Privacy Policy
Snowlint Agency
Last updated: 22 July 2026
Snowlint Agency is a public recruitment website at agency.snowlint.com. It shows open roles and job detail pages, and lets candidates submit an application. This policy covers general use of the website — browsing, contacting us, and the technical data behind that. If you submit a job application, that processing is covered by the separate Applicant Privacy Notice, which goes into more detail because applications involve more data (screening answers, an optional CV, and internal review). We don't duplicate that detail here.
1. Who we are (the data controller)
The data controller responsible for personal data processed through this website is:
- Legal entity: Arturs Vanags
- Registered address: Rīga, Latvia (full registered address available on request via [email protected])
- Country of establishment: Latvia
- Company registration number: Not applicable — sole trader (self-employed individual), not a registered company
- Privacy contact: [email protected]
We have not appointed a Data Protection Officer (not required at our scale); privacy questions go to [email protected]. We are established in the EU (Latvia), so an Article 27 GDPR EU representative is not required.
2. What this policy covers
This policy applies to anyone browsing agency.snowlint.com, contacting us directly, or signing in to an applicant or staff account. It does not separately restate the job-application data flow — see the Applicant Privacy Notice for that.
3. What we collect, why, and our lawful basis
| Data | Why we process it | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Technical request data (IP address, user agent, request metadata) | To operate, secure, and troubleshoot the website; rate-limiting and abuse prevention | Legitimate interests (security, reliability) — Art. 6(1)(f) |
| Account session data (see §4) | To keep signed-in users authenticated and enforce account access | Performance of a contract / legitimate interests — Art. 6(1)(b)–(f) |
| Content of emails you send us directly (e.g. to [email protected]) | To read and respond to your message | Legitimate interests (handling your enquiry) — Art. 6(1)(f), or performance of pre-contractual steps if your enquiry relates to a role — Art. 6(1)(b) |
| Pseudonymous technical telemetry: performance metrics, JavaScript errors, and traces (see §6) | To operate, monitor, and troubleshoot the website | Legitimate interests (security and reliability) — Art. 6(1)(f) |
| Pseudonymous recruitment-funnel and campaign events (see §6) | To understand whether candidates can complete the application journey | Consent — Art. 6(1)(a) |
We don't run advertising or cross-site tracking, so there's no data collected for those purposes.
4. Account sign-in
Users can sign in using a passwordless magic link sent by email or Google sign-in. Accounts have an applicant or recruiter role, and only recruiter accounts can access application-review tools. Applying for a role does not require an account. When an applicant signs in with a verified email address, we may link applications submitted with that matching email so the applicant can view them and withdraw applications that are still eligible for withdrawal. Signing in sets a short-lived, host-only session cookie in the user's browser.
5. Cookies and browser storage
We keep this lean. We do not use advertising or cross-site tracking. Technical monitoring uses a temporary browser-tab session. Optional recruitment analytics is activated only after you choose “Allow recruitment analytics”.
| Cookie | Purpose | Who gets it | Lifetime |
|---|---|---|---|
__Host-agency_session | Keeps a signed-in account holder authenticated | Applicant or staff account holders, after sign-in | 7 days |
__Host-agency_oauth | Short-lived anti-CSRF state for the "Sign in with Google" flow | Anyone using Google sign-in | 10 minutes |
agency_privacy_mode | Remembers whether applicant-sensitive workspace data should be masked on this device | Signed-in workspace members | Up to 12 months |
| Cloudflare security cookies (e.g. bot-mitigation / challenge cookies) and any Turnstile challenge cookie | Set by Cloudflare in front of the site for security; Turnstile protects application submission and account sign-in requests | Set by Cloudflare where applicable | Set by Cloudflare |
| Analytics preference stored in your browser | Remembers whether you allowed or declined optional recruitment analytics | After you make a choice | Up to 12 months |
| Pseudonymous telemetry session stored in your browser | Groups technical events and, when allowed, recruitment-journey events during a browsing session | All site visitors and signed-in account holders | Current browser tab |
Application draft in sessionStorage | Recovers applicant contact details and non-file screening answers after a reload; excludes uploaded files and the privacy acknowledgement | Applicants who begin completing a form | Current browser tab, up to 24 hours after the latest save; cleared after successful submission |
The authentication, security, technical-monitoring, application-draft, and consent-preference storage does not require optional recruitment-analytics permission. The application draft stays in the current browser tab and is not sent to our servers until you submit the form. The telemetry session uses a random identifier for the current browser tab and is not used to identify an account or applicant. We never save that session identifier or its browser details on an application record. If you submit an application after allowing recruitment analytics, we may separately save only the normalized source, medium, and campaign labels with that application, as explained below. A visitor who only browses job listings or submits an application without signing in never receives our account-session or OAuth cookies above. Cloudflare may set security cookies when it needs to perform a challenge.
