Privacy Policy — My ERP Network

Last updated: Feb 2026

1. Introduction

My ERP Network ("we", "us", "our") provides a professional networking ecosystem exclusively for ERP practitioners — covering the My ERP Network website, mobile applications (Android and, in future, iOS), and related services (collectively, the "Services"). This Privacy Policy describes how we collect, use, store, share and protect the personal information you provide when you use the Services, and the rights available to you under applicable privacy laws.

By using the Services you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Services.

2. Scope of this Privacy Policy

This policy applies uniformly to the My ERP Network website at https://myerpnetwork.com, the Android application distributed on Google Play, and any future iOS application distributed on the Apple App Store. It applies to every visitor, registered professional, recruiter and administrator interacting with the Services worldwide.

3. Information We Collect

We collect only the information necessary to operate the Services. Specifically:

3.1 Account Information

  • Full name (candidate) or contact name and company name (recruiter).
  • Email address (used as the login identifier and for account communication).
  • Password (stored only as a bcrypt hash — the plaintext is never stored or logged).
  • Role — candidate, recruiter, admin or super-admin.
  • Account status, email verification state and password-changed timestamps used for security.

3.2 Professional Profile Information

  • Professional headline, current designation, current company and location.
  • ERP skills, modules and versions (for example SAP FICO, Oracle Fusion HCM, Workday Studio).
  • Years of experience, implementation history, certifications.
  • Current CTC, expected CTC and notice period (optional; visible only to recruiters when you apply).
  • Education entries and social links (LinkedIn, GitHub, portfolio URLs) — all optional.
  • Public profile visibility toggle — you decide whether your profile is discoverable via search engines.

3.3 Files & Documents

  • Profile photo (avatar) and cover image — stored as compressed data-URIs inside your user document.
  • Resume file (PDF or DOCX, up to a size limit enforced at the API layer) — stored inside your user document; shared only with recruiters of jobs you have explicitly applied to.

3.4 Recruiter Information (recruiter accounts only)

  • Company name, company location, professional link (LinkedIn or company URL).
  • Job posts you create, applicants you shortlist and internal notes on your pipeline.

3.5 Activity & Usage Information

  • Jobs viewed, saved, applied to; feed posts created, liked or commented on; challenges completed; interview experiences shared; referral requests sent or received; searches performed.
  • Notifications delivered to you inside the Services.
  • Login and password-change events, with timestamps, for security auditing.

3.6 Device & Technical Information

  • IP address, browser user-agent, device type, operating system, screen size and locale — used for security (rate limiting, brute-force detection) and to render an appropriate layout.
  • Request IDs and short-lived request logs used for troubleshooting and audit.

3.7 Push Notification Tokens (mobile app users only)

  • Firebase Cloud Messaging (FCM) or Apple Push Notification service (APNs) device token, platform (android / ios / web), device identifier and application version. Used only to deliver notifications you have opted into.

3.8 Communications

  • Support emails you send us, feedback submitted via forms, and reports (for example: reports of inappropriate content) you file inside the platform.

We do not collect payment information (no monetary payments are processed by the Services), we do not track your precise geolocation, and we do not access your contacts, calendar, camera or microphone. We do not run advertising SDKs.

4. How We Use Your Information

  • To create and manage your account and authenticate you across the website and mobile app.
  • To match candidates with relevant ERP job opportunities and enable recruiter–candidate communication when you apply.
  • To deliver job alerts, referral responses, application status updates and other notifications you have opted into (email or push).
  • To display your public profile to search engines and other users, only when you have set public visibility to on.
  • To prevent abuse, fraud, spam, brute-force attacks and other security threats.
  • To measure aggregated usage of the Services (via Google Analytics 4) so we can improve product features.
  • To comply with legal obligations and to respond to lawful requests from regulators or courts.
  • Performance of a contract — to provide the account, feed, jobs, applications, referrals and communications you request.
  • Legitimate interests — to keep the Services secure, prevent fraud, run aggregate analytics and improve the product; we balance these interests against your privacy rights.
  • Consent — for optional cookies, push notifications, email marketing and any data you choose to make public via the visibility toggle. You may withdraw consent at any time.
  • Legal obligation — where we are required by law to retain or disclose specific information.

