Privacy Policy
Last updated: 23 July 2026
1. The short version
- We collect what you give us to run a hiring marketplace — nothing is resold to data brokers and nothing is used for advertising.
- The business model, plainly: employers pay us subscription fees, and paying employers can reveal a searchable candidate’s contact details by spending a credit. If you are a candidate, section 4 tells you exactly when your details become visible and how to prevent it.
- We run no third-party analytics, advertising pixels, or tracking cookies today — only the cookies the site needs to function.
- You can export everything we hold about you as JSON, and delete your account — including your resume file — yourself, at any time.
2. Who is responsible, and how to reach us
HealthcareHire operates healthcarehire.co and is the data fiduciary / controller for personal data processed on the service. For anything in this policy — questions, requests, complaints, grievances under India’s DPDP Act 2023, PIPEDA challenges, or US state privacy requests — contact support@healthcarehire.co. We aim to respond within 7 days and resolve grievances within the timelines applicable law requires.
3. What we collect
- Account data — name, email, password (stored as a hash by our authentication provider), account role, country/region, and the timestamps of your consent to the Terms and this policy.
- Candidate profile data (candidates only, provided by you) — phone number, city and relocation preferences, profession and specialization, experience, qualifications, optional registration/license numbers, current and expected salary, skills, headline, an optional photo, and your resume file.
- Employer workspace data — organization name, type, size, city, description, team member emails, job listings, and (for recruiters) optional end-client names.
- Activity the service needs — applications and their status, saved jobs, which employer workspace unlocked which profile (billing and audit), search-rate counters (kept days, for abuse prevention), a log of transactional emails (kept up to 12 months), payment state (plan, period, credits — card details never touch us; see section 6), and reviews you choose to submit.
- Cookies — essential only: your sign-in session and an
hh_regioncookie remembering your country selection. No analytics or advertising cookies exist on the site today; if that ever changes, this policy changes first.
4. Candidates: exactly who can see what, and when
Below 70% profile completeness: you are invisible to employer search. Employers cannot find you at all.
At 70% or above: your profile automatically enters employer search as a masked card — profession, specialization, experience band, city, skills, expected salary. Your name, phone, email, photo, and resume are not included.
Your contact details are revealed in exactly two cases:(1) you apply to a job — that employer receives your profile, contact details, and resume; (2) an employer on a paid plan spends a credit to unlock your profile — that workspace’s members can then see your name, phone, email, and resume for as long as their subscription stays active. Employers pay us for this access; that is how a service free for candidates is funded, and by making your profile searchable you consent to it.
Your controls: keep your profile under 70% if you do not want to appear in search; remove your resume or edit any field at any time; email support@healthcarehire.co to have your profile hidden from search without deleting it; or delete your account, which removes it entirely.
Employers are contractually limited to using revealed details for recruiting only — no resale, no sharing outside their workspace, no marketing lists — and must delete your data on request (Terms, section 5). Some US state laws may classify credit-based disclosure of contact details as a “sale” or “sharing” of personal information; the controls above, including full deletion, are your opt-out, and you can also invoke your state-law rights via support@healthcarehire.co.
5. What we use data for
- Operating the marketplace: matching, search, applications, and the unlock model described above (performance of our contract with you; consent for search visibility);
- Billing employer workspaces and preventing credit fraud (contract; legitimate interests);
- Transactional email only — verification, password reset, application updates, invites, billing notices. No marketing email without a separate, explicit opt-in;
- Abuse prevention: rate-limiting search, blocking scraping, moderating workspaces and reviews (legitimate interests);
- Publishing reviews you explicitly submit for publication, after moderation, with your name and role/organization line (consent).
6. Who we share data with
- Employers and recruiters on the service — as described in section 4, and only as described there.
- Supabase (database, authentication, file storage) — our infrastructure provider; data is hosted in the United States (AWS us-west-2).
- Vercel (application hosting and CDN, United States).
- Dodo Payments — merchant of record for employer billing. Dodo collects and processes payment details under its own privacy policy; we receive only subscription state, never card numbers.
- Zoho ZeptoMail — transactional email delivery (recipient address and message content).
- Authorities, when a valid legal demand requires it — narrowly, and with notice to you where lawful.
We do not sell personal data to data brokers, run advertising, or share data for cross-context behavioral advertising.
Cross-border transfers: because hosting is in the United States, personal data of users in India and Canada is transferred to and stored in the US, protected by the safeguards in section 8 and by our contracts with the processors above. By using the service you consent to this transfer.
7. How long we keep things
- Your account and profile — for as long as the account exists.
- On deletion — your profile, contact details, applications, saved jobs, and your resume file are deleted immediately and permanently. What survives: records we are legally required to keep, aggregate statistics that no longer identify you, and payment records held by Dodo under its own retention obligations.
- Email log — up to 12 months, then pruned.
- Search-rate counters — days (abuse prevention only).
- Billing webhook records — up to 24 months, for financial reconciliation.
8. How we protect data
Access control is enforced in the database itself, not just the application: row-level security on every table, and candidate contact data reachable only through audited functions that enforce the masking and credit rules of section 4. Resume files live in a private bucket and are served through signed links that expire within an hour. Employer search is rate-limited against harvesting. Passwords are hashed by our authentication provider; we never see them. No system is perfectly secure — if a breach affects your data, we will notify you and the relevant authorities as applicable law requires.
9. Your rights
- Access / portability — download everything we hold about you as JSON from your account page, self-serve.
- Correction — every profile field is editable in the app at any time.
- Erasure — delete your account self-serve from your account page; effects are described in section 7.
- Consent withdrawal — leave employer search (section 4 controls) or delete your account at any time.
- Complaints — contact support@healthcarehire.co first; you may also approach the Data Protection Board of India (DPDP Act 2023), the Office of the Privacy Commissioner of Canada (PIPEDA), or your US state attorney general.
10. Children
The service is for working healthcare professionals and employers. It is not directed at anyone under 18, and we do not knowingly collect data from anyone under 18; such accounts are deleted when found.
11. Changes to this policy
When we change this policy materially — new data types, new sharing, new analytics — we will update the date above and notify you through the service or by email before the change takes effect. The current version always lives at healthcarehire.co/privacy.