Skip to content

Privacy Policy

v2.0 Effective 12 May 2026 Last reviewed 12 May 2026
United KingdomEuropean UnionNetherlands

Privacy contact: hi@sponsorfinder.io

Introduction

Sponsor Finder ("we", "our", "us") operates the website at sponsorfinder.io (the "Service"), a free, advertising-supported aggregator of public visa-sponsor registers in the United Kingdom and the Netherlands, together with an authenticated job-application tracker. This Privacy Policy explains what personal data we process, why, on what lawful basis, how long we keep it, and how you can exercise your rights.

We are committed to processing your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (Regulation (EU) 2016/679), the UK Privacy and Electronic Communications Regulations 2003 (PECR), the EU ePrivacy Directive (2002/58/EC), and the Dutch Telecommunicatiewet (article 11.7a). Where the law of the United Kingdom, the European Union or the Netherlands grants you greater protection, that law applies.

If you do not agree with this Privacy Policy, please do not use the Service. We will not be able to provide the authenticated features (account, bookmarks, job tracker) without processing the data described below.

Data controller

Trading as
Sponsor Finder

What we collect

Account & authentication data

Information used to create and secure your account.

Email addressPassword (stored as a salted hash by Supabase Auth, never in plain text)Backend user identifier (UUID)Account role (USER or SUPER_ADMIN)Account creation timestamp
Source
user
Lawful basis
Contract (Art. 6(1)(b))
Retention
Until account deletion plus up to 180 days in encrypted backups.

OAuth profile data

Where you sign in with Google, the data Google returns to us as part of the OAuth flow.

Google account emailGoogle account identifierDisplay nameAvatar URL
Source
oauth
Lawful basis
Contract (Art. 6(1)(b))
Retention
Until account deletion.

Profile data

Information you choose to provide in your profile.

Full nameAvatar image (JPEG/PNG/WebP, up to 5 MB)
Source
user
Lawful basis
Contract (Art. 6(1)(b))
Retention
Until you delete it or delete your account.

Session data

Server-issued session tokens used to keep you signed in and let you review and revoke active devices.

Session identifierCreation, last-active and expiry timestampsWhether the session belongs to the current browser
Source
automated
Lawful basis
Contract (Art. 6(1)(b))
Retention
Access tokens: 1 hour. Refresh tokens: 7 days. Revoked sessions are deleted promptly.

Job tracker entries

Information you record about jobs you are tracking. Visible only to you.

Job title and companyStage and activity historySalary range, currency and pay basisPriority, favourite flag, source channelLocation, job type, application URLFree-text notesDeadline, applied-on and closed-on dates
Source
user
Lawful basis
Contract (Art. 6(1)(b))
Retention
Until you delete the entry or your account.

Recruiter contact data (third-party personal data)

Information you enter about a recruiter, hiring manager or other individual at the company you are applying to. This is personal data about someone other than you, and you must have a lawful basis under Article 6 GDPR to record it. We act as a processor of this data on your behalf when storing it; you remain the controller.

Recruiter nameRecruiter work email addressRecruiter LinkedIn URL
Source
third_party_via_user
Lawful basis
legitimate_interests
Retention
Until you delete the related tracker entry or your account.

Uploaded job documents

Documents you attach to a job in the tracker.

PDF and DOCX files up to 10 MB per file (e.g. CVs, cover letters, offer letters)
Source
user
Lawful basis
Contract (Art. 6(1)(b))
Retention
Stored in a private bucket with signed URLs (1 hour TTL). Deleted on file delete, job delete, or account delete.

Bookmarks

Organisations you have saved.

Organisation identifierCountry (UK or NL)Bookmark creation timestamp
Source
user
Lawful basis
Contract (Art. 6(1)(b))
Retention
Until you remove the bookmark or delete your account.

