Legal
Privacy Policy
Last updated: 15 September 2026
Supahiro (“Supahiro”, “we”, “us”) is a hiring platform operated by Zuvomo. It helps companies post jobs, screen applicants, schedule interviews and onboard new hires. This policy explains what personal data we handle, why, who we share it with, and the choices you have. It applies to supahiro.co and to the Supahiro application, including company careers pages and candidate pages hosted on it.
1. Who is responsible for your data
Companies that use Supahiro (“customers”) decide which jobs to run and which candidates to consider. For candidate data, the customer is the controller (data fiduciary) and Supahiro processes that data on the customer’s instructions. If you applied to a job, questions about how that company uses your application are best sent to that company; we will also help you reach them.
For account data of the people who sign up to and use Supahiro (“staff users”), and for visitors to supahiro.co, Supahiro is responsible.
2. What we collect
Staff users: name, work email, role, company name, password (stored only as a salted hash), login and activity records, notification preferences, and — if you choose to connect them — calendar accounts (see sections 4 and 5).
Candidates:
- What you submit when applying: name, email, phone, location and work preferences, resume, cover letter and links you provide (e.g. LinkedIn, GitHub, portfolio).
- Information extracted from your resume, such as skills, experience and education, and a match score against the job description.
- Hiring records created by the company: stage, notes, interview schedules, interview feedback and scorecards, assessments, offers, onboarding and background-verification status.
- Messages between you and the company, including email replies you send to a Supahiro reply address, which are added to your conversation with that company.
- If a company uses AI phone screening and you agree to it, the call outcome, duration and — only with your consent — the transcript and a summary.
- Your consent records (what you agreed to and when).
Everyone: basic technical data needed to run and secure the service, such as IP address, browser type and request logs. We use only essential cookies (to keep you signed in and to protect forms); we do not use advertising or cross-site tracking cookies.
3. How we use it
- To provide the service: running job postings and applications, organising candidates, scheduling interviews, sending emails and reminders, and generating reports the customer asks for.
- To run automations the customer turns on, such as screening applicants against a job’s requirements. Customers control these rules, can run them in a preview mode first, and can undo automated stage changes.
- To keep the service secure, prevent abuse and spam, and fix problems.
- To bill customers and meet legal, tax and accounting obligations.
- To send service messages to staff users (for example security notices or changes to these terms).
We do not sell personal data, and we do not use it for advertising.
4. Google user data
A staff user can connect a Google account (for example a company Google Workspace account or their own Google Calendar) so that Supahiro can schedule interviews on it. We request only these permissions:
- See the free/busy times on your calendars (
calendar.freebusy) — to show candidates only the times the interviewer is actually free. We read free/busy blocks only, not event titles, attendees or descriptions. Free/busy times are fetched when slots are shown and are not stored. - View and edit events on your calendars (
calendar.events) — to create, update and cancel the interview events Supahiro schedules, add a Google Meet link, and send invitations to the candidate and interviewer. We store the ID of each event we create so we can update or cancel it; we do not read or change other events. - See your email address (
userinfo.email) — to show which Google account is connected.
Storage and security. The access credentials Google gives us are encrypted at rest and used only by Supahiro’s servers to perform the actions above. Google user data is not shared with other customers, and it is not transferred to third parties except as needed to provide these features, to comply with law, or with your permission.
No AI training, no advertising. We do not use Google user data to develop, improve or train generalised AI or machine-learning models, we do not use it for advertising, and we do not sell it. Our staff do not read it unless you ask us to for support, it is needed for security, or the law requires it.
Your control. You can disconnect a Google account at any time from Settings in Supahiro, which deletes the stored credentials, or remove Supahiro’s access from your Google Account permissions page at myaccount.google.com/permissions.
Supahiro’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Microsoft (Outlook) data
If a staff user connects a Microsoft account, we request permission to sign you in, read your basic profile and email address, and read and write your calendar, with offline access so scheduling works when you are not signed in. We use this in the same limited way as Google: to check when the interviewer is busy and to create, update and cancel the interview events we schedule, including a Microsoft Teams link where available. Credentials are encrypted at rest and removed when you disconnect in Settings; you can also revoke access from your Microsoft account.
7. Security
We use encryption in transit (HTTPS), encrypt sensitive fields at rest (including connected-account credentials, identity documents and chat messages), keep each customer’s data separated from every other customer’s, restrict staff access by role, keep audit logs of important changes, and take regular database backups. No system is perfectly secure; if a breach affects your personal data we will notify affected customers and, where required, the relevant authorities.
8. How long we keep it
We keep account data while the account is active. Candidate data is kept for as long as the customer needs it for hiring, subject to the retention settings the customer chooses; rejected and withdrawn applications can be purged automatically after that period. When a customer closes their account we delete or anonymise their data within a reasonable period, except where we must keep records for legal, tax or security reasons. Backups roll off on a fixed schedule.
9. Your rights
Depending on where you live, including under India’s Digital Personal Data Protection Act, 2023 and the EU/UK GDPR, you may have the right to access, correct or erase your personal data, withdraw consent, object to or restrict certain processing, and receive a copy of your data. Candidates can view and update some of their details in the candidate portal. To make a request, email us at hiring@supahiro.co. Where a customer controls the data, we will pass your request to them and help them respond. You may also complain to your data protection authority.
10. International transfers
Some of our service providers process data outside the country where you live. When that happens we rely on their contractual commitments and appropriate safeguards to protect it.
11. Children
Supahiro is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
12. Changes to this policy
We will update this page when our practices change and revise the date at the top. If a change is significant we will tell customers by email or in the product before it takes effect.
13. Contact and grievances
For privacy questions, requests or complaints, including grievances under the DPDP Act, contact our grievance officer at hiring@supahiro.co. We aim to respond within 30 days.