Privacy policy
Last updated . This describes what secondjob.ca actually does with your information today, not what we intend to do later.
In short
The whole policy in eight lines. The detail below says the same things more carefully.
- You can search and read every job on this site without an account and without telling us anything about yourself.
- An account holds your email address, your name and whatever else you choose to put in your profile. We store a scrambled version of your password and never the password itself.
- Your CV is private. Only you, an employer you actually applied to with that CV, and a site administrator can open it. It is not searchable, not sold, and not shown to employers who are browsing.
- When you apply, the employer gets your application: your name, your email, the phone number you gave, your answers to their screening questions, your note, and the CV you attached.
- We use one cookie to keep you signed in, and we have no advertising trackers. We use Google Analytics, set so that it stores nothing on your device and writes no cookie. The section on cookies below says exactly what that means.
- Money goes through Stripe. Card numbers never touch our server.
- Job alert emails only go to an address that has confirmed it wants them. Ask for one while signed out and we send that address a single email with a confirmation link; nothing else goes out until somebody opens it. Every alert carries a one-click unsubscribe that works without signing in.
- You can ask us for a copy of your information, ask us to correct it, or ask us to delete it, through the contact form. Today a person does that by hand; there is no self-serve delete button yet, and we are not going to pretend otherwise.
Who we are, and who to ask
secondjob.ca is a Canadian job board. We decide what happens to the information described here, which under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) makes us the organisation accountable for it.
Questions about privacy, and any request about your own information, go to the same place as everything else:
What we collect, and why
Everything in this list is something you gave us or something the site had to record to work. Nothing is bought in from anywhere else.
If you only look
No account, no cookie beyond the theme setting described below, no profile. Our server keeps ordinary web-server records of requests, which include the IP address the request came from, because that is how the site's rate limits stop somebody hammering the login form. We do not use those records to build a picture of you.
Your account
Email address, a scrambled (hashed) password, your role (job seeker or employer) and the date you signed up and last signed in. Employers also give a company name.
Everything else on your profile is optional and is there because employers see it on an application: full name, phone number, city and province, the job titles and pay you are looking for, the kinds of work you are open to, your skills, your work authorisation, and a link to an online CV if you have one.
Applications and screening answers
When you apply we record which job, when, the CV you chose, the phone number as it was at that moment, your cover note, and your answer to each screening question the employer set. The employer who posted that job sees all of it, along with your name and email address, and can rate you, change your status and message you.
Messages between you and that employer are stored so both of you can read the thread, and so the site can work out whether the employer answered. That is what the public reply record on their postings is counted from. The reply record is a percentage and a typical number of days. It never names an applicant.
Saved jobs, alerts and reviews
Saved jobs are a private list. Only you see it.
A job alert stores the email address you gave, the search it repeats, how often you want it, whether that address has confirmed the alert, and a record that you consented: the date and time, and the IP address the request came from. Canadian anti-spam law requires us to be able to show that you asked for the email, so that record exists specifically to protect you from us. See Alerts and email.
A company review stores your rating, your words, and your account id. Your name is never published with a review: the site does not send it to the page at all. A moderator can see who wrote a review, because a review that nobody is accountable for is a review anyone can abuse.
Messages you send us
The contact form stores what you typed: name, email address, topic, subject and message, plus your account id if you were signed in, and the IP address the message came from, which is how the form's five-an-hour limit works. It is stored so we can read it and answer it, and for no other purpose. It does not create an account and does not sign you up for anything.
If you buy a job posting
We record what you bought, what it cost, the currency, the Stripe reference for the payment, and which postings the credits were spent on. That is our bookkeeping and yours.
We never see your card. The card details are typed on Stripe's own checkout page and stay with Stripe. Our server is told your email address, your user id and which product you chose, and is told afterwards whether the payment succeeded.
Your CV: who can open it
This is the part of the site that matters most, so here is exactly how it works.
An uploaded CV is a file on our own server, stored outside the part of the site the web serves. There is no URL that hands it out. The only way to read one is through a route that checks who is asking, every single time.
Three answers are allowed:
- You: the person who uploaded it.
- An employer holding your application: and only the exact file you attached to an application for one of their own jobs. If you later upload a different CV, they cannot see it. If you applied without attaching one, they get no file at all.
