Legal
Privacy policy
Recruit Swipe holds two very different kinds of data: information about you, the recruiter, and information about candidates that belongs to your ATS. This policy keeps them separate, because our obligations for each are different.
Last updated 2 August 2026
Draft — not yet reviewed by counsel
This text describes what the product actually does, but it has not been reviewed by a lawyer and the following still need completing:
- Legal entity name and registered address
- Supervisory authority and EU/UK representative, if we take on European customers
- Confirmation of the standard contractual clauses used with each subprocessor
Who we are
Recruit Swipe provides a mobile application that connects to a recruiter's applicant tracking system or job board and lets them review and action candidates from that system. This policy covers both this website and the application.
For questions about anything here, email privacy@recruiterswipe.com.
Data about you, the recruiter
We are the controller of this data. We collect:
- Account details — your email address, and the display name and organisation name you choose. Needed to give you an account and to show teammates who did what.
- Connection settings — which sources you have connected, and what you configured each swipe direction to do.
- Your activity — the swipes and grades you record, with a log of what each configured action returned from your ATS. This is the audit trail the product exists to give you.
- Device push tokens — only if you enable notifications, and only used to send alerts about your own requisitions.
- Billing records — your subscription plan, status, and seat count. Card details go to Stripe directly; we never see or store them.
- Messages you send us — anything you submit through a form on this site or by email, kept so we can reply and to follow up on partnership or access requests.
We use this to operate the service, to bill you, to support you, and to tell you about things you asked to be told about. We do not sell it, we do not share it with advertisers, and we do not use it to train models.
Candidate data from your ATS
When you connect a source, we read requisitions and candidate records from it on your instruction. For that data you are the controller and we are your processor. Your ATS remains the record of truth; we hold a working cache so a swipe deck does not re-fetch on every card.
- We only read the requisitions you select and the candidates on them.
- We only write back what you configured — a stage change, a rejection, a note, a tag — and we log the outcome of each.
- We do not pool candidate data across customers, do not build an independent candidate database, and do not make candidate data available to anyone outside your account and the teammates you share a connection with.
- Candidates do not have accounts with us and we do not contact them.
If a candidate exercises a data right against you, the authoritative copy is in your ATS. Delete the connection and our cached copy goes with it; ask us and we will confirm deletion of any residue.
Credentials
The API key or token for each connected source is stored encrypted in a vault, separate from the rest of the database. It is decrypted only inside the server function that is about to call your ATS, after checking that the calling session owns the connection. It is never stored on your device or included in the application bundle. Deleting a connection purges the encrypted secret in the same transaction.
This website
This site sets no cookies, runs no analytics, and loads nothing from a third-party server — fonts and images are served from our own domain. The only information it collects is what you type into a form and submit.
Form submissions are stored so we can respond, and trigger a notification email to us. Standard web server logs, including IP addresses, are kept by our hosting provider for security and troubleshooting.
Who else processes it
We use a small number of subprocessors: Supabase for the database, authentication, and the server functions that call your ATS; Stripe for billing; Expo for push delivery; Resend for email. Each is listed with its role on our security page. We do not add a subprocessor without updating that list.
How long we keep things
- Account data — for as long as you have an account, then deleted on request.
- Cached candidate and requisition data — until you delete the connection, or until you delete your account.
- Swipe and grade history — for as long as your account exists; it is your audit trail.
- Billing records — as long as tax and accounting rules require.
- Enquiries sent through this site — up to two years, then deleted.
Your rights
Depending on where you live, you can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. Email privacy@recruiterswipe.com and we will respond within 30 days. You can also complain to your local data protection authority.
Security
Encryption in transit and at rest, credential isolation in a vault, row-level access control enforced in the database, and automated tests that assert one account cannot read another's data. The detail is on our security page. To report a vulnerability, email security@recruiterswipe.com.
Children
Recruit Swipe is a professional tool for recruiters. It is not directed at anyone under 18 and we do not knowingly collect their data.
Changes
When this policy changes we update the date at the top. If a change materially affects how we handle your data, we will tell account holders by email before it takes effect.