1. Introduction
Hives.work ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, process, and disclose your information when you use our AI-powered cover letter generation service.
This policy applies to all users globally and complies with the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable privacy laws.
2. Information We Collect
2.1 Personal Information
We collect the following types of personal information:
Account Information:
- Name and email address
- Authentication credentials (managed by Clerk)
- Subscription and billing information
Profile Information:
- Contact details (address, phone number)
- Professional information (work history, skills)
- Resume and career-related documents
Generated Content:
- Cover letters created using our service
- Chat conversations with our AI
- Document preferences and templates
2.2 Technical Information
Automatically Collected:
- IP address and location data
- Device type, browser, and operating system
- Usage patterns and feature interactions
- Session duration and page views
Analytics Data:
- Google Analytics data (anonymized)
- Vercel Analytics data
- PostHog analytics data (when implemented)
3. How We Use Your Information
3.1 Primary Purposes
- Service Delivery: Generate cover letters using AI
- Account Management: Maintain your account and preferences
- Payment Processing: Handle subscriptions and billing
- Customer Support: Respond to inquiries and resolve issues
3.2 AI Processing
- Your content is processed by Microsoft Azure OpenAI
- Processing occurs in real-time for content generation
- We do not currently use your data to train AI models
- Future AI training will be opt-in only
4. Legal Basis for Processing (GDPR)
We process your personal data based on:
- Contract Performance: To provide our services
- Legitimate Interest: To improve and secure our service
- Consent: For optional features and communications
- Legal Obligation: To comply with applicable laws
5. Data Sharing and Disclosure
5.1 Third-Party Services
We share data with trusted partners:
Microsoft Azure OpenAI:
- Content for AI processing
- Covered by Microsoft's privacy terms
Clerk:
- Authentication and billing data
- Industry-standard security practices
Analytics Providers:
- Google Analytics (anonymized usage data)
- Vercel Analytics (performance data)
- PostHog (when implemented, anonymized data)
6. Data Storage and Security
6.1 Security Measures
- Encryption in transit and at rest
- Access controls and authentication
- Regular security audits and monitoring
- Industry-standard protection practices
6.2 Data Retention
- Account data: Retained while your account is active
- Generated content: Stored until account deletion
- Analytics data: Anonymized and aggregated
- Backup data: Securely deleted within 90 days of account deletion
7. Your Privacy Rights
7.1 GDPR Rights (EU Users)
You have the right to:
- Access: Request copies of your personal data
- Rectification: Correct inaccurate information
- Erasure: Delete your personal data ("right to be forgotten")
- Portability: Receive data in a portable format
- Restriction: Limit processing of your data
- Objection: Object to processing based on legitimate interest
- Withdraw Consent: Revoke previously given consent
7.2 CCPA Rights (California Users)
You have the right to:
- Know what personal information is collected
- Delete personal information
- Opt-out of the sale of personal information (we don't sell data)
- Non-discrimination for exercising your rights
7.3 Exercising Your Rights
To exercise your rights:
- Email us at privacy@hives.work
- Use in-app privacy controls
- Delete your account (automatic data deletion)
Response time: Within 30 days (GDPR) or 45 days (CCPA)
8. Cookies and Tracking
8.1 Types of Cookies
Essential Cookies:
- Authentication and session management
- Security and fraud prevention
Analytics Cookies:
- Google Analytics (can be opted out)
- Usage statistics and performance monitoring
9. International Transfers
We may transfer data to:
- Microsoft Azure (global infrastructure)
- Service providers outside your country
- Countries with adequate protection levels
Safeguards: Standard Contractual Clauses (SCCs), adequacy decisions, and binding corporate rules ensure your data remains protected during international transfers.
10. Children's Privacy
- Our service is not directed to children under 13
- We do not knowingly collect data from children under 13
- Parents may contact us to delete a child's information
- We will delete such information promptly upon discovery
11. Changes to Privacy Policy
- Material changes will be emailed to users
- Notice posted on our website
- Continued use implies acceptance
12. Contact Information
12.1 Privacy Officer
For privacy-related inquiries:
Email: privacy@hives.work
Address: [INSERT YOUR BUSINESS ADDRESS]
Response time: Within 5 business days
12.2 Data Protection Authority
EU users may contact their local Data Protection Authority to:
- File complaints about data processing
- Seek guidance on privacy rights
- Report privacy violations
This Privacy Policy is effective as of January 15, 2025. By using Hives.work, you acknowledge that you have read and understood this Privacy Policy.