1. Introduction
Welcome to HireHere ("we," "our," or "us"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at hirehere.me and use our services (collectively, the "Service").
This Privacy Policy has been drafted in accordance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws. It applies to all users of our Service, regardless of location, and covers both personal data processed automatically and data you provide to us directly.
By accessing or using HireHere, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service. We encourage you to review this policy periodically, as it may be updated from time to time to reflect changes in our practices or applicable laws.
2. Information We Collect
2.1 Information You Provide to Us
We collect information that you voluntarily provide when you create an account, use our services, or communicate with us. The type of information depends on your role:
For Candidates:
- Account information such as your name, email address, and password
- Resume and CV files, including work history, education, skills, and professional qualifications
- Profile information including job preferences, desired salary range, location preferences, and availability
- Communications you send to us or to employers through our platform, including interview chat messages
For Companies:
- Company account information including company name, contact person name, email address, and password
- Job posting details including job title, description, requirements, compensation, and location
- Billing and payment information processed through our payment provider, Stripe (we do not store full credit card numbers on our servers)
- Company profile data such as company description, website, logo, and industry
- Communications with candidates through the platform and support requests
2.2 Information Collected Automatically
When you visit or use our Service, we automatically collect certain information, including:
- Device and browser information such as your IP address, browser type and version, operating system, device type, and screen resolution
- Usage data including pages visited, time spent on pages, links clicked, search queries, job categories browsed, and referral URLs
- Cookies and similar tracking technologies as described in Section 5 of this policy
- Log data including access times, server logs, and error reports
2.3 Information from Third Parties
We may receive information about you from third-party sources, including Applicant Tracking Systems (ATS) such as Greenhouse, Lever, Workable, and Breezy when companies use these platforms to syndicate job listings to HireHere. This information is limited to job posting data and does not include candidate personal data from those platforms.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, maintain, and improve the Service, including displaying job listings, matching candidates with relevant opportunities, and facilitating communication between candidates and employers
- To create and manage your account, authenticate your identity, and provide customer support
- To process payments and transactions for job postings, upgrades, and featured placements
- To personalize your experience by showing relevant job recommendations based on your profile, skills, and browsing behavior
- To send you service-related notifications, including account verification, job alerts, application status updates, and important policy changes
- To analyze usage patterns and trends to improve the functionality, performance, and user experience of our platform
- To detect, prevent, and address fraud, security issues, and technical problems
- To comply with legal obligations, enforce our Terms of Service, and protect the rights, property, and safety of HireHere, our users, and the public
3.1 Resume Processing with AI Services
To provide personalized job recommendations and candidate matching, we use the Anthropic Claude API to process and analyze resumes uploaded by candidates. This AI-powered processing extracts relevant skills, job titles, specializations, and tools from your resume to improve the quality of job matches. We want you to be fully informed about how this works:
- Resume data is sent to Anthropic's API solely for the purpose of extracting structured skill and experience data; it is not used to train AI models
- Anthropic processes the data under a data processing agreement that prohibits them from retaining or using your data beyond what is necessary to provide the service
- Extracted skills and qualifications are stored in your candidate profile to power personalized job recommendations
- You can request deletion of your parsed resume data at any time by contacting us or deleting your account
- You can use HireHere without uploading a resume; however, job recommendations will be less personalized without this data
3.2 Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:
- Consent: Where you have given us explicit consent to process your data for specific purposes, such as uploading your resume for AI-powered skill extraction or subscribing to job alerts. You may withdraw your consent at any time.
- Performance of a Contract: Processing is necessary for the performance of a contract with you, including creating and managing your account, processing job postings, and facilitating payment transactions.
- Legitimate Interests: Processing is necessary for our legitimate interests, such as improving the Service, preventing fraud, ensuring platform security, and conducting analytics, provided these interests are not overridden by your data protection rights.
- Legal Obligation: Processing is necessary to comply with legal obligations to which we are subject, such as tax reporting, responding to lawful government requests, or complying with court orders.
4. How We Share Your Information
We do not sell your personal data. We may share your information in the following circumstances:
- With Employers: When you apply for a job or express interest in a position, your profile information, resume, and application materials are shared with the relevant employer. For paid job listings with candidate matching enabled, employers may receive AI-generated recommendations that include your profile summary and match score.
- Service Providers: We share data with trusted third-party service providers who assist us in operating the platform. These include Stripe for payment processing, Google Analytics for usage analytics, Google AdSense for advertising, and cloud hosting providers for infrastructure. These providers are contractually obligated to use your data only for the purposes of providing services to us and in accordance with this Privacy Policy.
- Legal Requirements: We may disclose your information if required to do so by law or in response to valid legal requests by public authorities, including to meet national security or law enforcement requirements, comply with a subpoena or court order, or protect against legal liability.
- Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or other similar event, your personal data may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal data.
- With Your Consent: We may share your information with third parties when you have given us explicit consent to do so, or when you direct us to share specific information.
5. Cookie Policy
We use cookies and similar tracking technologies to collect and store information about your interactions with our Service. Cookies are small text files placed on your device by your web browser.
5.1 Types of Cookies
- Essential Cookies: These cookies are strictly necessary for the operation of our website. They enable core functionality such as authentication, session management, and security features. You cannot opt out of essential cookies as the Service cannot function without them.
- Analytics Cookies: We use Google Analytics to understand how visitors interact with our website. These cookies collect information about pages visited, time spent on the site, and how users navigate between pages. This data is aggregated and anonymized.
