Privacy Policy

1. Who we are

This Privacy Policy explains how hirebmb ("Service", "we", "us", "our") collects and uses personal data when you use our website at https://hirebmb.com and the hirebmb application.

The data controller is the operator of hirebmb, a sole proprietorship based at 42 Clonminch Place, Tullamore, Co. Offaly, R35 H5R3, Ireland.

Contact: support@hirebmb.com

This policy is written to comply with the EU General Data Protection Regulation (GDPR), the Irish Data Protection Act 2018, and equivalent UK and US state privacy laws where they apply to you.

2. Personal data we collect

We collect the following categories of personal data:

2.1 Account data

  • Email address
  • Name (if you provide it)
  • Profile data you choose to add
  • Authentication identifiers from Google when you sign in with Google (your Google account email, Google ID, profile name, and avatar URL)

2.2 Content you submit

  • Achievements, career events, skills, notes, and any text you enter
  • Files you upload (documents) and URLs you save
  • Any other content you choose to store in the Service

2.3 Billing data

  • Subscription plan and status
  • Stripe customer ID and Stripe subscription ID
  • Billing email and billing country
  • We do not store full payment card numbers. Card data is collected and stored by Stripe.

2.4 Usage and device data

  • IP address (truncated where possible)
  • Browser type, operating system, device type, screen size, language
  • Pages visited, features used, clicks, scroll depth, session duration
  • Referring URL and UTM parameters
  • Error reports and stack traces

2.5 Communications

  • Emails you send us and our replies
  • Support requests and feedback

2.6 AI-generated content

  • Prompts you submit to AI features and the outputs returned to you
  • We pass these to Anthropic (Claude API) for processing on your behalf

3. Why we use your data (purposes and legal bases)

We process personal data on the following legal bases under GDPR Article 6:

Performance of a contract (Art. 6(1)(b)):

  • Creating and operating your account and authenticating you.
  • Providing the core tracking, content, and document features.
  • Processing payments and managing your subscription.
  • Sending transactional emails such as email verification, password resets, billing receipts, and security alerts.
  • Providing customer support.

Legal obligation (Art. 6(1)(c)):

  • Complying with tax, accounting, and other legal obligations.

Legitimate interests (Art. 6(1)(f)):

  • Protecting the Service against abuse, fraud, and security threats.
  • Error tracking and debugging.
  • Product analytics and usage measurement, where consent is not legally required.
  • Providing customer support in cases not strictly covered by the contract.

Consent (Art. 6(1)(a)):

  • Marketing emails and product updates.
  • Analytics cookies and similar technologies where ePrivacy/cookie rules require consent.

You can withdraw consent at any time. Where we rely on legitimate interests, you have the right to object - see Section 8.

4. Who we share your data with (processors and recipients)

We use the following processors. Each acts under a data processing agreement with us and only on our instructions.

  • Stripe - payment processing and subscription billing. Receives your email, billing address, payment method, subscription history, and IP address at checkout. Based in Ireland and the USA.
  • Postmark (ActiveCampaign) - transactional email delivery for verification, receipts, password resets, and security alerts. Receives your email, name, and the message content. Based in the USA.
  • PostHog - product analytics, session events, and feature usage. Receives a pseudonymous user ID, event data, truncated IP address, and device/browser information. Hosted in the EU (Frankfurt).
  • Google Analytics (Google Ireland Ltd.) - aggregated website analytics. Receives an anonymized IP where possible, device information, and page views. Based in the EU and USA.
  • Google (Sign in with Google) - OAuth authentication. Receives your email, Google ID, profile name, and avatar URL when you choose to sign in with Google. Based in the EU and USA.
  • Loops - marketing and lifecycle email, only with your consent. Receives your email, name, and lifecycle events. Based in the USA.
  • Sentry - error monitoring and crash reporting. Receives stack traces, user ID, browser/OS information, and breadcrumb data. Hosted in the EU.
  • Anthropic (Claude API) - AI feature processing. Receives prompt content and any data you include in it. Based in the USA.
  • Our hosting provider - application hosting, database, file storage, and backups. Processes all Service data. Located in the EU.

We do not sell your personal data. We do not share your personal data with third parties for their own marketing.

