Candidate data deserves careful, transparent handling
This page explains the information ShortlistLens processes, why it is used and the controls expected from hiring teams.
Effective date: 28 July 2026
1. Information we process
We process account information such as your name, email address and company; hiring-project information such as job descriptions and role requirements; candidate CV content submitted for screening; screening results; support messages; and payment/order records when a paid package is purchased.
2. How the information is used
Information is used to create and secure your account, operate saved hiring projects, process CVs against job-related criteria, provide rankings and evidence for human review, manage credits and payments, prevent misuse, troubleshoot errors and respond to support requests.
3. Candidate CVs and sensitive information
Customers should upload CVs only when they have a lawful basis and authority to process the candidate information. Do not intentionally use protected characteristics or unrelated sensitive information as screening criteria. ShortlistLens is designed to support—not replace—qualified human review.
4. Storage and service providers
Account data, projects and saved results are stored through Supabase. CV files and job requirements are sent to the configured n8n workflow and its connected document-processing or AI services only for the screening requested by the customer. Lemon Squeezy hosts the checkout and processes payment information. ShortlistLens receives order details needed to match a purchase, prevent duplicates and add credits; it does not receive full card details. Legacy payment proofs may remain in private storage with access controls.
5. Social sign-in and session data
When you choose Google or LinkedIn sign-in, the selected provider and Supabase Auth process the authentication request. ShortlistLens receives basic account information such as your name, email address and provider identifier. We do not receive your social-account password. Browser storage and essential authentication cookies or tokens are used to keep you signed in securely.
6. Retention and deletion
Saved projects and results remain available until the customer deletes the project or account, subject to operational backups and legal obligations. Temporary CV files should be deleted by the screening workflow after processing. Customers should not use ShortlistLens as permanent CV storage.
7. Access controls and security
ShortlistLens uses authenticated sessions, private database policies and restricted file storage. No internet service is completely risk-free, so customers should use strong passwords, limit account access and avoid uploading information not needed for recruitment.
8. Your choices
You can update basic account details, delete hiring projects and request help with access, correction or deletion by contacting support@shortlistlens.com. We may need to verify your identity before acting on a request.
9. International processing
Service providers may process information in countries different from yours. Customers remain responsible for candidate notices, transfer requirements and recruitment laws that apply to their organization.
10. Changes to this notice
We may update this notice as the product, providers or legal requirements change. The effective date above will be revised when material changes are published.