1.Introduction & Scope
Welcome to WorkoraJobs ("WorkoraJobs", "Company", "we", "us", or "our"). WorkoraJobs operates the enterprise talent marketplace, candidate ATS match systems, and employer hiring platform accessible via https://workorajobs.comand associated API services (the "Platform").
This Privacy Policy details our policies and practices regarding the collection, use, processing, storage, encryption, disclosure, and erasure of personal information provided by job seekers, candidate applicants, employer hiring managers, enterprise recruiters, and website visitors.
By accessing or using WorkoraJobs, creating an account, uploading a resume/CV, authenticating via Google or LinkedIn Single Sign-On (SSO), or posting job openings, you acknowledge that you have read and understood this Privacy Policy.
2.Definitions
Personal Data / Personal Information
Any information that identifies, relates to, describes, or is reasonably capable of being associated with a specific individual.
Job Seeker / Candidate
An individual registered on the Platform to search for tech careers, upload resumes, and submit job applications.
Employer / Recruiter
An organization or hiring manager authorized to publish job listings, review candidate applications, and manage recruitment pipelines.
OAuth / Single Sign-On (SSO)
Federated authentication protocols allowing login via third-party identity providers such as Google and LinkedIn.
3.Information We Collect
We collect personal information directly from you when you register, communicate with us, or utilize our staffing services, as well as automatically when you navigate the Platform.
A. Account Information
Full name, primary email address, normalized lowercase email identifier, encrypted password hashes (bcrypt), user role (JOB_SEEKER, EMPLOYER, ADMIN), profile picture URL, and phone number.
B. Employer Information
Company name, official work email domain, company logo, headquarters address, industry sector, company size, corporate website URL, hiring budget preferences, and recruiter contact names.
C. Job Seeker Profile & Resume/CV Uploads
Uploaded resume files (PDF, DOCX format), parsed work experience history, education records, programming languages, skill proficiencies, target job titles, preferred salary range, location/remote preferences, work authorization status, portfolio links (GitHub, personal site), and LinkedIn URL.
D. Payment & Billing Data
Payment transaction metadata, billing addresses, and invoice histories. Complete card numbers are processed directly by our PCI-DSS compliant payment gateway (Razorpay) and are never stored on WorkoraJobs servers.
E. Technical, Device & Analytics Information
IP address, geolocation (country/city level), browser type, browser version, operating system, device classification (Desktop/Mobile/Tablet), session timestamps, page views, clickstream data, HTTP headers, and referrer URLs.
4.Google OAuth & LinkedIn Single Sign-On (SSO)
Third-Party Identity Provider Compliance
WorkoraJobs supports seamless authentication via Google OAuth 2.0 and LinkedIn Developer Platform APIs. When you choose to authenticate using your Google or LinkedIn account:
- Requested Scopes: We request only basic identity scopes:
openid,profile, andemail. - Data Received: We receive your unique provider user ID (
sub), verified email address, full name, and avatar picture URL. - Google API Services User Data Policy: WorkoraJobs' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- No Unauthorized Access: We do NOT access your Google Drive, Gmail inbox, Google Contacts, LinkedIn messages, or private social connections.
- Account Unlinking: You can disconnect your Google or LinkedIn identity from your WorkoraJobs account at any time in Account Settings.
5.Authentication Tokens, Password Reset & Session Management
To ensure zero unauthorized access and resilient account protection, WorkoraJobs implements state-of-the-art enterprise authentication primitives:
- Password Hashing: Plaintext passwords are never stored. All passwords are hashed using
bcryptwith 12 salt rounds before database persistence. - Session Store: User sessions are stored in PostgreSQL and cached in high-performance Redis nodes with in-process LRU memory acceleration. Session tokens are 64-character cryptographically secure hex strings.
- HTTPOnly Cookies: Session tokens are transmitted exclusively via secure
httpOnly,sameSite=laxcookies markedsecurein production environments. - JWT Access Tokens: Signed with SHA-256 HMAC utilizing our enterprise secret (
JWT_SECRET) supporting dual-key secret rotation. - Password Reset & Email Verification: Tokens generated for password resets or email verification are hashed with SHA-256 before storage and automatically expire after 1 hour (resets) or 24 hours (verification).
6.How We Use Information
WorkoraJobs processes personal data exclusively for legitimate business purposes and staffing operations:
Staffing & Application Matching
Connecting candidates with relevant job opportunities and facilitating recruiter outreach.
AI Resume Processing
Extracting skills, generating ATS match scores, and ranking candidate profiles.
