Privacy Policy

Effective date: July 28, 2026

This Privacy Policy explains how DataSpark Tech LLC ("we," "us") collects, uses, and protects information in connection with HRGrove(the "Service") at hrgrove.com or any successor domain. It applies to workspace account holders and visitors to our marketing site. For the employee and candidate data our business customers submit to the Service, see Section 2 below and our Data Processing Addendum, which describes our role as a service provider/processor rather than the party who decides why and how that data is collected.

The Service is currently offered only to customers and users located in the United States. If that changes, we'll update this policy accordingly.

1. Information we collect directly from you

Account information. When you create a workspace we collect your name, work email, a securely hashed password (we never see or store it in plain text), and the company details you provide (company name, address, logo, brand color, industry).

Billing information. If you subscribe, our payment processor Stripe collects and stores your payment method details directly. We never see or store your full card number. We do receive billing-related information from Stripe such as your subscription status, plan, and transaction history.

Communications. If you contact support or reply to our emails, we keep a record of that correspondence to help you and improve the Service.

Usage & device data. Basic technical logs (IP address, browser type, device information, pages visited, timestamps) used for security, fraud prevention, debugging, and to improve the Service.

2. Information our customers submit about their employees & candidates

As an HR platform, the Service stores information our business customers ("Customers") add about their employees and job candidates: names, contact information, roles, employment type, compensation, start dates, onboarding and time-off records, performance notes, resumes and job applications, documents, and e-signatures. For this data, the Customer is the controller/business that decides what to collect and why. We process it as their service provider, solely to provide the Service to them, following their instructions and our DPA. If you're an employee or candidate whose information is in the Service, see Section 8 for how to exercise your rights, and Section 9 for who to contact.

Sensitive identifiers (e.g. Social Security Numbers). Where a Customer chooses to collect a Social Security Number or similar tax ID as part of onboarding paperwork (e.g. Form I-9/W-4 workflows), that value is protected with dedicated field-level encryption (AES-256-GCM) at rest, on top of our standard database encryption. It's stored separately from the rest of an employee's record and is not included in the context we send to our AI provider (Section 4).

3. How we use information

We use information to operate the Service: authenticate you, store and display your HR data, generate documents, process payments, send service-related emails, provide support, monitor and improve performance and security, detect and prevent fraud or abuse, and comply with legal obligations. We do not sell personal information, and we do not use employee or candidate personal information for advertising or to build profiles unrelated to providing the Service.

4. AI features — what's shared with our AI provider

Some features send limited, relevant context to our AI provider, Anthropic, to generate a response:

Offer letters send role title, employment type, compensation, start date, manager name, and company name/location. Onboarding checklists send role and start-date information. The HR assistant sends the question you type (and recent chat history) plus general company context. Resume scoringsends the candidate's resume content and the job posting it's being matched against. We do not send Social Security Numbers, passwords, or payment information to our AI provider. Anthropic processes these requests to generate the output and does not use this data to train its models under our agreement with them.

AI-generated content is a draft for your review, not legal advice. See our Terms of Service for the full disclaimer.

5. Where your data lives & who we share it with

We don't sell your data. We share it only with the service providers ("subprocessors") below, each engaged to help us run the Service, when required by law or to protect our rights, or in connection with a merger, acquisition, or sale of assets (in which case this policy's protections continue to apply to previously collected data):

Supabase: database, authentication, and file storage, hosted in the United States. Every customer's data is isolated at the database level using row-level security; one customer can never query another's records.
Vercel: application hosting and content delivery.
Stripe: payment processing and subscription billing.
Anthropic: AI processing for the features described in Section 4.
Resend: transactional email delivery (e.g. signature requests, interview scheduling, support replies).
Google (Google Analytics): aggregate traffic analytics on our public marketing site only, as described in Section 6. Not used inside the signed-in application.
Cloudflare: bot and abuse protection (Turnstile) on our public sign-up and contact forms.
Slack, Microsoft Teams: only if a Customer chooses to connect these integrations, to send notifications or schedule interviews; data shared with them is limited to what that integration needs and controlled by the Customer's settings.

We enter into appropriate data protection terms with our subprocessors and remain responsible for their handling of your data as described in this policy. We'll update this list if it changes materially.

6. Cookies & analytics

Strictly necessary cookies.We use cookies for authentication and session management (set by our infrastructure provider, Supabase). These are required for the Service to work and can't be switched off.

Analytics.Our public marketing site uses Google Analytics 4 to understand aggregate traffic patterns — which pages are visited, roughly where visitors come from, and how they move through the site. This sets first-party Google Analytics cookies (for example _ga) and shares page-view data and a truncated IP address with Google, acting as our subprocessor. We use it only to improve the site. We don't use advertising or cross-site tracking cookies, we don't run remarketing or ad personalization, and we don't sell or share personal information for advertising purposes.

Your choices.You can opt out of Google Analytics by installing Google's browser opt-out add-on, or by using your browser's cookie-blocking settings. Analytics runs only on our public marketing pages — it is not loaded inside the signed-in application, so the employee and candidate records our customers store in HRGrove are never sent to Google.

7. Security

We use industry-standard measures: encrypted connections (TLS 1.2+) for all data in transit, encryption at rest, additional field-level encryption for Social Security Numbers, hashed passwords (we never store plaintext passwords), row-level tenant isolation between customers, optional two-factor authentication, role-based access controls, and audit logging of sensitive actions. No system is perfectly secure. If we become aware of a security incident affecting your personal information, we'll notify affected Customers without undue delay and in a manner consistent with applicable law. Report suspected security issues to info@hrgrove.com.

8. Your rights

If you're a Customer (account holder). Depending on your state, you may have rights to access, correct, export (in a portable format), or delete your personal information, and to opt out of the sale or "sharing" of personal information (we don't engage in either) and of certain targeted advertising (we don't do this either). These rights are available under laws such as the California Consumer Privacy Act (CCPA/CPRA) and comparable laws in other states (for example Virginia, Colorado, Connecticut, Utah, and others that have since adopted similar frameworks). We won't discriminate against you for exercising these rights. To exercise a right, email info@hrgrove.com; we'll verify your identity before acting on the request and respond within the time required by applicable law.

If you're an employee or candidate whose information a Customer entered into the Service,that Customer (your employer or prospective employer) controls that data and is the right party to direct requests to in the first instance, since they determine what's collected and why. We'll support our Customers in fulfilling verified requests from their employees and candidates, and will also honor direct requests we're legally required to act on ourselves.

9. Data retention & deletion

We retain Customer Data for as long as the workspace is active. You may request export or deletion of your workspace data at any time by emailing us; we'll complete verified deletion requests within 30 days, except where we're required to retain information by law (for example, certain billing and tax records). After a subscription is cancelled or terminated, we retain Customer Data for up to 30 days to allow for export or reactivation, after which we delete or anonymize it unless legally required to retain it longer. Backups are overwritten on a rolling schedule and aren't retained indefinitely.

Employers, not HRGrove, are responsible for retaining any employee or candidate records they're independently required to keep under employment, tax, or immigration law (for example I-9, W-4, or payroll records) for periods longer than the export window above. We recommend exporting anything you're required to keep before cancelling or requesting deletion.

10. Children

The Service is a business tool and isn't directed to, or knowingly used by, individuals under 18. If we learn we've collected personal information from someone under 18 without appropriate authorization, we'll delete it.

11. Changes to this policy

We'll post changes to this policy here and update the effective date. For material changes, we'll announce them in the app or by email before they take effect.

12. Contact

DataSpark Tech LLC · info@hrgrove.com