Last updated: April 4, 2026
Welcome to mentors.coach ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mentorship platform and services.
We collect personal information that you voluntarily provide to us when you:
This information may include: name, email address, phone number, professional background, career goals, resume/CV, LinkedIn profile, other socials, and payment information.
We automatically collect certain information when you visit, use, or navigate our platform, including: IP address, browser type, device information, usage data, and cookies.
We use third-party analytics services including Google Analytics and Yandex Metrica to collect and analyze usage data. These services may use cookies and similar technologies to track your interactions with our platform. For more information about how we use cookies, including cookie categories, retention periods, and consent mechanisms, please see our Cookie Policy.
Data Controller: mentors.coach acts as the data controller for personal information collected through our platform. As the data controller, we determine the purposes and means of processing your personal data.
Data Processors: We engage third-party service providers who act as data processors on our behalf, including:
All data processors are contractually bound to process your data only in accordance with our instructions and applicable data protection laws. We maintain data processing agreements (DPAs) with all processors that include appropriate safeguards for your data.
Under the General Data Protection Regulation (GDPR), we process your personal information based on the following legal bases:
For each processing activity, we ensure that at least one legal basis applies. You have the right to object to processing based on legitimate interests, and we will consider your objection in accordance with applicable law.
We use your information to:
We may share your information in the following situations:
We implement appropriate technical and organizational security measures to protect your personal information. However, no electronic transmission or storage system is 100% secure, and we cannot guarantee absolute security.
We implement role-based access control (RBAC) to ensure that only authorized personnel can access personal data. Access is limited to employees and contractors who need it to perform their job functions. All access is logged and regularly reviewed. We use strong authentication methods, including multi-factor authentication (MFA) where appropriate.
For more detailed information about our security practices, please see our Security page.
Our platform uses automated systems to match mentees with appropriate mentors based on:
This automated matching constitutes "profiling" under GDPR Article 22. The automated decision-making is necessary for the performance of our mentorship services and does not produce legal effects or similarly significantly affect you.
Your Rights: You have the right to:
To exercise these rights, please contact us using the information provided in the Contact Us section below.
Depending on your location, you may have the following rights:
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
We do not sell personal information. To exercise your rights, please contact us using the information provided in the Contact Us section below.
In addition to California, residents of the following states have privacy rights under their respective state laws:
To exercise your rights under any of these state laws, please contact us using the information provided in the Contact Us section below.
If you are located in the European Economic Area (EEA) or United Kingdom, you have the right to file a complaint with your local data protection authority (supervisory authority) if you believe we have violated your data protection rights. You may also contact us first to resolve any concerns.
A list of EU data protection authorities can be found at edpb.europa.eu. UK residents can contact the Information Commissioner's Office (ICO) at ico.org.uk.
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required by law. Specific retention periods are as follows:
After the retention period expires, we will securely delete or anonymize your personal information in accordance with our data deletion procedures.
Your personal information is stored and processed in the following locations:
We do not transfer your personal data across AWS regions unless necessary for disaster recovery or service availability. Any such transfers are conducted with appropriate safeguards in place.
Your information may be transferred to and processed in countries other than your country of residence, including the United States where some of our service providers operate. These countries may have different data protection laws.
We ensure appropriate safeguards are in place for such transfers, including:
Following the European Court of Justice's Schrems II decision, we have implemented additional safeguards for transfers of EU/EEA personal data to the United States and other third countries. These include technical measures (encryption, pseudonymization), contractual measures (SCCs with supplementary clauses), and organizational measures (access controls, audit procedures). We regularly review and update these safeguards to ensure continued compliance.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will:
We maintain an incident response plan and regularly review our security measures to prevent data breaches. If you suspect a security incident, please contact us immediately using the information in the Contact Us section below.
As a company operating from the United States that processes personal data of individuals in the European Economic Area (EEA) and United Kingdom, we are required under GDPR Article 27 to appoint an EU/EEA representative.
We are currently in the process of appointing an EU/EEA representative. Once appointed, we will update this Privacy Policy with the representative's contact information. In the meantime, you may contact us directly using the information provided in the Contact Us section below.
Under GDPR Article 37, we are not currently required to appoint a Data Protection Officer (DPO) because our core activities do not consist of processing operations that require regular and systematic monitoring of data subjects on a large scale, nor do we process special categories of data on a large scale. If our processing activities change in a way that requires a DPO, we will appoint one and update this Privacy Policy accordingly.
We follow the principle of data minimization, collecting and processing only the personal information that is necessary for the purposes outlined in this Privacy Policy.
Access to personal data within our organization is strictly limited:
We regularly audit access logs and review permissions to ensure that access remains appropriate and necessary.
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
Your continued use of our Service after any changes to this Privacy Policy constitutes your acceptance of the updated policy.
We use Stripe, Inc. ("Stripe") to process payments. When you make a payment, Stripe collects and processes your payment information, including credit card details, billing address, and transaction data.
Stripe's collection and use of your payment information is governed by their Privacy Policy, available at stripe.com/privacy. We do not store your full payment card details on our servers. Stripe is PCI DSS Level 1 compliant, the highest level of certification in the payment industry.
For questions about payment processing or to exercise your rights regarding payment data, you may contact Stripe directly or contact us using the information below.
We use Amazon Web Services Simple Email Service (AWS SES) to deliver transactional and marketing emails, including verification codes, account notifications, and service updates.
AWS SES processes email delivery data (sender, recipient, subject, delivery status) in accordance with AWS's data processing agreement and applicable security standards. Email content is transmitted securely and stored temporarily for delivery purposes only.
For more information about AWS SES, please visit aws.amazon.com/ses.
The Mentors Coach browser extension helps job seekers save and track job applications from career sites and optionally fill application forms with their resume data when they choose to.
Permission justifications (for Chrome Web Store Privacy practices):
| Permission | Justification |
|---|---|
| activeTab | Used to access the currently active tab only when the user invokes the extension, in order to show in-page popovers and read the page URL for "application for this page" checks and form capture. |
| host_permissions | Used to communicate with the mentors.coach API and to run content scripts on job and career sites where the user applies, solely to offer save-application and form-assist features. |
| remote code | The extension does not execute remote code. Content scripts are bundled with the extension and run on pages the user visits; no code is fetched or executed from remote servers. |
| storage | Used to store the user's session token, selected resume ID, API base URL, and theme preference locally so the extension works across tabs and after browser restart. |
| tabs | Used to get the active tab's URL for application-for-this-page checks, to send messages to the content script in the current tab (e.g. show popover), and to close the OAuth callback tab after sign-in. |
We certify that the extension's collection and use of data complies with Google's Developer Program Policies. Data is used only for the stated single purpose. We do not sell user data. Our full Privacy Policy above applies to the extension.
If you have questions or concerns about this Privacy Policy, or to exercise your privacy rights, please contact us at:
Email: hello@mentors.coach
Address: 30 N Gould ST STE R Sheridan, WY 82801 USA
Phone: +381-621-496-696
We will respond to your request within 30 days as required by applicable law. If you are a California resident, you may also contact us to request information about our data sharing practices or to opt-out of certain data sharing.