- A site administrator, who can open any of them. That is how a posting gets moderated and how a support request gets answered, and it is a real power, so we are naming it rather than burying it.
Nobody else. Employers cannot browse a CV database here, because there is no CV database to browse. We do not sell CVs, and we do not pass them to recruiters.
Deleting a CV in your profile removes the record and unsets it as your default. An application you already sent keeps its own link to the file that was attached at the time, because an employer's record of an application they received is theirs, and quietly emptying it later would be dishonest to both of you. If you want a CV pulled out of an employer's hands entirely, ask us and we will do it by hand.
Cookies, and what we keep in your browser
There are no advertising cookies on this site and nothing here is used to build an advertising profile of you. There is one cookie, and a short list of things this site keeps in your own browser and never sends anywhere:
We do count visits, and here is exactly what that means. When a page loads, this site records the page you looked at, the moment you looked at it, the website that sent you here if one did, and whether you are on a phone, a tablet or a computer. If you press Apply, it records which listing. That is the whole list.
There is no IP address in those records, no cookie involved and no account. That counting is done by our own server, and nothing about it is sent anywhere else.
We also count how many people visited, and this part deserves a plain explanation. To tell one visitor from two, the server takes your IP address and your browser's description of itself, adds a secret that changes at midnight, and runs the three through a one-way hash. What it keeps is the result: a string of characters, and the date. Your IP address and your browser details are used for the length of that calculation and are never written down.
Because the secret changes every day, the same visitor produces a completely different string tomorrow, and there is no way to tell that the two belong to the same person. Not by us, and not by anyone who obtained the table. That is deliberate, and it has a cost we would rather state than hide: it means we can tell you how many people came on a given day, and we genuinely cannot tell how many different people came over a month. Where this site shows a figure for a longer period, it is each day's count added together, and somebody who visited on three days is in it three times.
These daily counts are deleted after 90 days, along with the individual records of page views.
We also use Google Analytics, and it is set to store nothing. It is loaded with every storage permission denied before it runs, which is Google's own "consent mode": it writes no cookie, keeps no identifier on your device, and cannot recognise you on a later visit. What it does send to Google is the page you are on, the site that sent you here if one did, and rough details of your browser and device. Your IP address reaches Google as part of making that request, as it does with any website you load, and we ask them to shorten it rather than record it in full.
Google is a third party, and we would rather say so than let this page imply otherwise. If you would rather it did not run at all, a tracking blocker or your browser's Do Not Track setting will stop it, and nothing on this site behaves any differently when it is blocked. Because nothing is stored on your device, there is no cookie consent for us to ask you for, and that is why you are not shown a banner.
What you type into the search box is counted differently again. We keep a tally of how many times each phrase was searched on each day, and nothing else. The tally is not attached to the page you were on, the device you used, the site you came from, or the time of day, so there is no way to put a search back together with a visit. Individual records of page views are deleted after 90 days; the daily totals and the search tallies are kept, because by then they are counts and nothing more.
- The session cookie (
sj_session): set only when you sign in, and the only cookie on the site. It is a random token, not your identity; it cannot be read by JavaScript (HttpOnly), it is not sent to other sites (SameSite=Lax), and over HTTPS it is markedSecure. It lasts 30 days. Signing out deletes it here and ends the session on our server. - Your theme choice: light or dark, kept in your browser's local storage
as
sj_theme. - Your language choice: English or French, kept in local storage as
sj_langwhen you use the switcher in the header or the footer. A?lang=on a link somebody sent you changes that one page only and does not overwrite what you chose. - Whether this browser has been shown the audience survey: one word,
answeredordeclined, kept in local storage assj_survey. It is what stops the survey card on the job search appearing a second time. It does not hold your answers. - The postings you have opened in this tab: the last 300, kept in session
storage as
sj_visited, which is what greys out a result you have already read. Gone when you close the tab. - A draft job posting: if you are an employer part-way through the
posting form, the draft is kept in your own browser's session storage as
sj_post_draftso a refresh does not lose your work. It is gone when you close the tab. - A checkout hand-off: the id of a Stripe checkout, kept in session
storage as
sj_billing_sessionfrom the moment an employer leaves for Stripe until they come back, so the receipt can be matched to the right purchase. - An administrator's key:
sj_keyin session storage, and only ever in the browser of somebody signed in to the admin tools. It is gone when that tab closes.
