Privacy Policy

Last updated: 8 October 2026

1. Who We Are

UK Trade Jobs is operated by Blue Canvas AI Ltd, company number NI737502, a limited company registered in Northern Ireland.

Registered office: 22c Spacehub, Balliniska Road, Derry BT48 0NA.

Contact: info@uktradejobs.com

2. What Data We Collect

We collect the following personal data when you use our site:

  • Account registration: your name and email address.
  • Newsletter sign-up: your email address.
  • Job alerts, beta signup, and day-rate tools: your trade, postcode or outward postcode, experience level, work preference, email address or UK mobile number, consent text version, consent timestamp, source page, primary intent, career stage, biggest blocker, feedback-call consent, partner-contact consent, and any optional self-declared CSCS or partner-card details you choose to provide.
  • CV Builder: you can build and print a CV in your browser without uploading it or creating an account. An editable device copy is saved when you choose to save it. Account saving submits the CV details needed for that feature; requesting optional suggestions also sends the details needed for those suggestions. Job alerts require a separate choice.
  • Optional trade profile: if you choose to complete it, we store your trade, experience, postcode area, travel radius, availability, work preference, driving-licence answer and self-declared tickets or qualifications. Ticket details are not treated as verified unless we explicitly tell you they have been checked.
  • Job browsing: we display job listings sourced from the Reed.co.uk API, Sourcing Square, WhatJobs, direct employer postings, and opted-in employer careers feeds. We do not share your contact details with those sources just because you browse a listing.
  • Analytics & cookies: if you accept analytics cookies, we use Google Analytics (GA4), Microsoft Clarity and Ahrefs Web Analytics. We also record consented first-party page and action events in Supabase so we can improve job search and signup journeys. These events use a pseudonymous session identifier that expires after 30 minutes of inactivity and a page-instance identifier. We do not create a persistent cross-session visitor identifier for this testing.
  • Employer journeys: only after you accept the updated analytics notice, we use a random journey reference to record employer button clicks, form submissions and checkout starts. The reference expires in your browser after 30 minutes of inactivity. With that consent, we also send it to Stripe in the Checkout Session metadata to connect the journey to a purchase. Payments without consent have an unknown path. We do not reconstruct earlier activity or use the reference to identify you across devices.
  • Employer-reported outcomes: after a listing expires, you can optionally report applications received, suitable applications and whether you hired someone. These are labelled employer-reported, kept separately from views and clicks, and are not independently verified. Do not include applicant details.
  • Assisted posting: we keep a private record of time spent, drafts produced, drafts approved and whether payment is confirmed, to manage the help you request.
  • Requested-service records: when you create an alert or account, or save a CV, we keep a minimal server-side event confirming that the requested action succeeded. This does not set an analytics cookie. Pseudonymous session or experiment context is attached only when you have accepted analytics.
  • Employer service records: for paid or authorised employer vacancies, we record the vacancy and employer identifiers attached to a job-detail view, an apply start or a completed on-site application. We also record payment, feed-authorisation and employer-report events needed to provide the paid service. These operational records do not use an advertising pixel and do not include a candidate's contact details.

3. How We Use Your Data

  • To create and manage your account.
  • To send job alerts, day-rate follow-ups, and newsletters you have opted into.
  • To match jobseekers with relevant trade, location, pay, site-readiness and CV actions.
  • Where you separately opt in, to use your trade profile to identify suitable roles and contact you when a verified employer is interested. We do not give an employer your contact details or CV without asking you first.
  • To understand beta demand by trade, location, career stage, apprenticeship interest, site-card readiness, and jobseeker blockers.
  • To contact you about relevant recruiter, employer, or training-provider opportunities only where you have explicitly given partner-contact consent.
  • To improve the site and understand usage patterns.
  • To respond to your queries.
  • To report aggregated vacancy response to a paying employer and maintain accurate payment, renewal and service records.

We do not share candidate contact details or CVs with recruiters, employers, or training providers unless you have explicitly agreed to that contact or sharing. Completing a trade profile does not make it publicly searchable.

We process your data under the lawful bases of consent (including email subscriptions and analytics), contract (including delivering paid employer services), and legitimate interest (including service security, fraud prevention, limited service measurement and responding to enquiries).

