Privacy Policy
1. Introduction
This Privacy Policy explains how personal data is collected, used, and protected in connection with the Feedbook service, available at feedbook.dev (the “Service”). Feedbook is a recruiting workflow application that helps hiring teams manage candidate résumés, evaluations, and interview scheduling.
The Service is currently operated as a private beta. The data controller for the purposes of the EU General Data Protection Regulation (GDPR) is the operator of feedbook.dev. Because the Service is offered pseudonymously during the beta period, all data-protection correspondence is handled through a single dedicated contact address: privacy@feedbook.dev.
2. Data We Collect
We collect and process the following categories of personal data:
- Account information. The name and email address you provide when creating an account, together with authentication metadata (hashed password, OAuth identifiers).
- Candidate and résumé data. Résumés, CV files, contact details, work history, and evaluation notes that account holders (recruiters and hiring managers) upload or enter into the Service in the course of their hiring workflow.
- Google Calendar data. When you connect a Google account, we access the Google Calendar API to read your free/busy availability and to create, update, or cancel calendar events representing interviews you schedule through the Service.
- Technical data. IP address, user-agent string, and basic request metadata used to secure sessions, detect abuse, and diagnose errors. Session cookies used to keep you signed in.
3. How We Use Your Data
Personal data is used only for the following purposes:
- To provide and operate the recruiting workflow features of the Service.
- To create, read, update, and cancel calendar events on your behalf through the Google Calendar API when you schedule or reschedule interviews.
- To send transactional email such as password resets, invitations, and workflow notifications you have opted into.
- To secure the Service against fraud and abuse and to diagnose technical problems.
- To comply with applicable legal obligations.
We do not use your data for advertising, profiling for marketing purposes, or automated decision-making that produces legal effects concerning you.
4. Google API Services User Data Policy
In practice this means that data accessed through Google APIs (in particular, Google Calendar data) is used solely to provide the interview-scheduling features described in this Policy. It is not sold, not used for advertising, not used to train generalized machine-learning models, and not disclosed to third parties except as strictly necessary to provide those features, to comply with applicable law, or as expressly authorized by you.
5. Data Sharing
We do not sell personal data. We do not share personal data with advertising networks or data brokers. We share limited data only with the following categories of processors, each of which is bound by a written data-processing agreement:
- Our hosting provider, which supplies the cloud infrastructure on which the Service runs.
- Our email infrastructure provider, used to deliver transactional email such as invitations, password resets, and workflow notifications.
- Google, when you have connected a Google account, for the sole purpose of reading your calendar availability and creating or updating calendar events you initiate through the Service. Because Google is a US-based provider, calendar data processed through the Google Calendar API is transferred to the United States under Google’s Standard Contractual Clauses.
We may also disclose data where required by a valid legal request, or where necessary to protect the rights, property, or safety of the Service, its users, or the public.
6. Data Retention
- Account and candidate data are retained for the life of your account. When an account is deleted, associated résumés and candidate records are permanently deleted within 30 days, subject to any shorter periods required by law.
- Google Calendar tokens are stored only while your Google integration is connected and are revoked immediately when you disconnect the integration or delete your account.
- Server and access logs are retained for up to 90 days, after which they are automatically deleted.
7. Your Rights
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction that grants comparable data-protection rights, you have the right to:
- access the personal data we hold about you;
- request rectification (correction) of inaccurate or incomplete data;
- request erasure of your data (“right to be forgotten”);
- request restriction of, or object to, processing;
- receive a portable copy of the data you have provided; and
- lodge a complaint with your local data-protection authority.
To exercise any of these rights, email privacy@feedbook.dev. We will respond within 30 days.
8. Security
All connections to the Service are encrypted in transit using TLS. Data at rest is protected using industry-standard encryption. Access to production systems is restricted and logged. We apply security updates on a regular schedule and monitor the Service for anomalous activity. No system is perfectly secure; if you become aware of a vulnerability, please report it to privacy@feedbook.dev.
9. Cookies
The Service uses first-party session cookies solely to keep you signed in and to maintain basic application state. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. Because we do not place any non-essential cookies, no cookie consent banner is required under the ePrivacy Directive.
10. Changes to This Policy
We may update this Policy from time to time. When we do, we will update the effective date at the top of the page and, for material changes, provide reasonable advance notice through the Service or by email. The current version of this Policy is always available at feedbook.dev/privacy.
11. Contact
Questions about this Policy or about how your personal data is handled should be directed to privacy@feedbook.dev.