Legal

Privacy Policy

Effective August 16, 2026. This policy explains how Tech Seeker collects, uses, discloses, stores, and deletes personal information.

1. Accountability and scope

Tech Seeker is responsible for personal information under its control. Our Privacy Officer can be reached at privacy@techseeker.io. This policy applies to our website, candidate and company accounts, applications, messages, administration tools, and related support.

2. Information we collect

  • Account and identity: name, email address, profile image, chosen account role, email-verification status, and Google account identifiers when you choose Google sign-in.
  • Security and session: session tokens, IP address, user agent, timestamps, and authentication/account metadata.
  • Candidate and application: name, contact details, CV, cover message, links, applications, application status, and hiring-team messages.
  • Company and posting: company profile, ownership/claim information, addresses, logos, job postings, applicant review activity, and hiring messages.
  • Browser preferences: saved jobs, recent searches, market/language choices, posting drafts, privacy choices, and map viewport preferences stored on your device.
  • Optional product analytics: after opt-in, an ephemeral session identifier, visited route, referring hostname, broad device class, country, search and filter counts without raw search text, job/source/company identifiers, and job-read, save, map, pagination, and apply actions.
  • Billing: customer, subscription, credit, and transaction identifiers if billing is enabled. Payment-card details are handled by Stripe, not stored by Tech Seeker.
  • Support and operations: communications with us, error and security records, request and database timings, and workflow/deployment logs.

3. How we collect it

We collect information directly from you, automatically when your browser communicates with our service, from Google when you authorize sign-in, and from companies and candidates interacting through the marketplace.

4. Why we use it

  • Create, authenticate, secure, and administer accounts.
  • Display jobs and companies, support applications, and enable hiring communications.
  • Store CVs and company images and deliver transactional verification messages.
  • Remember choices requested by you and, only when enabled, provide interactive maps.
  • Moderate postings, prevent abuse, debug failures, and protect users and infrastructure.
  • Administer billing if enabled and comply with tax, accounting, legal, and regulatory duties.
  • Operate and improve the service using aggregated or de-identified information where practical.

5. Consent and choices

We ask for information needed to provide features you request. Where processing is optional, we provide separate choices. Product analytics and Mapbox are disabled by default until you enable them. You may change either choice through “Privacy choices” in the footer. Disabling analytics stops new events and removes its current browser-session identifier. You may withdraw consent, subject to legal or contractual restrictions; doing so may make the related feature unavailable. See our Cookie Policy.

6. Who receives information

  • Employers: a candidate’s application, CV, and messages are disclosed to the company managing the posting and its authorized hiring users.
  • Cloudflare: website and API hosting, security, private file storage, and transactional email delivery.
  • Neon: managed PostgreSQL database hosting.
  • Google: authentication when you select Google sign-in.
  • Mapbox: map and network/device information only after interactive maps are enabled.
  • Stripe: billing and payment information if paid services are enabled.
  • Authorities or transaction parties: where required by law, necessary to protect rights and safety, or as part of a business transaction subject to appropriate safeguards.

We do not sell personal information and do not use advertising trackers.

7. Where information is processed

Our providers may process information in Canada, the United States, and other countries where they or their subprocessors operate. Information processed outside your province or Canada may be subject to foreign law. We use contractual, access, and security measures intended to provide appropriate protection and assess cross-border processing where required.

8. Retention and deletion

We keep personal information only for as long as reasonably needed for the purposes above, to maintain security and marketplace records, and to satisfy legal obligations. In general:

  • Account and profile data are retained while the account is active and then deleted or de-identified when the account is deleted, subject to exceptions below.
  • Applications, CVs, and related messages are retained while needed for the recruitment process and legitimate dispute, security, and record-keeping needs, then deleted or de-identified.
  • Company postings and public company information may remain after an individual account is deleted where needed to maintain marketplace records; ownership identifiers are removed or reassigned.
  • Authentication challenges and sessions expire; operational logs and consented analytics events are retained for limited operational and product-improvement periods and then expire under configured provider schedules.
  • Billing, fraud, security-incident, and legal records may be retained for the period required by law. PIPEDA security-breach records are retained for at least two years.
  • Deletion from active systems may not immediately remove encrypted backups; backup copies age out under provider schedules and are not restored except for recovery.

You can permanently delete your account from Account Settings. This removes your sign-in account, sessions, candidate profile, applications, related messages, and CV files. Analytics events are not linked to the account or user ID and therefore cannot reliably be selected by account deletion; their ephemeral session identifiers expire and retained events age out. For assistance or a deletion request you cannot complete in the product, email privacy@techseeker.io from your account email. We will verify the request, explain any information that must be retained, and normally respond within 30 days. Deleting an account cannot retract information already lawfully reviewed by an employer or sent to an external site.

9. Your rights

Subject to applicable law, you may request access to your personal information, information about its use and disclosure, correction of inaccurate information, withdrawal of consent, or deletion. You may also challenge our compliance. Contact the Privacy Officer at privacy@techseeker.io. If unresolved, you may complain to the Office of the Privacy Commissioner of Canada or the privacy regulator in your province.

10. Safeguards

We use role-based access controls, authenticated administrative routes, encrypted network transport, managed infrastructure, restricted production secrets, private file storage, and operational monitoring appropriate to the information. No system is completely secure. If a breach creates a real risk of significant harm, we will notify affected individuals and regulators as required.

11. Young people

Tech Seeker is not directed to children under 16. Do not create an account or submit personal information if you cannot provide legally valid consent. Contact us if you believe a child has provided information improperly.

12. Changes

We will update the effective date when this policy changes and provide additional notice for material changes, including when fresh consent is required.