Privacy Policy

Last updated: July 28, 2026

Consultant Finder is a marketplace that connects ERP contract consultants with companies looking to hire them. This page explains, in plain language, exactly what we collect, why we collect it, who can see it, and what you can ask us to do with it. It describes how the service actually works today — not how we might like it to work later. If we change how we handle your information, we will update this page and the date above.

Who we are

Consultant Finder is operated by an individual based in Alberta, Canada. For privacy purposes, that operator is the data controller. You can reach us at any time at info@flowkm.com.

Our users come from several countries, so this policy is written to cover Canadian privacy law (PIPEDA, and Alberta's Personal Information Protection Act) as well as the rights people have under the GDPR in the UK and EU and under California privacy law.

What we collect, and why

We only collect what the product needs to function. There is no hidden profiling, and nothing is collected for advertising.

Account information

  • Signing up with an email and password: your name, email address, and password. Your password is stored only as a bcrypt hash — we never store, see, or have any way to recover the password itself.
  • Signing up with Google: we receive your email address, your name, and the URL of your Google profile picture. That is all we request and all we store. We do not get access to your Gmail, Drive, contacts, or calendar, and nothing in this service ever sends email from your account.
  • Account type: after signing up you choose whether you are a consultant or a firm owner. Firm owners also give us a company name.

Consultant profile

  • Everything you type into your profile: headline, bio, city or location, country, work-type preference (remote, hybrid, onsite), years of experience, the ERP systems you work with, whether you are a functional or technical consultant, your hourly rate range, your availability, and your skills with years of experience for each.
  • Whether you have turned on “open to work”, which is the only thing that puts your profile in our consultant directory. It is off by default, and only you can turn it on.

Your resume

  • If you upload a resume (PDF, DOCX, or TXT, up to 10 MB), we store the file encrypted, along with its filename.
  • We read the text of the resume to pre-fill your profile fields — name, headline, location, bio, years of experience, and skills — so you do not have to type them twice. We store that extracted summary alongside your profile. Nothing is saved to your profile until you press Save, and you can edit or clear anything we filled in.
  • How the parsing is done:processing may happen on our own systems, or through AI service providers acting on our behalf and under contract to us. In either case it is used only to fill in your profile — never to train anyone else's models, and never shared for any other purpose.
  • Uploading a resume never turns on “open to work”, and never makes your resume file visible to anyone else — see who can see your information.

Using the service

  • Applications: when you apply to a role posted directly on the platform, we record the application, its status (received, viewed, shortlisted, rejected), and timestamps, so both sides can track it.
  • Hiring posts and job postings created by firm accounts, including the criteria, budget range, and description they enter.
  • Roster invitations: if a firm invites you to the group of consultants it manages, we store the email address it invited and your accept or decline decision. The firm sees nothing about you unless and until you accept.
  • Security information: if you turn on two-factor authentication, we store a hashed copy of emailed one-time codes, an encrypted copy of your authenticator secret, and hashed single-use backup codes.

Technical information

  • Our hosting and database providers generate ordinary server logs as part of delivering the site — things like IP address, browser user-agent, requested page, and timestamp. We use these for security and debugging, not to build a profile of you.

Who can see your information

This is the part most people care about, so we are being specific rather than general.

  • Nothing about you is visible to the public internet. Every page of the service except the landing page, the About page, login, signup, and these legal pages requires you to be signed in. Consultant profiles are not reachable by logged-out visitors and are not indexed by search engines.
  • Your profile is private until you opt in.A consultant profile appears in the Find Consultants directory only if you switch on “open to work”. We never scrape, buy, or infer consultant profiles — every profile in the directory belongs to someone who created it and chose to be listed.
  • Once you opt in, your profile is visible to signed-in users. In practice that means companies looking to hire, which is the point of the marketplace — but the directory is gated on having an account, not on being a firm owner, so other consultants with accounts can see it too. What is shown is: your name, your email address, headline, bio, location and country, work type, years of experience, ERP systems, consultant type, hourly rate range, and skills. If you would rather not be listed, leave “open to work” off — and you can switch it off again at any time, which removes you from the directory.
  • Your resume file is never shared. There is no way for another user — firm or consultant — to download a resume you uploaded. A firm whose roster invitation you have accepted can see the filename and the profile fields you saved, and nothing more.
  • Applying shares your profile with that company. When you apply to a role posted directly on the platform, the company that posted it sees your application and your profile on its dashboard. That is the purpose of applying.
  • Roster access is consent-gated. A firm can add you to the consultants it manages only by inviting your email address, and only if you accept. Until you accept, the firm sees nothing but the address it typed. You can decline, and a membership can be ended by either side afterwards.
  • The site operator can see your data. As the person running the service, the operator has administrative access to the database and uses it for support, troubleshooting, and manually introducing consultants to companies.
  • We do not sell your personal information, and we do not share it with advertisers, data brokers, or recruiters who are not users of the platform.

Companies that process data for us

We use a small number of service providers to run the platform. Each one only receives what it needs to do its job.

  • Supabase — hosts our PostgreSQL database, which holds all of the account and profile data described above. Our database is located in the United States (US East, Ohio region).
  • Vercel — hosts and serves the website itself, and carries the traffic between your browser and our application.
  • Google— only if you choose “Continue with Google”. Google handles the sign-in and tells us your email, name, and profile picture URL. We send Google nothing about your activity on the platform. The information we receive from Google sign-in is used solely to authenticate you and create and maintain your account. It is never sold, never shared with anyone else, and never used for advertising, and our use of it follows the Google API Services User Data Policy, including its Limited Use requirements.
  • Resend — delivers our email. It receives the recipient address and the contents of the message being sent.
  • Job data sources (Adzuna, and potentially Jooble, Careerjet, and JSearch) — these are read-only. We query them with fixed ERP-related search terms to collect public job listings. No user data of any kind is sent to them. They never receive your identity, your profile, your searches, or the fact that you exist.

