Privacy Policy
Last updated August 23, 2026
1. Overview
Hiered LLC, a Michigan limited liability company (“we,” “us,” or “our”), operates the Hiered platform at hiered.net — a service connecting students, campus organizations, and recruiters. This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using Hiered, you agree to the practices described here.
As the platform changes, our data practices may change with it. We will update this policy and notify users of material changes — see section 13.
2. Information we collect
Information you provide
- Account details: first and last name (or organization name), email address, username, and password (hashed by Supabase Auth — never stored in plaintext)
- Profile information: biography, avatar, LinkedIn URL, website, public contact email, phone number, location, school, class year, and your current job title, company, and industry
- Your resume, if you upload one, along with the filename you gave it
- Organization data: name, description, school affiliation, organization type, website, custom stats, member roster, position titles and hierarchy, and year recap photos and descriptions
- Recruiter data: company name, job title, industry, work email, and affiliated organizations
- Content and actions: bulletin posts, interest reactions, join, affiliation and invitation requests, resume-access requests and decisions, saved profiles, and reports you submit
- Verification submissions: the email address you verify and the review request it creates
- Payment information: processed directly by Stripe — we never see or store your card number
Email addresses an organization gives us about you
An organization admin can import a spreadsheet of their members' email addresses so we can invite those people to Hiered. When they do, they must affirm that the people listed are members of their organization and that they are authorized to share the addresses with us; we store that affirmation alongside the admin's account ID and the time they made it.
We use an imported address for one thing: a single invitation email naming the organization that supplied it. It is not added to any mailing list, is not sold or shared, and does not create an account or place anyone on a roster — the recipient decides whether to sign up, and after signing up still decides whether to accept the organization's invitation. Every invitation carries a link that stops Hiered from sending invitations to that address again, from any organization. Only organizations we have verified can invite an address that does not already belong to a Hiered account.
If you receive an invitation you did not expect, the fastest remedy is the opt-out link in it; you can also contact us using the details in section 14.
Information collected automatically
- Profile and organization page views, including who viewed (see section 6), and other feature usage
- Resume view records — which recruiter opened which member's resume, and when — used to enforce monthly limits and to show members who has viewed theirs
- IP address and browser type, collected by our hosting infrastructure and used for rate limiting and abuse prevention
- Cookies and session tokens managed by Supabase Auth. We do not use advertising or third-party tracking cookies.
- Error and performance diagnostics, which may include your account ID and the page you were on
- Moderation and audit records: suspension reasons, member-removal logs, and admin action logs
3. How we use your information
- To operate the platform: authentication, profile display, search, rosters, hierarchies, and bulletin boards
- To process payments via Stripe and manage subscription status
- To send transactional emails (verification codes, account and security notices, organization and resume requests, suspension notices, and billing notices) via Resend
- To send a single invitation email to an address an organization imported, naming the organization that supplied it, with a one-click opt-out
- To power candidate search and matching across roles and organizations
- To show you analytics about views of your own profile or organization page
- To verify email addresses and review verification requests before granting a badge
- To apply rate limits, detect automated abuse, and diagnose errors
- To review reports of harmful content and enforce our Terms of Service
We do not use your data to train machine learning models, and we do not run advertising on Hiered.
4. Data sharing
We do not sell your personal data. We share information only with:
- Supabase — database, authentication, and file storage (EU/US infrastructure)
- Stripe — payment processing. Governed by Stripe's Privacy Policy
- Resend — transactional email delivery
- Vercel — hosting and infrastructure
- Cloudflare — DNS, DDoS protection, and the Turnstile check on our signup and login forms (request metadata only)
- Upstash — the rate-limit counters that protect login, signup, and resume access
- Sentry — error monitoring and diagnostics
- Law enforcement when required by a valid legal process, and others where we must to protect the safety, rights, or property of users or the public
- Our staff, who can view any account — including a suspended one — in order to review reports, decide verification requests, and provide support
- A buyer or successor, if Hiered is involved in a merger, acquisition, financing, or sale of assets — in which case we will notify you before your data becomes subject to a different privacy policy
5. What is public, what is not
Organization pages
Organization pages are public: anyone on the internet can view an organization's overview and its hierarchy and recap without an account, and we submit those pages to search engines. The alumni directory, bulletin board, and affiliated-recruiter tabs require membership or affiliation. There is no private-organization setting.
Member and recruiter profiles
Profiles require a Hiered account to view. Signed-out visitors see only a name, avatar, and verification badge. Members can additionally set their profile to private, which hides everything below that same minimal card — biography, experience, contact details, links, location, school, employer, and resume — from everyone but themselves, and stops their profile views from being recorded. Our staff can still view profiles that are private or suspended, which is what lets us act on reports. Recruiter and organization accounts are always public to signed-in users, since being findable is the point of those account types.
Contact details
Your public contact email is shown on your profile to signed-in users. It starts out as the address you signed up with; you can change it or clear it entirely in settings, and clearing it stops us publishing an address for you. Your sign-in email address is never shown to other users and is never included in data exports.
