Privacy policy
Effective September 23, 2026
This policy explains what personal data HiringOps handles, why, and what control you have over it. It covers our website at hiringops.io, the HiringOps application at app.hiringops.io, and the careers sites HiringOps hosts for our customers.
Who we are
HiringOps is operated by Tazo Tandilashvili, Tbilisi, Georgia ("HiringOps", "we", "us"). You can reach us about anything in this policy at support@hiringops.io.
Our two roles
HiringOps is software that companies use to run their hiring. That gives us two different roles:
- For candidate data, we act for our customers. When you apply for a job through a company's careers site, or a company adds you as a candidate, that company decides what happens to your data. We process it on their behalf and under their instructions. If you're a candidate with a question or request about your data, contact the company you applied to. If you contact us instead, we'll pass your request to them and help them respond.
- For account and website data, we decide. We are responsible for the data about the people who sign in to HiringOps (recruiters, HR admins, hiring managers and interviewers) and about visitors to hiringops.io.
What we collect
Account data
Your name, work email address, the company workspace you belong to, your role in it, and a securely hashed version of your password. We never store your password itself.
Hiring data our customers put into HiringOps
Jobs, candidate profiles, CVs and other files, notes, ratings, scorecards, interview details, offer letters and messages. What this includes is up to each customer.
Data candidates submit on a careers site
Your name, email address, phone number, CV, any links you add (such as LinkedIn or a portfolio), and your answers to the application questions, for example how you heard about the role and your earliest start date.
Access requests from our website
If you use the "Request access" form on hiringops.io, we collect the name, work email address, company and team size you enter, plus anything you write in the optional message, so that we can reply to you about using HiringOps; we email those details to our own support address and keep the request so we can follow up. If you would like it deleted, email us and we will remove it.
Technical and security data
When you use HiringOps we record your IP address, browser type, the pages and actions requested, and timestamps. We use this to keep the service secure, to limit repeated sign-in attempts, and to investigate problems. Important actions, such as sign-ins, team invitations and changes to candidate records, are written to an audit log that records who did them and when.
Google user data
Connecting a Google account is optional. A recruiter can connect Gmail, Google Calendar, or both, from Settings, then Integrations. This section describes exactly what HiringOps does with the data Google gives us.
What we access
- Your Google account email address and basic profile (
openid,email), so we know which account you connected. - Permission to send email as you (
gmail.send), so the candidate emails you write in HiringOps go out from your own address. - Permission to manage calendar events (
calendar.events), so interviews you schedule in HiringOps appear on your calendar with a Google Meet link.
How we use it
- We send only the emails you write or trigger in HiringOps, such as a message you compose to a candidate or the invitation for an interview you schedule.
- We create, update and cancel only the calendar events for interviews you schedule, reschedule or cancel in HiringOps.
- We do not read, search, change or delete the messages in your Gmail inbox, and we do not work with calendar events that HiringOps did not create.
How we store and protect it
The access tokens Google issues are encrypted before we store them. When you disconnect the account in HiringOps, we delete them. You can also remove HiringOps' access at any time from your Google Account at myaccount.google.com/permissions.
What we never do with it
- We do not sell Google user data.
- We do not use it for advertising, and we do not transfer it to anyone except as needed to provide the HiringOps features described above, to comply with the law, or with your consent.
- No person at HiringOps reads it, unless you ask us to while we help you, it is needed to investigate security or abuse, or the law requires it.
- We do not use it to develop, improve or train generalized artificial intelligence or machine learning models.
Microsoft user data
Connecting Outlook or a Microsoft 365 shared mailbox is also optional. When you do, HiringOps uses the permissions you grant to send candidate emails from your mailbox, bring candidates' replies into HiringOps so the conversation stays with the candidate, and create calendar events with a Microsoft Teams link for interviews you schedule. The same protections apply as for Google: tokens are encrypted, deleted when you disconnect, never sold, and never used for advertising or to train AI models.
How we use personal data
- To provide HiringOps: hosting careers sites, receiving applications, and running the hiring features our customers use.
- To send service emails, such as team invitations, password resets, and notifications to candidates about their application or interview.
- To keep HiringOps secure, prevent abuse and fix problems.
- To answer your questions when you contact us.
- To meet our legal obligations.
Where data protection law requires a legal basis, we rely on performing our contract with you or your employer, our legitimate interest in running a secure and reliable service, and, where needed, your consent. For candidate data, the customer who collects it is responsible for its legal basis.
Who we share it with
We don't sell personal data. We share it only with the service providers we use to run HiringOps, each bound to protect it and to use it only for the service they provide to us:
- Hetzner Online GmbH, which hosts our servers and databases in Nuremberg, Germany.
- Postmark, which delivers service emails such as invitations and password resets, and which receives and processes candidate replies to emails sent from HiringOps.
- Google and Microsoft, only when you connect one of their accounts, to send your email and manage your calendar events as described above.
We may also disclose data if the law requires it, or to protect the rights and safety of our users and the public.
How long we keep it
- Candidate data is kept for as long as the customer decides. Customers can set how long candidate records are kept, and HiringOps deletes them automatically once that period ends.
- Account data is kept while you have an account, and deleted after your account is closed, except where we must keep it for legal reasons.
- Server logs are rotated and kept only briefly. Audit records are kept for as long as the workspace exists.
How we protect it
Every company's data lives in its own workspace and is not visible to other companies. Access within a company follows each person's role, and jobs can be made private to their hiring team. All traffic uses encrypted HTTPS connections, passwords are hashed, connection tokens are encrypted, and resetting a password signs out every other session.
Cookies
When you sign in, HiringOps sets one essential cookie that keeps you signed in. It is marked so that scripts on the page cannot read it and it is only sent over HTTPS. We don't use advertising or tracking cookies. Our website loads its fonts from Google Fonts, which means your browser sends your IP address to Google when it downloads them.
Your rights
Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to how it is used, receive a copy in a portable format, and withdraw consent you have given. To use any of these rights for your account data, email support@hiringops.io. If you're a candidate, contact the company you applied to, as they control your data. You also have the right to complain to your local data protection authority.
International transfers
We store data in Nuremberg, Germany. When a service provider processes data in another country, we make sure appropriate safeguards are in place, such as the European Commission's standard contractual clauses.
Children
HiringOps is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes to this policy
If we change this policy, we'll update the date at the top. If a change is significant, we'll tell account holders by email or in the application before it takes effect.
Contact
Tazo Tandilashvili, Tbilisi, Georgia
Email: support@hiringops.io