That is the whole list, and it is written from the code rather than from memory. Everything on it except the session cookie stays on your device: none of it is sent to our server, and none of it can follow you to another site.
The site loads its typefaces from Google Fonts. That means your browser makes a request to Google to fetch the font files, and Google's servers see that request. It is the one third party involved in simply reading a page here.
The audience survey, and “Locate me”
Two features that ask you for something. Here is exactly what each one keeps.
The audience survey on the job search
After you run a search on the job board, a card may appear above the results asking two optional questions: your age band and your gender. It is a card, not a pop-up. It never covers the results and you can ignore it entirely.
What is stored is the whole of what is stored: the answer to each of those two questions, the province of the search that was already on screen, and the date. That is five columns including the row's own id, and there is no column beside them: no name, no account, no email address, no IP address and nothing about your device or your browser. Nothing links a row to the person who filled it in, including for us.
The province is the one already chosen in the search, as a two-letter code. It is never asked for, never taken from your device, and never narrower than a province.
You are asked at most once. Answering, or pressing No thanks, writes one
word into your own browser (sj_survey, above) and the card is never
shown on that browser again.
The answers are published as percentages on the labour market report, and only once enough people have answered that no single answer can be picked out of the totals. That page prints the exact number needed and how many have answered so far. Below it, nothing is published at all.
The “Locate me” button
The job search, the home page and the company directory each have a button that fills the location box in for you. It runs only when you press it. This site never asks for your position on load, and your browser will ask your permission before anything happens.
Your coordinates never leave your browser. They are compared, in the page itself, against the list of Canadian cities the site already downloaded, and the nearest one is typed into the location box. We are never told the coordinates; no third party is either. What reaches our server is the same thing that reaches it when you type a city name yourself: the name of the city you are searching in.
Nothing about your position is stored, on your device or on ours. Say no to the browser prompt, or never press the button, and the site works exactly as it does now. Type a place instead.
The companies that handle some of it for us
Short list, and it is the whole list.
- Stripe: payments, and only for employers buying a posting. They receive your email address, a reference to your account and the item you bought. Card details go to them directly and never reach us.
- Our email provider (Resend or Postmark, depending on which is configured): sends job alert digests, review notifications and any message we send you. They handle the email address it is going to and the contents of that email. Nothing is sent to them until a message is actually due to go out.
- Google Fonts: serves the two typefaces the site uses, as described above.
- Whoever hosts the server: the database, the uploaded CVs and the logs sit on it.
Some of these companies are outside Canada, so information handled by them may be stored or processed outside Canada and may be reachable by the courts and authorities of the country it sits in. PIPEDA allows this, and requires us to tell you it happens.
We do not sell your information, and we do not trade it for anything. An employer sees an application because you sent it to them.
How long we keep things
Honest answer first: most of this is kept for as long as your account exists, because it is the account. Here is what expires on its own:
- Signed-in sessions: 30 days, then the cookie and the server-side record both expire. Expired records are deleted automatically every six hours.
- Job postings: a posting runs for the length the employer paid for and then closes on its own. A closed posting stays visible to the employer in their dashboard as their own record of it.
- Queued email: a message that has been sent, or that failed three times, keeps its row so the operator can see what happened.
Two things now delete themselves, and the clock each one runs on matters more than the number:
- The CV on your profile: 24 months after you last signed in, not 24 months after you uploaded it. Signing in resets it, so a CV you are still using is never removed from under you. We write to the address on the account a month before, so nothing goes without warning.
- An application, and the copy of the CV attached to it: 24 months after the day you applied. That one is not measured from your last visit, because it is as much the employer's record as yours. Both go together: the employer stops being able to open it on the same day you do.
Twenty-four months is chosen, not rounded. An employer can face an employment standards claim for two years after the fact and a human rights application for one, and an employer who has thrown away the applications cannot show who they hired or why. Deleting sooner would take away the record that answers the complaint.
Kept for as long as your account exists: your profile, your saved jobs, your alerts, your reviews, and the messages you sent us through the contact form. Delete your account and those go with it. Payment records are kept longer, because tax and accounting rules require it.
If you want something gone sooner, ask. See below.
Your rights, and how to use them
Under PIPEDA you can ask us to:
- Show you what we hold about you, and tell you what it has been used for and who it has been given to.
