Privacy policy
Privacy notice for xr-jobs
This notice explains which personal data we process on xr-jobs, why we need it, and which rights you have under the GDPR.
1. Controller
xr-jobs is responsible for data processing on this website. For privacy-related requests you can contact us at support@xr-jobs.com.
2. Website provision, hosting, and security
When you access xr-jobs, technically necessary data is processed so the website can be delivered, secured, and maintained. This may include IP address, date and time, requested path, referrer, browser and device data, and server or security logs.
We use Firebase App Hosting, Cloud Functions, Firestore, and related Google Cloud infrastructure for this purpose. Processing takes place on the basis of Art. 6(1)(f) GDPR because secure and stable operation of the website would not be possible without it.
We currently do not activate non-essential analytics or marketing tracking tools by default. Optional analytics, if enabled for xr-jobs later, will only start after your explicit consent through the privacy settings.
3. Language preference, theme, and local storage
We store your selected language, your theme preference, and your consent choice in cookies and local browser storage so the website can reopen with the correct settings and so the consent banner does not have to be shown again on every page view.
Where this involves storing or accessing information on your device, the legal basis for necessary settings is Section 25(2) No. 2 TDDDG. The subsequent processing takes place on the basis of Art. 6(1)(f) GDPR because these settings are required for a consistent, secure, and user-friendly experience.
Optional analytics, if activated later, will only be stored or read after your explicit consent under Section 25(1) TDDDG and will then be processed on the basis of Art. 6(1)(a) GDPR. You can change your choice at any time through the privacy settings in the footer.
4. Job and service submissions, moderation, and publication
If you submit a job or service listing, we process the data you provide, especially your contact email address, company or provider name, listing text, compensation details, location, tags, links, and moderation-related metadata.
We use this data to review submissions, prevent misuse, communicate with you, and publish approved listings. Approved listing content becomes publicly visible on xr-jobs. Your poster email address and internal moderation data are not displayed publicly.
The legal basis is Art. 6(1)(b) GDPR insofar as processing is necessary to handle your submission and Art. 6(1)(f) GDPR for platform integrity, moderation, and abuse prevention.
5. Management links and admin access
To let posters manage their own listings, we send time-limited management links by email. When such a link is used, we process the token and related listing metadata to verify authorization and carry out the requested edit or deletion.
Our internal admin area is protected through Firebase Authentication and restricted to authorized admin accounts. Access-related data may be processed for security, auditing, and abuse prevention.
The legal basis is Art. 6(1)(b) and Art. 6(1)(f) GDPR.
6. Newsletter and email delivery
If you subscribe to our newsletter, we process your email address, confirmation status, language, and technical anti-abuse data in a double opt-in flow. We also send operational emails relating to listing review, publication, rejection, and management access.
We use Resend as our email delivery provider. The legal basis for newsletter emails is Art. 6(1)(a) GDPR. The legal basis for operational emails is Art. 6(1)(b) and Art. 6(1)(f) GDPR.
You can withdraw newsletter consent at any time with effect for the future via the unsubscribe link in every email or by contacting support@xr-jobs.com.
7. External services used during platform features
For location suggestions, the search term you enter is sent to OpenStreetMap's Nominatim service. If you use the optional AI import, the public URL you submit and the publicly accessible page content retrieved from that URL are processed through Firebase AI Logic and related Google AI services to generate a draft listing.
The AI import is intended only for public pages. Private, local, internal, or authenticated URLs are rejected. The legal basis for these optional features is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR for an efficient submission workflow.
8. Future payment providers
The website does not currently operate an integrated customer checkout. If paid placements or other paid features are introduced later, payment processing may be handled by providers such as Stripe, PayPal, Google Pay, or comparable payment services.
In that case, the payment provider will process the billing and transaction data required to complete the payment. We would typically receive only the information needed to document the booking, prevent fraud, and handle accounting, support, or legal obligations.
The applicable legal basis would generally be Art. 6(1)(b) GDPR. Before payment functionality is activated, provider-specific information will be made available in the relevant checkout or booking flow.
9. Storage period
We only keep personal data for as long as it is needed for the relevant purpose, for security, or to comply with statutory retention duties. Newsletter data is kept until you unsubscribe or the subscription otherwise ends.
Listing data is retained while a listing is active and afterwards as needed for moderation, support, documentation, or legal claims. Listings marked for deletion are hidden immediately and are generally purged shortly afterwards unless longer retention is required.
Local browser storage remains on your device until you remove it.
10. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection to certain types of processing. You also have the right to lodge a complaint with a data protection supervisory authority.
11. Updates
We update this privacy notice if functions, legal requirements, or our processing activities change. The current version is always available on this page.