6. Cookies and Similar Technologies

The Services use a minimal set of cookies and browser-storage keys:

  • Authentication cookie — an HTTP-only, Secure, SameSite=None cookie that stores your session JWT after login. Required for the Services to function.
  • Session token in localStorage (mobile app / same-site web only) — mirrors the authentication cookie so the mobile shell can authenticate API calls.
  • Analytics cookies — Google Analytics 4 uses first-party cookies to aggregate usage statistics. No personally identifying signal (email, name) is sent to Google.

See the separate Cookie Policy for the complete list.

7. Mobile App Permissions

The Android application (and future iOS application) requests only the permissions listed below, and only for the stated purpose:

  • Internet access — required for every online feature. Granted automatically.
  • Post notifications (Android 13+ / iOS) — requested only after you choose to enable push notifications; used solely to deliver alerts you have subscribed to. You can revoke it at any time from your device settings.

The application does not request access to your camera, microphone, precise location, contacts, calendar, SMS, phone log, storage, Bluetooth, biometrics or any other sensitive permission. Profile photos and resumes are uploaded through the platform’s standard file-picker, which does not require app-level storage permission on modern Android or iOS.

8. Push Notifications

If you opt in, we deliver push notifications about job matches, application status, referral responses and platform announcements. We store your FCM/APNs token along with device metadata (platform, device identifier, application version, locale) so we can route messages correctly and de-duplicate across devices. You can unsubscribe at any time from your device notification settings or by tapping "Disable push notifications" inside the app; the token is deleted from our servers immediately on unsubscribe.

9. Third-Party Services and Integrations

The Services rely on the following processors. Each provider handles only the data required for its function, under contract and with equivalent privacy safeguards.

  • MongoDB Atlas (database hosting) — stores all application data. Encrypted at rest and in transit.
  • Cloudflare (CDN + DDoS protection) — routes web traffic; processes IP addresses and standard HTTP headers.
  • Google Analytics 4 (aggregated usage analytics) — receives anonymised event data; does not receive email, name or resume content.
  • Resend (transactional email delivery) — receives the email address and message body of any operational email we send you (OTP, password reset, job alert, referral notification).
  • hCaptcha (bot protection) — verifies human interaction on signup, login and password-reset forms.
  • Firebase Cloud Messaging and, on iOS, Apple Push Notification service — deliver push notifications to your device when the mobile app is installed.
  • Google Play & Apple App Store — distribute the mobile app; their own privacy practices govern the download.
  • Optional hosting/CDN providers used to serve static assets (favicons, brand images).

We do not use any advertising SDK, analytics network beyond Google Analytics 4, or third-party tracker.

10. Sharing of Information

  • With recruiters — a recruiter can view your full application profile only when you explicitly apply to one of their job postings. Public profiles you have chosen to publish are also visible to verified recruiters.
  • With other members — content you post to the feed, communities or interview experiences, and your public profile (if enabled), is visible to other users of the Services.
  • With service providers — as listed in Section 9, only to operate the Services.
  • With authorities — where we are legally required to disclose information in response to lawful requests, or to protect the rights, property or safety of the Services and their users.
  • In a business transfer — if we are involved in a merger, acquisition or sale of assets, personal data may transfer to the successor entity under the same privacy commitments.

We never sell, rent or lease your personal information to third parties for marketing purposes.

11. Data Security

  • Passwords are stored only as bcrypt hashes (cost factor 11). The plaintext is never stored, transmitted after login, or logged.
  • All traffic between your device and our servers is protected by HTTPS/TLS 1.2+.
  • Session tokens (JWTs) are signed with a high-entropy secret and carry a token-version claim so we can invalidate all outstanding tokens instantly on password change, password reset, account deletion or admin action.
  • Rate limiting, per-account lockouts, cross-site request forgery defences and content-security-policy headers protect against automated attacks.
  • File uploads are validated by content type and size; uploaded images and resumes never execute on the server.
  • Administrative actions are recorded in an internal audit log with actor and timestamp.