Security & Fraud Prevention
Detecting credential abuse, rate-limiting brute force attacks, and verifying employers.
Platform Communications
Sending application updates, job alerts, interview invites, and system notices via Resend email infrastructure.
7.AI Features & Automated Processing
Automated Resume Parsing & Recommendation Engine
WorkoraJobs utilizes machine learning models and NLP algorithms to analyze uploaded resumes, compute ATS compatibility scores, and generate automated job recommendations.
Human Oversight: Automated ATS scores serve as assistive recommendations for employer hiring managers. WorkoraJobs does not make sole automated decisions regarding hiring, rejection, or employment contracts without human review.
8.Communications, Email Notifications & Preferences
We deliver transactional emails (account verification, password reset, interview requests) and optional communications (weekly staffing digest, custom job alerts).
Managing Preferences:You may opt out of promotional communications at any time by clicking the "Unsubscribe" link embedded at the bottom of any marketing email or by updating your notification preferences in Account Settings. Essential transactional and security notifications cannot be disabled while maintaining an active account.
10.Third-Party Subprocessors & Infrastructure Services
WorkoraJobs contracts with vetted, enterprise-certified third-party subprocessors to host infrastructure, process authentication, and monitor service reliability:
| Subprocessor | Purpose & Function | Data Shared | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud Hosting, RDS PostgreSQL, S3 File Storage | Encrypted User & Resume Data | United States / Global |
| Google Cloud & OAuth | Single Sign-On (SSO) & Identity Verification | Google User ID, Email, Name, Avatar | Global |
| LinkedIn Developer Platform | OAuth SSO & Candidate Profile Integration | LinkedIn Profile ID, Email, Name | Global |
| Resend Inc. | Transactional Email Delivery & Job Alerts | Recipient Email, Name, Notice Content | United States |
| Cloudflare Inc. | CDN Cache, DNS, WAF Security & DDoS Shield | IP Address, Request Traffic Metadata | Global Edge Network |
| Razorpay Software Private Limited | Payment Processing & Subscription Billing | Billing Name, Address, Payment Token | United States / Global |
11.Data Security, Infrastructure & Encryption
WorkoraJobs maintains robust administrative, technical, and physical safeguards designed to ensure the confidentiality, integrity, and availability of personal information:
Encryption Standards
TLS 1.3 encryption in transit; AES-256 encryption at rest for database and S3 storage.
Role-Based Access (RBAC)
Strict least-privilege access control protecting database models and administrative tools.
WAF & DDoS Defense
Cloudflare Web Application Firewall and rate limiting guarding API endpoints.
12.Data Retention & Account Erasure
We retain personal data for as long as your account remains active or as needed to provide staffing services. If you delete your account (via POST /api/v1/auth/delete-account), your personal profile, uploaded resumes, and active sessions will be permanently purged from production databases within 30 days, except where retention is required by law.
13.European Union Privacy Rights (GDPR)
If you reside in the European Economic Area (EEA), United Kingdom, or Switzerland, you possess specific data subject rights under the General Data Protection Regulation (GDPR):
- Right of Access: Request a copy of your personal data processed by WorkoraJobs.
- Right to Rectification: Correct inaccurate or incomplete profile information.
- Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your personal records.
- Right to Data Portability: Obtain your profile and resume data in a structured, machine-readable JSON format.
- Right to Object & Restrict Processing: Object to automated processing or direct marketing communications.
14.California Consumer Privacy Act (CCPA / CPRA)
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have the right to know what personal information we collect, request deletion of their personal information, opt out of the sale or sharing of personal information, and receive non-discriminatory service for exercising their rights.
No Sale of Personal Data: WorkoraJobs has not sold any personal information to third parties in the preceding 12 months.
16.International Data Transfers
WorkoraJobs is headquartered in the United States. Personal data collected globally may be transferred to, stored, and processed in AWS data centers located in the United States. For cross-border data transfers from the EEA or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.
17.Children's Privacy (Minimum Age 16+)
WorkoraJobs is an enterprise staffing portal designed for professional job seekers and employers. The Platform is strictly prohibited for individuals under 16 years of age. We do not knowingly collect personal data from children under 16.
18.Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our legal obligations or platform features. We will notify users of material changes by posting an update banner on the Platform or sending an email notification prior to the change taking effect.
19.Contact Privacy Officer
If you have any questions, requests, or privacy concerns regarding this Privacy Policy or wish to exercise your GDPR/CCPA rights, please contact our Data Protection Office: