Privacy Policy
Your privacy is critically important to us. This policy explains how HiringFleet Inc. collects, uses, and protects your personal and career data when you use our platform.
1. Information We Collect
We collect the following types of information to provide our services:
- Account Information: Name, email address, university name, and graduation date.
- Resume Data: Resume content you upload for AI analysis. This data is encrypted at rest and in transit.
- Visa Timeline Data: OPT/CPT dates and visa status information you voluntarily provide for timeline tracking.
- Usage Data: Pages visited, features used, and interaction patterns to improve our service.
- Payment Data: Processed securely via Stripe. We never store your full credit card number.
- Authentication & Sign-in Activity: For each successful or failed sign-in we record the IP address, user-agent, sign-in method (Google, GitHub, password), and timestamp. This is used solely for security review (showing you recent activity in Settings, alerting on unfamiliar sign-ins, and powering rate-limit / lockout protection).
- Email Activity: We log when transactional email is dispatched (verification, password reset, sign-in alerts) along with the recipient and delivery state, so you can see exactly which messages we sent you.
2. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, maintain, and improve the HiringFleet platform.
- To generate AI-powered resume analysis and employer sponsor recommendations.
- To send critical visa deadline alerts and proactive CPT/OPT notifications.
- To process payments and manage your subscription.
- To analyze platform usage through anonymized, aggregated data.
3. Data We Never Sell or Share
We believe your data belongs to you. We maintain strict rules regarding data sharing:
- We never sell your personal data to third-party recruiters, advertisers, or data brokers.
- We never use your resume data to train public AI models.
- We never share your visa status with employers, universities, or government agencies.
4. Data Security
We implement industry-standard security protocols to protect your information, including:
- AES-256 encryption for data at rest.
- TLS 1.3 encryption for data in transit.
- SOC 2-aligned access controls and audit logging.
- Regular third-party security assessments.
4a. Data Retention
- Account data is kept while your account is active.
- Sign-in logs and email logs are kept for the most recent 180 days for security review and customer support, then purged automatically.
- Verification tokens expire within 1–24 hours and are deleted immediately on use.
- When you delete your account from Settings, all rows tied to your user (profile, OAuth links, sessions, sign-in logs, email logs, 2FA secrets, recovery codes) are removed within minutes. We may keep de-identified aggregate metrics (e.g. total signups by month) but those cannot be linked back to you.
4b. Job Listings and Data Sources
Job listings on HiringFleet come from legal, sanctioned sources: employers who post directly to us, employer applicant-tracking systems (such as Greenhouse, Lever, Ashby, and Workday), licensed job aggregators (such as Adzuna), open job APIs (such as Remotive, RemoteOK, and Arbeitnow), and public government data (USAJOBS and U.S. Department of Labor disclosures). For listings sourced from aggregators we show a short preview and link back to the original posting, where you apply directly with the employer.
5. Cookies
We use essential cookies to maintain your session securely. We also use analytics cookies (only with your explicit consent) to understand platform usage. You can manage your preferences at any time via your browser settings.
6. Your Rights
Depending on your location (GDPR, CCPA), you hold the following rights over your data:
- Access: Request a copy of all personal data we hold about you.
- Deletion: Request permanent deletion of your account and all associated data.
- Portability: Export your data in a standardized, machine-readable format.
- Opt-out: Opt out of marketing communications instantly at any time.
You can exercise these rights yourself from Settings: Download my data for a JSON export, or Delete account to permanently remove everything tied to your user. For anything that needs human help, email privacy@hiringfleet.com.
7. Google User Data & Gmail Access
If you connect your Google account to send outreach emails, HiringFleet requests only the gmail.send scope. This lets us send emails on your behalf when you click Send. It does not allow us to read, browse, modify, or delete any of your existing emails.
- We only access Google data to provide the outreach-email feature you explicitly use.
- We never sell or transfer your Google data, and never use it for advertising.
- We do not use your Google data to train generalized or foundation AI models.
- Your Google OAuth tokens are encrypted at rest. You can disconnect Google at any time from Settings, which revokes our access.
- Outreach emails you send include a small open-tracking image and a one-click unsubscribe link, so you can see engagement and recipients can opt out. Anyone who unsubscribes is recorded as opted-out and is never emailed through HiringFleet again.
HiringFleet's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Contact Us
For privacy-related questions, data access requests, or security concerns, our dedicated Privacy Team is here to help. You can contact us via email at privacy@hiringfleet.com.
HiringFleet Inc.
Privacy & Security Team