Hirevate
Legal documents

Hirevate Privacy Policy

This policy explains what personal information Hirevate handles, why it is needed, which providers receive it, and the privacy choices available to users.

Effective

1. Scope and who is responsible

This Privacy Policy applies to https://www.hirevate.com, Hirevate accounts, and the job-search, resume, cover-letter, application-tracking, subscription, and support features provided by Hirevate. It does not govern an employer, applicant-tracking system, job source, Stripe-hosted page, or other third-party service reached through Hirevate.

Hirevate is responsible for Hirevate's handling of personal information. Privacy questions and requests may be sent to support@hirevate.com. Additional operator information appears in the Hirevate Legal Notice.

2. Information Hirevate collects

  • Account and profile information: name, username, email address, authentication identifiers, account dates, country preference, and account settings. Authentication is provided through Supabase; Hirevate does not store a readable copy of the user's password.
  • Subscription information: selected plan, Stripe customer and subscription references, payment status, billing interval, renewal or cancellation status, and relevant transaction dates. Full card numbers and card security codes are collected by Stripe and are not stored on Hirevate servers.
  • Job-search and application information: saved jobs, application stages, priorities, follow-up dates, contacts, salary notes, user notes, and related activity entered into the application tracker.
  • Resume and writing information: resume drafts, career facts, skills, job descriptions, job links, cover-letter inputs, selected templates, and AI-generated output when a user chooses to use those tools.
  • Service activity and security information: feature requests, trial and access-control records, timestamps, error and security logs, device or browser information made available to hosting providers, and communications with support.
  • Optional analytics information: consent choice, a pseudonymous visitor identifier, pages visited, visit counts, approximate country derived from infrastructure headers, and standard Google Analytics information when optional analytics is accepted. Hirevate's own visitor record does not store an IP address.

3. Where information comes from

Hirevate receives information directly from users, from their use of the service, from Stripe payment and subscription events, from authentication and infrastructure providers, and from consented analytics. Approximate country may be inferred from request headers supplied by hosting infrastructure.

Public job listings come from company career pages, public applicant-tracking-system boards, job APIs, and other public hiring sources. Public job information is not treated as a user's personal account information merely because it appears in search results.

4. How Hirevate uses information

  • Create and secure accounts, authenticate users, remember settings, and provide customer support.
  • Provide job discovery, saved jobs, application tracking, resume analysis, resume generation, cover-letter drafting, document export, and related account features.
  • Administer free access, subscriptions, payment status, renewals, cancellations, refunds, fraud controls, and service limits.
  • Fetch a public job page only when needed to display a listing or when a user asks Hirevate to analyze that page.
  • Operate, debug, protect, measure, and improve the service; detect misuse; enforce the Terms; and comply with legal obligations.
  • Send transactional account, security, billing, and service messages. Marketing messages are sent only where permitted and can be declined using the method provided in the message or by contacting support.

5. Legal bases for EEA and UK users

Where data-protection law requires a legal basis, Hirevate relies on performance of a contract to provide requested account and paid features; legitimate interests in securing, supporting, and improving the service; consent for optional analytics or marketing; and legal obligations relating to payments, tax, disputes, and lawful requests. Consent may be withdrawn at any time without affecting earlier lawful processing.

6. Payments and Stripe

Stripe processes Checkout, card details, payment authentication, invoices, recurring subscription charges, refunds, and payment-risk signals. Hirevate sends Stripe the account email, internal user reference, selected plan, and information needed to create and manage the subscription. Stripe returns customer, subscription, Checkout, invoice, payment, and status references needed to grant or remove paid access.

No payment method is requested to start the three-day trial. Stripe receives payment information only if a user actively chooses a paid membership and proceeds to Stripe Checkout. Hirevate records trial dates and access-control information needed to provide the trial, prevent repeat trials, apply service limits, and schedule a trial-ending reminder.

Stripe handles payment information under its own privacy terms and applicable role as a payment provider. Users should not send full card information to Hirevate by email or support message.

7. Resume, cover-letter, and AI processing

Resume-builder drafts and resume-match text are stored in the user's browser by default. They remain there until the user resets the tool, clears browser storage, or removes the data through browser controls.

