Draft template. This document describes how the product works today but has not yet been reviewed by legal counsel. It is not a binding agreement until finalised and, where relevant, signed.

Privacy Policy

Last updated 28 September 2026

How GrowthPPL handles personal data. We describe only what the product actually does today. For candidate/employee data we process on behalf of our customers, the customer is the controller and this policy is supported by our DPA.

Data we collect

Account data: name, work email, and a hashed password for the people who log in to a workspace.

Customer-provided data: the candidate, employee and hiring records a customer adds — processed on their instruction.

Operational data: structured server logs (request and error context) used to run and secure the service. We do not sell personal data or use candidate data to train models.

How we use it

To provide the service, authenticate users, send transactional email (invites, sign-in links, notifications), and keep the platform secure and reliable.

Sub-processors

Depending on how a workspace is configured we use these sub-processors: Neon (PostgreSQL database, Singapore region); Vercel (application hosting, Singapore region); Cloudflare R2 or Amazon S3 (file and résumé storage); Resend (transactional email); Upstash (rate limiting); Sentry (error reports, with personal data removed before sending); Anthropic, OpenAI or Google (AI features, only when enabled, or the workspace's own key); Groq (transcription of video screening answers, when enabled); Meta (WhatsApp messages, and a workspace's own advertising pixel when it turns one on); Cashfree (subscription payments). We notify customers of material changes under the DPA.

Security

Passwords are hashed with bcrypt; tenants are isolated by tenant-scoped queries in the application layer; sessions expire; invite and password-reset links are single-use and stored hashed; traffic is served over TLS. See the Security page for the full, honest posture (including what we have not yet done).

Retention & your rights

User data is soft-deleted first and purged on request or account closure. Individuals can ask us, via the controlling customer, to access, correct, export or delete their data; we support these requests.

Contact

Privacy questions and data requests: privacy@growthppl.com.