Resumes
Your resume is never public and is never visible to guests, to other members, or to unverified recruiters. See section 7.
6. Profile views and analytics
When a signed-in user views your profile or your organization page, we record that view and show it to you in your analytics — including the viewer's name. Views are counted once per viewer per month rather than per visit. Members with a private profile are not tracked and do not appear as viewers. Recruiters who open your resume are recorded separately and shown to you.
7. Resume access
You choose who can open your resume, from four settings:
- Verified recruiters — any recruiter whose work email we have verified
- Verified + affiliated — only verified recruiters affiliated with an organization you belong to
- Verified + approved by you — verified recruiters must request access, and you approve or decline each one individually
- Hidden — nobody but you
A verified recruiter is the floor under all of these: members, guests, and unverified recruiters can never open a resume, whichever setting you pick. Resume files are stored privately and served only through short-lived signed links after we check your setting on every request. If you use the approval setting, you can revoke any approval at any time, and we keep a record of requests and decisions so that limits on re-requests can be enforced. Declining a request is silent — we do not email the recruiter about it.
8. Data retention
We retain your data for as long as your account is active. You can delete your account yourself at any time from your account settings; an organization is deleted from its settings, which also removes the organization's login account. Deletion is permanent and immediate — your profile, resume, avatar, and associated content are removed and any live subscription is canceled. Records that are not about you alone may be retained after deletion where we need them: moderation and audit logs, notifications already delivered to other users, and billing records held by Stripe under their own retention policy. A suspended account's data is retained so the suspension can be reviewed or lifted. Verification codes are deleted as soon as they are used or expire.
Unsent and unclaimed organization invitations expire 30 days after they are sent. An address that has opted out of invitations is kept indefinitely on our do-not-contact list, and for that purpose alone — it is the only way to recognize the address and honor the choice if an organization uploads it again.
9. Security
All data is transmitted over HTTPS. Passwords are hashed by Supabase Auth and never stored in plaintext. Our service role database key is server-side only and never exposed to client code. We apply row-level security policies on user-facing tables, and sensitive profile columns — sign-in email, phone number, contact email, and resume details among them — are readable only by our server, never by the browser directly. Despite these measures, no system is perfectly secure — use a strong, unique password. If we become aware of a breach affecting your personal data, we will notify you and any regulator we are required to notify, without undue delay.
10. Children's privacy
Hiered is for people aged 16 and over. It is not directed at children, we do not knowingly collect personal information from anyone under 16, and we delete such an account and its data when we learn of one. If you believe someone under 16 has provided us with personal data, contact us and we will remove it promptly.
11. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, export a copy, delete it, or object to or restrict certain uses. Most of this is self-serve: you can edit your profile and privacy settings, and delete your account, from your account settings. For anything else, email privacy@hiered.net. We will not treat you differently for exercising any of these rights, and we will respond within the time your law allows.
California. We do not sell your personal information and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA — and we have not done so in the preceding 12 months. The categories we collect, why, and who we disclose them to are described in sections 2 through 4.
Outside the United States. Hiered is operated from the United States and our service providers process data in the United States and the European Union, so using Hiered involves transferring your data to the United States. Where the law requires a transfer mechanism, our providers rely on Standard Contractual Clauses.
12. Verification & badges
How email verification works
When you create a Hiered account or verify a secondary email address in settings, we send a one-time 6-digit code to prove you control that address. The code is hashed (SHA-256 with a random per-request salt) before being stored — we never retain the plaintext code. Codes expire after 10 minutes and are deleted immediately after a successful verification attempt.
The .edu verified badge
If the email address you verify ends in .edu, your profile automatically receives the verified badge. This badge signals that you have demonstrated control of a .edu email address. It does not guarantee current enrollment, graduation, or affiliation with any particular institution. If your school does not use a .edu domain, verifying that address instead sends the request to us for manual review.
The recruiter verified badge
Recruiters who verify a work email address go through a manual admin review before the badge is granted. We confirm the email domain appears to belong to a legitimate company. The badge does not guarantee the recruiter's employment status, seniority, or the legitimacy of any specific job posting.
The organization verified badge
An organization can request verification of the school it says it belongs to. It is granted by manual admin review and attests only to that claim.
When a badge is revoked
A badge attests to a specific fact we checked, so it is revoked as soon as that fact changes — a recruiter changing their work email, a member moving off a school address, or an organization changing its school affiliation. We tell you in the app when this happens, and the claim is re-queued for review automatically.
Data handling
Verified email addresses and badge status are stored in your profile. Verification codes (hashed) are deleted once used or expired. Verification review requests visible to Hiered admins are retained for audit purposes.
13. Changes to this policy
We may update this policy from time to time. We will notify users of material changes via a platform announcement or email. Continued use of Hiered after changes take effect constitutes acceptance of the updated policy.
14. Contact
Questions about this policy? Email us at privacy@hiered.net.
