Privacy Policy
Last updated July 14, 2026
Effective date: July 14, 2026. This Privacy Policy explains how hira.work, an individual sole proprietor operating the Hira service (the “Operator”, “we”, “us”), collects, uses, and shares personal information in connection with hira.work and the Hira service (the “Service”). For GDPR/UK GDPR we are the data controller; for U.S. state privacy laws (such as the CCPA/CPRA) we are the business.
Plain-language summary
This summary is for convenience only and is not part of the Policy.
- What we collect today: essentially just the email address you submit to join the waitlist, plus limited technical data our hosting providers process to run and secure the site.
- Analytics: we use privacy-friendly, cookieless web analytics (Vercel Web Analytics and Speed Insights) to see aggregate visit and performance numbers. It sets no cookies, stores no IP address, and does not track you across sites.
- We do not use advertising, ad networks, or third-party ad trackers on the website, and we do not sell or share your personal information.
- Later: when the paid product launches, we’ll also process account and payment data (payments handled by Stripe). Those parts are clearly marked below.
- Your rights: you can ask us to access, correct, or delete your data, or to be removed from the waitlist — email hello@hira.work.
1. Who this applies to
The Service is intended for business users aged 18 or older. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. As of the effective date the only live feature is the waitlist; sections describing accounts and payments apply when the paid product launches.
2. Information we collect
Information you provide. When you join the waitlist we collect the email address you submit and the date/time of sign-up. If you email us, we receive your message and email address. When the paid product launches, we may collect account information (name, email, credentials) and limited payment details from Stripe (such as a confirmation, the last four digits of a card, and billing country) — we do not collect or store full payment-card numbers.
Information collected automatically. Like any website, our hosting providers process technical data such as your IP address, browser and device type, referring page, and timestamps in server logs, to operate, secure, and troubleshoot the Service.
Analytics. We use Vercel Web Analytics and Speed Insights to understand aggregate traffic and site performance — for example, page views, referring sites, approximate location by country, device and browser type, and web-vitals timings. This analytics is privacy-friendly and cookieless: it does not set cookies, does not store your IP address, and does not track you across websites or over time. The data is aggregated and is not used to identify you.
What we do not do. We do not use advertising, ad networks, cross-site trackers, or cookie-based tracking on the website. We do not sell or “share” (as defined by the CCPA/CPRA) your personal information, and we do not intentionally collect sensitive personal information through the waitlist.
The hiring data Hira analyzes. Hira interprets publicly available job postings that companies publish themselves (Greenhouse, Lever, Ashby, Workable). This is about companies and roles and is generally not personal information about you. We do not scrape private or gated data.
3. How we use information
- Operate the waitlist and notify you about the launch, the lifetime deal, and related updates you signed up for;
- Respond to your questions and support requests;
- Operate, secure, and improve the Service, and prevent fraud and abuse;
- Provide the paid product and process payments (when available); and
- Comply with law and enforce our Terms.
4. Legal bases (GDPR / UK GDPR)
Where GDPR or UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Adding you to the waitlist and emailing launch updates | Consent — you can withdraw at any time |
| Operating and securing the Service (server logs) | Legitimate interests |
| Providing the paid product and your account (when live) | Performance of a contract |
| Keeping payment, tax, and accounting records (when live) | Legal obligation |
| Responding to your requests and enforcing our Terms | Legitimate interests |
5. Cookies and tracking technologies
The website uses no cookies today — not even for analytics. Our analytics provider (Vercel Web Analytics) is cookieless and measures aggregate visits without storing your IP address or tracking you across sites, so it does not require a consent banner under the ePrivacy Directive or GDPR. The waitlist form works without setting tracking cookies, and we do not use advertising or third-party ad-tracking technologies. When the paid product launches we expect to use strictly necessary cookies to keep you signed in and secure your account. If we ever introduce non-essential cookies or tracking that requires consent, we will update this Policy and ask for your consent first.
6. How we share information (subprocessors)
We do not sell your personal information. We share it only with service providers who process it on our behalf under contract, and where required by law. Our current providers:
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Vercel Inc. | Website hosting, infrastructure, and cookieless web analytics | Technical/log data; aggregate, non-cookie analytics (page views, referrer, country, device) | United States |
| Neon Inc. | Managed Postgres database (stores the waitlist) | Email address and sign-up timestamp | United States |
| Resend | Transactional email (your invite) — when enabled | Email address and email content | United States |
| Stripe, Inc. | Payment processing — when the paid product launches | Billing and transaction data | United States |
We may also disclose information to comply with law or a lawful request; to protect our rights, safety, or property, or those of others; and in connection with a merger, sale, or other business transfer (in which case we will require the recipient to honor this Policy or notify you).
7. International data transfers
We are based in, and use service providers located in, the United States. If you access the Service from outside the U.S. (including the EEA, UK, or Switzerland), your personal information will be transferred to and processed in the United States. Where we transfer personal information out of the EEA, UK, or Switzerland, we rely on appropriate safeguards, such as the EU-U.S. Data Privacy Framework where a provider is certified and/or the European Commission’s Standard Contractual Clauses (with the UK Addendum). Contact us for more information about these safeguards.
8. Data retention
- Waitlist email: kept until you ask to be removed, until you delete your data, or until we discontinue the waitlist — whichever comes first — then deleted or anonymized.
- Server/log data: a limited period (typically up to a few weeks) as configured by our infrastructure providers.
- Account data (when live): for as long as your account is active.
- Payment, tax, and accounting records (when live): as long as required by law.
9. Security
We take reasonable technical and organizational measures to protect personal information, including encryption in transit (HTTPS/TLS), reputable infrastructure providers, access limited on a need-to-know basis, and data minimization. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your privacy rights
Depending on where you live, you may have some or all of these rights, and we will not discriminate against you for exercising them.
GDPR / UK GDPR (EEA, UK, Switzerland): access, rectification, erasure, restriction, objection (including to direct marketing), data portability, withdrawal of consent, and the right to lodge a complaint with your local supervisory authority (in the UK, the ICO).
U.S. state rights (California and similar): to know/access, delete, and correct your personal information; to opt out of the “sale” or “sharing” of personal information (we do not sell or share it); to limit the use of sensitive personal information (we do not use it for such purposes); and non-discrimination.
How to exercise your rights. Email hello@hira.work. We will verify your identity (for example, by confirming control of the email associated with your data) and respond within the time required by law (generally 30 days under GDPR, or 45 days under the CCPA/CPRA, with extensions where permitted).
11. Children’s privacy
The Service is for business users 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us and we will delete it.
12. Third-party links
The Service and our blog may link to third-party websites. We are not responsible for their privacy practices; review their policies before providing personal information.
13. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will update the “Last updated” date and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect means you accept the updated Policy.
14. How to contact us
For any privacy question or to exercise your rights, email hello@hira.work. Data controller: hira.work, sole proprietor. If you are in the EEA or UK and believe we have not resolved your concern, you may complain to your local data-protection supervisory authority. See also our Terms of Service.