Privacy Policy
Effective date: [DATE] — DRAFT, pending legal review
This policy explains how [ENTITY] ("Hire1", "we") collects, uses, and shares personal information in connection with hire1.io, the Hire1 platform at new.hire1.io, our Chrome extension, and related services (the "Service").
We handle personal information about three groups: visitors to our websites, users (recruiters and their teams), and candidates (professionals whose profiles appear in the Service).
1. Information we collect
From visitors: contact details you submit (e.g., booking a demo), and basic technical data (IP address, browser type, pages viewed) collected via server logs and any analytics described in section 6.
From users: account details (name, work email, password hash, workspace), billing details when purchasing (processed by our payment processor — we do not store full card numbers), content you create in the Service (projects, notes, sequences, uploaded lists), connected-account data described in section 3, and usage/diagnostic data (feature activity, error logs).
About candidates: professional-profile information — such as name, current and past roles, employer, skills, education, location, and business contact details — obtained from licensed third-party data providers who compile publicly available professional sources; plus information users add (notes, tags, correspondence history) and candidates' replies to outreach.
2. How we use it
- Provide and operate the Service: search, matching and scoring, pipeline management, and sending outreach on users' behalf from their own connected mailboxes.
- Generate AI-assisted outputs (search plans, match scores and insights, drafted messages). Model inputs are limited to what the feature needs.
- Enforce sending-safety controls (daily limits, ramp-ups, spacing, opt-out suppression).
- Billing, account administration, support, and service communications.
- Security, abuse prevention, and debugging.
- Improve the Service, using aggregated or de-identified data where practicable.
We do not sell personal information, use candidate data for advertising, or permit its use for employment-eligibility, credit, insurance, or other FCRA-style consumer-report purposes.
3. Google user data (Gmail / Google Workspace)
When a user connects a Google account, we access only the scopes granted at consent, and use them only to: send the user's outreach messages, detect replies and delivery failures (including bounce/auto-reply detection), and display the resulting message history inside the user's workspace.
Hire1's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Gmail data for advertising; we do not sell it; we do not use it to train generalized AI/ML models; humans do not read it except with the user's explicit permission, for security/abuse purposes, to comply with law, or where necessary for internal operations after aggregation/de-identification.
Users can revoke access at any time in the Service or at myaccount.google.com/permissions; we then stop accessing the account and delete cached tokens.
4. Chrome extension
The extension activates only when the user invokes it. It reads the page the user chooses to capture in order to save that candidate/profile into the user's workspace, and transmits it to the Service over HTTPS. It does not track browsing history, collect data from pages the user doesn't capture, or inject advertising.
5. How we share information
With service providers (subprocessors) that host and support the Service, bound by contract to process data only on our instructions — currently in the categories of: cloud hosting and databases, content delivery and security, transactional email, AI model providers for the features in section 2, candidate-data providers, payment processing, and error monitoring.
With the user's workspace: content and candidate interactions are visible to teammates in the same workspace. Outreach is sent from the user's own mailbox and is visible to its recipients like any email.
Legal and corporate: when required by law or legal process, to protect rights and safety, or in a merger/acquisition/asset sale (with notice where required).
6. Cookies and analytics
The marketing site uses only essential cookies. The platform uses session cookies required for login. We do not use third-party advertising cookies.
7. Retention
Account data: for the life of the account and up to [90] days after closure (backup cycles may extend this briefly). Workspace/candidate data: while the subscription is active; exportable for 30 days after termination, then deleted on the same schedule. Gmail OAuth tokens: until disconnection or account closure. Logs and diagnostics: up to [12] months. Billing records: as required by tax law.
8. Security
Encryption in transit (TLS) for all Service traffic; credentials stored hashed; access to production systems restricted to authorized personnel; error monitoring configured to avoid capturing message bodies. No method is 100% secure; we will notify affected parties of breaches as required by law.
9. Your rights
Depending on your location (e.g., GDPR in the EEA/UK, PIPEDA in Canada, CCPA/CPRA in California), you may have rights to access, correct, delete, port, or object to processing of your personal information, and to complain to a supervisory authority.
Candidates: you may request access to or deletion of your profile from the Service, or opt out of further outreach, by emailing wecare@hire1.io. Opt-outs are honored globally across the platform — every workspace's campaigns suppress you permanently. Where we process candidate data, we rely on legitimate interests in facilitating professional recruitment, balanced against your rights; our providers compile only professional (not private-life) information from public sources.
Users and visitors: email wecare@hire1.io and we will respond within the legally required period. We do not discriminate for exercising rights.
10. International transfers
We are based in Canada and use service providers in Canada, the United States, and the EEA. Where data moves across borders from a jurisdiction that restricts transfers, we rely on appropriate safeguards such as standard contractual clauses.
11. Children
The Service is for business use by adults; we do not knowingly collect data from anyone under 18. If you believe a minor's data has been collected, contact us for deletion.
12. Changes and contact
We will post updates here with a new effective date and notify account owners of material changes.
Contact / privacy requests: wecare@hire1.io · [ENTITY], [ADDRESS]