1. Overview
This Privacy Policy describes how [ENTITY NAME] doing business as SourceHire (“SourceHire”, “we”) collects, uses, shares, and protects Personal Data when you use the SourceHire websites and Services (defined in our Terms of Service).
2. Who We Are
[ENTITY NAME], a [STATE OF FORMATION] limited liability company with a place of business at [BUSINESS ADDRESS], is the data controller for Personal Data processed through the candidate-facing Services. Where we provide the Services to a Customer (e.g., a posting employer or talent-acquisition team), we act as a data processor for that Customer in respect of the application data submitted to that Customer's jobs (see Section 4).
3. Scope
This Policy applies to the websites, web applications, and APIs of SourceHire, including the marketing site, the public job board at /jobs, the apply flow, the candidate self-service surface at /apply/me, and the operator console at /admin. It does not apply to any third- party site or service we link to, which has its own privacy policy.
4. Controller / Processor Roles
For Personal Data of website visitors, prospective candidates, and unauthenticated users browsing the public surfaces, Source Unlimited acts as the data controller.
For Personal Data submitted by a Candidate as part of an application to a Customer's job, SourceHire acts as a processor on behalf of that Customer, who is the data controller for the processing of that application. For Personal Data submitted by a Candidate to the network for discoverability rather than a specific job, SourceHire acts as the data controller.
Customers and SourceHire are bound by the Data Processing Addendum which governs the controller-processor relationship.
5. What We Collect
5.1 What you submit at apply time
- Identity: name, email, optional phone, optional preferred name, optional pronouns.
- Documents: resume (required), cover letter (optional). Uploaded files are stored with a SHA-256 content hash for integrity verification.
- Declared logistics: work authorization, salary expectations, relocation preference, work-arrangement preference.
- Declared catalogs: products you regularly use, products you are learning.
- Voice of candidate: first-person free-text answers to the prompts shown on the apply form.
- Consent grants: the boolean state of each of the six consent options (Section 9), captured per Section 9.2.
- EEO self-identification (optional, separated): if you complete the post-apply EEO survey, your responses to demographic questions defined by applicable equal-employment law. Stored in an isolated table; never joins the talent-search or operator-export query path.
5.2 What we derive from your documents
Where you grant ai_extraction consent: a structured profile derived from your resume by AI extraction, including current role and employer, total years of experience, location, seniority, highest degree, and a list of extracted skills. Each field carries a source attribution (declared vs extracted) and a confidence value where available.
5.3 Operational metadata
- IP address and user agent at the time of any consent grant or revocation, recorded in the Consent Ledger for legal demonstrability.
- IP address, user agent, and timestamp of operator actions (review, unmask, export), recorded in the Audit Log.
- Authentication tokens (magic-link tokens for
/apply/me; session cookies for operator authentication). - Minimal request logs for security, abuse prevention, and debugging.
5.4 What we do not collect
- We do not collect biometric data. We do not run video-interview biometric analysis.
- We do not collect financial or credit data. We do not run consumer-reporting-agency background checks.
- We do not request gender identity, race, ethnicity, religion, sexual orientation, disability, or veteran status as part of the apply form. The optional EEO survey is the only place such attributes are collected, and they remain isolated from every other surface.
- We do not embed cross-context behavioral advertising trackers, third-party AdTech pixels, lookalike-modeling SDKs, or identity-resolution beacons.
6. How We Collect It
Almost all Personal Data we hold about you was submitted by you directly through the apply form or through your authenticated /apply/me session. Operational metadata (IP, user agent, timestamps) is observed automatically when you interact with the Services. We do not purchase or otherwise acquire candidate Personal Data from third-party data brokers.
7. Why We Process It
- To provide the candidate apply flow and the resulting record.
- To process your documents into a structured profile for hiring review (subject to your
ai_extractionconsent). - To make you discoverable in the network-wide talent search (subject to your
discoverabilityconsent). - To allow recruiters of jobs you applied to to evaluate your application.
- To operate the consent ledger, the audit log, and the demonstr- ability artifacts that allow us to prove lawful processing.
- To respond to your data-rights requests (access, correction, erasure, portability, restriction, objection).
- To send platform-related communications you have opted into (subject to your
marketingconsent). - To enforce our Terms of Service and Acceptable Use Policy, and to comply with our legal obligations.
8. Legal Bases (GDPR)
Where GDPR applies, we rely on the following legal bases:
- Consent (Article 6(1)(a)) — for
ai_extraction,discoverability,sensitive_accommodations,marketing, andprofessional_enrichment. Withdrawable at any time. - Contract (Article 6(1)(b)) — for the
core_processingconsent, which is required to perform the apply transaction you initiated. - Legal obligation (Article 6(1)(c)) — for retention and disclosure obligations imposed on us by applicable law.