Search queries and product activity

Queries you submit and interactions you take on the Service. Where you have granted analytics consent, the raw search string (truncated to 100 characters) and event metadata are forwarded to Google Analytics 4 and Vercel Analytics. Without analytics consent, we still process your search backend-side to return results but do not share it with third parties beyond returning matching organisations.

Search query strings (truncated to 100 characters when shared with analytics providers)Filters appliedPagination, suggestion clicks, organisation views and outbound link clicks
Source
user
Lawful basis
Consent (Art. 6(1)(a))
Retention
Analytics retention: GA4 is configured for 14 months. Vercel Analytics retains aggregated metrics per its policy.

Technical & log data

Information collected automatically by our servers and our infrastructure providers when you use the Service.

IP address (captured in backend application logs)User-agent stringReferrer and route informationRequest timestamps and latency, response status codesRate-limit counters keyed by IP
Source
automated
Lawful basis
legitimate_interests
Retention
IP addresses and request logs: 30 days. Aggregated metrics: 90 days.

Bug reports

When you submit a bug report through the in-product widget, the following are forwarded to our form host (Tally.so).

The free-text description you writeCurrent page URL and routeTruncated user-agent string and screen dimensionsHTTP status code, error message (up to 500 characters) and stack trace (up to 2000 characters)Your backend user identifier, email address and roleApplication version and report type
Source
user
Lawful basis
legitimate_interests
Retention
Stored by Tally on our behalf and reviewed by us; deleted when the issue is resolved or sooner on request.

Cookies, local storage and consent preferences

Small pieces of information stored on your device. Strictly-necessary items are used regardless of consent; analytics and advertising items are only set after you grant the corresponding consent. See the Cookies section below for the full list.

Authentication cookies (sb-access-token, sb-refresh-token)Consent state cookie (sf_cc_cookie)Analytics cookies set by Google Analytics 4 / Google Tag ManagerAdvertising cookies set by Google AdSenseTheme preference and small UI caches in localStorage
Source
automated
Lawful basis
Consent (Art. 6(1)(a))
Retention
See the cookie table for individual durations.

Public sponsor register data

Information we ingest from public government registers. This is the data the Service is built to expose; it is not personal data about you, but is described here for completeness.

UK Home Office register of licensed sponsors (gov.uk)Netherlands IND register of recognised sponsorsCompanies House enrichment (company identifier, SIC codes, sector)
Source
public_register
Lawful basis
legitimate_interests
Retention
Refreshed on a daily schedule. Removed organisations retained for 180 days; change-event history archived after 365 days and deleted after 730 days.

Sub-processors & recipients

Third-party services that receive personal data
ProviderPurposeRegionTransfer mechanismData sharedLinks
Supabase, Inc.Authentication, Postgres database and private object storage for user accounts, sessions and uploaded documents.Ireland (or selected project region) · EUeu_sccsAccount, profile, session, job tracker and uploaded-file data.
Upstash, Inc.Managed Redis used for caching and rate-limit counters.EUeu_sccsIP-address-keyed rate-limit counters and short-lived cached responses.
Vercel, Inc.Hosting of the website, edge network, Vercel Analytics and Speed Insights.United States (with EU edge presence) · globaleu_dpfRequest metadata (IP, user-agent, referrer, performance metrics). Where you grant analytics consent, custom analytics events including user_id, user_role, page and event properties.
Google LLC / Google Ireland LimitedGoogle Tag Manager (GTM), Google Analytics 4, Google AdSense, and Google Fonts.United States (and EU) · globaleu_dpfWhere you grant analytics consent, GA4 receives event metadata including user_id, user_role, page paths and the structured event properties described in the analytics section. Where you grant marketing consent, AdSense receives ad-impression and click data. Google Fonts is loaded directly by your browser when using the site (no font-related cookies are set on this domain).
Tally B.V.Hosted form used by the in-product bug-report widget.Belgium · EUnoneBug-report description, page URL, route, status code, error message and stack trace (truncated), user-agent and screen size, your user_id, email address, role, app version and report type.
Telegram FZ-LLCOperational alerts to our administrators when public-register data changes.othereu_sccsAggregated change counts and the names of affected organisations. No user personal data is sent to Telegram.
OpenStreetMap FoundationNominatim geocoding (city to coordinates) and OpenStreetMap tile servers for organisation maps.United Kingdom · EUAdequacy decisionWhen map tiles or geocoding lookups are requested by your browser, the OpenStreetMap service receives your IP address, user-agent and the city string or tile coordinates requested.
Companies House (UK Government)Enrichment of UK organisation records with company identifier, SIC codes and sector data.United Kingdom · UKnoneOutbound organisation-name lookups only. No personal data about you is shared.
UK Home Office (gov.uk)Source of the United Kingdom register of licensed sponsors. Refreshed daily.United Kingdom · UKnoneOutbound public-data download only. No personal data about you is shared.
Immigration and Naturalisation Service (IND), NetherlandsSource of the Netherlands register of recognised sponsors.Netherlands · EUnoneOutbound public-data download only. No personal data about you is shared.
Sanity.io (Lab Digital Norway AS)Headless CMS used to serve the content of this Privacy Policy and other legal pages.EUeu_sccsWhen you view this page, your browser fetches the policy content from Sanity’s CDN. No account data is written from the website to Sanity.

