Privacy policy

Version 1

What VouchedJobs is

VouchedJobs operates a job discovery, application tracking, employee referral, and employer hiring platform. Some jobs are imported from contracted sources and send you to an external employer or partner site. Other jobs accept an application directly on VouchedJobs. The data we receive depends on which path and features you choose.

Data we collect

Account and security data
Email address, display name, email-verification and sign-in challenges, provider account identifiers when you use social sign-in, active sessions, consent records, locale, currency, and timezone. Security tokens and API keys are stored as hashes or in encrypted credential envelopes where applicable.
Candidate workspace data
Career profile, skills, work authorization preferences, salary target, saved and captured jobs, application board, status timeline, notes, tags, tasks, recruiter contacts, application answers, support conversations, and notification preferences. Fields marked private are not made public.
Optional commute data
If you explicitly enable commute fit, the precise origin you provide is encrypted and the account page displays only a coarse hint. The origin is sent to the configured routing provider only when you request an estimate for a non-remote job. Cached results contain route fingerprints, mode, duration, distance, and expiry, not the address itself. Remote jobs do not disclose an origin. Replacing or revoking the preference erases the prior origin and its cached estimates.
Documents and coaching data
Extracted resume text, editable resume and cover-letter versions, document analysis, evidence you supply to career tools, and their generated working drafts. Uploaded resume binaries are parsed in memory and are not retained by the current implementation.
Applications and hiring data
For hosted applications, the selected documents, screening answers, status events, employer messages, interview details, availability, scorecards, offers, typed acceptance or decline, and onboarding tasks. Interviewer scorecards are visible only to authorized employer members, not to other candidates.
Referral and verification data
Work-email domain, employee-verification state and evidence, referral request and introduction state, consent, campaign milestones, rewards, wallet events, disputes, and payout status. Payout providers may separately request identity, tax, or bank information under their own policies.
Employer and recruiter data
Organization and domain, company profile, team members and roles, recruiter verification, job postings, candidate pipeline, interview kits, campaigns, integration settings, contracts, invoices, payment references, support, moderation, and audit events.
Connected email and calendar data
Only after your explicit provider consent, VouchedJobs uses the stated OAuth scopes to read job-application status messages or manage interview events. Access and refresh tokens are encrypted. Mail classification stores a bounded status-relevant preview and evidence, not a copy of your complete mailbox. You can disconnect and remove the stored token from the consent center.
Clicks, device signals, and logs
For outbound jobs and separately labelled affiliate resources, we record the job or offer, source, channel, timestamp, browser user-agent, referring placement, and a one-way hash of the IP address. We do not store the raw IP in the click ledger. When you are signed in, the click may also be linked to your account so it can appear in your activity export and support attribution or fraud review. We classify clicks for fraud prevention, attribution, billing, and reconciliation. Operational logs may temporarily contain request and error metadata needed to secure and run the service.
Referral sharing and messaging
Tracked referral links record the request, creator, channel, timestamp, attribution classification, and de-identified device signals. If you opt in to WhatsApp or Telegram alerts, the phone number or chat identifier is encrypted. We retain a masked hint, verification and consent version, approved template, delivery status, and provider message reference. Verification codes are hashed, expire quickly, and are single-use. You can disable alerts or revoke and erase the destination from account settings. Native push device tokens are stored in encrypted envelopes with a one-way lookup hash; only the configured FCM/APNs gateway receives a token when delivering an alert you enabled.
Purchases, affiliates, and licensed portals
Optional purchases record the server-side product, amount, currency, invoice, payment state, credits, and provider reference. Contextual affiliate clicks are kept separate from job results and carry the displayed commercial disclosure. White-label customers may operate a branded portal or scoped API under a signed contract; metered API events record route, units, rate snapshot, and invoice.
Local device storage
The PWA stores public cache files, push-subscription information, and any offline application drafts you explicitly create. Offline drafts remain in your browser storage until you remove or sync them. They are never submitted to an employer while offline.