- Legitimate interests (Article 6(1)(f)) — for security, abuse prevention, audit logging, and the operational integrity of the Services. Where we rely on this basis, we have balanced our interests against your fundamental rights and freedoms; you may object as described in Section 16.
For Special Category Data (Article 9) — limited to optional accommodations and EEO survey responses — we rely on your explicit consent (Article 9(2)(a)).
9. Consent Options
9.1 The six consents
You are presented with six discrete consent options at apply time. Each is independent. The minimum required to apply is core_processing; without it we cannot process your application. The other five are genuinely optional and are individually revocable.
core_processing— store your documents, generate a structured profile, retain for hiring review.ai_extraction— process documents with AI (Anthropic Claude). When declined, only declared fields are surfaced.discoverability— appear in the network-wide talent search.sensitive_accommodations— capture and surface accommodation needs.marketing— receive SourceHire platform emails about new opportunities. Does not authorize Recruiter outreach outside applied jobs, and does not authorize sharing your data with third parties.professional_enrichment— enrich your profile with supplementary professional context inside the platform. Does not authorize sharing enriched data outside the platform.
9.2 The Consent Ledger
Each grant or revocation creates a row in your Consent Ledger. Each row contains: timestamp (ISO 8601 UTC), consent option, the granted boolean, your IP address, your user agent, the policy version then in effect, the verbatim text shown to you at grant time, and a SHA-256 hash chained to the previous row's hash. This makes the ledger tamper-evident: any mutation, deletion, or reordering is detectable by chain verification.
9.3 Revoking consent
You may revoke any consent at any time via your authenticated /apply/me session or by emailing privacy@sourceunlimited.co. Revocation is effective on receipt for new processing. Revoking core_processing initiates erasure of your record.
11. What We Will Not Do
- We will not sell your Personal Data within the meaning of CCPA Cal. Civ. Code § 1798.140(ad) or equivalent terms in any other jurisdiction.
- We will not share your Personal Data for cross- context behavioral advertising within the meaning of CCPA Cal. Civ. Code § 1798.140(ah).
- We will not include your Personal Data in any bulk data product, data feed, licensed dataset, or marketplace listing for the consumption of third parties.
- We will not provide your Personal Data to any third party for the training, fine-tuning, evaluation, benchmarking, or improvement of any AI or machine-learning model.
- We will not transmit your Personal Data to authenticated external partner systems on a schedule, via webhook, or via a partner-facing API.
- We will not include protected-class attributes (gender identity, race, ethnicity, veteran status, age, disability) in any Operator export, regardless of any consent flag.
- We will not use the existence of any one consent as standing authorization for any operation that consent does not specifically describe.
12. Subprocessors
We use a small set of subprocessors to provide the Services. Each subprocessor is bound by data protection terms at least as protective as this Policy. We update this list when we add or remove a subprocessor; material changes are notified per Section 21.
- Vercel Inc. — application hosting and edge delivery. United States.
- Neon Inc. — managed Postgres database. United States (with EU/UK regions available on request).
- Vercel Blob (storage) — file storage for uploaded resumes and cover letters. United States.
- Anthropic, PBC — AI extraction (Anthropic Claude). Subject to your
ai_extractionconsent. Anthropic processes your data only to provide the inference service for us; under our agreement with Anthropic and Anthropic's commercial terms, your data is not used to train Anthropic's models. - Inngest Inc. — background job orchestration. United States.
- Resend, Inc. — transactional email delivery (magic links, notifications). United States.
- GitHub, Inc. — source-code hosting. Does not process Candidate Personal Data; listed for completeness as part of our development infrastructure.
13. International Transfers
SourceHire is incorporated in the United States and our primary processing infrastructure is located in the United States. If you are located in the European Economic Area, the United Kingdom, or Switzerland, your Personal Data is transferred to the United States subject to appropriate safeguards, specifically the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914) as supplemented by the UK International Data Transfer Addendum and the Swiss FADP adaptations, together with a Transfer Impact Assessment.
14. Retention
- Active candidate records and uploaded files: for as long as your record is active in the Services, plus a reasonable wind-down period not exceeding 180 days after revocation of
core_processingconsent or successful erasure request, whichever is earlier. - Consent Ledger rows: retained as required for legal demonstrability under GDPR Article 7(1) and equivalent statutes, with tombstones replacing erased payload after the candidate record is erased.
