Privacy policy
Effective 26 July 2026
This notice explains how personal data is handled when you visit, register, pay for or use The Talent Road.
Who controls your data
The Talent Road, operated by Stephen T Molloy, is the data controller for this service. The controller's business address is The Talent Road, 35 Mountjoy Square South, Dublin 1, D01 K235, Ireland. You can contact the controller at thetalentroadltd@gmail.com or through the contact page.
Information we collect
We collect account and contact details, marketing choices, payment and transaction references, bookings, questionnaire answers, documents, applications, messages and coaching records you choose to provide. Career Health Check answers are scored in your browser and are not saved. Stripe handles complete card details; The Talent Road does not store your full card number.
Why we use it
We use data to create and secure accounts, take payments, provide digital resources and coaching, manage appointments, respond to enquiries, keep financial records, prevent abuse and meet legal obligations. These activities rely on performing our contract, taking steps you request before a contract, legitimate interests in operating a secure service, legal obligations and, for optional marketing and Google Analytics, your consent.
Service providers and transfers
We use Supabase for authentication and database services, Stripe for payments, Vercel for hosting and public-page analytics, Resend for transactional email, Google Analytics for optional consent-based measurement, and Google Search Console for aggregate search-performance reporting. Search Console does not add a tracking script to this website. These providers process information under their own security and data-processing terms. Where information is processed outside the EEA, we rely on an adequacy decision or approved safeguards such as standard contractual clauses.
Privacy-respecting measurement
Vercel Web Analytics measures visits to public information pages without analytics cookies. Google Analytics is also available on those public pages, but its tag remains completely blocked unless you accept analytics. When accepted, Google may process a pseudonymous visitor identifier, public page path, general device/browser information, approximate location and referral information. Advertising signals are disabled, query strings are removed and private routes are excluded. You can withdraw permission using the cookie-settings control.
The Talent Road separately records a small number of completed outcomes, such as a submitted enquiry, completed Career Health Check, registration or booking payment. These conversion records contain only the outcome type, time and optional euro value. They do not contain names, email addresses, account IDs, IP addresses, browser identifiers, referrers, query strings or form answers, and they are not used to profile individuals or make automated decisions.
Retention and deletion
Working career data is kept while your account is active and only for as long as needed to provide the service. An administrator can delete an account, which immediately revokes access, removes user-created working data and anonymises retained business records. Contact enquiries are deleted 12 months after the last activity. Stripe event payloads are not retained; limited webhook identifiers and unpaid failed or abandoned registration attempts are deleted after 30 days. Administrative audit logs and aggregate conversion records are deleted after 24 months. Completed financial records are normally retained for six years to meet Irish tax and accounting obligations, or longer only while a relevant dispute or legal requirement remains open. Where restricted backups apply, deleted data may remain until the configured backup cycle expires. If a backup is restored, deletion and retention controls are reapplied before normal use.
Your rights
You may request access, correction, restriction, portability, objection, withdrawal of marketing or analytics consent, or deletion where applicable. Consent withdrawal does not affect earlier lawful processing. Requests are handled without undue delay and normally within one month. You may also complain to the Irish Data Protection Commission at dataprotection.ie.
Security and updates
Access is protected through authenticated sessions, role-based database rules, restricted administrator tools, multi-factor authentication and encrypted connections. No system is risk-free, so please use a unique password and contact us if you suspect misuse. Material policy changes will be published here and, where appropriate, notified to account holders.
