This is the current version of our Privacy Policy (effective August 27, 2026), shown here as an archived snapshot for reference. View the live policy.
Published August 27, 2026. See the full change history for what changed in this version.
Privacy Policy
1. Introduction
Zero Hiring ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and dispose of information when you use our AI-powered recruitment platform — whether you are a job candidate, an employer or recruiting-partner user, or a visitor to our public pages.
Our role. When we handle candidate data on an employer's behalf and on their instructions — your application to a specific job, and the hiring system we operate for them — Zero Hiring acts as a service provider (a "processor") for that employer. Two things are ours rather than theirs: our own candidate sourcing database — profiles we obtain from third-party data providers and reuse across engagements, independently of any single employer — and how you are assessed, since we design the scoring model, the criteria it applies, and the automated interview, and the employer does not choose or see that methodology. For both of those we act as a controller, and this policy is our notice to you for them. Whichever applies, you can raise anything described here with us directly at privacy@zerohiring.com, and we will handle it or route it to the right employer for you. Section 12 sets out who is responsible for what.
2. Information We Collect
2.1 Organization Information
Account information (name, email, company name, password)
Company details (industry, size, hiring volume)
Billing and payment information
Job descriptions and requirements
Usage data and platform interactions
2.2 Candidate Information
We collect candidate information from two sources:
Applicants — candidates who apply directly to a job: personal identifiers (name, email, phone number), resume and application materials, interview recordings (audio and/or video), interview transcripts and AI-generated assessments, and employment history and qualifications.
Sourced candidates — candidates we identify on an employer's behalf from third-party professional-profile databases before they have applied to anything (see §3 "How We Collect Information"). We collect profile data such as name, headline, current title/employer, publicly listed skills and experience, and contact details supplied by that database. If you are contacted this way and do not wish to be, every outreach message includes an unsubscribe/suppression link, and you may also contact us directly.
2.3 Automatically Collected Information
IP address and device information
Browser type and operating system
Usage patterns and session data
Cookies and similar tracking technologies (see §8)
3. How We Collect Information, and Why (Purpose & Lawful Basis)
We collect information directly from you (account creation, job applications, interviews), from the employer you are interacting with (job requisitions, and a sync with whichever applicant tracking system they connect), from third-party sourcing databases (for sourced candidates who have not applied), and automatically as you use the platform (cookies, device data). Each purpose below has a specific lawful basis under GDPR/UK GDPR. Where a purpose is marked *, we rely on legitimate interest and keep a balancing assessment for it; you can ask us for our reasoning, or object to that processing, at privacy@zerohiring.com.
Purpose
Lawful basis
Operate the applicant-tracking & interview platform for an employer
Employer's contractual basis; Zero acts as service provider
Conduct AI interviews (recording, transcription, AI-processing)
Your explicit consent, captured before each interview
Score/rank résumés and candidates (ZeroFit)
Employer's contractual basis, or our legitimate interest in an effective ranking feature*
Source candidates from third-party profile databases
Legitimate interest*, balanced against your expectations
Send outreach email to sourced candidates
Legitimate interest*, with an unsubscribe/suppression mechanism in every message
Train and improve our résumé-scoring and matching models
Legitimate interest*, with direct identifiers removed and an objection route — see §4
Billing, fraud prevention, legal compliance
Contract performance / legal obligation
4. AI Processing and Automated Decisions
Our platform uses artificial intelligence to:
Conduct automated interviews with candidates
Analyze interview responses and generate assessments
Score candidates based on job requirements
Parse and evaluate resumes
Important: AI assessments are recommendations only. A score or AI-generated report does not by itself end your candidacy — rejection decisions for applicants are made by a human at the employer (or, for candidates we source who do not respond to outreach, may be closed out automatically after a period of no engagement; that automatic step does not use your AI score and does not on its own affect any other application you may have). You have the right to request human review of any automated assessment and to receive an explanation of the factors behind it — contact us at privacy@zerohiring.com or use Your data & privacy.
Training and improving our models. We use candidate data — résumés, application materials, interview transcripts, and the outcomes of hiring decisions made on our platform — to train and improve the models that score and match candidates. Before data is used this way we remove direct identifiers such as your name, email address and phone number. We do not describe the result as anonymous: a résumé can still identify the person it belongs to, so we continue to treat it as personal data and protect it accordingly.