- Audit Log entries: retained for a minimum of 24 months for security and compliance review.
- Backups: rolling daily backups retained for 30 days. Backup erasure is performed by aging-out rather than direct redaction of historical snapshots; we do not restore from backups in a way that resurrects an erased record.
15. Security
We implement administrative, technical, and physical safeguards designed to protect Personal Data against unauthorized access, loss, alteration, and destruction. Specific measures include encryption in transit (TLS 1.2+); encryption at rest; scoped role- based access control with the strict role hierarchy viewer < recruiter < reviewer < admin; PII masking by default in reviewer surfaces with audit-logged unmask; per-row consent re-checks at every export; hash-chained consent ledgers; append-only audit logging; secret rotation; least- privilege subprocessor configurations; and regular review of the security posture of every component.
In the event of a Personal Data breach affecting your data, we will notify you and, where required, the relevant supervisory authority, within the timeframes specified by applicable law (within 72 hours under GDPR Article 33; without unreasonable delay under U.S. state breach-notification statutes).
16. Your Rights
Subject to applicable law and any statutory exceptions, you have the right to:
- Access the Personal Data we hold about you and receive a copy.
- Correct inaccurate Personal Data.
- Erase your Personal Data (right to be forgotten).
- Restrict certain processing.
- Object to processing based on legitimate interests or for direct marketing.
- Port your data to another service in a structured, commonly used, machine-readable format.
- Withdraw consent at any time, with the same ease as it was given.
- Lodge a complaint with a supervisory authority in your jurisdiction.
- Not be subject to solely automated decisions with legal or similarly significant effects (GDPR Article 22). We do not make automated employment decisions on behalf of Customers; hiring decisions are made by human Operators after review.
The most direct path to access is the self-service surface at /apply/me using a magic link sent to your email on file. The DSAR JSON download includes the full record, the complete Consent Ledger with chain hashes, and the audit-log entries that involve you as a subject. For all other rights, email privacy@sourceunlimited.co. We respond within statutory timeframes.
17. Children
The Services are not directed to children under 16. We do not knowingly collect Personal Data from children under 16 without the verifiable consent of a parent or legal guardian, where such consent is required by applicable law. If we learn we have collected Personal Data from a child under 16 in violation of this Policy, we will delete it.
18. California Residents
If you are a California resident, you have specific rights under the CCPA as amended by the CPRA. We do not “sell” or “share” (as those terms are defined in CCPA Cal. Civ. Code § 1798.140) your Personal Information. We honor Global Privacy Control signals as a request to opt out of any future sale or share, even though we don't engage in those activities.
Categories of Personal Information we collect (per CCPA Cal. Civ. Code § 1798.140(v)): identifiers; characteristics of protected classifications (only via the optional EEO survey); commercial information (limited to the application transaction); internet and other electronic network activity (limited operational metadata); professional and employment-related information; education information; and inferences (only structured-profile extraction with your ai_extraction consent).
You have the right to know, the right to delete, the right to correct, the right to limit use of sensitive Personal Information, the right to non-retaliation for exercising any right, and the right to designate an authorized agent. Submit requests to privacy@sourceunlimited.co.
19. European Residents
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the rights described in Section 16 under GDPR, UK GDPR, and the Swiss Federal Act on Data Protection respectively. The legal bases on which we rely are described in Section 8.
Our representative for purposes of GDPR Article 27, where one is required, is [EU REPRESENTATIVE TO BE NAMED]. You may also lodge a complaint with the supervisory authority in your member state of residence, place of work, or place of the alleged infringement.
20. Other Jurisdictions
We honor data protection rights granted under the laws of other jurisdictions where applicable, including but not limited to: Canada (PIPEDA, Quebec Law 25); Brazil (LGPD); Australia (Privacy Act 1988); New Zealand (Privacy Act 2020); Japan (APPI); Korea (PIPA); India (DPDPA 2023); Singapore (PDPA); UAE (DIFC, ADGM, and federal PDPL); and South Africa (POPIA). Where the applicable law provides rights more protective than those described above, the more protective regime applies.
21. Changes
We may update this Policy from time to time. The version and effective date appear at the top of this page. Where the change is material, we will notify Customers by email and Candidates by a banner on the public site at least thirty (30) days before the change takes effect. Previous versions are preserved and available on request.
22. Contact
[ENTITY NAME] d/b/a SourceHire
[BUSINESS ADDRESS]
Privacy: privacy@sourceunlimited.co
Data Protection Officer (where applicable): dpo@sourceunlimited.co