- Marketing Cookies: We use Google AdSense to display advertisements on our platform. These cookies may be used to deliver ads relevant to your interests and to measure the effectiveness of advertising campaigns. Ad personalization is managed through Google's consent mechanisms.
- Preference Cookies: These cookies remember your choices and preferences, such as language settings, display preferences, and recently viewed job categories, to provide a more personalized experience.
5.2 Managing Cookies
You can manage your cookie preferences through our consent management platform, which is presented when you first visit our site. You can update your preferences at any time by accessing the cookie settings in the footer of our website. Additionally, most web browsers allow you to control cookies through their settings. Please note that disabling certain cookies may affect the functionality of the Service. For more information about opting out of interest-based advertising, visit https://optout.aboutads.info/.
6. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal data under the GDPR, CCPA, and other applicable data protection laws:
- Right of Access and Portability: You have the right to request a copy of the personal data we hold about you in a structured, commonly used, and machine-readable format. You may also request that we transfer your data directly to another service provider where technically feasible.
- Right to Correction: You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. You can update most of your information directly through your account settings.
- Right to Deletion: You have the right to request that we delete your personal data, subject to certain legal exceptions. When you delete your account, we will remove your personal data from our active systems, though some data may be retained in backups for a limited period or as required by law.
- Right to Object: You have the right to object to the processing of your personal data for direct marketing purposes or where processing is based on our legitimate interests. Upon receiving an objection, we will cease processing unless we can demonstrate compelling legitimate grounds.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of your data or have objected to processing pending verification.
- Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority in your country of residence if you believe that our processing of your personal data violates applicable data protection laws.
To exercise any of these rights, please contact us at privacy@hirehere.me. We will respond to your request within 30 days, as required by applicable law.
7. Data Security
We take the security of your personal data seriously and implement appropriate technical and organizational measures to protect it against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS/SSL protocols and encryption of sensitive data at rest
- Secure password hashing using BCrypt for all user accounts
- Rate limiting and abuse prevention through Rack::Attack to protect against brute-force attacks and denial-of-service attempts
- Regular security assessments and code reviews, including automated security scanning
- Access controls and authentication requirements for all administrative functions and sensitive data
While we strive to protect your personal data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, and you acknowledge that you provide your information at your own risk. If you become aware of any security breach, please notify us immediately at security@hirehere.me.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Specific retention periods are as follows:
- Account Data: Your account information, profile data, and resume are retained for as long as your account is active. Upon account deletion, personal data is removed from active systems within 30 days, though encrypted backups may persist for up to 90 days.
- Job Postings: Published job listings are retained on the platform for as long as they are active. Expired or removed job postings may be retained in archived form for up to 12 months for analytical purposes.
- Payment Records: Transaction records and billing information are retained for 7 years as required by tax and financial regulations.
- Analytics Data: Aggregated and anonymized analytics data may be retained indefinitely as it cannot be used to identify individual users. Non-anonymized analytics data is retained for up to 26 months.
- Server Logs: System logs, access logs, and error reports are retained for 90 days for security monitoring and debugging purposes, after which they are automatically deleted.
9. International Data Transfers
HireHere operates globally, and your personal data may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your jurisdiction.
When we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we rely on appropriate safeguards, including:
- Standard Contractual Clauses (SCCs): We use European Commission-approved Standard Contractual Clauses with our service providers and data processors to ensure that your data receives an equivalent level of protection when transferred outside the EEA.
- Adequacy Decisions: Where applicable, we transfer data to countries that have received an adequacy decision from the European Commission, confirming that they provide an adequate level of data protection.
You may request a copy of the safeguards we have in place by contacting us at privacy@hirehere.me.
10. Children's Privacy
HireHere is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children under 16 years of age. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information as promptly as possible.
If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us at privacy@hirehere.me and we will take appropriate action to remove the data.
11. Third-Party Services
Our Service integrates with and relies on several third-party services. Each of these services has its own privacy policy governing how they collect and use data:
- Stripe: We use Stripe for secure payment processing. When you make a payment, your payment information is collected and processed directly by Stripe. We do not store your full credit card details on our servers. For more information, see Stripe's Privacy Policy.
- Anthropic: We use Anthropic's Claude API for resume parsing and candidate matching. Resume data is processed under a data processing agreement. For more information, see Anthropic's Privacy Policy.
- Google Analytics: We use Google Analytics to analyze website traffic and usage patterns. Google Analytics uses cookies to collect anonymized data about your interactions with our Service. For more information, see Google's Privacy Policy.
- Google AdSense: We use Google AdSense to display advertisements on our platform. AdSense may use cookies and web beacons to serve ads based on your prior visits to our website or other websites. For more information, see Google's Advertising Policies.
We encourage you to review the privacy policies of these third-party services to understand how they handle your data.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will notify you through one or more of the following methods:
- Posting the updated Privacy Policy on this page with a revised "Last updated" date at the top
- Sending an email notification to the address associated with your account for material changes that significantly affect how we process your data
- Displaying a prominent notice on our website or within the Service for a reasonable period following the change
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data. Your continued use of the Service after the effective date of any updated Privacy Policy constitutes your acceptance of the changes.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, you can reach us through the following channels:
- Privacy Inquiries: privacy@hirehere.me
- Data Protection Officer: dpo@hirehere.me
- General Support: support@hirehere.me
We are committed to addressing your concerns and will respond to all privacy-related inquiries within 30 days of receipt. If your request is particularly complex or you have made multiple requests, we may extend this period by an additional 60 days, in which case we will notify you of the extension and the reasons for it.
By using HireHere, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein. If you have any questions, please do not hesitate to contact us.