Privacy Policy
Your data, handled
with care.
Last updated 2 July 2026. This policy explains what we collect, why, and the control you keep over it.
Who we are
CampFire ("we", "us") operates campfire — a talent platform connecting job seekers and employers. For data covered by this policy, CampFire is the data controller. Questions and requests: hello@campfire-talent.com.
What we collect
- Account data — your name, email address, and password (stored only as a salted hash by our authentication provider).
- Profile data — your headline, location, and company details you choose to add.
- CV data — CVs you upload, and the rules-based digest of each one (skills, roles, achievements, seniority, and people-skill summary).
- Assessment data — your answers and the self-reported archetype and skill-signal reports calculated from them.
- Job descriptions — role text employers submit for matching.
- Messages — contact requests and conversations between employers and candidates, and inquiries sent to our team.
- Usage data — aggregate page-area visit counts and error reports. We do not use third-party advertising trackers.
How we use it
- To run the CampFire workspace: CampFire extracts selectable text from uploaded CVs, detects explicit evidence, and compares it with structured job requirements. The process runs inside our backend and does not send CV content to a generative AI provider.
- To connect the two sides of the marketplace: employers see the digests and latest assessment reports of candidates who are visible, and can request contact. Your CV file itself is only shared with an employer through match results while you are visible.
- To send transactional email (verification, password resets, pipeline results, contact notifications) via our email provider, Resend.
- To keep the platform safe: rate limiting, abuse prevention, and security monitoring.
Your visibility, your choice
Job seekers control a Visible to employers switch in Settings. When it is off, employers cannot find your CVs, see your digests or assessment reports, or send you contact requests. Declining a contact request never reveals a reason.
Cookies
We use strictly necessary cookies only: session and security cookies that keep you signed in and protect authentication. We set no advertising cookies.
Retention & deletion
We keep your data while your account is active. Deleting a CV removes the file and its digest immediately. Deleting your account (Settings → Danger zone) permanently removes your profile, CVs, assessment reports, roles, match results, and conversations. Backups age out within 30 days.
Your rights
You may access, correct, export, or delete your personal data at any time — most of it directly in the product, or by emailing us. If you are in the EU/UK, these rights are backed by GDPR; we respond to all requests within 30 days.
Processors we rely on
- Convex — database and file storage
- Resend — transactional email
- Vercel — application hosting
Changes
If this policy changes in a way that matters, we'll notify you by email or an in-product notice before the change takes effect.