Last updated: August 16, 2026
This Privacy Policy explains how Hi Maya ("we", "us", "our") collects, uses, and discloses personal data in the course of providing our recruiting and interview-scheduling platform (the "Service").
"Personal Data" means any information relating to an identified or identifiable person that we process as described here. "Customer" means a recruiting team or organization that uses the Service. "Candidate" means a job applicant or interviewee whose data is handled through the Service.
For account, billing, website, and marketing data, we act as the data controller. When a Customer uses the Service to manage applications, message candidates, or schedule interviews, we act as a data processor on the Customer's behalf, and the Customer is the controller of that candidate data. Data is strictly isolated per tenant. If you are a candidate and want to exercise your rights over data an employer holds about you, please contact that employer directly.
Account data. When a Customer sets up an account we collect names, email addresses, and login credentials for each team member.
Billing data. If your organization subscribes to a paid plan, our payment processor collects the billing details needed to process the payment. We store only limited billing metadata, never full card numbers.
Candidate data. Customers upload or receive candidate data (name, contact details, CV, application answers, interview notes) that candidates submit through careers pages, booking links, or that the Customer imports. We process this data on the Customer's instructions.
Communications. If you contact us for support or feedback, we keep the content of those messages to respond and improve the Service.
Log and device data. When you use the Service we automatically record technical information such as IP address, browser type, device and operating system, referring pages, and timestamps.
Cookies and local storage. We and our service providers use cookies, local storage, and similar technologies to keep you signed in, remember preferences, and understand how the Service is used. On public booking and careers pages you can adjust non-essential cookies at any time through the "Cookie settings" link in the page footer. Strictly necessary cookies are required to authenticate and operate the Service and cannot be turned off.
Usage data. We collect information about how the Service is used, such as which features are used and how often, to monitor, secure, and improve the product.
Website analytics. On our own marketing website (gethimaya.com) we use Microsoft Clarity, a product-analytics tool that helps us understand how visitors use the site through aggregated metrics, session insights, and heatmaps. Clarity may record general interactions such as clicks, scrolls, and navigation; sensitive input fields are masked. If you request a demo, we associate that request with an anonymous site identifier so we can review how you used the site. Clarity's use is also governed by Microsoft's privacy statement.
The Service includes AI-powered features: automatic CV parsing and summarization, semantic search over candidate profiles, AI-suggested match scores, drafting assistance, and the Maya assistant (in the product and, where a recruiter connects them, over Slack or WhatsApp). To provide these features, relevant data - including CV text, candidate profile information, job descriptions, and assistant conversation content - is processed by our AI model provider, Google (Gemini API), acting as a sub-processor. This data is used only to generate the requested output for the workspace; it is never sold and never used by us for advertising. We use Google's paid API tier, under which Google does not use submitted data to train its models.
AI outputs are assistive suggestions for recruiters. No hiring decision is made solely by automated means: decisions with legal or similarly significant effect on a candidate (such as rejection) require confirmation by a human recruiter, and AI-suggested scores and summaries are recommendations that recruiters review. Every action the assistant takes is logged and reversible by the workspace.
Emails sent through the Service (for example application confirmations, interview invitations, and recruiter messages) are delivered by our email provider and include standard delivery, open, and click tracking (a tracking pixel and wrapped links). Engagement events are stored so recruiters can see whether their message arrived and was read. Replies sent to our reply addresses are processed to thread them into the correct application.
Customers can connect their own analytics to their public careers and booking pages. When a Customer configures Google Analytics (GA4) or the Meta (Facebook) Pixel, those third-party tools load on that Customer's public pages and collect usage data subject to the visitor's cookie choices. These tools are controlled by the Customer, and their use is also governed by Google's and Meta's own privacy terms. To opt out of Google Analytics, you can install the Google Analytics opt-out browser add-on.
Recruiters may connect their Google account to schedule interviews. When connected, we access Google Calendar with two scopes: calendar free/busy, to read only the busy time windows of the connecting recruiter's own calendar, used transiently to suggest interview times (busy windows are not stored); and calendar events, to create, update and delete the interview events the recruiter schedules through the platform (we store only the identifier of events we created, never the contents of other calendar events). We do not access Gmail, contacts, or any other Google data.
Google user data is never used for advertising, never sold, and never transferred to third parties except as required to provide the scheduling feature itself. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
A recruiter can disconnect Google at any time from the platform's Integrations page (which deletes the stored tokens) or revoke access at myaccount.google.com/permissions.
We use the information described above to:
We do not use candidate email addresses collected through booking or careers pages to send our own direct marketing.
Service providers and sub-processors. We use vetted sub-processors for cloud hosting, email delivery, search, and payment processing. They may access personal data only to perform services for us and are bound to keep it secure. Third-party calls are made server-side only.
Integration partners. Where a Customer connects an integration (such as Google Calendar or an email provider), we exchange the data needed to make that integration work.
Legal and safety. We may disclose information where reasonably necessary to comply with the law or a legal request, to enforce our terms, or to protect the rights, property, or safety of any person.
Reorganization. If we are involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy.
We retain personal data for as long as needed to provide the Service and for legitimate business or legal purposes. Candidate data is retained on behalf of, and deleted according to, the Customer's instructions. When a tenant is closed, its data is deleted or anonymized within a reasonable period.
Data is stored in access-controlled infrastructure with tenant isolation enforced at the application and database layers. We take reasonable technical and organizational measures to protect personal data, though no method of transmission or storage is completely secure. Keep your credentials private and unique.
We and our sub-processors may process data in countries other than your own. Where required, we rely on appropriate safeguards, such as standard contractual clauses, for international transfers.
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. Customers can review and update their account information in the platform at any time. Candidates should contact the relevant employer to exercise rights over data that employer controls; Customers can fulfil these requests within the platform. You can also contact us at the address below and we will route your request appropriately.
For Customers and candidates in Israel, we process personal data in accordance with the Israeli Protection of Privacy Law, 5741-1981, as amended, and the Privacy Protection (Data Security) Regulations. Customers remain responsible for their own obligations under that law with respect to the candidate databases they control, including any registration or notification duties.
The Service is not directed to children, and we do not knowingly collect personal data from children. If we learn that we have, we will delete it.
We may update this Policy from time to time. If we make material changes we will update the date above and post the revised Policy on this page.
Questions about this Policy: [email protected]