We may disclose personal data to: (a) law enforcement or other authorities where required by a valid legal request; (b) professional advisers (accountants, lawyers) under confidentiality; (c) a successor entity in the event of a sale, merger, or reorganization of the business.

5. International transfers

Some of our processors are located outside the EU/EEA, primarily in the United States. Where personal data is transferred outside the EU/EEA, we rely on one or more of the following safeguards:

  • EU-U.S. Data Privacy Framework (where the processor is certified, e.g. Google, Stripe).
  • Standard Contractual Clauses ("SCCs") approved by the European Commission.
  • Supplementary technical and contractual measures where required.

You can request a copy of the relevant safeguard by contacting support@hirebmb.com.

6. How long we keep your data

We retain personal data for as long as needed for the purpose it was collected and to meet legal obligations:

  • Account data - while your account is active, then deleted within 30 days of an account deletion request.
  • Content you submit (achievements, files, links, notes) - while your account is active, then deleted within 30 days of account deletion.
  • Billing records, invoices, and tax records - 6 years after the transaction, as required by Irish tax law.
  • Email logs (Postmark) - up to 45 days.
  • Analytics events (PostHog, Google Analytics) - up to 12 months in identifiable form.
  • Error reports (Sentry) - up to 90 days.
  • Support emails - up to 3 years from the last reply.
  • Backups - rolling backups overwritten within 35 days.

After these periods we delete or irreversibly anonymize the data.

7. Cookies and similar technologies

We use:

  • Strictly necessary cookies for authentication, security (CSRF), and load balancing. These cannot be disabled.
  • Analytics cookies / local storage (PostHog, Google Analytics) only after you accept them through our cookie banner where consent is legally required.
  • Stripe sets cookies on its checkout pages for fraud prevention.

You can change your cookie preferences at any time via the cookie settings link in the site footer, and you can clear cookies in your browser settings.

8. Your rights

Under the GDPR and equivalent laws you have the right to:

  • Access a copy of your personal data.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten") subject to legal retention obligations.
  • Restrict processing in certain situations.
  • Object to processing based on legitimate interests, including direct marketing.
  • Portability: receive your data in a structured, commonly used, machine-readable format and transfer it to another controller.
  • Withdraw consent at any time where we rely on consent (this does not affect lawfulness of processing before withdrawal).
  • Not be subject to automated decisions with legal or similarly significant effects (we do not make such decisions).

To exercise any of these rights, email support@hirebmb.com. We respond within one month. If we cannot fulfil your request we will explain why.

You can also lodge a complaint with the Irish Data Protection Commission (https://www.dataprotection.ie) or the supervisory authority in your country of residence. If you are in the UK, you can complain to the Information Commissioner's Office (https://ico.org.uk). If you are in California, see Section 11 for additional rights.

9. Security

We protect personal data with technical and organisational measures.

No system is fully secure. If we become aware of a personal data breach likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and, where required, notify you directly.

10. Children

The Service is not directed to children under 16 (EU) or under 13 (US). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, email support@hirebmb.com and we will delete it.

11. Additional US state rights (California, Virginia, Colorado, Connecticut, Utah, and others)

If you are a resident of certain US states you have additional rights:

  • The right to know what personal information we collect and disclose.
  • The right to delete your personal information.
  • The right to correct inaccurate information.
  • The right to opt out of "sale" or "sharing" of personal information for cross-context behavioural advertising. We do not sell personal information as defined by the CCPA, and we do not share it for cross-context behavioural advertising.
  • The right to non-discrimination for exercising these rights.

To exercise any of these rights, email support@hirebmb.com. We will verify your identity using the email address on your account.

12. Automated decision-making

We do not make decisions that produce legal or similarly significant effects about you using automated processing alone. AI features in the Service produce content for you to review; they do not make binding decisions about you.

13. Third-party links

The Service may link to third-party websites. We are not responsible for the privacy practices of those sites. Read their privacy policies before sharing personal data with them.

14. Changes to this policy

We may update this Privacy Policy. The "Last updated" date at the top reflects the latest revision. For material changes we will notify you by email or in-app at least 15 days before they take effect.

15. Contact

For privacy questions, data requests, or complaints:

hirebmb 42 Clonminch Place, Tullamore, Co. Offaly, R35 H5R3, Ireland Email: support@hirebmb.com

Last updated: 14/05/2026