Skip to content
Recruit Swipe

Legal

Privacy policy

Recruit Swipe holds two very different kinds of data: information about you, the recruiter, and information about candidates that belongs to your ATS. This policy keeps them separate, because our obligations for each are different.

Last updated 2 August 2026

Draft — not yet reviewed by counsel

This text describes what the product actually does, but it has not been reviewed by a lawyer and the following still need completing:

  • Legal entity name and registered address
  • Supervisory authority and EU/UK representative, if we take on European customers
  • Confirmation of the standard contractual clauses used with each subprocessor

Who we are

Recruit Swipe provides a mobile application that connects to a recruiter's applicant tracking system or job board and lets them review and action candidates from that system. This policy covers both this website and the application.

For questions about anything here, email privacy@recruiterswipe.com.

Data about you, the recruiter

We are the controller of this data. We collect:

  • Account details — your email address, and the display name and organisation name you choose. Needed to give you an account and to show teammates who did what.
  • Connection settings — which sources you have connected, and what you configured each swipe direction to do.
  • Your activity — the swipes and grades you record, with a log of what each configured action returned from your ATS. This is the audit trail the product exists to give you.
  • Device push tokens — only if you enable notifications, and only used to send alerts about your own requisitions.
  • Billing records — your subscription plan, status, and seat count. Card details go to Stripe directly; we never see or store them.
  • Messages you send us — anything you submit through a form on this site or by email, kept so we can reply and to follow up on partnership or access requests.

We use this to operate the service, to bill you, to support you, and to tell you about things you asked to be told about. We do not sell it, we do not share it with advertisers, and we do not use it to train models.

Candidate data from your ATS

When you connect a source, we read requisitions and candidate records from it on your instruction. For that data you are the controller and we are your processor. Your ATS remains the record of truth; we hold a working cache so a swipe deck does not re-fetch on every card.

  • We only read the requisitions you select and the candidates on them.
  • We only write back what you configured — a stage change, a rejection, a note, a tag — and we log the outcome of each.
  • We do not pool candidate data across customers, do not build an independent candidate database, and do not make candidate data available to anyone outside your account and the teammates you share a connection with.
  • Candidates do not have accounts with us and we do not contact them.

If a candidate exercises a data right against you, the authoritative copy is in your ATS. Delete the connection and our cached copy goes with it; ask us and we will confirm deletion of any residue.

Credentials

The API key or token for each connected source is stored encrypted in a vault, separate from the rest of the database. It is decrypted only inside the server function that is about to call your ATS, after checking that the calling session owns the connection. It is never stored on your device or included in the application bundle. Deleting a connection purges the encrypted secret in the same transaction.

This website

This site sets no cookies, runs no analytics, and loads nothing from a third-party server — fonts and images are served from our own domain. The only information it collects is what you type into a form and submit.

Form submissions are stored so we can respond, and trigger a notification email to us. Standard web server logs, including IP addresses, are kept by our hosting provider for security and troubleshooting.

Who else processes it

We use a small number of subprocessors: Supabase for the database, authentication, and the server functions that call your ATS; Stripe for billing; Expo for push delivery; Resend for email. Each is listed with its role on our security page. We do not add a subprocessor without updating that list.

How long we keep things

  • Account data — for as long as you have an account, then deleted on request.
  • Cached candidate and requisition data — until you delete the connection, or until you delete your account.
  • Swipe and grade history — for as long as your account exists; it is your audit trail.
  • Billing records — as long as tax and accounting rules require.
  • Enquiries sent through this site — up to two years, then deleted.

Your rights

Depending on where you live, you can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. Email privacy@recruiterswipe.com and we will respond within 30 days. You can also complain to your local data protection authority.

Security

Encryption in transit and at rest, credential isolation in a vault, row-level access control enforced in the database, and automated tests that assert one account cannot read another's data. The detail is on our security page. To report a vulnerability, email security@recruiterswipe.com.

Children

Recruit Swipe is a professional tool for recruiters. It is not directed at anyone under 18 and we do not knowingly collect their data.

Changes

When this policy changes we update the date at the top. If a change materially affects how we handle your data, we will tell account holders by email before it takes effect.