When a user requests AI job analysis, resume generation, or cover-letter writing, the relevant job link or pasted job description and the career facts or writing inputs needed for that request are sent through Hirevate servers to the configured OpenAI service. Requests are configured with model-response storage disabled. Provider processing and limited security retention may still apply under the provider's terms.

Hirevate does not sell resume content, use it to make employment decisions, or represent that an AI output is accurate. Users should remove unnecessary sensitive information and review every generated statement before use.

8. Cookies, local storage, and analytics

Essential cookies and similar technologies support sign-in, session refresh, security, and consent preferences. Local browser storage may hold resume drafts, resume-match text, interface preferences, and time-limited offer display state.

Optional analytics runs only after the user accepts optional measurement. It may include Hirevate's pseudonymous daily visitor measurement and Google Analytics. Users can reject optional analytics without losing essential account functionality and can change the choice by clearing the saved consent preference. Additional details appear in the Cookie and Local Storage Policy.

9. When information is shared

  • Supabase for authentication, database, account, and application-tracker infrastructure.
  • Vercel and related infrastructure providers for website hosting, request delivery, security, and operational logs.
  • Stripe for Checkout, recurring billing, payment processing, fraud prevention, refunds, and subscription management.
  • OpenAI when a user requests AI job analysis, resume generation, or career writing.
  • Resend or another configured email provider for transactional service messages, including a scheduled membership reminder shortly before a trial ends.
  • Google Analytics only after optional analytics consent.
  • Professional advisers, authorities, courts, or counterparties when reasonably necessary to comply with law, protect users or the service, investigate misuse, establish legal claims, or complete a legitimate business reorganization subject to appropriate safeguards.

10. Selling, advertising, and automated decisions

Hirevate does not sell personal information and does not share it for cross-context behavioral advertising. Hirevate does not make employment, credit, housing, insurance, or other legally significant decisions about users. Resume-match scores and AI suggestions are advisory editing tools and are not employer decisions or predictions of a hiring result.

11. International processing

Hirevate and its providers may process information in countries other than the user's country. Where required, Hirevate relies on contractual protections, adequacy decisions, or another lawful transfer mechanism. Provider locations and safeguards may change as infrastructure changes.

12. Retention

  • Account, profile, saved-job, application-tracker, and access-control records are generally kept while the account remains open and are deleted or de-identified after account deletion, subject to backups and legal exceptions.
  • Subscription and transaction references are kept for billing, reconciliation, fraud prevention, tax, accounting, dispute, and legal-record purposes for the period required or reasonably necessary.
  • Support, security, and operational records are retained only as long as needed to resolve the request, protect the service, document consent, enforce rights, or meet legal obligations.
  • Browser-stored resume and preference information remains under the user's browser controls. Aggregated or de-identified statistics that no longer identify a person may be retained.

13. Security

Hirevate uses HTTPS, access controls, scoped credentials, row-level database protections, payment-provider Checkout, and other technical and organizational safeguards appropriate to the service. No online service can guarantee absolute security. Users should use a unique password, protect their account, and promptly report suspected unauthorized access.

14. Privacy rights and choices

Depending on location, a user may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information; withdraw consent; opt out of marketing; or appeal a denied request. Users may update available profile fields or permanently delete an account through account controls, or email the legal contact.

Hirevate may verify identity and authority before fulfilling a request. Legally permitted exceptions may apply, including records needed for security, fraud prevention, billing, disputes, or law. Hirevate will not discriminate against a user for exercising a privacy right. Users may also complain to their local data-protection authority.

15. Children

Hirevate is intended for people aged 18 or older and is not directed to children. If Hirevate learns that it collected personal information from a child contrary to applicable law, it will take reasonable steps to delete it.

16. Changes and contact

Hirevate may update this policy to reflect legal, provider, security, or product changes. The effective date will be updated, and material changes will receive additional notice where required. Questions, complaints, and privacy requests should be sent to support@hirevate.com. Do not include passwords, full card details, government identifiers, or other unnecessary sensitive information.

Contact

Send questions or formal requests to support@hirevate.com.

Hirevate Privacy Policy | Hirevate