Legal
Privacy Policy
Last updated: October 6, 2026
This policy explains what personal data hireable.lol collects, how it is used and the choices you have. The data controller is [operator legal name]. Contact: [contact email].
1. Data we collect
When you sign in
From GitHub or Google we receive your name, email address, profile picture URL and an account identifier. We store a session record with your IP address and browser user agent to keep you signed in and protect your account.
Your candidate profile
Everything you enter in your profile: display name, username, avatar, headline, bio, category, skills, country and city, work preferences, availability, optional compensation range, links, contact URL and experience. When your profile is public, this information is visible to anyone and may be indexed by search engines. Your email address is never shown publicly unless you add it yourself as a contact link.
Boost purchases
Payments are handled by Dodo Payments as Merchant of Record. We never see or store your card details. We receive a payment identifier, the purchased package, the boosted candidate and, if you were signed in, your account ID. Dodo Payments processes your billing details under its own privacy policy.
Usage and technical data
- Product analytics events about boost purchases ("checkout started" and "payment completed") sent from our servers to PostHog, linked to your account ID, the boosted candidate or an anonymous identifier. We do not use client-side advertising or tracking scripts.
- Abuse-prevention counters derived from a one-way hash of your IP address. Raw IP addresses are not stored in these counters, which are deleted within about an hour.
- Standard server logs kept by our hosting provider for security and debugging.
2. Why we use it
- To provide the Service (performance of our contract with you): sign-in, publishing your profile, calculating rankings, processing boosts.
- To keep the Service safe and working (legitimate interests): rate limiting, fraud and abuse prevention, debugging.
- To improve the Service (legitimate interests): aggregated product analytics.
- To meet legal obligations: keeping payment records for accounting and tax purposes.
We do not sell your personal data and we do not use it for advertising.
3. Cookies
We use one essential cookie to keep you signed in. We do not use advertising or cross-site tracking cookies, so no cookie banner is needed for optional cookies.
4. Who we share data with
We use these service providers, who process data on our behalf or as independent controllers:
- Vercel — website hosting and server logs
- Neon — database hosting
- GitHub and Google — sign-in
- Dodo Payments — payment processing and Merchant of Record
- PostHog — product analytics
Some of these providers are located outside your country, including in the United States. Where required, transfers rely on appropriate safeguards such as standard contractual clauses. We may also disclose data if required by law or to protect rights and safety.
5. How long we keep it
- Account and profile data: until you ask us to delete your account.
- Session records: until the session expires or you sign out.
- Payment and boost records: as long as needed for accounting, tax and dispute handling, even after account deletion.
- Rate-limit counters: about one hour.
6. Your choices and rights
- Edit your profile at any time from your profile settings.
- Hide your profile from the public and the leaderboard by turning off "Public profile".
- Ask us for a copy of your data, to correct it, or to delete your account by emailing [contact email]. We will respond within 30 days.
Depending on where you live (for example under the GDPR, UK GDPR or KVKK), you may also have the right to object to or restrict processing, to data portability, and to complain to your data protection authority.
7. Children
The Service is not intended for anyone under 16, and we do not knowingly collect their data.
8. Changes
We will update the "Last updated" date when this policy changes and give notice of material changes on the Service.