1. Who we are
HireHappy is operated by Xaventra, based in Sri Lanka. In this policy, “HireHappy”, “we” and “us” mean Xaventra and the HireHappy service, including this website, the HireHappy app and the job boards it hosts. You can reach us at [email protected].
2. Customers and candidates
HireHappy deals with two kinds of people:
- Customers: organizations that sign up for HireHappy, and the team members they invite to use it.
- Candidates: people who apply to a customer's jobs through that customer's job board.
For information about team members, HireHappy decides how it's used and is responsible for it (the “controller”).
For information about candidates, the hiring organization is the controller: it decides which jobs to post, what to ask, and what to do with each application. HireHappy processes candidate information on that organization's behalf, to provide the service to them. If you've applied for a job, the organization you applied to is your first point of contact for questions about your application and your data.
3. What we collect
About team members
- Your name and email address, and your password. We never store your password itself, only a one-way hash of it (Argon2).
- Details of your organization, such as its name and job board, and your role in it.
- Activity in the app, such as when you were last active and which applications you've read, so the app can show what's new.
- What you create in HireHappy: job posts, hiring stages, questions, scoring criteria, interviews and calls you schedule, notes, ratings and feedback.
- If you connect a Google account, its email address and an access token (see Google user data).
About candidates
- What you give when you apply: your name, email address, phone number, LinkedIn URL, resume file and answers to the application questions.
- Take-home assessment work you upload (zip files) and your answers to assessment questions.
- Interview and call details, such as times, the people involved and any meeting links.
- What the hiring team records about your application: notes, ratings, feedback, the stage you're at and their decision.
- If a job's criteria ask about it, public profile information from GitHub (see AI features).
When you use the service
Like most web services, our servers handle technical information such as your IP address and browser type in order to deliver pages and keep the service secure.
4. How we use it
- To run HireHappy: sign you in, show your team's jobs and pipeline, accept applications and show candidates the status of their application.
- To send service emails from [email protected], such as email verification, password resets, team invitations, new-application summaries, interview invitations and assessment updates.
- To provide the AI features described below, at the hiring team's request.
- To keep the service secure, prevent abuse, fix problems and improve HireHappy.
- To answer you when you contact us.
We don't sell personal information, we don't show ads, and we don't use your information for advertising.
5. AI features
HireHappy uses Google Gemini (through the Google AI API) to:
- read resumes and fill in application forms from them;
- score applicants against the criteria the hiring team sets;
- draft text for the hiring team, such as stage descriptions, interview focus areas and call guides.
To do this, the relevant resume, application answers and job content are sent to Google's API for processing. When a job's criteria ask about a candidate's public code, HireHappy may read their public GitHub profile through GitHub's API.
AI scores and drafts are aids for the hiring team, not decisions. People on the hiring team decide who moves forward, and they can change any rating.
6. Google user data
Team members can choose to connect their Google account so HireHappy can create Google Meet links for interviews they schedule. Connecting is optional; HireHappy works without it.
What we ask for
openidandemail: to know which Google account is connected, so we can show it to you.https://www.googleapis.com/auth/meetings.space.created: to create Google Meet meeting spaces as you.
What we store
- The connected Google account's email address.
- An OAuth refresh token, encrypted at rest, so we can create meetings when you ask without making you sign in to Google each time.
- The list of permissions you granted, as Google reports it.
How we use it
Only to create a Meet link when you click the Google Meet button while scheduling an interview. The link is saved on that interview and sent to the candidate in the calendar invitation.
HireHappy does not:
- read your calendar, email, contacts or any of your other meetings;
- share your Google user data with anyone;
- use it for advertising;
- use it to develop, improve or train AI or machine learning models.
Disconnecting
You can disconnect at any time in HireHappy under Settings → Google Meet. This deletes the stored token and the stored account details, and revokes HireHappy's access at Google. You can also remove HireHappy's access from your Google account at myaccount.google.com/permissions. Meet links already created stay on the interviews they were made for.
HireHappy's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Who we share it with
Within HireHappy, information stays inside the organization it belongs to: team members only see their own organization's jobs and candidates. Candidates see only the status of their own application, never the team's notes or other applicants.
We use a small number of service providers to run HireHappy. They process information only to provide their service to us:
- Cloudflare R2: object storage for files such as resumes and assessment uploads.
- Our email provider: delivers service emails over SMTP.
- Google (Gemini API): the AI features described above.
- Google (Meet API): creating Meet links, only for team members who connect a Google account.
- GitHub: we read public profile data from GitHub; we don't send candidate information to it.
We may also disclose information if the law requires it, to protect people's safety or our rights, or as part of a merger or sale of the business, in which case this policy would continue to apply.
8. Cookies
HireHappy sets a single cookie: an httpOnly session cookie that keeps you signed in to the app. It's needed for the service to work. We don't use advertising or tracking cookies, and this website doesn't run analytics scripts.
9. Keeping and deleting data
- We keep information for as long as the organization's HireHappy account is active, so the team can see its hiring history.
- Customers can delete candidates and applications in the app at any time.
- You can ask us to access, correct or delete your information by emailing [email protected]. If you're a candidate, please contact the organization you applied to first: they control your application. If you contact us, we'll work with them on your request.
- Disconnecting Google deletes the stored Google token straight away (see Google user data).
10. Security
We take reasonable measures to protect information, including:
- encryption in transit (TLS) between your browser and HireHappy;
- passwords stored only as Argon2 hashes;
- Google tokens encrypted at rest;
- access limited per organization, so one customer can't see another's data.
No service can promise perfect security. If you think something is wrong, please tell us at [email protected].
11. Your rights
Depending on where you live, you may have the right to access the information we hold about you, correct it, delete it, object to or limit how it's used, or get a copy of it.
If you're in the EU or UK, you have these rights under the GDPR (and UK GDPR), and you can also complain to your local data protection authority.
To exercise any of these rights, email [email protected]. Candidates should contact the hiring organization first, as above. We may need to confirm your identity before acting on a request.
12. Where data is processed
HireHappy is operated from Sri Lanka, and our service providers may process information in other countries. Wherever it's processed, we protect it as this policy describes.
13. Children
HireHappy is a tool for hiring and isn't meant for children. If you believe a child has given us personal information, contact us and we'll delete it.
14. Changes to this policy
We'll update this policy when the service changes. When we do, we'll change the “Last updated” date above, and for significant changes we'll let customers know by email or in the app. See also our Terms of Service.
15. Contact us
Questions about privacy or this policy? Email [email protected].