Because our database and hosting are in the United States, your information is stored and processed there regardless of where you live. If you are in the UK, EU, or elsewhere outside the US, using the service involves that transfer.

Job listings from other sources

Many of the roles you see on Consultant Finder were not posted here. They are aggregated from third-party job APIs, and those listings — including the job text, company names, and links — belong to their respective owners and sources. We display them for reference and link back to the source. We do not control them, cannot guarantee they are current or accurate, and applying to one usually means leaving our site. Roles posted directly by companies with accounts here are marked as such, and are applied to on the platform.

If you own a listing and want it removed from our index, email info@flowkm.com and we will remove it.

Email we send you

  • Service email. We send email that is part of the service working correctly, and it cannot be turned off while you have an account. Today that is account confirmation and security messages, including two-factor codes. As the product develops we may also send service notices relating to your matches, applications, and messages.
  • Product email, if we send any. We may occasionally send product updates and platform news. If and when we do, every such email will include an unsubscribe link, and unsubscribing from it will not affect the service email above.
  • We do not sell or rent your email address, and we do not send third-party ads.

Cookies and tracking

We use one kind of cookie: the session cookie that keeps you signed in after you log in. It is strictly necessary — without it, the site cannot tell that you are logged in.

We do not run any analytics, advertising, or tracking software. There is no Google Analytics, no tag manager, no advertising pixel, no session recorder, and no third-party script of any kind on this site. Our fonts are served from our own servers rather than a font CDN, so simply loading a page does not tell anyone else that you visited. This is a deliberate choice, and if it ever changes, this page will say so first.

How long we keep things

  • We keep your account and profile data for as long as your account exists, because that is what makes the profile work.
  • Deletion is handled by request, by a person. There is no automated delete button, and no automatic clean-up runs in the background. When you email us from the address on your account, we verify it is you and then delete your account and the data attached to it — your profile, skills, applications, and any resume file you uploaded — within a reasonable period, and no later than 30 days.
  • Because the process is manual rather than automatic, an uploaded resume file stays in our storage until we act on a deletion request. It remains encrypted, and no other user can reach it, but we are not going to describe it as automatically erased when it is not.
  • Records of roster invitations may retain the email address they were sent to, since that address is how the invitation was addressed.
  • Our database provider maintains backups, so deleted data may persist in those backups for a period after we remove it from the live service.
  • Job listings collected from third-party sources are hidden once they go stale rather than deleted, so we can recognise the same listing if it reappears. These contain no personal information about our users.

Your rights over your data

Whatever country you are in, you can ask us to do the following, and we will:

  • See what we have. Ask for a copy of the personal information we hold about you.
  • Correct it. Most of it you can fix yourself in Settings at any time. If something is wrong that you cannot edit, tell us and we will correct it.
  • Delete it. Ask us to delete your account and your data. There is currently no self-service delete button, so email info@flowkm.com from the address on your account. Once we have confirmed the request came from you, we will delete it within a reasonable period and no later than 30 days.
  • Stop being visible.Turn off “open to work” in your profile and you immediately stop appearing in the consultant directory, without deleting anything.
  • Withdraw consent.Decline or leave a firm's roster, unsubscribe from product email, or close your account.

If you are in the UK or EU, the GDPR also gives you the right to object to or restrict certain processing, the right to data portability, and the right to complain to your local data protection authority. If you are in California, you have the right to know what we collect, to request deletion, and not to be treated differently for exercising those rights — and note that we do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of there. In Canada, PIPEDA gives you access and correction rights, and you may complain to the Office of the Privacy Commissioner of Canada.

Send any of these requests to info@flowkm.com. We will respond within 30 days. We may need to confirm that you control the account's email address before acting on a request.

How we protect your information

No service can promise perfect security, and we are not going to. Here is specifically what we do:

  • Passwords are stored as bcrypt hashes, never in a readable form.
  • Uploaded resume files are encrypted at rest with AES-256-GCM.
  • Authenticator (TOTP) secrets are encrypted at rest; emailed one-time codes and backup codes are stored hashed.
  • Two-factor authentication is available on every account — by email code or an authenticator app — and we recommend turning it on in Settings.
  • All traffic to the site is served over HTTPS.
  • Every request that reads or writes data checks that the data belongs to the account making the request.

If we become aware of a breach affecting your personal information, we will notify you and the appropriate regulator as required by law.

Children

Consultant Finder is a professional service for working ERP consultants and the companies that hire them. It is not directed at children, and we do not knowingly collect information from anyone under 16. If you believe a child has created an account, email info@flowkm.com and we will delete it.

Changes to this policy

If we change how we handle personal information, we will update this page and change the “last updated” date at the top. Where a change materially affects your rights or how your data is used, we will take reasonable steps to tell account holders before it takes effect — for example by notice on the site or by email. Checking this page is the reliable way to see the current version.

Contact

For any privacy question, request, or complaint, email info@flowkm.com. A person reads it.

The same address handles reports about content on the platform — a listing or profile that looks fake or abusive, a copyright concern, or a job listing you own and want removed from our index. Tell us what you found and where, and we will look into it.

Questions about this document? Email info@flowkm.com. See also our Terms of Service.