Our lawful basis for this is our legitimate interest* in building a scoring system that works, weighed against your interest in controlling how your information is used. You can object at any time by emailing privacy@zerohiring.com, and we will stop using your data for this purpose. To be straightforward about the limit of that: we can exclude your data from future training, but we cannot remove what a model has already learned, so an objection applies going forward rather than retroactively.
5. Data Sharing, Disclosure & Subprocessors
We may share your information with:
Organizations: Candidate data is shared with the organization that posted the job
Service Providers (subprocessors): Cloud hosting, AI processing, payment processing, email, and other services — see our full list of subprocessors for names, services provided, and data categories
ATS Integrations: When an organization connects its own applicant tracking system, so your application stays in step between that system and ours
Legal Requirements: When required by law or to protect our rights. We maintain a record of authorized disclosures of personal information to third parties and, unless legally prohibited, notify affected customers of legally binding requests for disclosure of their data.
We do not sell personal information to third parties, and we do not authorize any subprocessor to use your data for its own purposes. The subprocessor list linked above is the single, itemized register of every subprocessor we use — kept there rather than duplicated in this policy as a separate summary that could drift out of sync with it — with its own dated change log and RSS feed. We notify customers before adding or replacing a subprocessor that processes personal data, so they have an opportunity to raise concerns.
How your candidate identity is shared across employers you interact with: our platform is used by many separate employers. Job postings themselves are intentionally public — anyone can browse open roles, employer name included, at zerohiring.com/jobs, since that is how candidates find and apply to them. What is not shared across employers is your candidacy: each employer's record of your application status, interview recordings/transcripts/scores, and ATS-synced pipeline stage for you is kept fully separate from every other employer's. The one deliberate exception is a small core identity record — your name, email and phone, alongside profile-level facts about your background: your current title and employer, approximate years of experience, general location, and the skills drawn from your materials. If you apply to a job, are sourced for one, are added directly to an employer's pipeline (for example, an employer inviting you by email, or connecting an Applicant Tracking System that already has your information), you are recognized as the same person rather than re-profiled from scratch each time, so that identity record is not duplicated per employer. An employer gains visibility into that shared record only once one of those things has happened between you and them — never an employer you have no relationship with at all — and everything else about your candidacy (which jobs, your status, interview content, scores) stays scoped to that specific employer. This is a deliberate design choice that powers duplicate-application detection and a consistent candidate profile, not an oversight.
Your résumé is not part of that shared record. People write different résumés for different roles, and a document you wrote for one employer is not something another employer should be reading. Each résumé you send us stays attached to the application you sent it with: that file, and the summary we generate from it, are visible only to the employer you sent it to. If an employer sources you or adds you to their pipeline without an application, they see the profile-level record above and any résumé you provided to them — never one you sent to someone else. We also do not tell an employer which other employers you are talking to.
6. Data Retention & Disposal
Our retention targets are:
Organization accounts: Until account deletion plus 30 days
Candidate data: 2 years after last activity, or as required by the organization
Interview recordings: 1 year, or until the organization deletes them
Payment records: 7 years for legal compliance
Deleting your data sooner. You can ask us to delete your candidate data at any time, without waiting for the periods above to elapse, through Your data & privacy — this removes your résumé, interview recordings, transcripts, scores, and related records from our systems (with one narrow exception: records of an outreach campaign having occurred are anonymized rather than deleted, so we can maintain accurate suppression/compliance records without retaining your identity). You do not need an account to use it: if we sourced your profile from a third-party database and you never applied, enter your email address on that page instead and we will send you a confirmation link. Confirming it identifies you well enough for us to act, and covers sourcing records as well as applications. You can still email privacy@zerohiring.com if you prefer.
7. Data Security
We implement technical and organizational security measures including:
Encryption in transit (TLS/SSL) and at rest (AES-256)
Role-based access controls and authentication, scoped per organization
Audit logging of access to candidate records
Regular security audits and vulnerability scanning
Employee security and privacy training
Documented incident response procedures
How organization data is kept separate. Access is enforced in the application — every database query for an organization's job records, applications, interviews, and results is bound to that organization's own identity from the authenticated session before it runs (this is about your employer dashboard's access to those records — the public job board described above is a separate, intentionally public read path). We test this directly rather than assume it: automated tests run against a real database with two separate seeded organizations and confirm, on every change, that one organization's session cannot read or write another's records, including when we deliberately remove a scoping check to confirm the test would actually catch it. The shared candidate-identity record described above sits outside this per-organization scoping, for the same reason it is shared across employers in the first place — which employers can reach it, and when, is described in that section.
8. Cookies and Tracking
We use cookies and similar technologies for:
Essential: Authentication and security
Analytics: Understanding usage patterns (Amplitude)
Error Monitoring: Identifying and fixing issues (Sentry), with session replay masking all text, inputs, and media
Analytics is off by default in regulated regions (EU/UK/CH) and only runs after you opt in via our consent banner; elsewhere it runs by default with the same opt-out available. Session replay is stricter and different: it is off by default in every region, including outside the EU/UK/CH, and only runs if you separately check the session-replay option in that same banner — it is never turned on by the region-based default the way analytics is. You can change or withdraw either choice at any time from Your data & privacy, or control cookies through your browser settings.
9. Your Rights
Depending on your location, you may have the right to:
Access: Request a copy of your personal data
Correction: Request correction of inaccurate data — see §10 on data quality
Deletion: Request deletion of your data
Portability: Receive your data in a portable format
Objection: Object to certain processing activities, including sourcing, outreach, and the use of your data to train our models (see §4)
Withdraw Consent: Withdraw consent where processing is based on consent (e.g. interview recording)
Human review: Request human review of any AI-generated assessment (GDPR Art. 22)
To exercise these rights, visit Your data & privacy to export or delete your data and manage tracking preferences, or contact us at privacy@zerohiring.com.
10. Data Quality & Your Role
We rely on the accuracy of the information you and, where applicable, third-party sourcing databases provide. If any information about you is inaccurate or out of date — including a sourced profile compiled without your direct input — you can request its removal yourself at Your data & privacy, and request a correction by emailing privacy@zerohiring.com. We will investigate and correct or remove inaccurate data we control within a reasonable time.
11. International Data Transfers
Zero Hiring is established in the United States, and all of the personal data described in this policy is processed there — our application infrastructure in AWS US East and our database with Neon, also in the United States. If you are in the European Economic Area, Switzerland or the United Kingdom, that means your information is transferred outside your own jurisdiction.
Where we make such a transfer, we intend to do so under one of the safeguards Chapter V of the GDPR permits: the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum or the Swiss equivalent where those apply; or an adequacy decision where one covers the recipient, including the EU–US Data Privacy Framework for recipients certified under it. We are in the process of putting the applicable safeguard in place with each subprocessor and will update this section as that work completes. Which subprocessors receive your data, what each does, and where each processes it are listed on our subprocessor register.
A transfer does not reduce your rights. Everything described in §9 applies wherever your data is processed, you can exercise it against us directly at privacy@zerohiring.com, and you can complain to your local supervisory authority. If you are in the EU or EEA you may also raise it with our Article 27 representative, whose details are in §17 — you do not have to pursue a company on another continent to get an answer.
12. Who Is Responsible for Your Data
Data-protection law asks which organization decides why and how your information is used. That organization is the "controller" and is the one accountable to you. For Zero Hiring the answer depends on the stage:
Your application to a specific job. The employer that posted the role is the controller. Zero Hiring operates the hiring system on its behalf and acts on its instructions. If you ask us to delete or disclose that application, we will pass your request to that employer and support them in answering it.
Our own candidate database. Where we obtained your profile from a third-party source before you applied, Zero Hiring is the controller. We chose to collect and keep that record, so the responsibility to tell you about it and to have a lawful basis for holding it is ours. We answer requests about it ourselves.
How you are screened, scored and interviewed. Zero Hiring is responsible for this in its own right, not on any employer's behalf. We design the scoring model and the criteria it applies, and we design the automated interview and what it assesses. The employer supplies the job description and decides what to do with the result, but does not choose the methodology. Requests about how you were assessed — including asking for human review of an automated decision — we answer ourselves.
Where an employer is itself acting for another company — for example a recruitment agency hiring on a client's behalf — that company is the controller, the agency is the processor, and Zero Hiring operates beneath them for the application record. Our responsibility for our own database and for the screening methodology is unchanged.
Zero Hiring and an employer are not joint controllers. We each decide different things and are separately accountable for them — the employer for the role and the hiring decision, us for our database and our screening methods — rather than deciding the same processing together. There is therefore no joint controller arrangement to publish under Article 26 of the GDPR. If that changes, we will set out the essence of the arrangement in this section, including which party is the point of contact for each type of request.
You do not need to work out which case applies before contacting us. Send any privacy request to privacy@zerohiring.com and we will either answer it or route it to the responsible employer and tell you that we have.
13. Purpose Limitation & Data Minimization
We use personal information only for the purposes described in this policy, and we aim to collect no more than each purpose requires. When we source candidate profiles from third-party databases, we receive and store the profile record that database returns, which can be broader than the fields we display. You can ask us what we hold about you, or have it deleted, at any time — see §9.
