Privacy Policy
Information We Collect
1.1 Google Account Profile
When signing in via Google OAuth, we receive basic identity metadata: your full name, primary email address, and avatar URL. This information is utilized exclusively to establish and display your candidate session.
1.2 Gmail Data & Message Parsing
gmail.readonlyWhere's My Offer? requests read-only authorization to your mailbox solely to index official campus placement correspondence. Specifically, this access is used to:
- Identify campus placement emails from official CDC/NeoPAT senders (e.g., noreply.cdcinfo@vitstudent.ac.in).
- Extract company profiles, test schedules, PPT invitations, and interview rounds.
- Sync drive status (Registered, Test, Interview, Selected) to your dashboard.
- Match your Candidate Registration ID against shortlist attachments (PDFs and Excel sheets).
🔒 We strictly do NOT read personal emails, bank statements, personal correspondence, or any messages outside verified placement sender patterns.
1.3 Google Calendar Data (Optional)
calendar.eventsIf you opt into Google Calendar sync, we utilize the calendar.events scope strictly to publish and update recruitment timelines, assessments, and interview slots to your personal calendar.
1.4 User-Provided Credentials
During onboarding or in Settings, you provide your Candidate Registration ID and College Gmail address. These identifiers are stored securely and used only to match your name on shortlist rosters.
How We Use Information
All parsed data is strictly utilized to provide automated placement tracking services directly to you:
Displaying upcoming deadlines, registrations, and CTC packages.
Alerting you when your candidate ID appears in shortlisted results.
Populating your agenda with test links and interview windows.
Sending opt-in instant browser alerts for urgent placement circulars.
We DO NOT sell, rent, monetize, or trade your data. We DO NOT share your data with advertisers, third-party brokers, or data analytics firms. We DO NOT use your email data to train public AI/LLM models.
Data Storage & Cryptographic Security
We implement industry-grade defense-in-depth security standards to protect your credentials and indexed records:
Supabase PostgreSQL with Row-Level Security (RLS)
Your synced records reside in an enterprise PostgreSQL database protected by strict Row-Level Security policies. Users can only query and mutate their own authenticated data partition.
AES-256 Token Encryption at Rest
OAuth refresh tokens are cryptographically encrypted using AES-256 before being committed to persistent storage. Encryption keys are decoupled from application databases.
Zero Password Footprint & Ephemeral Ingestion
We never see or store your Google password. Email message contents are parsed in memory, transformed into structured drive events, and raw bodies are never retained indefinitely.
Google API Services — Limited Use Disclosure
Where's My Offer?'s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements:
Your Rights & Data Erasure
You maintain unconditioned control over your personal data at all times:
Instant Account Deletion
Permanently erase all synced emails, company records, and credentials from Settings → Danger Zone.
Settings Page →Revoke OAuth Tokens
Revoke app permissions directly from your Google Security console at any time.
Google SecurityData Portability
Request an export of all structured drive records associated with your account.
Contact Support →Contact & Support Desk
If you have any questions regarding this Privacy Policy, compliance audits, or data deletion procedures, please submit a ticket through our Feedback & Support Desk:
Where's My Offer? Engineering Desk
VIT Bhopal University · Student Platform
© 2026 Where's My Offer?. All rights reserved.