Privacy

How we handle your data

Cookies, local storage, and your California privacy rights

Cookies & Local Storage

In addition to standard Shopify cookies required for site functionality (session management, shopping cart), we use your browser's local storage to:

  • Remember your email — so you stay logged in across visits
  • Buffer pending changes — tracking notes and hire status are saved locally and synced when your connection is stable
  • Preserve navigation state — search filters and selected candidates are maintained during your session

We also use Google Analytics 4 (cookies prefixed _ga) to measure site performance — page views, navigation flow, and aggregate usage. It is configured with privacy-respecting settings: Google Signals disabled, advertising features disabled (no ads personalization, no ad-user-data sharing), and 14-month event retention. We do not share this data with advertisers.

We don’t use ad-targeting cookies or remarketing pixels. Our GA4 setup runs with advertising features disabled, and no data flows to advertisers or ad networks.

California Privacy Rights

CCPA / CPRA

If you are a California resident, you have specific rights regarding your personal information under the California Consumer Privacy Act and the California Privacy Rights Act.

Information We Collect

  • Identifiers — name, email address, phone number, postal address (from employer registration and candidate intake)
  • Commercial information — credit purchases, unlock records, transaction history
  • Professional or employment-related information — skills, certifications, years of pool-service experience, pay-rate expectations, availability, driver's license status (from candidate intake)
  • Resume content — resume files you upload (PDF, DOCX, JPG, PNG, or HEIC) and the plaintext we extract from them. For image formats (phone-photos of resumes), we extract the text on our own servers using an open-source OCR engine. The original resume file is not sent to any third-party AI service. The plaintext we extract on our own servers may be sent to our AI service providers (see “How We Share” below) so they can pull location details (city, state, ZIP) from your resume and pre-fill your profile.
  • Geolocation data — ZIP-level service area you are willing to work in (candidates) or hire in (employers). We do not collect precise geolocation.
  • Internet or network activity — search queries, pages visited, browser storage data (from site usage)

How We Use It

To operate the candidate marketplace, process credit purchases, facilitate candidate-employer connections, and improve site functionality.

How We Share — and What CCPA Classifies as a “Sale”

  • Shopify — payment processing and site hosting. Shopify acts as a service provider under CCPA §1798.140(ag); we do not “sell” personal information to Shopify. If you choose to create an optional SkimHire account to track your candidate profile, your account email and login activity are processed by Shopify as our service provider; your resume and other profile details remain on systems we operate ourselves.
  • AI service providers — to classify inbound messages (so candidate replies are routed correctly), draft response options that a SkimHire team member reviews before sending, and pull location details (city, state, ZIP) from resumes, we use commercial AI service providers. We currently use OpenAI and Anthropic, and we may rotate between them or add additional providers for reliability. Per the providers’ standard API terms, your data is not used to train AI models and is retained only as long as needed to provide the service and monitor for abuse. AI providers act as service providers under CCPA §1798.140(ag); we do not “sell” personal information to them. SkimHire does not make hiring or screening decisions automatically — every outbound message that an AI service has drafted is reviewed by a SkimHire team member before it is sent.
  • Employers — when an employer purchases an unlock credit (approximately $20–$30), SkimHire makes the matched candidate’s name, phone number, email address, and work-history summary available to that employer. Employers are contractually limited to using this information for their own hiring purposes and may not resell or redistribute it (see our Terms of Service).

Under California law (Civ. Code §1798.140(ad)), this credit-based unlock of candidate contact information qualifies as a “sale” of personal information because we make a consumer’s personal information available to a third party for monetary consideration. California-resident candidates have the right to opt out; see “Do Not Sell or Share My Personal Information” below.

We do not share, rent, or lease personal information for advertising, cross-context behavioral advertising, or marketing purposes unrelated to employer matching. We do not sell the personal information of persons we know to be under 18.

Resume Uploads & Storage

If you create a profile through our self-serve intake page (apply.skimhire.com), you may upload a resume in PDF, DOCX, JPG, PNG, or HEIC format (5 MB maximum). Here is how we handle that file:

  • Text extraction — we extract plaintext from your resume so we can pre-fill the screening questions. PDF and DOCX text is read directly; JPG, PNG, and HEIC images are processed by an open-source OCR engine running on our own servers. The original resume file is not sent to any third-party AI service. After we extract the plaintext on our own servers, that plaintext may be sent to our AI service providers (see “How We Share” above) for limited downstream processing — specifically, pulling location details (city, state, ZIP) from your resume so we can pre-fill the profile form for you.
  • Active-disk storage — the original file is held on our servers in unencrypted form for up to 72 hours after submission so a SkimHire team member can review the file against the parsed data if needed. After 72 hours (or up to 30 days, if a manual quality-check hold has been placed on your file), the original is encrypted and moved to our archive tier.
  • Encrypted archive — the original file is encrypted at rest using industry-standard encryption and held in our archive tier for up to four years past your last recruiting activity (see “Retention” below). Decryption keys are accessible only to SkimHire operators.
  • Extracted text — the plaintext we extracted from your resume is stored in our database and used internally to populate your candidate profile (skills, experience, certifications, contact information, and location). The resume file itself and the extracted plaintext are not included in the personal information we sell to Employers; Employers see only the structured profile fields (see “Categories of Personal Information Sold” below).

