Privacy Policy
Last updated: March 7, 2026
1. Introduction
MoonTrack™ ATS ("MoonTrack™ ATS," "we," "our," or "us") is a product of Stanley & Akatu HR Partners, Africa and is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your information when you use MoonTrack™ ATS, our AI-powered recruitment platform (the "Service").
This Policy applies to all users of the Service, including hiring-team members ("Users"), job candidates ("Candidates"), and visitors to our public-facing pages ("Visitors"). Where we process personal data on behalf of our customers as a data processor, our customer's privacy policy governs that processing; this Policy describes our own processing activities and applies directly to Candidates who interact with our public career portals.
For the purposes of the EU General Data Protection Regulation (GDPR), MoonTrack™ ATS is the data controller for data we collect from Users and Visitors. When processing Candidate data submitted by an employer-customer, MoonTrack™ ATS acts as a data processor on that customer's behalf, governed by our Data Processing Agreement.
2. Information We Collect
2.1 Account & Profile Data
- Name, email address, phone number, and mailing address
- Job title, department, and organizational role
- Account credentials (passwords are hashed and never stored in plaintext)
- Profile photo (optional)
- Multi-factor authentication configuration
2.2 Candidate Data
- Resume/CV content, cover letters, and portfolio links
- Employment history, education, and professional qualifications
- Skills, certifications, and professional licensure
- Interview evaluations, scorecard ratings, and internal notes
- Application status and pipeline stage history
- Communication logs (emails, messages sent through the platform)
- Offer details: salary, benefits, start date, and signed documents
- Onboarding documents and employee profile data (for hired candidates)
2.3 Sensitive & Special Category Data
Where permitted by law and with appropriate consent, the following categories may be processed:
- Equal Employment Opportunity (EEO) data: Race, ethnicity, gender, veteran status, and disability status — collected on a voluntary basis solely for anonymised diversity and compliance reporting. EEO data is never used in hiring decisions or AI scoring.
- Background check data: Criminal history, employment verification, and education verification — every request is first shown to the candidate in-app and checks only commence after explicit candidate acceptance; processing is handled by certified third-party providers.
- National identification: National ID, passport number, NYSC certificate (Nigeria) — collected only during the onboarding phase for employment verification, encrypted at rest.
2.4 AI-Generated Data
- Match scores and candidate rankings
- Extracted skills and experience summaries
- AI-generated screening summaries and key-strength/concern assessments
- Job description suggestions
- Fairness audit logs and bias-detection events
2.5 Usage & Technical Data
- IP address, browser type, operating system, and device identifiers
- Pages visited, features used, and clickstream data
- Session duration and timestamps
- Error logs and performance metrics (collected via Sentry)
- Referring URLs and search terms
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following lawful bases:
| Processing Activity | Lawful Basis |
|---|---|
| Account creation & management | Contract performance (Art. 6(1)(b)) |
| Providing the recruitment platform | Contract performance (Art. 6(1)(b)) |
| AI-assisted screening & scoring | Legitimate interest (Art. 6(1)(f)) — efficient recruitment |
| Sending transactional emails | Contract performance (Art. 6(1)(b)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
| EEO & diversity data collection | Explicit consent (Art. 9(2)(a)) |
| Background checks | Explicit consent (Art. 9(2)(a)) & Legal obligation |
| Error monitoring & security | Legitimate interest (Art. 6(1)(f)) — platform security |
| Legal compliance & audit | Legal obligation (Art. 6(1)(c)) |
| Consent logging | Legal obligation (Art. 6(1)(c)) & Legitimate interest |
Where we rely on legitimate interest, we have conducted a balancing test confirming that our interests do not override your fundamental rights and freedoms. You may request a copy of our Legitimate Interest Assessment by contacting our Data Protection Officer.
4. How We Use Your Information
- To provide, operate, and maintain the recruitment platform
- To match candidates with job opportunities using AI-assisted scoring
- To facilitate communication between hiring teams and candidates
- To generate analytics, reports, and KPI dashboards for customers
- To process offer letters, e-signatures, and onboarding workflows
- To send transactional notifications (application updates, interview reminders)
- To send marketing communications (only with your consent; unsubscribe available)
- To improve our services, train internal models (anonymised data only), and conduct research
- To detect, prevent, and address fraud, abuse, and security threats
- To comply with legal obligations, respond to lawful requests, and enforce our Terms
5. AI & Automated Decision-Making
Our Service uses artificial intelligence models to assist in the recruitment process. Specifically, AI is used for:
- Candidate screening: Parsing resumes, extracting skills, and generating match scores against job requirements
- Scoring & ranking: Producing numerical scores that reflect a candidate's potential fit based on experience, skills, and qualifications
- Summary generation: Creating AI-written summaries of candidate profiles for recruiter review
- Job description generation: Suggesting job description text based on role parameters
- Conversational assistant: Answering hiring-team questions about pipeline data and analytics
Your Rights Regarding Automated Decisions
Under GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. MoonTrack™ ATS ensures:
- AI-generated scores and recommendations are advisory only — a human recruiter always makes the final decision
- You may request human review of any AI-generated assessment by contacting the hiring organization or us at privacy@moontrackhr.com
- You may contest an automated decision and receive an explanation of the logic involved
- You may opt out of AI profiling entirely — inform the hiring organization, and they can disable AI screening for your application
Fairness & Bias Monitoring
We employ algorithmic fairness guardrails and continuously monitor for adverse impact across protected demographic groups. Fairness events are logged and available to customers for audit. We publish annual transparency reports on our Trust Center.