Cookies & similar technologies

Functional

Functional cookies
NameProviderStoragePurposeDurationFirst-party
themesponsorfinder.iolocalStorageStores your light/dark theme preference.Persistent until cleared by youYes
geocoding-coordinates-cachesponsorfinder.iolocalStorageCaches city-to-coordinate lookups so organisation maps load faster.Persistent until cleared by youYes

Analytics

Analytics cookies
NameProviderStoragePurposeDurationFirst-party
_vercel_* (analytics identifiers)VercelcookieVercel Analytics and Speed Insights collect aggregated traffic and Web Vitals. Vercel hashes IP addresses and rotates the hash daily; no cookies are set client-side by Vercel Analytics itself, but Vercel may set operational cookies for its hosting platform.Per Vercel defaultsNo
_gaGoogle Analytics 4cookieDistinguishes individual users for Google Analytics. Only set after you grant analytics consent.13 monthsNo
_ga_<container-id>Google Analytics 4cookiePersists session state for Google Analytics. Only set after you grant analytics consent.13 monthsNo
_gidGoogle AnalyticscookieDistinguishes individual users for Google Analytics. Only set after you grant analytics consent.24 hoursNo
_dc_gtm_<container-id>Google Tag ManagercookieThrottles requests to Google Analytics. Only set after you grant analytics consent.1 minuteNo

Advertising

Advertising cookies
NameProviderStoragePurposeDurationFirst-party
__gadsGoogle AdSensecookieUsed by Google to deliver and measure advertising. Only set after you grant marketing consent.13 monthsNo
__gpiGoogle AdSensecookieUsed by Google for ad personalisation. Only set after you grant marketing consent.13 monthsNo
IDEGoogle (doubleclick.net)cookieUsed by Google to register and report on advertising interactions. Only set after you grant marketing consent.13 monthsNo

strictly_necessary

strictly_necessary cookies
NameProviderStoragePurposeDurationFirst-party
sb-access-tokensponsorfinder.io (Supabase Auth)cookieAuthenticates your session for the duration of an access token. HttpOnly and Secure.1 hourYes
sb-refresh-tokensponsorfinder.io (Supabase Auth)cookieAllows your session to be refreshed without re-entering credentials. HttpOnly and Secure.7 daysYes
sf_cc_cookiesponsorfinder.iocookieStores the cookie-consent choices you make (necessary / analytics / marketing) so we do not ask again on every visit.182 daysYes
reset_token_hash, recovery_tokenssponsorfinder.iosessionStoragePasses Supabase recovery tokens from the auth callback page to the password-reset page when you reset your password.Browser sessionYes

How long we keep data

Retention periods by data category
DataPeriodJustificationDeletion trigger
Account, profile, sessions, job tracker, bookmarks and uploaded filesUntil you delete the relevant item or your account, plus up to 180 days in encrypted backupsPerformance of contract (provision of the Service to you) and a short backup window to allow recovery from operational incidents.User-initiated deletion, account deletion request, or scheduled backup expiry.
Access and refresh sessionsAccess token: 1 hour. Refresh token: 7 days. Revoked sessions: deleted promptly.Security: short-lived tokens limit the window for misuse if a session is compromised.Token expiry, sign-out, revoke-other-sessions or revoke-all.
Application request logs (including IP addresses captured by Winston)30 daysNecessary for security, abuse detection and incident investigation under our legitimate interests (Article 6(1)(f) GDPR).Automated log rotation.
Aggregated application metrics (request counts and latency, no IP)90 daysOperational monitoring of the Service.Automated metric expiry.
Organisation change events (public-register data)Archived after 365 days, deleted after 730 daysProvides a longitudinal view of register activity to users and supports operational quality checks.Scheduled retention job.
Organisations that have been removed from a public register180 daysAllows users to find an organisation that recently lost its sponsor status while keeping the database current.Scheduled retention job.
Database backups180 daysDisaster recovery.Scheduled backup expiry.
Google Analytics 4 event data (where you grant analytics consent)14 monthsGA4 retention is set to the shortest practical period.Google Analytics auto-deletion.
Bug reports stored by Tally on our behalfUntil the underlying issue is resolved, or sooner on requestNecessary to investigate and fix product issues.Manual deletion by us, or on user request.

International transfers

Sponsor Finder is operated from the United Kingdom and the European Union. Some of our sub-processors are based in or transfer data to the United States. Where personal data is transferred outside the UK or the EEA, we rely on the following safeguards under Articles 44 to 49 of the UK GDPR / EU GDPR:

  • The EU-US Data Privacy Framework (DPF) adequacy decision of 10 July 2023 and the UK Extension to the DPF (effective 12 October 2023) for transfers to participating US providers (including Google and Vercel where DPF-certified).
  • The European Commission Standard Contractual Clauses (Decision (EU) 2021/914) for transfers from the EEA where the DPF is not relied upon.
  • The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs for restricted transfers from the United Kingdom.

We carry out transfer-impact assessments where required and apply supplementary measures (such as encryption in transit and at rest, and access controls) where appropriate. The sub-processor table above identifies the mechanism we rely on for each provider. You can request a copy of the relevant SCCs by writing to hi@sponsorfinder.io.

Your rights

Right of access

Art. 15

You can ask us to confirm whether we process personal data about you and to receive a copy of that data together with the information set out in Article 15(1) GDPR.

How to exercise
Email hi@sponsorfinder.io with the subject "Article 15 access request".
Response time
Within 1 month (extendable by up to 2 further months for complex or numerous requests).

Right to rectification

Art. 16

You can ask us to correct inaccurate personal data and to complete incomplete personal data we hold about you.

How to exercise
Most profile fields can be edited directly from your dashboard. For anything else, email hi@sponsorfinder.io.

Right to erasure (right to be forgotten)

Art. 17

You can ask us to delete personal data about you where one of the grounds in Article 17(1) GDPR applies, including withdrawing your consent or where the data is no longer necessary.

How to exercise
A full account-deletion endpoint is not yet exposed in-product. Email hi@sponsorfinder.io with the subject "Article 17 erasure request" from the email address registered to your account. We will confirm receipt, verify your identity and complete deletion within 30 days, with corresponding deletion from encrypted backups occurring at the next backup-rotation cycle (no later than 180 days).
Limitations
We may retain limited data where required for legal claims, regulatory obligations or to prevent fraud.

Right to restriction of processing

Art. 18

In the circumstances listed in Article 18 GDPR, you can ask us to limit processing of your personal data to storage only.

How to exercise
Email hi@sponsorfinder.io.

Right to data portability

Art. 20

Where we process your personal data on the basis of consent or contract and by automated means, you can ask to receive that data in a structured, commonly used, machine-readable format.

How to exercise
A self-service export endpoint is not yet exposed in-product. Email hi@sponsorfinder.io requesting an export and we will provide your account, profile, bookmarks and job-tracker data as JSON within 30 days.
Limitations
Data we hold about third parties (for example recruiter contacts) and public-register data is not subject to portability.

Right to object

Art. 21

You can object to processing carried out on the basis of our legitimate interests (Article 6(1)(f)), including processing for analytics where we rely on that basis.

How to exercise
Email hi@sponsorfinder.io. You can also withdraw cookie-based analytics and advertising consent at any time using the cookie-settings link in the website footer.

Right not to be subject to solely automated decisions

Art. 22

We do not carry out solely-automated decision-making that produces legal or similarly significant effects on you.

How to exercise
Not applicable — see the "Automated decision-making" section.

Right to withdraw consent

Art. 7(3)

Where we process personal data on the basis of your consent (for example, analytics and advertising cookies), you can withdraw that consent at any time.

How to exercise
Use the cookie-settings link in the website footer to update or revoke your consent choices.

How to exercise your rights

To exercise any of the rights listed above, email hi@sponsorfinder.io from the address registered to your account, including a clear description of the right you are exercising and any context we need to act on your request. We may ask for additional information to verify your identity where there is reasonable doubt.

Responding to your request is free of charge except where the request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act (Article 12(5) GDPR). We respond within one month and may extend by up to two further months for complex or numerous requests, in which case we will tell you why.

If you are not satisfied with how we handle your request, you have the right to lodge a complaint with a data-protection supervisory authority — in particular, the supervisory authority of your habitual residence, place of work or where you consider an infringement to have occurred. See the "Supervisory authorities" section below.

Supervisory authorities

United Kingdom

Information Commissioner’s Office (ICO)

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom

Netherlands

Autoriteit Persoonsgegevens

Postbus 93374, 2509 AJ Den Haag, Netherlands

European Union (lead body)

European Data Protection Board (EDPB)

Rue Wiertz 60, 1047 Brussels, Belgium

Children

Minimum age: 16

The Service is not directed at children. You must be at least 16 years old to create an account. If you are under 16, please do not use the Service or provide any personal information to us. If we become aware that we have collected personal data from a child under 16 without verified parental consent, we will delete that information promptly.

Automated decision-making

Not in use

We do not use solely-automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (within the meaning of Article 22 GDPR). Search results, sponsor-register matches and analytics are not used to make decisions about you.

Who we are

Sponsor Finder is operated as a free, advertising-supported service. Throughout this Privacy Policy, "controller", "processor", "personal data", "processing", "data subject" and "supervisory authority" have the meanings given to them in Article 4 of the UK GDPR / EU GDPR.

Our contact email for privacy enquiries is hi@sponsorfinder.io. We have not appointed a Data Protection Officer because the conditions in Article 37(1) GDPR do not apply to us; we keep this position under review as the Service grows.

Lawful bases for processing

We process your personal data under one or more of the following lawful bases (Article 6(1) GDPR):

  • Performance of a contract — Article 6(1)(b). To create and maintain your account, to authenticate you, and to provide the features you ask for (search, bookmarks, job tracker, profile, file uploads, session management).
  • Consent — Article 6(1)(a) and PECR / Tw 11.7a. For analytics cookies (Google Analytics 4) and advertising cookies (Google AdSense). You can withdraw consent at any time using the cookie-settings link in the footer.
  • Legitimate interests — Article 6(1)(f). For security and abuse-prevention (including IP-based rate limiting and short-retention request logs), aggregated operational metrics, in-product bug reporting, and cookieless aggregated traffic measurement using Vercel Analytics and Speed Insights. We have carried out a balancing test for each of these purposes and you can request a summary by writing to hi@sponsorfinder.io. You have the right to object under Article 21 GDPR.
  • Legal obligation — Article 6(1)(c). Where we are required to retain or disclose information to comply with applicable law (for example, in response to a valid request from a supervisory authority).

Personal data you provide about others (recruiters and contacts)

The job tracker lets you record information about people other than yourself — typically the name, email address and LinkedIn URL of a recruiter or hiring contact. This is personal data about third parties.

You are the controller of that data: you decide what to record and why. We act as a processor on your behalf when we store it for you. By entering it into the Service, you warrant that you have a lawful basis under Article 6 GDPR (typically your own legitimate interest in pursuing a job application) and that you are using it in a manner consistent with what the individual would reasonably expect in a professional job-search context.

If a recruiter or other third party contacts us asking what data is held about them, or asks to exercise their rights under Article 14 to 22 GDPR, we will forward their request to you and may take reasonable steps to comply ourselves where required to do so under data-protection law.

Bug reports and Tally

If you use the in-product bug-report widget, your report is submitted to our form host Tally (Tally B.V., based in Belgium). To help us investigate the issue, the report is pre-filled with the page URL, route, status code, an error message (truncated to 500 characters), a stack trace (truncated to 2000 characters), your user-agent (truncated to 500 characters), your screen dimensions, your user identifier, the email address registered to your account, your role, the app version and the report type, in addition to anything you type yourself.

We process this data under our legitimate interest in operating and maintaining the Service. You can avoid submitting it by not using the bug-report widget; you can also ask us to delete a report we hold by emailing hi@sponsorfinder.io.

Security

We implement appropriate technical and organisational measures under Article 32 GDPR, including: TLS for all traffic; passwords stored as salted hashes by Supabase Auth (never in plain text); HttpOnly, Secure and SameSite cookies for sessions; rate limiting of API endpoints by IP; row-level security on database tables; private object storage with short-lived signed URLs for file uploads; restricted access to production systems on a need-to-know basis; secrets held in environment variables and never logged; and circuit breakers and timeouts around third-party calls. No system can be guaranteed completely secure, and we will tell affected users and the relevant supervisory authority about a personal-data breach where required by Articles 33 and 34 GDPR.

Public sponsor-register data

The organisation data shown on the Service is sourced from public government registers (the UK Home Office register of licensed sponsors, refreshed daily; and the Netherlands IND register of recognised sponsors) and enriched with data from Companies House for UK entities. This data describes organisations, not individuals. We refresh and reconcile this data on a schedule and provide change history (added, removed, reactivated events) so that users can see how a sponsor’s status has evolved over time.

Administrative alerts via Telegram

When the public-register data we ingest changes, our backend sends summary alerts (the names and counts of affected organisations) to a private Telegram channel monitored by our operators. These alerts contain no personal data about users of the Service.

Deletion and data export (current process)

Most data you create can be deleted directly from the product: bookmarks, individual job-tracker entries, uploaded files, your avatar, individual sessions and "sign out everywhere". A self-service "delete my account" button and a structured data-export endpoint are not yet exposed in-product.

Until they are, you can exercise Articles 17 and 20 GDPR by emailing hi@sponsorfinder.io from the address registered to your account. We will verify your identity, complete deletion or export within 30 days, and confirm backup-purge completion at the next backup-rotation cycle (no later than 180 days). We are actively working to add a self-service deletion and export flow in the product.

Changes to this Privacy Policy

We will update this Privacy Policy when our practices change or to reflect changes in the law. The current version and effective date are shown at the top of this document. Where a change is material we will tell registered users by a notice in the product or by email before the change takes effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy where consent is not separately required.

Changes to this policy

Material changes will be communicated by an in-product notice and, where we hold your email address, by email at least 14 days before they take effect. A version history is maintained at the top of this Privacy Policy.