Retention

We retain candidate profile, resume, screening, referral, and transaction records for up to four years after the last relevant recruiting activity unless a longer period is required for legal, dispute, security, or compliance purposes.

“Last relevant recruiting activity” means the most recent of: when you were last listed on the marketplace, when an Employer last unlocked your contact information, when you opted out under “Do Not Sell or Share My Personal Information”, or when your record was marked stale because you did not respond to outreach within our re-engagement window. At the four-year mark, we delete the encrypted archive copy of your resume and clear the extracted resume text and screening fields from our database. Aggregate transaction records (for example, the count of unlock credits an Employer purchased) may be retained longer where required for accounting, dispute, or legal-compliance purposes.

You may request earlier deletion at any time by contacting support@skimhire.com; we will honor verified deletion requests subject to the legal exceptions described under “Your Rights” below.

Categories of Personal Information Sold

For candidates who consent to be listed on our marketplace, the following categories of personal information are sold to Employers via the credit-unlock mechanism:

  • Identifiers — name, phone number, email address
  • Professional or employment-related information — work-history summary, skills, certifications, years of experience, availability, pay-rate expectations, driver’s license status
  • Geolocation data — ZIP-level service area

Categories of third parties to whom personal information is sold: pool service companies (“Employers”) operating in SkimHire’s service markets, who have registered an account and purchased one or more unlock credits through our Shopify-powered checkout.

We do not sell:

  • Employer personal information
  • Site-visitor browsing data
  • Candidate information for purposes other than the Employer-unlock mechanism described above (no advertising, no data brokering, no remarketing)
  • The personal information of any candidate who has opted out of “sale” under CCPA/CPRA (see the opt-out process below)

Look-back period: SkimHire is a pre-launch business as of this page’s last-updated date. Once SkimHire begins accepting paid traffic, we will update this section annually with the preceding-12-months disclosure required by CCPA §1798.130(a)(5)(C).

Your Rights

  • Right to know — request what personal information we have collected about you
  • Right to delete — request deletion of your personal information (subject to legal exceptions)
  • Right to opt-out of sale and share — California-resident candidates can direct us not to make their contact information available for purchase by Employers. See “Do Not Sell or Share My Personal Information” below, or use our dedicated opt-out webform. Employers do not have a right to opt out of “sale” because we do not sell Employer information.
  • Right to non-discrimination — we will not treat you differently for exercising your rights

To make a request, email support@skimhire.com. We will verify your identity and respond within 45 days.

Do Not Sell or Share My Personal Information

If you are a California resident whose information appears on our candidate marketplace — or may appear in the future based on an application you submitted to a job posting we operate or source from — you have the right under CCPA/CPRA to direct us not to “sell” or “share” your personal information.

Two ways to opt out

  • Webform (preferred): submit our Do Not Sell or Share opt-out webform. You will need to provide the phone number or email address you used when you first spoke with SkimHire so we can match the request to your record.
  • Email: write to support@skimhire.com with the subject line “Do Not Sell — Candidate Opt-Out”. Include the phone number or email address you used when you first spoke with SkimHire.

What happens after you opt out

Within 15 business days of a verified request we will:

  • Withdraw your profile from the candidate marketplace.
  • Mark your record as “do not sell” so your information is not made available to any new Employer.
  • Retain your record only to the extent required by law or to honor this opt-out in the future.

Employers who previously unlocked your contact information before you opted out will retain that information in their own records. We have no technical ability to recall information that has already been delivered to an Employer; your opt-out stops future sharing only.

For prospective candidates whose data we hold but who are not currently listed

Same process — use the webform or email the address above. We will mark your record as “do not sell” and will not list you on the marketplace.

Global Privacy Control (GPC)

We honor the Global Privacy Control signal sent by your browser as a valid opt-out request under CCPA §7025. Two layers:

  • Site-visitor analytics. When your browser sends GPC, our analytics tag (Google Analytics 4) is not loaded at all on your visit. No measurement ping is sent, no client identifier is set, no consent state is initialized. This applies whether you are signed in or not.
  • Logged-in candidates. If you are signed in to a candidate account on SkimHire and your browser sends GPC, we treat the signal as an automatic opt-out: your profile is withdrawn from the candidate marketplace, suppressions are added across email and SMS, and future sale/sharing of your contact information stops. The reversal flow is the same one used for any opt-out (the “Undo unsubscribe” link from the unsubscribe confirmation page) — if your browser sends GPC by default and the auto opt-out was not what you wanted, the listing can be restored.

If you are not signed in, GPC alone cannot withdraw a candidate profile because we cannot match a browser signal to a specific candidate record without an identity hook. Use the webform or email support@skimhire.com — the methods listed above — and we will match your request to your record manually.

Right to non-discrimination

We will not retaliate against candidates who exercise their CCPA rights. Opting out of sale means your profile is not listed and Employers cannot purchase access to your contact information; this is the direct operational consequence of the opt-out, not discrimination.

Authorized agent requests

You may designate an authorized agent to submit a CCPA request on your behalf. We will require written permission signed by you and will verify your identity directly before fulfilling the request, as permitted by 11 CCR §7063.

Last updated May 8, 2026 · Full Privacy Policy · Do Not Sell or Share