Summary
MRHRM (mrhrm.com) provides recruiting, hiring, and HR-related software for businesses and the professionals who use it. This policy explains what personal data we collect, why we collect it, how we use it, and the controls available to you.
We collect the minimum data needed to operate the platform, we use email only for account-related and product communication you opted into, and we never sell your personal information.
Who this policy applies to
This policy covers visitors to mrhrm.com, registered MRHRM users, candidates whose information is uploaded to the platform by an employer or recruiter, and anyone who contacts us through our support channels.
When you use MRHRM as part of an employer or tenant account, that organization is the controller of the personal data they upload, and MRHRM acts as a processor on their behalf.
Data we collect
Account data
When you register, we collect the information you provide such as your first and last name, email address, and the password you set. If you sign in with Google, we receive your basic Google profile (name, email, profile photo) so we can authenticate you.
Profile data
You may add details such as a headline, location, work history, education, certifications, skills, and links. You control what is public, what is visible to your network, and what stays private from your account settings.
Usage data
We log standard server-side request data (IP address, user agent, request paths, and timestamps) for security and reliability. We do not run third-party advertising trackers on the product surface.
Support data
When you email support, we receive whatever information you include in your message. We retain support correspondence so we can resolve your issue and improve the service.
How we use your data
- To create and authenticate your account.
- To deliver core product features (your profile, hiring workflows, messaging).
- To send transactional and account-related emails (sign-up confirmation, email verification, password reset, security alerts, important product changes).
- To answer support requests and to investigate and prevent abuse.
- To improve reliability, security, and product quality.
We do not use your data to train external advertising models, and we do not sell personal information to third parties.
Email communications
MRHRM sends two categories of email:
- Transactional / account emails — sign-up confirmation, email verification, password reset, security notifications, and material product or policy changes. These are sent because they are necessary to operate your account and you cannot opt out without closing your account.
- Optional product emails — digests, product updates, and recruiting activity summaries. These are opt-in and can be turned off any time from notification preferences or by following the unsubscribe link in the message.
Every marketing email includes a one-click unsubscribe link. We honor unsubscribe requests promptly. We do not send unsolicited bulk email and we do not buy or rent email lists.
Legal bases for processing
If you are in a region governed by GDPR or comparable laws, our legal bases are:
- Contract — to provide the service you signed up for.
- Legitimate interests — to keep the service safe, reliable, and improving.
- Consent — for optional product communications and any non-essential cookies.
- Legal obligation — to comply with applicable law and lawful requests.
Data retention
We keep account and profile data while your account is active. If you delete your account, we remove or anonymize personal data within 30 days, except where retention is required by law (for example, billing records).
Protection measures
We use industry-standard controls to protect your data: TLS in transit, encryption at rest for sensitive fields, hashed passwords, scoped API tokens, and continuous monitoring. For our broader operational and legal posture, see Data Protection & Compliance.
No system is perfectly secure. If you believe your account has been compromised, contact privacy@mrhrm.com and use Sign out everywhere from your settings.
Your rights and choices
You can exercise the following rights at any time:
- Access and download your data.
- Correct or update your information from Edit Profile or Settings.
- Delete your account from Settings → Data & Account.
- Manage notification preferences from Settings → Notifications.
- Object to or restrict certain processing where applicable.
To exercise any of these rights, write to privacy@mrhrm.com. We respond within 30 days.
International data transfers
MRHRM operates globally and uses cloud regions in multiple jurisdictions. Where personal data is transferred internationally, we rely on Standard Contractual Clauses or other safeguards approved under applicable law.
Children
MRHRM is not intended for individuals under 16. We do not knowingly collect personal data from children. If you believe a child has used MRHRM, please contact privacy@mrhrm.com and we will remove the account.
Changes to this policy
We may update this policy. When we do, we update the effective date above. For material changes that affect your rights or how we use your data, we notify registered users by email and surface a prompt inside the app.
Contact us
For privacy questions, data requests, or concerns, contact us at privacy@mrhrm.com. For general support, see our Support center.