Privacy Policy
Last updated: April 3, 2026
1. What data we collect
We collect the following types of data:
- Account data: Name, email address, and authentication credentials when you create an account. If you sign in with Google, we receive your name, email address, and profile photo from your Google account.
- Job posting data: Job titles, descriptions, company information, and salary details submitted by employers.
- Payment data: Collected and processed by Stripe. We do not store credit card numbers on our servers.
- Usage data: Page views, apply clicks, and search queries — anonymised and used to improve the service.
- Cookies: See the Cookies section below.
2. How we use your data
- To provide and operate the Recruiter Roles service
- To send job alerts you have opted into
- To send transactional emails (job management, receipts, account notifications)
- To monitor errors and performance to improve site reliability
We do not sell your data to third parties.
3. Data storage and security
Your data is stored in Supabase (PostgreSQL) on AWS infrastructure in the United States. Passwords are hashed using industry-standard algorithms. Payment information is managed entirely by Stripe and never touches our servers.
4. Cookies and local storage
Essential cookies (no consent required)
- Authentication cookies (
sb-*-auth-token): Managed by Supabase to keep you signed in and maintain your session. - Bot protection cookies: Set by Cloudflare Turnstile to verify you are human when submitting forms.
- Cookie consent (
rr_cookie_consent): Remembers whether you have accepted our cookie notice. Expires after 1 year.
Analytics cookies (set after consent)
- Google Analytics (
_ga,_ga_*): Used to understand how visitors use the site — pages viewed, time on site, and traffic sources. These cookies are set by Google and are governed by Google's Privacy Policy. You can opt out via Google's opt-out browser add-on.
Error monitoring
- Sentry: We use Sentry for error tracking and performance monitoring. Sentry may set cookies or use local storage to track sessions for debugging purposes. No personal data is intentionally sent — only technical error details and anonymised performance traces.
Local storage (browser only)
We also use your browser's local storage (not cookies) for the following purposes. This data never leaves your device:
- Form draft auto-save (
rr_draft,rr_draft_company): Preserves your job posting form progress so you don't lose work if you navigate away. Cleared on submission. - Sign-in redirect (
rr_auth_return): Remembers where to return you after signing in with Google. - Apply click counter (
rr_apply_count): Tracks how many apply buttons you have clicked in a session.
We do not use third-party advertising cookies.
5. Your rights
You have the right to:
- Access the personal data we hold about you
- Delete your account and associated data via your account settings
- Opt out of email alerts at any time
- Request data export or deletion by emailing hello@recruiterroles.com
6. Data retention
- Active accounts: Data is retained while your account exists.
- Deleted accounts: Personal data is anonymised within 30 days of deletion. Job listings are retained until their natural expiry. Payment records are retained as required by tax and legal obligations.
7. Third-party services
We use the following third-party services, each with their own privacy policies:
- Stripe — Payment processing (Privacy Policy)
- Supabase — Database hosting (Privacy Policy)
- Vercel — Hosting and deployment (Privacy Policy)
- Cloudflare — DNS, bot protection (Turnstile), file storage (R2) (Privacy Policy)
- Mailtrap — Email delivery (Privacy Policy)
- Google — OAuth sign-in, Analytics, Indexing API (Privacy Policy). When you sign in with Google, we access only your name, email address, and profile photo. This data is used solely for account creation and authentication. We do not transfer, sell, or use your Google data for advertising, and our use complies with Google API Services User Data Policy, including the Limited Use requirements.
- Sentry — Error tracking and performance monitoring (Privacy Policy)
- OpenAI — Job sector classification (job content only, no personal data) (Privacy Policy)
8. International data transfers
Your data is processed and stored in the United States. If you are located outside the United States, your data will be transferred to and processed in the US. By using the Service, you consent to this transfer.
9. Additional rights for EU/EEA residents (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following additional rights under the General Data Protection Regulation (GDPR):
- Legal bases for processing: We process your data based on (a) your consent (analytics cookies, marketing emails), (b) contractual necessity (account creation, job posting, payment processing), and (c) legitimate interest (essential cookies, error monitoring, security).
- Right to withdraw consent: You may withdraw consent for analytics cookies at any time using the "Cookie Settings" link in our site footer. You may also unsubscribe from marketing emails via the link in each email.
- Right to data portability: You may request a machine-readable copy of your personal data by contacting us.
- Right to object: You may object to processing based on legitimate interest by contacting us.
- Right to lodge a complaint: You have the right to lodge a complaint with your local data protection authority.
10. Additional rights for California residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with the following additional rights:
- Right to know: You may request the categories and specific pieces of personal information we have collected about you, the categories of sources, and the business purposes for collection.
- Right to delete: You may request deletion of your personal information, subject to certain exceptions (such as legal obligations or completing a transaction).
- Right to correct: You may request correction of inaccurate personal information.
- Right to opt out of "sharing": Google Analytics may constitute "sharing" of personal information under the CCPA. You can opt out by declining analytics cookies via our cookie banner, using the "Cookie Settings" link in the footer, or installing Google's opt-out browser add-on.
- No sale of personal information: We do not sell your personal information to third parties.
- Non-discrimination: We will not discriminate against you for exercising any of your privacy rights.
To exercise any of these rights, contact us at hello@recruiterroles.com. We will respond within 45 days.
11. Contact for privacy enquiries
For questions about this privacy policy or to exercise your data rights, contact us at hello@recruiterroles.com or via the contact form.