No online service can guarantee absolute security, but we apply industry-standard controls proportional to the sensitivity of the data.

12. Data Retention

  • Account and profile data is retained while your account is active.
  • When you delete your account, personal identifiers (name, email, phone, avatar, cover image, resume, social links) are removed from the platform. Public content you authored (feed posts, comments, interview experiences, community answers) is anonymised (author displayed as "Deactivated member") so that community discussions remain coherent for other members.
  • Push notification tokens are deleted on unsubscribe or account deletion.
  • Audit logs, transactional email logs and short-lived security records are retained for up to twenty-four (24) months to satisfy security-review and legal obligations, then permanently deleted.

13. International Data Transfers

My ERP Network is a global service. Data may be processed in the country where our servers or those of our sub-processors are located (for example the United States, the European Union, India or Singapore). Where required, we rely on Standard Contractual Clauses (for EU/UK transfers), adequacy decisions, or equivalent safeguards to protect your data during international transfer.

14. Your Privacy Rights

Regardless of where you live, you can exercise the following rights over the personal data you have provided to us:

  • Access — request a copy of the information we hold about you.
  • Correction — edit your profile, resume, skills, education and other fields directly from your account.
  • Deletion / erasure — delete your account at any time from Settings; deletion follows the process described in Section 16.
  • Data portability — request a machine-readable export of the data you have provided.
  • Withdraw consent — disable push notifications, opt out of email alerts, toggle your public profile off, or remove uploaded documents at any time.
  • Restrict / object to processing — where the legal basis is legitimate interests, you can object to a specific processing activity.
  • Complain to a supervisory authority — in the EU/UK, India (Data Protection Board), California (Attorney General), Brazil (ANPD) or your local authority.

To exercise any of these rights write to our contact address listed in Section 18. We respond within thirty (30) days, or sooner where required by local law.

15. Children’s Privacy

The Services are intended for professional users aged 18 and above. We do not knowingly collect personal information from children under 16 (or the equivalent age of digital consent in your jurisdiction). If we learn we have inadvertently collected such information, we delete it promptly. If you believe a minor has provided data to us, please contact the addresses in Section 18.

16. Account Deletion

You can delete your My ERP Network account from Settings → Delete Account. The deletion is confirmed with a second step to prevent accidental loss. On deletion we:

  • Remove your profile, resume, avatar, cover image, saved jobs, saved posts, connections, follows, referral requests, notifications, push tokens, email-verification records and password-reset records.
  • Anonymise content you authored in shared spaces (feed, communities, interview experiences, questions and answers) — the content stays visible but is attributed to "Deactivated member".
  • Retire your public profile slug from search results and the platform sitemap on the next refresh cycle.

The endpoint that performs the deletion is exposed inside the app; recruiters delete their accounts via the same Settings flow.

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When changes are material we will notify registered users by email and by posting a notice inside the Services before the changes take effect. The "Last updated" date at the top of this page always reflects the current version.

18. Contact Information

For any question about this Privacy Policy or your personal data:

19. Compliance Statement

My ERP Network has designed its Services and this Privacy Policy to comply with the following frameworks:

  • Google Play Developer Policy and User Data Policy, including the Data Safety declaration requirements.
  • Apple App Store Privacy requirements, including Privacy Nutrition Labels.
  • General Data Protection Regulation (GDPR) — European Union.
  • UK General Data Protection Regulation (UK GDPR).
  • California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA).
  • Lei Geral de Proteção de Dados (LGPD) — Brazil.
  • Digital Personal Data Protection Act 2023 (DPDP) — India.
  • Generally accepted international information-security and privacy standards.

20. Final Acceptance Statement

By creating an account, installing or using the My ERP Network website or mobile applications, you acknowledge that you have read this Privacy Policy, understand how your personal data is collected and used, and consent to the practices described here. If you do not agree, please discontinue use of the Services and, where applicable, delete your account.

© 2025 My ERP Network. All rights reserved.