Privacy Policy & Data Protection
Protocol Version 3.2 · Compliant with GDPR, CCPA, Google OAuth 2.0 & LinkedIn OpenID Connect (OIDC) Specifications.
Introduction & Data Controller
Welcome to Mentorfinders (the “Platform”, “we”, “us”, or “our”). We are committed to upholding the utmost standards of user privacy, transparency, and data sovereignty. As the Data Controller, Mentorfinders manages the collection, storage, and processing of your personal information in strict accordance with international data protection laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
By accessing or utilizing Mentorfinders, you acknowledge the data practices detailed in this document. If you do not agree with any provision of this Privacy Policy, please discontinue platform use immediately.
Personal Data We Collect
To provide verified mentorship matchmaking, secure payments, and interactive video rooms, we collect the following categories of information:
Full name, email address, salted password hashes (Bcrypt), country of residence, and date of birth.
Professional summary, years of experience, primary skills, educational history, and verified licensing credentials.
Session bookings, preferred timezones, meeting timestamps, and marketplace job proposals.
Transaction reference IDs, wallet balance ledgers, and payment receipts (card numbers are processed strictly via PCI-DSS gateways).
LinkedIn & Google OAuth Data Protocol
Mentorfinders supports single-click authorization through Third-Party Identity Providers, specifically Google OAuth 2.0 and LinkedIn OpenID Connect (OIDC).
OAuth Scope Transparency
- Requested Scopes: We only request standard
openid,profile, andemailscopes. - Retrieved Data: We collect only your primary verified email address, full name, and avatar picture to automatically verify your identity.
- No Offline Access: We do not store offline refresh tokens or access private messages, connections, or posts.
- Zero Advertising Resale: Under no circumstances do we sell, rent, or distribute OAuth-obtained profile data to third-party ad networks or brokers.
Purpose & Legal Basis of Data Processing
All personal data processed by Mentorfinders is done under legitimate interest, contractual necessity, or explicit user consent:
- Credential Auditing: Reviewing and approving mentor certification documents to ensure authentic mentorship.
- Automated Timezone Conversion: Converting UTC meeting timestamps into your local geographic regional time to prevent missed appointments.
- Escrow Accounting: Protecting mentee payments in escrow until 48 hours following successful meeting completion.
- Automated Notifications: Sending calendar reminders, session invitations, and transactional receipts from our dedicated desk.
Data Retention & Right to Erasure (Data Deletion)
We retain user profile data for as long as your account remains active. Financial transaction records are archived solely for mandatory legal and taxation auditing.
How to Request Account & Data Deletion:
You may exercise your right to erasure at any time. Simply send an email to our compliance desk from your registered email account:
All personal identifiers, OAuth linkages, and records will be permanently wiped within 30 calendar days.
Your Rights Under GDPR & CCPA
Regardless of your physical residency, Mentorfinders extends comprehensive global privacy rights to all registered users:
You can request a machine-readable export of all profile records and transaction ledgers stored on our systems.
You can update your personal name, country, date of birth, and bio directly via your Profile Settings.
You can revoke OAuth permissions at any time from your Google or LinkedIn security dashboard.
Data Security & Cryptographic Safeguards
Mentorfinders implements defense-in-depth infrastructure safeguards, including TLS 1.3 / SSL 256-bit encryption in transit, HTTPOnly & SameSite session cookies, automated Cross-Site Request Forgery (CSRF) tokens on every POST request, XSS input sanitation, and continuous database audit logging.