6. Telemetry / monitoring
We run first-party technical monitoring on all routes and sessions to keep the website reliable. Web Vitals, JavaScript errors, and traces are sent to our own collector on our own EU infrastructure — not a third-party advertising or analytics vendor. Technical telemetry can include a random tab-scoped session identifier, browser and device metadata, sanitized page URLs, timing information, and JavaScript error details. Query strings and fragments are removed from telemetry URLs, and internal UUID route segments are redacted. We do not attach account or applicant identity to this telemetry.
If you allow recruitment analytics, we additionally record a small set of funnel events, such as viewing a role, opening the application form, and whether submission succeeded. These events contain the job identifier, language, and the utm_source, utm_medium, and utm_campaign labels from a tracking link where present. They do not contain application identifiers, applicant names, contact details, files, or form answers.
If you then submit an application, we copy only the normalized source, medium, and campaign labels into that application record so we can understand which recruitment channels produce completed applications. We do not copy or store the Faro session identifier, browser/device metadata, page history, errors, or performance events with the application. The attribution snapshot follows the application retention and deletion rules in the Applicant Privacy Notice.
We use technical telemetry only to keep the site working, and optional recruitment analytics only to understand whether candidates can complete the application journey. We do not use either for advertising, cross-site tracking, applicant profiling, or hiring decisions. Signed-in workspace owners, administrators, recruiters, and viewers receive technical monitoring but are excluded from recruitment-funnel analytics.
You can decline recruitment analytics without losing any site functionality. You can also change or withdraw your choice at any time through “Privacy settings” in the footer. Withdrawing stops future recruitment-funnel collection and campaign attribution in that browser; limited technical monitoring continues. Withdrawal does not affect processing that was lawful before it.
7. Who we share data with
For general site traffic, our infrastructure is:
| Provider | What they do for us | Where |
|---|---|---|
| Our EU-based hosting provider | Hosts the website's backend and databases | EU data centres |
| Cloudflare | DNS, CDN, WAF, and Turnstile for application submission and account sign-in | Global edge network (US company); EU–US/UK/Swiss Data Privacy Framework + Standard Contractual Clauses |
| Our telemetry collector | First-party technical monitoring and optional recruitment-funnel analytics | Our own EU infrastructure |
Job applications and optional account access additionally involve email delivery, resume storage, and Google sign-in. Those sub-processors and international-transfer details are listed in the Applicant Privacy Notice §5–6.
8. Retention
- Technical/security logs are kept only as long as needed for security and troubleshooting, typically a short period.
- Pseudonymous browser telemetry is automatically deleted after 30 days.
- Emails you send us directly are kept only as long as needed to handle your enquiry, then deleted.
- Account session cookies and sign-in tokens expire on the timelines in §5.
- Application data has its own retention policy — see the Applicant Privacy Notice §7.
9. Your rights
If you're in the EU/EEA (and in many other places), you have the right to access, rectify, erase, restrict, or object to our processing of your personal data, and to data portability where applicable. To exercise these rights, email [email protected]. We'll respond within the time limits required by law (generally within one month) and may need to verify your identity first.
Complaints: if you think we've mishandled your data, we'd appreciate the chance to fix it first — but you have the right to lodge a complaint with a supervisory authority, including our lead authority: Datu valsts inspekcija (Data State Inspectorate of Latvia) — https://www.dvi.gov.lv.
10. Children
Snowlint Agency is a recruitment website for adult jobseekers and is not directed at children. We don't knowingly collect personal data from children under the applicable age of digital consent (13, the age set by Latvia under GDPR Article 8). If you believe a child has provided us data, contact us and we'll delete it.
11. Changes to this policy
We may update this policy as the site or the law evolves. When we make material changes, we'll update the "last updated" date at the top. The current version always lives at agency.snowlint.com/privacy.
12. Contact
Questions, requests, or concerns about your data:
Email: [email protected] Controller: Arturs Vanags, Rīga, Latvia (full registered address available on request) Governing law / jurisdiction for this policy: the laws of Latvia, and the courts of Latvia have exclusive jurisdiction