Back to Home
Security & Data Protection Statement

How MoonTrack protects your candidate data

MoonTrack™ is an applicant tracking system operated by S&A Partners. This page is written for the person who has to approve us internally: what is in place today, what is not, and who else touches your data.

Last reviewed: February 2026

Controls in place today

Tenancy isolation

Every customer organisation is a separate tenant. Isolation is enforced in the database itself with row-level security on candidate, application, job, message and document tables — not in application code that a bug could bypass. Automated cross-tenant tests run on every deployment and fail the release if one tenant can read another tenant’s rows.

Encryption

All traffic between your browser and MoonTrack uses TLS 1.2 or higher. Data at rest, including database storage, file uploads and backups, is encrypted with AES-256 by our infrastructure provider. Third-party integration credentials are stored encrypted and are never returned to the browser.

Access control and authentication

Role-based access control separates platform owners, organisation admins, hiring team members and candidates. Multi-factor authentication is available to all accounts and can be required for an organisation. Passwords are hashed, checked against known-breached password lists, and sessions expire automatically.

Audit logging

Administrative actions, permission changes, candidate CV downloads and data exports are written to an append-only audit log with actor, timestamp and organisation. Logs are scrubbed of personal data such as email addresses, phone numbers and tokens before storage.

Backups and recovery

The production database is backed up continuously with point-in-time recovery. Recovery procedures are documented in our business continuity plan and rehearsed against a restore target of 24 hours.

Personnel and least privilege

Production access is limited to named administrators, requires multi-factor authentication, and is logged. Support staff cannot read candidate records outside a customer-authorised support session.

Nigeria Data Protection Act 2023

For Nigerian customers, you are the data controller for candidate data you process in MoonTrack and we act as your data processor. We process personal data only on your documented instructions, assist with data subject requests, and notify you without undue delay if we become aware of a personal data breach affecting your organisation.

A Data Processing Agreement covering these terms is available on request and can be signed before onboarding. Where a customer is subject to GDPR or CCPA, the same agreement covers those obligations.

We do not sell personal data, and we do not use your candidate data to train AI models. AI screening sends only the candidate material required for the evaluation you requested, and the provider does not retain it for training.

Data residency

Production data is stored in our managed cloud infrastructure with backups held in the same region. AI screening requests are processed by our AI provider and may transit outside your country of operation for the duration of the request. We will confirm the current storage region in writing for any customer that needs it for their own compliance record, and we can discuss region requirements before onboarding.

Retention and deletion

Data retention schedule
DataRetention
Candidate and application recordsRetained for the life of your account, then deleted within 30 days of termination unless you ask us to delete sooner.
Uploaded CVs and documentsSame as candidate records. Deleting a candidate removes the stored file.
Operational logs90 days.
Audit logs365 days.
BackupsRolling window; deleted data ages out of backups within 30 days.

You can export your organisation’s data at any time from the dashboard, and you can request full deletion by emailing us. Your data belongs to you.

Sub-processors

Current sub-processors
ProviderPurpose
SupabaseDatabase, authentication, file storage, serverless functions
Google (Gemini via Lovable AI Gateway)AI screening and CV parsing
ResendTransactional email delivery
Paystack, FlutterwavePayment processing

We publish material changes to this list. The live list is also available in the Trust Center.

What we do not yet have

Stated plainly so you are not surprised later in your review.

  • SOC 2 Type IIRoadmap — controls implemented, no independent audit completed. We do not claim certification.
  • ISO 27001Roadmap — not currently certified.
  • Independent penetration testRoadmap — internal and automated security testing only at present.
  • Customer-configurable retention windowsRoadmap — retention is currently set by the schedule above.

Security contact

Vulnerability reports, security questionnaires and DPA requests: security@moontrackhr.com

We acknowledge reports within two business days and will keep you updated until the issue is resolved. We do not pursue legal action against good-faith researchers.

We use cookies to improve your experience. Essential cookies are always active. You can accept or reject non-essential cookies used for error monitoring and analytics. Learn more