Privacy Policy
Last updated: June 2025
1. Who We Are
CommitHire (“we”, “us”, “our”) operates the CommitHire platform at commithire.netlify.app. We are the data controller for personal information collected through the Platform. Questions can be directed to support@vigya.app.
2. What Data We Collect
We collect the following categories of personal data:
- Account data — name, email address, password (hashed), and account type (seeker or employer).
- Profile data — headline, bio, location, notice period, desired salary, avatar, and links you choose to share.
- Application data — CVs, cover notes, committed salary, notice period, and any other information submitted when applying for a role.
- Evidence Vault data — files and documents you upload to support your CV claims (certificates, portfolios, work samples, references).
- Employer / company data — company name, logo, website, description, and job listings posted.
- Usage data — pages visited, searches performed, and actions taken on the Platform, collected via server logs.
3. How We Use Your Data
- To create and manage your account.
- To match job seekers with relevant listings and share application data with employers.
- To send transactional emails (application confirmations, stage updates, role-filled notices, expiry alerts).
- To calculate and display your Evidence Score to employers who view your profile.
- To enforce the CommitHire Standard (salary disclosure, stage feedback, no-ghosting rules).
- To improve the Platform through aggregated, anonymised analytics.
- To comply with legal obligations.
We do not sell your personal data to third parties, and we do not use your data for advertising or profiling outside the Platform.
4. Legal Basis for Processing (UK/EU Users)
- Contract — processing necessary to provide the service you signed up for.
- Legitimate interests — improving the Platform, preventing fraud, and ensuring platform integrity.
- Legal obligation — where required by applicable law.
- Consent — for any optional communications you opt into.
5. Who We Share Data With
- Employers — when you apply for a role, your application data (CV, committed salary, notice period, Evidence Score) is shared with that employer only.
- Supabase — our database and authentication provider, hosted on AWS infrastructure in the EU.
- Resend — our transactional email provider, used solely to deliver notifications triggered by your activity.
- Vercel / Netlify — our hosting provider; server logs may include IP addresses and request metadata.
All third-party processors are bound by data processing agreements and may only process your data on our instructions.
6. Evidence Vault Files
Files uploaded to your Evidence Vault are stored in private, access-controlled storage. They are only accessible to you and to employers you explicitly share your profile with during an active application. Files are not indexed by search engines and are not publicly accessible.
7. Data Retention
- Account data is retained for as long as your account is active.
- Application data is retained for 12 months after a listing closes or your application concludes.
- Evidence Vault files are retained until you delete them or close your account.
- After account deletion, anonymised data may be retained for analytical purposes.
8. Your Rights
Under UK GDPR and applicable data protection law, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — request deletion of your data (“right to be forgotten”).
- Portability — receive your data in a machine-readable format.
- Restriction — ask us to limit how we process your data.
- Objection — object to processing based on legitimate interests.
To exercise any of these rights, email us at support@vigya.app. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
9. Cookies
CommitHire uses only essential cookies required for authentication and session management (via Supabase Auth). We do not use tracking, advertising, or analytics cookies. No cookie consent banner is required for essential cookies under UK GDPR.
10. Security
We implement industry-standard security measures including encrypted data in transit (TLS), hashed passwords, row-level security on the database, and private storage buckets for sensitive files. No system is completely secure; if you suspect a breach, contact us immediately at support@vigya.app.
11. Children
CommitHire is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email. The “Last updated” date at the top of this page reflects the most recent revision.
13. Contact
For any privacy-related questions or requests, contact us at support@vigya.app.