- Correct it if it is wrong or out of date. Most of it you can correct yourself in your profile.
- Delete it: your account, your CVs, your applications, your alerts, your reviews, or all of it.
- Withdraw your consent at any time, including to job alert emails. Some things we cannot then continue to do. An account with no email address cannot sign in.
How it works today, plainly: there is no button in the site that deletes your account, and no automatic export. A request goes to a person, who does it by hand and writes back. That is a limitation of the software as it stands, not a policy, and saying "you can delete your data at any time" while shipping no way to do it would be a claim we cannot back up.
Send the request through the contact form with the topic set to privacy, or call the number above. Use the email address on your account if you can, so we can tell it is you; if you cannot, we will ask you something only the account holder would know rather than take your word for it. PIPEDA gives us 30 days to answer, and we aim to be well inside that. We do not charge for a request.
If you are not happy with how we handled it, you can complain to the Office of the Privacy Commissioner of Canada, which oversees PIPEDA. We would rather you told us first, but you are not obliged to.
How it is protected
What the code actually does:
- Passwords are stored as a salted scrypt hash. We could not tell you your password if you asked; we can only check one.
- The session cookie holds a random token, and even that is stored on our side only as a hash, so a copy of our database does not hand anyone a live session.
- Uploaded CVs live outside the served part of the site and come out only through a route that checks permission on every request.
- Uploads are limited to 5 MB and to document formats, and the file's first bytes are checked against the extension it claims.
- Sign-in, uploads, applications, reviews and the contact form are all rate limited, and a failed sign-in takes the same time whether or not the email address exists, so the login form cannot be used to find out who has an account here.
No system is perfectly safe, and anyone who tells you theirs is has stopped paying attention. If you find a hole, tell us. We would much rather hear it from you.
If your information is ever exposed
PIPEDA calls this a breach of security safeguards: your information being lost, accessed or disclosed when it should not have been. Here is what we would do, rather than what a template would say.
- Every one gets written down. The law requires a record of every breach, however small and whether or not anyone needs to be told, and those records can be asked for by the Privacy Commissioner. So one gets kept even for the ones that turn out to be nothing.
- We work out whether it could actually hurt you. The test in the Act is a real risk of significant harm, and it depends on what was exposed and who could have seen it. A CV, an application to a named employer, or an email address next to a job search are all capable of meeting that bar. Assume we treat them as capable of it.
- If it meets that bar, we tell you and we tell the Commissioner. The notice goes to the address on your account, and it says what happened, what of yours was involved, what we have done about it and what you can do. If an employer or a supplier needs to know in order to reduce the harm, they are told too.
- We say when we do not know yet. The Act requires notice as soon as feasible, and we are not going to invent a number of hours we cannot promise. A first message that says what we know and what we are still finding out is better than silence while somebody assembles a complete story.
The site is run by a very small team, so the person who finds out is the person who writes to you. Nothing waits for a committee.
Job alerts and email
We send you email in three situations: you asked for a job alert, something happened on your own account (an employer replied, a review you wrote went live), or you wrote to us and we are answering.
Alerts follow Canada's anti-spam law (CASL). That means:
- An address has to confirm before an alert is sent to it. Ask for one without signing in, from the home page or the job search, and we send that address a single email with a confirmation link in it. No alert goes out until somebody opens that link, and if nobody ever does, nothing is ever sent. An alert you set up while signed in is confirmed by your account.
- We record when the alert was asked for, from what IP address, and whether the address confirmed it, so the consent can be shown if it is ever questioned.
- Every alert email says who is sending it and how to reach us.
- Every alert email carries a one-click unsubscribe that works without signing in and takes effect immediately. Your email client's own "unsubscribe" button works too, because we send the header that drives it.
- An alert with nothing to say sends nothing. We do not email you to tell you there were no new jobs.
You can also change the frequency of an alert, switch it off, or unsubscribe from all of them at once in your job alerts.
Children, and changes to this policy
This site is for people old enough to work. It is not aimed at children, and we do not knowingly keep accounts for them. If a child's information has ended up here, tell us and we will remove it.
When this policy changes we will change the date at the top of the page. If a change actually affects what happens to your information, such as a new processor or a new use, we will say so on the site rather than quietly editing a paragraph.
Related: Terms of use · Contact us