Skip to main content

Privacy policy

Anonymous salary contributions stay separate from professional identity. If you create a Career Passport, you control what is saved, what is visible, and whether the account continues to exist.

Effective date: 22 July 2026

1. What we collect

When you submit salary information, we collect: job title, industry, location (city), seniority level, organisation type, monthly gross pay, currency, and optional benefits and notes.

Anonymous salary submissions do not request your name, email address, phone number, employer name, or national ID and are not linked to a PayYako account.

If you create a Career Passport, we store the account email and the professional information you choose to add, such as your name, headline, location, experience, career goals, CV-derived profile, achievements, credentials, references, verification requests, and profile-visibility choices.

If you create a salary watchlist, we store the benchmarks you follow, your alert thresholds, optional target medians, and whether you requested email delivery.

If you submit an employer or institution enquiry, we collect your name, work email, organisation, role, organisation or cohort size, stated need, and the context you provide so we can assess and respond to it.

For abuse prevention and rate-limiting, a one-way cryptographic hash of your network address may be stored with actions like salary submissions. This hash is not stored with web analytics. Raw IP addresses are never persisted.

2. How we use your data

Submitted salary data is used solely to calculate and publish aggregate benchmarks — including medians, percentile ranges, averages, and sample counts — grouped by role, industry, location, and seniority.

Individual submissions are never displayed, sold, licensed, or shared with any third party. Only aggregate statistics meeting a minimum sample-size threshold are published.

Career Passport data is used to provide the profile, career tools, user-requested verification, and opted-in public or employer discovery. Private or unlisted profile data is not sold as a candidate database.

Salary watchlist settings are used only to show benchmark changes and deliver alerts you explicitly enable.

Employer and institution enquiry details are used to assess fit, respond to the request, and understand aggregate product demand. They are not sold or used as a third-party lead list.

We may use aggregate, non-identifiable statistics internally to improve the platform, detect abuse, and measure programme outcomes.

3. Publication threshold

A benchmark group is only published when it contains at least five approved submissions. This threshold exists to prevent any individual contributor from being identified through their data.

If a group has fewer than five records, its data remains internal and is not visible to any public user, employer, or API consumer.

4. Cookies and analytics

PayYako does not use advertising cookies or third-party tracking pixels. We do not use Google Analytics or any external analytics service.

We may use essential cookies for session management and security purposes (such as CSRF protection). These cookies contain no personal information and cannot be used to identify you.

We run first-party, privacy-respecting analytics to understand aggregate usage. For each page view we record only the page path (query strings are stripped), the referring site, and a random session identifier stored in your browser's session storage that is cleared when you close the tab. We do not store your IP address or user-agent with analytics, and we do not use it to build a profile of you.

Pages tied to a specific person or private link — including public profiles, career cards, saved reports, and verification links — are excluded from analytics entirely.

Analytics events are retained for 90 days and then automatically deleted.

5. Data storage and security

Salary data is stored in a secured database with access restricted to authorised administrators. All data in transit is encrypted via TLS.

Administrative access to raw submission data is protected by authentication, and admin actions are logged.

We do not store raw network addresses. The one-way hash used for rate limiting cannot be reversed to recover your IP address.

6. Your rights

Signed-in users can download a portable JSON copy of their Career Passport data and permanently delete their account from the profile page.

Account deletion removes the profile, saved Career Passport, experiences, verification requests, evidence log, and employer memberships associated with the account. Anonymous salary submissions are unaffected because PayYako cannot link them to an account.

You can keep a profile private, make it unlisted for link-only sharing, or explicitly make it public and discoverable. You may change that choice at any time.

You may ask us to correct or delete business-contact details submitted through an employer or institution enquiry by using the contact page.

7. Third-party services

PayYako may use third-party infrastructure providers (hosting, database services) that process data on our behalf under strict contractual obligations.

We may use AI language models for career matching, CV analysis, and related tools. Text or CV content supplied to those tools is sent to the configured AI provider for that request. Raw CV files are not retained by PayYako unless a future feature obtains separate, explicit consent.

We do not sell, rent, or share raw submission data with any third party for any purpose.

8. Changes to this policy

We may update this privacy policy from time to time. Material changes will be noted on this page with a revised effective date.

Continued use of PayYako after changes are posted constitutes acceptance of the updated policy.

Questions about your privacy?

If you have any questions about this policy or how we handle data, please reach out through our contact page.