Privacy Policy
Last updated: September 11, 2026
Overview
TradeRecruit OS (“we”, “us”, or “the platform”) is a placement platform for HVAC, electrical, and plumbing skilled trades. We collect and process data to operate the platform, manage candidate placements, and provide recruitment services. This policy explains what data we collect, how we use it, and your rights.
Data We Collect
Account Data
- Name, email address, and role (owner, admin, recruiter)
- Hashed password (argon2 — never stored in plaintext)
- Session tokens (JWT, 24-hour expiry, Secure cookies)
Candidate Data
Recruiter users may input candidate information including:
- Name, phone, email, address, city, state, ZIP
- Current employer, job title, union status and local
- Specialties, certifications (with expiration dates)
- Work history, reference checks, background screenings
- Pay expectations, availability, shift and travel preferences
- Driver's license status, tool ownership
- Uploaded documents (resumes, certification scans) — stored in Cloudflare R2
Company Data
- Company name, address, contacts, agreements
- Job orders, submissions, interview and placement records
- Invoices, payments, expenses
Activity Data
- Audit log entries (append-only — creates, updates, exports, logins)
- Communications history (email threads, outreach sequences)
- AI run records (prompts, outputs, human review status)
How We Use Your Data
- To operate the recruitment and placement platform
- To manage candidates, job orders, and placements
- To process payments via Stripe
- To send emails via Resend (outreach, daily digests, inbound replies)
- To provide AI-assisted drafting, summaries, and matching (with mandatory human review)
- To maintain an audit trail for compliance and accountability
- To generate financial and regulatory exports
Data Storage
- Database: Neon Postgres (encrypted at rest, SSL/TLS in transit)
- Documents: Cloudflare R2 (private bucket, no public access, authenticated downloads only)
- Payments: Stripe (card data never touches our servers — Stripe Checkout handles all card information)
- Email: Resend (outbound email delivery and inbound webhook processing)
- Hosting: Vercel (application hosting, CDN)
AI Usage
AI features are OFF by default and must be explicitly enabled in Settings. When enabled, AI is used for drafting communications, generating summaries, and suggesting matches. AI never makes autonomous decisions — every AI output requires human approval before use. No candidate video, voice, facial features, or emotion data is ever stored or analyzed. AI prompts and outputs are logged in the audit trail.
Data Retention
- Candidate data is retained until soft-deleted by a user or exported and removed
- Audit log entries are retained indefinitely (append-only, no delete path)
- Payment records are retained for 7 years (tax compliance)
- Documents are retained until the associated candidate is removed
- Session tokens expire after 24 hours of inactivity
Your Rights
- Access: Export your data via the backup and export features
- Deletion: Request account deletion in Settings
- Correction: Edit candidate and company data through the platform
- Portability: Export candidates, companies, and financial data to CSV
- Objection: Disable AI features at any time in Settings
Security Measures
- Role-based access control (owner, admin, recruiter)
- Rate limiting on authentication endpoints
- Input validation on all API routes
- Content-Type and file size validation on uploads
- Webhook signature verification (Stripe, Resend)
- Secure cookies (__Secure- prefix, HttpOnly, SameSite)
- Security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options)
- Source maps disabled in production
- Structured logging with sensitive data redaction
Contact
For privacy questions or data requests, contact: david@wilwrx.com