Privacy Policy

This Privacy Policy describes how My Faces Production ("we", "us", "mantracv") collects, uses, and protects your personal data when you use the mantracv resume-building service (the "Service"). It is published in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable provisions of the Information Technology Act, 2000 of India.

1. Data we collect

1.1 Account data

  • Email address (used as your login identifier)
  • Full name (entered at signup or imported from your resume)
  • Encrypted password hash (stored by Supabase, never in plaintext)

1.2 Resume content

  • Contact details, work history, education, skills, projects, certifications, and any other content you enter into a resume.
  • Resumes are stored as JSON in our database with row-level security — only you (and admin users for support) can read them.

1.3 Payment data

  • We never see or store your card or UPI details. Razorpay processes payments and shares only a non-sensitive payment identifier with us for receipt purposes.
  • We retain the Razorpay payment ID, amount, plan purchased, and timestamp for accounting and tax compliance.

1.4 Usage data

  • Pages visited, buttons clicked, downloads made (basic analytics)
  • IP address and user-agent (rate limiting and abuse prevention)

2. How we use your data

  • To provide the Service (render your resume, export PDFs)
  • To process payments and prevent fraud
  • To improve features (aggregated analytics, never sold)
  • To send transactional emails (welcome, payment receipt, password reset). We do not send marketing emails without your explicit consent.
  • To comply with legal obligations (tax, fraud investigations)

3. AI processing

4. Sharing your data

We share your data only with:

  • Supabase (database + auth provider, hosted in the EU)
  • Razorpay (payment processor, India)
  • Government bodies, only if compelled by a valid Indian court order.

We will never sell your data to advertisers, recruiters, or any third party.

5. Data retention

  • Active account: data is retained for as long as you use the Service.
  • After deletion: when you delete your account, all personal data (profile, resumes, subscription) is permanently removed within 30 days. Payment receipts are retained for 7 years for Indian tax compliance, with personal identifiers redacted after 90 days.

6. Your rights under the DPDP Act

You may at any time:

  • Access your data — download a JSON export from your account page.
  • Correct your data — edit your profile and resume content directly.
  • Delete your account and all associated personal data via /profile/account.
  • Withdraw consent — stop using the Service and delete your account.
  • File a grievance — see Contact below.

7. Security

All traffic is encrypted with TLS 1.2+. Passwords are hashed with bcrypt by Supabase. Database access is gated by row-level security policies. Payment signatures are verified using HMAC-SHA256 with constant-time comparison.

8. Children

mantracv is not directed at children under 18. We do not knowingly collect data from minors. If you believe a minor has signed up, contact us and we will delete the account.

9. Changes

We may update this Policy. Material changes will be notified by email at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.

10. Contact / Grievance Officer

My Faces Production
Email: info@mantracv.com
Response time: within 7 business days as required by the DPDP Act.