owner's address and what they entered on their company profile; the notice that a listing is waiting for review; and a refund request, which names the address it came from and the reason written on it. It is the mailbox, so it holds whatever you write to us as well.
  • Sentry also receives one thing your browser sends directly, without passing through us: if a page tries to load something our security policy forbids, the browser reports that block, and such a report names the page it happened on and identifies your device by IP address. Two pages are excluded from this entirely — the ones reached from a password-reset or sign-up email — because their address contains a single-use key, and a report would carry it.

Beyond those five: no analytics, no advertising or tracking technology, and no marketing tools. Sentry is here to tell us that something failed, not who was using the site.

We do send email now, and only about things that happened to you: a new application on your listing, a final decision on an application you sent, an invitation from an employer who would like you to apply, an unread message waiting for you, a password reset you asked for, a warning that one of your listings is about to leave the board and notice once it has, and — if you have asked for a refund — where that request has got to. There is no marketing mail. It is sent through Resend, from an address on houseedge.gold. The notification tells you something is waiting; it does not repeat what was written.

Paddle sends its own email about a purchase — the receipt, the invoice, and notice of a renewal. Those come from Paddle because the sale is Paddle's, and they are not something we can switch off for you.

07Cookies

One cookie of ours: `he-refresh-token`, which keeps you signed in. It is set only after you sign in, it is HttpOnly so no script can read it, and it is scoped to this host alone.

There are no analytics or advertising cookies, and therefore no consent banner — there is nothing here to consent to. Your sign-in token itself is held in memory by the page and is gone when you close the tab.

One exception, and it only arises if you open the checkout: doing so loads Paddle's script and opens Paddle's own frame in the page. Anything Paddle stores in your browser at that point is set by Paddle under its own policy, for its own purposes as the seller, and we neither set it nor read it. Nothing on the rest of the site loads it — the script is fetched when you click to buy, not on every page.

08Your rights

You can ask us to give you a copy of your data, correct it, delete it, or hand it over in a portable form, and you can object to how we use it.

Some of this you can already do yourself: your profile is editable at any time, and you can delete your CV from your profile page, which removes the stored file.

Everything else — including closing your account — goes through us for now, because there is no self-service account deletion yet. Write to the address below and we will act within 30 days. See the retention page for exactly what happens to each kind of data.

Two limits on deletion worth stating rather than discovering: a record that a payment was taken or refunded has to be kept for as long as accounting and tax law requires, so it outlives the account it belonged to; and for the payment data you gave Paddle directly, Paddle is the controller — we can pass a request on, but the copy held there is answered by them.

09Children

HouseEdge is a service for people looking for and offering work, and is not intended for anyone under 16. If you believe a child has created an account, tell us and we will remove it.

10Changes and contact

If this policy changes in a way that affects what we do with your data, we will change the date at the top and, where the change is material, tell account holders directly once transactional email is in place.

Questions, requests and complaints: support@houseedge.gold.

Privacy · HouseEdge