14. Monitoring & Enforcement
Our privacy program is overseen internally and reviewed against this policy at least annually (see §16). Personnel with access to candidate data are bound by confidentiality obligations and receive privacy training. Suspected violations of this policy, whether by our personnel or a subprocessor, are investigated and remediated, and material incidents are reported per our incident response procedures and applicable breach-notification law.
15. Children's Privacy
Our Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
16. Policy Review & Change Notification
We review this Privacy Policy at least annually, and sooner if our processing changes. Every version of this policy is recorded, with a plain-English description of what changed and why, in our public change history, which you can also follow via RSS.
Material changes — a change to what personal data we collect, our purposes or lawful bases for processing it, who we share it with, how long we retain it, your rights, or the introduction of a new purpose not previously described here (including a case covered by GDPR Article 13(3)) — are announced by email to each customer's administrator at least 30 days before the change takes effect, so you have a real opportunity to review, ask questions, or export your data first. The email is sent when the change is published, not when it takes effect, and states the nature of the change; the same information is published in the change history the same day.
Administrative changes — wording or clarity fixes, contact-detail updates, formatting, or correcting a description without changing what we actually do — take effect immediately on publication and are recorded in the change history, without a separate email.
Your continued use of the Service after a change takes effect constitutes acceptance of the updated policy.
17. Contact Us
For privacy-related questions or to exercise your rights:
Email: privacy@zerohiring.com Address: Zero Hiring, Inc. — 42 Broadway, Suite 12-443, New York, NY 10004
Data Protection Officer (GDPR Article 37)
Zero Hiring, Inc. has designated a Data Protection Officer, responsible for monitoring our compliance with data protection law, advising on data protection impact assessments, and acting as the contact point for data subjects and supervisory authorities. You may contact our Data Protection Officer directly on any matter relating to the processing of your personal data or the exercise of the rights described in §9, at privacy@zerohiring.com.
EU Representative (GDPR Article 27)
Zero Hiring, Inc. is established outside the European Union. We have designated the following representative in the European Union under Article 27 GDPR. If you are in the EU or EEA, you may contact our representative — in addition to, or instead of, contacting us directly — on any matter relating to our processing of your personal data, including to exercise the rights described in §9. Supervisory authorities may address the representative on the same basis.
Prighter EU Rep GmbH Schellinggasse 3/10, 1010 Vienna, Austria prighter.com/q/14119625741
California Residents
If you are a California resident, the CCPA as amended by the CPRA gives you the rights below. These rights apply to job applicants and candidates, not only to customers — since 2023 California treats applicant data the same as any other personal information, and applicants are most of the people whose data we handle.
Know and access — what personal information we collect, the sources we collect it from, why we collect it, and who we disclose it to. These are itemized in §2 (categories), §3 (sources and purposes), §5 (disclosure and subprocessors) and §6 (retention) above, which together form our CCPA notice-at-collection.
Delete — request deletion of your personal information.
Correct — request correction of inaccurate personal information by email (see §10).
Opt out of sale or sharing — we do not sell personal information, and we do not share it for cross-context behavioral advertising. We use no advertising networks or ad-tech subprocessors, so there is nothing here to opt out of; we state the right because the law requires us to, not because we exercise the practice.
Limit how we use sensitive information — California treats certain categories as sensitive: government ID numbers, financial account details, precise location, health, racial or ethnic origin, and a few others. We do not ask you for any of them and have nowhere to store them. If you include something in one of those categories anyway — in your résumé, or in an interview answer — you can tell us to use it only to provide the service, and we will.
Non-discrimination — we will not deny you service, charge you a different price, or give you a lesser experience for exercising any of these rights. For candidates specifically: exercising a privacy right has no effect on your candidacy.
To access, export or delete your information, or to change your tracking preferences, use Your data & privacy — no account is required. For a correction, or to limit the use of sensitive personal information, email privacy@zerohiring.com; those are handled by a person rather than self-serve. You may also use an authorized agent acting on your behalf; we will ask the agent for proof of your permission and may ask you to verify your own identity directly.
European Union Residents
Under GDPR, you have additional rights regarding your personal data, including the rights described in §9 and the automated-decision safeguards described in §4. You may raise any of these with our Data Protection Officer or with our EU representative under Article 27 GDPR, whose contact details are both in §17, and you may lodge a complaint with your local supervisory authority.