Privacy Policy

Last updated: March 2026

Work References is a stateless cryptographic tool for issuing and verifying employment references. All signing operations happen in your browser. We do not have user accounts, a database, or an email system. This policy explains what limited data we process and your rights in relation to it.

1. Who We Are

The Work References Foundation ("we", "us", "our"), a Charitable Incorporated Organisation registered in England, is the data controller for any personal data processed through workreferences.org. You can contact us at support@workreferences.org.

2. What Data We Process

2.1 Verification Requests

When someone verifies a reference, the reference data (candidate name, role, dates, reference text, and digital signature) is sent to our verification API. This data is processed in memory only to check the signature against a DNS public key. Nothing is stored.

2.2 DNS Lookups

Our server queries public DNS TXT records to retrieve the public key associated with a domain. These are publicly available records and no personal data is involved.

2.3 Analytics (Opt-in)

We use PostHog (EU-hosted) for website analytics. PostHog is only activated if you explicitly opt in via our cookie consent banner. Until you consent, no analytics data is collected. PostHog stores data using localStorage rather than cookies.

2.4 Server Logs

Our hosting provider (Vercel) automatically collects standard server logs including IP addresses and request timestamps. These are retained according to Vercel's own data retention policy and are used for security and debugging purposes.

3. What Stays in Your Browser

Work References is designed so that sensitive operations never leave your device:

  • Key generation: Ed25519 key pairs are generated entirely in your browser.
  • Reference signing: references are signed locally using your private key.
  • Private keys: your private signing key is never sent to our servers. You are responsible for storing it securely.
  • Cookie consent preference: stored in your browser's localStorage.

4. Legal Basis for Processing

We rely on the following legal bases under UK GDPR:

  • Legitimate interest: processing verification requests and maintaining server logs for security and service reliability.
  • Consent: analytics data collection via PostHog (opt-in only).

5. Cookies and Local Storage

5.1 Essential Cookies

No essential cookies are currently required. The site functions without setting any cookies.

5.2 Analytics

PostHog (EU-hosted) is used for analytics and is only activated with your explicit consent. When enabled, it collects anonymised usage data such as pages visited, referral source, browser type, and general location (country level). We do not use advertising cookies or any other third-party tracking.

5.3 Managing Your Preferences

You can change your analytics preference at any time by clicking "Cookie Settings" in the website footer. Your preference is stored in your browser's localStorage under the key cookie-consent. Clearing your browser data will reset your preference, and you will see the consent banner again on your next visit.

6. Third-Party Processors

We use the following third-party services:

  • Vercel (vercel.com): application hosting. Processes requests, serves the application, and retains standard server logs.
  • PostHog (posthog.com): website analytics (EU region, opt-in only). Collects anonymised usage data only with your consent.

7. Your Rights

Under UK GDPR, you have the right to:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: ask us to correct any inaccurate data.
  • Erasure: ask us to delete any personal data we hold about you.
  • Data portability: receive your data in a structured, machine-readable format.
  • Object: object to processing based on legitimate interest.
  • Restriction: ask us to restrict processing in certain circumstances.

To exercise any of these rights, email us at support@workreferences.org. We will respond within 30 days.

Because Work References does not have user accounts or a database, the personal data we hold about you is limited to server logs and, if you opted in, anonymised analytics data.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Security

Work References uses a client-side cryptographic architecture. Your Ed25519 private signing key is generated in your browser and never sent to our servers. All reference signing happens locally. Verification relies on public keys published in DNS TXT records that you control.

9. Changes to This Policy

We may update this policy from time to time. The "last updated" date at the top of this page indicates when the policy was last revised.

10. Contact

For any questions about this privacy policy or our data practices, contact us at support@workreferences.org.