Why we use the data

We use data to provide the service you request, authenticate and protect accounts, match and explain jobs, process hosted applications and referrals, coordinate hiring, deliver notifications, enforce contracts, prevent fraud, reconcile revenue, handle payments and disputes, support users, comply with law, and improve reliability.

Depending on your location and the activity, the legal basis may be consent, performance of a contract, legitimate interests, or a legal obligation. Marketing is opt-in. Connected mailbox, calendar, push, and messaging channels are disabled unless you consent and the relevant provider is configured. Precise commute routing is also disabled until you separately save an origin and consent to on-demand routing-provider disclosure.

Matching, automation, and human review

Candidate matching and career tools currently use deterministic, explainable rules. They use structured career and job data and do not use protected attributes. Resume and writing tools are instructed to transform only evidence you provide. Automated scam, quality, qualification, and risk signals can flag or prioritize work, but moderation appeals and adverse trust decisions have a human-review path. These tools can be wrong and do not make an employment decision on behalf of an employer.

Who receives data

  • An employer receives the hosted application, referral, interview, or onboarding data you choose to submit to that employer.
  • A verified employee referrer receives only the information required for a referral request and warm introduction, subject to your consent and profile visibility.
  • An external job source or employer receives the click identifier and ordinary web request data when you leave VouchedJobs to apply.
  • Hosting, database, email, OAuth, calendar, push, payment, payout, messaging, routing, analytics, security, and support providers process only the data needed for their contracted service. A messaging provider receives a verified destination and approved template parameters only after opt-in. A routing provider receives the precise origin, public job destination, and chosen mode only for an estimate you request.
  • A disclosed affiliate partner receives ordinary redirect and attribution data when you choose its resource. A white-label or API customer receives only the contract-scoped marketplace data and not a candidate's private workspace unless that candidate separately submits an application to the customer.
  • We may disclose information where law requires it or to protect users, the platform, or legal rights. We do not sell personal data.

Retention

Click-ledger records are scheduled for deletion after 400 days unless a lawful dispute or accounting hold applies. Unconfirmed alert sign-ups are deleted after 30 days, and completed data requests are removed after their operational retention window. Account and workspace data is normally kept while the account is active and then deleted or de-identified following a valid request, subject to security, financial, contractual, dispute, and legal retention duties.

Successful commute estimates expire after no more than 24 hours and unavailable-route responses expire sooner. Expired estimates are purged by the retention worker. A precise commute origin remains only while its preference is active; revocation immediately replaces the encrypted value with an empty value and clears estimates.

Regional and data-class policies may require different periods. The applicable policy and lawful hold take precedence over a general period. Backups expire on their own controlled rotation.

International processing and security

Providers may process data outside your country. Where required, the operator must put appropriate transfer terms and safeguards in place. The platform uses HTTPS, least-privilege roles, encryption for stored credentials, hashed secrets, revocable sessions, rate limits, idempotency, tenant isolation, audit records, and incident controls. No system can guarantee absolute security.

Your choices and rights

You can edit profile and notification settings, disconnect providers, revoke sessions and API keys, remove local drafts, withdraw marketing consent, and ask for access, correction, portability where applicable, restriction, objection, or deletion. Start through the data request form or contact kollusathvic@gmail.com. Some data may be retained where law, fraud prevention, payment, dispute, or security duties require it.

In India, unresolved privacy grievances may be directed to the grievance officer, Sathvic Kollu at kollusathvic@gmail.com. Other regions may also give you a right to complain to a data protection authority.

Children

This employment marketplace is not designed for children below the minimum age permitted to enter employment-related contracts in their region. Do not submit a child's personal data without a lawful basis and required guardian authorization.

Operator and contact

TECHTENSTEIN SERVICES PRIVATE LIMITED, Flat 101, MRVS Apartment, K.B Layout, Tirupati 517501. Governed from the stated jurisdiction of India. Material changes are published as a new policy version and, where required, notified or presented for renewed consent.