Slash Trace

Privacy policy

What we collect, why, who sees it, and how long we keep it.

Last updated 21 August 2026

Slash Trace watches company careers pages and tells you when roles appear. This page describes the data that involves. It covers slashtrace.com, the application, and the Claude connector at api.slashtrace.com/mcp.

What we collect

What you give us

  • Your name and email address, from signup.
  • Your password, stored only as a bcrypt hash. We cannot read it, and it is never included in any response from our API.
  • The careers pages you choose to track. These are public pages belonging to other companies. We store the URL you gave us and the one we resolved it to.
  • Your email notification preference, and whether your address has been verified.

What we generate

  • Job listings read from the careers pages you track: title, location, department and link. This is public information published by those companies. We do not collect anything about the people who apply.
  • A record of each read: when it ran, whether it worked, and how many roles it found, so a failing board can be diagnosed.
  • Notifications, one per new role on a board you track.
  • Sign-in timestamps, and short-lived hashed codes when you verify an email address.

Billing

If you subscribe, we store your Stripe customer and subscription identifiers, your plan, its status and its renewal date. We never see or store your card details. Checkout is a redirect to Stripe, so card numbers are entered on Stripe's own pages and never reach our servers.

Cookies

One cookie, named token. It holds your session, is set httpOnly so no script can read it, and expires after seven days. There are no analytics, advertising or tracking cookies on this site, and no third-party scripts that would set any.

How we use it

  • To run the product: read the boards you track and show you the roles.
  • To email you: a daily digest of new roles if you have those on, plus account mail such as email verification.
  • To take payment and apply the right plan limits.
  • To answer you when you contact us.

We do not sell your data, we do not share it for advertising, and we do not use your data to train machine learning models.

Who else sees it

We use a small number of processors. Each receives only what its job requires.

  • Stripe: payments and subscriptions. Receives your email address and billing details you enter with them.
  • Resend: sends our email. Receives your email address and the contents of the message.
  • Google (Gemini): used once per careers page, when a board is first added, to work out how to read it. Receives the content of that public careers page. It is never sent your personal data.
  • The Companies API: used when you search for a company by name instead of by URL. Receives the company name you typed.
  • logo.dev: company logos, requested by your browser using the company's domain.

We may also disclose data where the law requires it, or to protect the security of the service.

The Claude connector

If you connect Slash Trace to Claude, the connection is authorised with OAuth 2.0. Your password is never shared with Claude. Claude receives an access token that you can revoke at any time from Settings, and it can read the boards you track, search the roles on them and add or remove boards. It has no access to billing, to other accounts, or to admin.

How long we keep it

  • Your account, for as long as it exists.
  • Job listings, including ones that have closed. A closed role is marked closed rather than deleted, so that a role reappearing can be told apart from a new one.
  • Notifications and read history, for as long as the board is on someone's list.
  • Boards you remove: removing a board deletes your link to it. The board itself and its history remain, because careers pages are shared between accounts and other people may be tracking the same one.

Deleting your account

There is no self-serve delete button yet. Email [email protected] from your account's address and we will delete your account, your tracked boards and your notifications. Public job listings that other accounts also track are not deleted, because they are not yours.

Your rights

Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to some processing. Write to [email protected] and we will act on it. You can turn email off at any time in Settings, or with the unsubscribe link in any digest.

Security

Traffic is served over HTTPS. Passwords are stored as bcrypt hashes and session cookies are httpOnly. No system is perfect; if you believe you have found a vulnerability, please write to [email protected] rather than disclosing it publicly, and we will respond promptly.

Changes

If this policy changes materially we will update the date at the top and, where the change affects how your data is used, tell you by email.

Contact

[email protected].