4. Where Your Data Is Stored

  • Supabase — account data, alert preferences, candidate lead preferences, and day-rate report requests are stored securely in Supabase (cloud-hosted PostgreSQL).
  • Vercel — the site is hosted on Vercel's global edge network.
  • Resend — transactional and marketing emails are delivered via Resend.
  • Google, Microsoft and Ahrefs — consented analytics may be processed by Google Analytics, Microsoft Clarity and Ahrefs Web Analytics.

Some of these services may process data outside the UK. Where this occurs, appropriate safeguards (such as Standard Contractual Clauses) are in place.

5. Cookies

We use the following types of cookies:

  • Essential cookies: required for the site to function (e.g. authentication).
  • Analytics cookies and events: Google Analytics, Microsoft Clarity, Ahrefs Web Analytics and our first-party Supabase usage events are only activated if you accept analytics via our consent banner.
  • Cookie-free service events: payment confirmation, employer feed authorisation and aggregated response events for paid vacancies are necessary service records. They do not set an analytics cookie or load an advertising pixel.
  • Preference storage: we store your cookie consent choice and, during limited product tests, a first-party experiment assignment and a completed-alert flag in your browser. This keeps the experience consistent and prevents us showing the same signup prompt after you convert. It is not used to identify you across websites.

You can stop analytics on this browser using the button below. This clears the employer journey reference and reloads the page to stop analytics scripts. It does not delete payment records or copies already held by a service provider. Contact us for a reviewed access or deletion request.

6. Your Rights Under UK GDPR

You have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — request deletion of your personal data.
  • Restriction — ask us to limit how we use your data.
  • Portability — receive your data in a portable format.
  • Object — object to processing based on legitimate interest.
  • Withdraw consent — where processing is based on consent, you can withdraw it at any time.

Signed-in users can download a machine-readable copy of data linked to their account from My Account. For correction, restriction, objection or a fuller reviewed request, email us at info@uktradejobs.com. We normally respond within one month.

7. Data Retention

Our working retention periods are:

Cards and expiry reminders: device-only tickets stay in that browser until you clear them. Account tickets are self-declared and kept until you remove them or delete your account. Expiry emails use a separate opt-in; stopping them does not stop job alerts. We do not collect card numbers or certificate uploads. Pending reminders stop when you withdraw consent or request account deletion; a message already being sent may still arrive. Delivery-queue diagnostics are minimised after 90 days, while a small record prevents duplicate reminders for the same saved ticket version. Those owned queue records are removed with the ticket or account. Consent evidence follows the separate period below.

  • Account, profile and saved-job data: while your account is active, then removed or anonymised after a verified deletion request unless an exception below applies.
  • Account CV drafts and uploaded CV files: one current editable draft and one private PDF or Word file per account, until you remove them or your reviewed account deletion is completed. These are not sent to employers automatically. You can download and remove each separately. Removed or replaced files lose account access immediately; storage removal is retried daily if it fails. The account data export includes the draft and file details; download the original file separately from your account.
  • CV submissions, candidate leads and day-rate requests: up to 12 months after the latest submission or interaction.
  • Active job alerts and newsletters: until you unsubscribe or ask us to stop. Contact and preference data is removed or anonymised within 90 days after opt-out, except for a minimal suppression and consent record.
  • Applications: up to 12 months after the relevant vacancy closes.
  • Analytics and product events: up to 14 months, including employer journey references in our records and Stripe metadata, and optional employer-reported outcomes.
  • Email delivery and security logs: up to 12 months, with shorter provider logs where the provider applies them.
  • Employer enquiries and assisted-posting work logs: up to 24 months after the last contact. Contract, payment and tax records may be retained for up to six years where required; optional analytics references are handled separately.
  • Consent, suppression and privacy-request evidence: up to six years where needed to demonstrate compliance or honour an opt-out.

We may keep a record longer where required by law, needed to resolve a dispute, or necessary to prevent fraud or repeated unwanted contact. At the end of a period, the record is deleted or anonymised. Email subscriptions can be cancelled through the unsubscribe link in each email.

8. Account Deletion

If you are signed in, submit a verified deletion request from My Account. You can also email info@uktradejobs.com from the address linked to your account. Submitting a request does not immediately delete data: we verify its scope, check legal exceptions and confirm when the reviewed deletion or anonymisation is complete. This protects accounts from unauthorised deletion.

9. Changes to This Policy

We may update this policy from time to time. Any changes will be posted on this page with an updated "Last updated" date.

10. Complaints

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).