Privacy Policy
This Privacy Policy describes how Pivots Global LLC collects, uses, and shares information about you when you use the Pivots Hiring platform at pivots-hiring.com. By using the Service, you agree to the collection and use of information as described in this policy.
Who This Policy Applies To
Client Users
Companies that sign in and use the hiring dashboard
Applicants
Individuals who submit job applications through the platform
Visitors
Anyone who browses public pages such as job listings or candidate profiles
Information We Collect
Information You Provide — Clients
- Name and email address (via Google OAuth sign-in)
- Company name (entered during account setup)
- Payment information (processed by Stripe — we do not store raw card data)
- Job listings and hiring pipeline data you create
Information You Provide — Applicants
- Full name, email address, and phone number
- LinkedIn URL, GitHub URL, personal website, portfolio links
- Resume / CV (uploaded as PDF or text)
- Cover letter and code examples
- Video and text interview responses
Collected Automatically
- Pages visited, features used, time spent on pages
- Browser type, operating system, IP address
- Authentication session cookies and CSRF tokens
- AI screening scores, fit decisions, and interview transcripts
From Third Parties
- Google OAuth: name, email, profile picture — no Google password, no access to other Google services
- Stripe: customer ID, subscription status, billing events — no full card number stored
How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Provide and operate the Service | Contract performance |
| Process payments and manage subscriptions | Contract performance |
| Screen and score job candidates using AI | Legitimate interest / Contract |
| Send transactional emails (confirmations, invites, status updates) | Contract performance |
| Send account and billing notifications | Contract performance |
| Analyze and improve the Service | Legitimate interest |
| Prevent fraud and abuse | Legitimate interest |
| Comply with legal obligations | Legal obligation |
Email Communications
To Clients
- Account setup and welcome
- Subscription confirmation, renewal reminders, and receipts
- New candidate application notifications
- Interview request confirmations
- Platform updates and feature announcements (unsubscribable)
To Applicants
- Application received confirmation
- AI screening result notification
- Interview invitation and scheduling
- Status update notifications
To unsubscribe from non-transactional emails, use the unsubscribe link in any marketing email or contact [email protected].
Cookies
| Category | Name | Purpose | Required |
|---|---|---|---|
| Authentication | authjs.session-token | Keeps you signed in | Yes |
| CSRF Protection | authjs.csrf-token | Prevents cross-site request forgery | Yes |
| Callback URL | authjs.callback-url | Restores redirect destination after OAuth | Yes |
| Analytics | Plausible / Vercel | Anonymous usage statistics | No (consent) |
| Payment | Stripe.js | Fraud prevention during checkout | Yes (payment pages) |
| Preferences | cookie_consent | Stores your cookie consent choice | Yes |
You can control non-essential cookies through your browser settings or our cookie consent banner. Disabling authentication cookies will prevent you from signing in.
Payment Processing
We store only: Stripe customer ID, subscription ID, plan name, and billing status.
Stripe's privacy policy: stripe.com/privacy
Analytics
We may use:
- Plausible Analytics — privacy-friendly, no cross-site tracking, no personal data sold
- Vercel Analytics — infrastructure-level, anonymized
- Custom event logging for feature usage (stored in our own database)
Data Sharing
We share your information only in the following circumstances:
Data Retention
| Data Type | Retention Period |
|---|---|
| Client account data | Until account deletion + 90 days |
| Candidate application data | 2 years from submission, or until deletion request |
| Payment records | 7 years (legal/tax requirement) |
| AI analysis results | 2 years or until candidate deletion request |
| Session/auth tokens | 30 days (rolling) |
| Server logs | 90 days |
You may request deletion of your data at any time (see Section 11).
Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has submitted data, contact us and we will delete it promptly.
Your Rights
Access
Request a copy of the personal data we hold about you
Correction
Request correction of inaccurate data
Deletion
Request deletion of your data ("right to be forgotten")
Portability
Request your data in a machine-readable format
Objection
Object to processing based on legitimate interest
Withdraw consent
Withdraw consent for analytics or marketing at any time
California residents (CCPA): You have the right to know what personal information is collected, the right to delete it, and the right to opt out of sale (we do not sell personal data).
EU/UK residents (GDPR): You have the right to lodge a complaint with your local data protection authority.
Data Security
Despite these measures, no system is 100% secure. We will notify affected users of any data breach within 72 hours of discovery.
International Transfers
Our servers are located in the United States. If you are located outside the US, your data will be transferred to and processed in the US. We use Standard Contractual Clauses (SCCs) for transfers from the EU/UK where required.
Changes to This Policy
Contact Us
Pivots Global LLC
Privacy: [email protected]
Legal: [email protected]
Third-Party Services
| Service | Purpose | Privacy Policy |
|---|---|---|
| Google OAuth | Authentication | policies.google.com/privacy |
| Stripe | Payment processing | stripe.com/privacy |
| Anthropic Claude API | AI candidate screening & interviews | anthropic.com/privacy |
| Vercel | Hosting & infrastructure | vercel.com/legal/privacy-policy |
