Legal · Draft

Privacy Policy

Version
2026-05-21-draft-001
Last updated
2026-05-21

Scope of this Policy

Pending counsel — do not rely

Counsel to define the Policy's coverage: hireroom.tech web app, browser extension, marketing site, transactional emails, mobile PWA. Specify what's NOT covered (linked third-party sites).

Categories of Personal Information we collect

Pending counsel — do not rely

Counsel to map our actual collected fields (profile + resume + applications + AI usage logs) onto CCPA categories A–K. Skeleton list to follow: identifiers (A), customer records (B), commercial info (D), internet activity (F), professional info (I), inferences (K).

Sources of information

Pending counsel — do not rely

Direct collection from user (profile entry, resume upload, application activity) vs derived (AI tailoring outputs cached locally) vs third-party (Clerk OAuth providers if used).

Why we process Personal Information

Pending counsel — do not rely

Service operation, AI tailoring, communications, billing, fraud prevention, product analytics, marketing (only if user opts in). Counsel to draft + map purposes to lawful bases (GDPR Art. 6).

How long we keep it

Pending counsel — do not rely

Default: while account active + 30-day grace post-deletion. Audit logs longer per legal-hold needs. Counsel to set definitive periods per category.

Third-party Processors

The processors below are wired into HireRoom in this release. New processors will appear in this table only when the code that uses them ships.

ProcessorPurposeData sharedDPA
ClerkAuthentication + Stripe billing wrapperEmail, name, plan tier, sign-in eventslink
Stripe (via Clerk)Payment processingName, billing address, card token, transaction IDslink
VercelHosting + Analytics + Speed InsightsRequest logs, performance metrics (no PII by default)link
Turso (libSQL)Database hostingApplication data including resume content, applications, profile
DPA availability to be confirmed by counsel before public launch.
link
Anthropic (via Vercel AI Gateway)LLM inference (default per D-009)Resume text + job posting text sent at request time
Zero retention through Vercel AI Gateway.
link
OpenAI (via Vercel AI Gateway)LLM fallback + Realtime voice for mock interviewsResume text, job posting text, voice audio (only when voice mock used)link
ResendTransactional email (welcome, alerts, OPT countdown, etc.)Email address, transactional contentlink

International transfers

Pending counsel — do not rely

HireRoom hosts in US (Vercel + Turso US regions). Counsel to draft SCC / DPF / Art. 49 derogation analysis if/when EU users are accepted (deferred per L3 design §3.4).

Sensitive Personal Information (GDPR Art. 9 carve-out)

Pending counsel — do not rely

Resumes can contain inferable sensitive data (religious affiliation via employer name, disability via accommodation history, sexual orientation via affinity-group employment). Counsel to draft (a) explicit consent language, (b) HireRoom's commitment to not derive features from inferred sensitive data, (c) user's right to redact.

Your CCPA / CPRA rights (California)

Pending counsel — do not rely

Standard list: right to know, delete, correct, limit use of sensitive PI, opt out of sale/sharing, non-discrimination. Counsel to draft each + reference DSR endpoint.

Your TDPSA rights (Texas)

Pending counsel — do not rely

Per Texas Data Privacy and Security Act (effective 2024-07-01). Counsel to draft access/correction/delete/portability/opt-out-of-sale-or-targeted-advertising rights for Texas residents.

Sale of Personal Information and Sharing of Personal Information (Talent Marketplace)

Pending counsel — do not rely

Per D-007 Talent Marketplace is gated on opt-in (≥ 500-1000 inventory threshold), and per D-008 the opt-in is unbundled. Counsel to draft what specifically is 'sold' or 'shared' (de-identified profile + outcomes vs raw resume), to whom (paying recruiters), and how to opt out (DNSMPI page + /consent toggle + GPC).

Global Privacy Control signals

Pending counsel — do not rely

Counsel to draft: 'HireRoom honors browser-sent Global Privacy Control signals as an opt-out of Sale and Sharing per CCPA §1798.135(b). The signal is detected via the Sec-GPC header and applied for the duration of the browsing session and persistently for authenticated users.'

Children's Privacy

Pending counsel — do not rely

HireRoom is not directed to children under 13 (COPPA) / 16 (GDPR). Counsel to draft minimum-age clause + deletion-on-discovery commitment.

Changes to this Policy

Pending counsel — do not rely

Material vs. non-material changes; notice cadence (email + in-app banner for material). Tie to LEGAL_DOC_VERSION.

Contact + Data Subject Requests

Pending counsel — do not rely

Submit requests via legal@hireroom.tech or the /consent dashboard. Counsel to add response SLA + identity-verification method.

HireRoom is a product of Trenith LLC. Questions about this document? Email legal@hireroom.tech.

This is a structural draft. Final language is pending review by counsel and is not binding until that review is complete and a non-draft version is published.