6. Data Sharing & Disclosure
We may share your information with the following categories of recipients:
- Employer-customers: When you apply for a position, your application data is shared with the hiring organization's authorized team members
- Within your organization: Hiring team members, interviewers, and administrators within the same organization can access candidate data based on role-based access controls
- Background check providers: With your explicit consent after you review the request, we share only the data necessary with authorized background screening vendors
- Subprocessors: Service providers who help us operate the platform (see Section 7)
- Legal authorities: When required by law, subpoena, court order, or to protect safety and rights
- Business transfers: In connection with a merger, acquisition, or sale of assets (with notice to you)
We do not sell your personal data. We do not share personal data with third parties for their own marketing purposes.
7. Subprocessors
We use the following subprocessors to deliver the Service. Each subprocessor has been evaluated for adequate security and privacy practices:
| Subprocessor | Purpose | Data Categories | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All platform data | United States |
| Sentry | Error monitoring & performance tracking | Error logs, IP addresses, browser data | United States |
| Resend | Transactional & marketing email delivery | Email addresses, names, message content | United States |
| Google AI (Gemini) | AI-powered candidate screening & text generation | Candidate profiles, job descriptions (no EEO data) | United States |
We maintain a current subprocessor list and will notify customers at least 30 days before adding a new subprocessor. Customers may object to a new subprocessor as described in our DPA.
8. International Data Transfers
The Service is primarily hosted in the United States. If you are located outside the United States, your personal data will be transferred to and processed in the US.
For transfers from the EEA, UK, or Switzerland to the United States, we rely on:
- EU-US Data Privacy Framework: Where our subprocessors are certified participants
- Standard Contractual Clauses (SCCs): As approved by the European Commission (Module 2: Controller-to-Processor and Module 3: Processor-to-Processor)
- Supplementary measures: Including encryption in transit and at rest, access controls, and contractual restrictions on government access
Copies of the applicable transfer mechanisms are available upon request from our Data Protection Officer.
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, unless a longer retention period is required by law.
| Data Category | Retention Period |
|---|---|
| User account data | Duration of subscription + 30 days post-termination |
| Candidate application data | 2 years after job requisition closure (or as specified by customer) |
| Interview & evaluation data | 2 years after job requisition closure |
| Offer & onboarding data | Duration of employment relationship + 7 years (legal requirement) |
| Background check results | 1 year after hiring decision (or as required by law) |
| AI screening results | Same as candidate application data (2 years) |
| Consent logs | Duration of relationship + 5 years (compliance audit trail) |
| Audit & security logs | 3 years |
| Error & performance logs (Sentry) | 90 days |
| Marketing consent records | Until consent is withdrawn + 1 year |
You may request earlier deletion of your data at any time, subject to legal retention requirements. See Section 10 for details on exercising your rights.
10. Your Rights Under GDPR
If you are located in the EEA, UK, or Switzerland, you have the following rights under the GDPR:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data
- Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements
- Right to Restriction (Art. 18): Request that we limit the processing of your data in certain circumstances
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV)
- Right to Object (Art. 21): Object to processing based on legitimate interest, including profiling
- Right Regarding Automated Decisions (Art. 22): Not be subject to solely automated decisions with legal or significant effects; request human review of AI assessments
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw at any time without affecting the lawfulness of prior processing
- Right to Lodge a Complaint: File a complaint with your local Data Protection Authority (e.g., the Irish Data Protection Commission, the UK Information Commissioner's Office)
To exercise any of these rights, contact our Data Protection Officer at dpo@moontrackhr.com. We will respond within 30 days (extendable by 60 days for complex requests, with notice).
11. Your Rights Under CCPA/CPRA (California Residents)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the sources, purposes, and categories of third parties with whom we share it
- Right to Delete: Request deletion of personal information we have collected (subject to exceptions)
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing: We do not sell personal information and do not share it for cross-context behavioral advertising. No opt-out is needed, but you may submit a request for confirmation
- Right to Limit Use of Sensitive Personal Information: Request that we limit our use of sensitive personal information to what is necessary for providing the Service
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
Categories of Personal Information Collected (Past 12 Months)
- Identifiers (name, email, IP address)
- Professional/employment information (resume, work history)
- Education information
- Internet/network activity (browsing history, interactions with Service)
- Inferences (AI-generated scores and profiles)
- Sensitive personal information (government IDs — only during onboarding with consent)
To exercise your California privacy rights, contact us at privacy@moontrackhr.com or call +2348038257162. We will verify your identity before fulfilling requests.
12. Data Security
We implement industry-leading security measures to protect your personal information:
- Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Authentication: Multi-factor authentication (MFA/TOTP) available for all accounts; mandatory for privileged access
- Access controls: Role-based access control (RBAC) with least-privilege principles; organization-level data isolation
- Audit logging: Comprehensive audit trails for data access, modifications, and administrative actions
- Secret management: API keys and credentials rotated quarterly; stored in encrypted vaults
- Vulnerability management: Regular dependency scanning, penetration testing, and security audits
- Incident response: Documented incident response plan with breach notification within 72 hours (GDPR) or as required by applicable law
- SOC 2 compliance: We are pursuing SOC 2 Type II certification (expected completion: Q4 2026)
Despite our efforts, no method of transmission over the Internet or electronic storage is 100% secure. We encourage you to use strong passwords and enable MFA.
13. Children's Privacy
The Service is not directed at individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at privacy@moontrackhr.com.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice via email or an in-app notification before the changes take effect. We encourage you to review this page periodically. The "Last updated" date at the top indicates when the latest revision was published.
15. Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights, or have a complaint, please contact us:
Data Protection Officer
MoonTrack™ ATS, a product of Stanley & Akatu HR Partners, Africa.
Email: dpo@moontrackhr.com
Privacy inquiries: privacy@moontrackhr.com
Phone: +2348038257162
If you are in the EEA and are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority.