Privacy Policy
Last Updated: July 3, 2026
MapJob (“MapJob,” “we,” “our,” or “us”) operates the job board platform at mapjob.io. This Privacy Policy explains how we collect, use, disclose, and protect information about you when you use our services. It also describes your rights and choices regarding your personal information.
By using MapJob, you agree to the practices described in this policy. If you do not agree, please do not use our services.
1. Information We Collect
We collect information you provide directly, information generated by your use of the platform, and limited information from third parties.
Information you provide
- Account information: name, email address, password (hashed), and account type (job seeker or employer).
- Seeker profile: resume, work history, skills, desired job type, location preferences, profile photo.
- Employer profile: company name, website, description, logo, billing contact information, and phone number (verified by SMS via Twilio for trust verification; stored encrypted at rest).
- Job postings: job title, description, location, compensation, requirements submitted by employers. MapJob also displays aggregated job listings sourced from authorized third-party APIs (see “Aggregated Job Content” below).
- Applications: cover letters, answers to screening questions, documents submitted when applying.
- Messages: content of messages exchanged between job seekers and employers through our platform.
- Support requests: information you provide when contacting our support team.
- Feedback: if you submit a note through the in-app feedback widget, we collect your message, the page you were on, your browser's user-agent string, and the email address and account type associated with your session. We use this to triage bug reports and product suggestions.
- Payment information: billing address and payment method details (processed by Stripe — we do not store raw card numbers).
Information generated automatically
- Usage data: pages visited, features used, search queries, job listings viewed, applications submitted, time on site.
- Device and browser: IP address, browser type and version, operating system, device identifiers, screen resolution.
- Location data: approximate location derived from IP address; precise location if you grant permission when using map features. When you browse the job map, your approximate viewport location is used to fetch nearby jobs. We do not permanently store your browsing location.
- Cookies and similar technologies: session identifiers and, if you opt in, analytics cookies. See our Cookie Policy for details.
- Log data: server logs including request timestamps, HTTP status codes, and referring URLs.
Aggregated job content
In addition to employer-submitted job postings, MapJob displays aggregated job listings sourced from authorized third-party APIs, including USAJobs (the federal government's official employment site) and JSearch via RapidAPI (which aggregates listings from sources such as LinkedIn, Indeed, and Glassdoor). This content is provided for informational purposes and is not user-generated. MapJob does not collect personal information from you in connection with displaying aggregated listings. However, if you click an external apply link on an aggregated listing, you will be redirected to a third-party website that is governed by its own privacy policy and data practices. MapJob is not responsible for the privacy practices of those external sites, and we encourage you to review their policies before submitting any personal information.
Information from third parties
- Stripe: payment confirmation and billing status after a transaction.
- Google (Sign in with Google): if you choose to sign in or sign up using Google, we receive your name, email address, Google account ID, and (if available on your Google profile) profile picture URL. We do not receive your Google password. Your use of Sign in with Google is also subject to Google's Privacy Policy.
- Email verification services: deliverability signals to confirm your email address is valid.
- Job aggregation APIs: MapJob receives job listing data (such as job titles, descriptions, locations, and employer names) from USAJobs and JSearch (via RapidAPI) to display aggregated listings. No personal information about you is shared with these providers as part of this data retrieval.
2. CCPA/CPRA Categories of Personal Information
For California residents, we collect the following statutory categories of personal information:
- Identifiers: real name, alias, email address, account username, IP address, device identifiers.
- Personal records: name, address, phone number, employment history, education history contained in resumes.
- Protected classification characteristics: we do not intentionally collect characteristics such as race, gender, age, or disability status. Seekers may voluntarily include such information in resumes or profiles; we do not use it for decision-making.
- Commercial information: credits purchased, transaction history, billing records.
- Internet or other electronic network activity: browsing and search history within the platform, interactions with job listings.
- Geolocation data: approximate location (IP-based) and precise location (if granted by device permission).
- Professional or employment-related information: job history, skills, job preferences, application materials.
- Inferences: job category preferences and geographic search patterns derived from usage.
- Sensitive personal information: account login credentials (password hash); precise geolocation if granted. We do not use sensitive personal information to infer characteristics about you or for purposes beyond providing the service.
3. How We Use Your Information
- Providing the service: displaying job listings on the map, routing applications to employers, enabling employer–seeker messaging, managing credits and billing.
- Account management: creating and maintaining your account, verifying your identity, enabling two-factor authentication.
- Communications: sending transactional emails (application confirmations, messages, password resets) and, unless you opt out, onboarding tips, product updates, and job alerts. Every such email includes a one-click unsubscribe link, and you can manage categories at any time from your email preferences page.
- Safety and fraud prevention: detecting fake listings, abusive accounts, and fraudulent payment activity.
- Security, logging, and abuse prevention: we record IP addresses, user-agent strings, and request metadata in server logs and security audit records to detect and prevent fraud, brute-force attacks, abusive behavior, and unauthorized access. Security audit records of administrative actions are retained for up to two years. These records are not used for marketing or for inferring characteristics about you.
- Analytics and improvement: understanding how people use the platform so we can improve features and fix bugs. Third-party analytics tools are only loaded if you opt in to analytics cookies. Separately, we keep first-party records of searches run on the platform — the search terms (after removing anything that looks like an email address or phone number), the filters applied, and the number of results — to improve search quality and find gaps in job coverage. These search records are linked to your account only if you have opted in to analytics cookies; if you have not opted in, or your browser sends a Do Not Track or Global Privacy Control signal, they are stored without any user identifier.
- Legal compliance: complying with applicable laws, responding to lawful requests from government authorities, and enforcing our Terms of Use.
- Billing and payments: processing credit purchases, issuing refunds, and resolving disputes through Stripe.
4. How We Share Your Information
We do not sell your personal information. We share information only as described below.
- Employers and job seekers (MapJob Apply): when a seeker applies to a job via MapJob Apply, the application is submitted directly on the platform with one click using the seeker's saved profile. The following information is shared with the relevant employer: your name, email address, resume, and application message. Employers may only use this data to evaluate you for the posted position. For jobs that link to an external website or applicant tracking system, your data is submitted to that third party and is subject to their privacy practices. Employer company profiles and job listings are visible to seekers. Messages are shared between the parties to the conversation.
- Resume visibility: your resume is only visible to employers who receive your applications. If you opt in to the talent CRM browse feature, employers with active accounts may also browse your profile and resume. You can opt out of talent CRM browse at any time in your account settings.
- Service providers: we use third-party vendors to operate the platform. Each vendor processes data on our behalf under contractual obligations limiting their use, and is subject to its own privacy policy:
- Stripe — payment processing and billing (stripe.com/privacy).
- Amazon Web Services (AWS): hosting, S3 file storage for resumes and uploads, and Amazon SES for transactional email delivery (aws.amazon.com/privacy).
- Vercel — web hosting and edge delivery; processes IP addresses and request metadata (vercel.com/legal/privacy-policy).
- Vercel Analytics & Speed Insights — aggregated, privacy-friendly usage analytics and page-performance telemetry. Only loaded after you opt in via the cookie banner or our Cookie Preferences page. Processes a per-visit pseudonymous identifier, page URL, referrer, country (derived from IP, IP itself is not stored), and basic device/browser metadata. Same privacy policy as Vercel above.
- PostHog — product analytics (funnel, retention, feature usage) used to understand how the platform is being used so we can improve it. Only loaded after you opt in via the cookie banner or our Cookie Preferences page. Processes a pseudonymous user identifier, the events you trigger (page views, signups, applications), page URL, referrer, and basic device/browser metadata. We do not send your email address or resume content to PostHog (posthog.com/privacy).
- Neon (Databricks) — managed PostgreSQL database (databricks.com/legal/privacynotice).
- Upstash, Inc. — managed Redis hosting: session storage, caching, and rate-limit counters (upstash.com/trust/privacy.pdf).
- Meilisearch — full-text search indexing of job listings (meilisearch.com/privacy-policy).
- Twilio — SMS delivery for phone number verification; processes phone numbers (twilio.com/legal/privacy).
- Cloudflare Turnstile — bot protection on authentication and form submissions; processes IP addresses and browser fingerprint signals (cloudflare.com/privacypolicy).
- Sentry — error monitoring and performance tracing; may capture user identifiers, IP addresses, and request metadata embedded in stack traces (sentry.io/privacy).
- MapTiler — map tile delivery for the job map; processes IP addresses (maptiler.com/privacy-policy).
- Geoapify — geocoding and location autocomplete; processes IP addresses and search query strings (geoapify.com/privacy-policy).
- USAJobs API — source of federal government job listings; no personal information about you is shared with USAJobs as part of this retrieval (usajobs.gov/Help/privacy).
- JSearch via RapidAPI — aggregated third-party job listings; no personal information about you is shared with RapidAPI as part of this retrieval (rapidapi.com/privacy).
- Adzuna — aggregated third-party job listings; no personal information about you is shared with Adzuna as part of this retrieval (adzuna.com/privacy-policy).
- Analytics providers: if you opt in to analytics cookies, aggregate and pseudonymous usage data may be shared with analytics tools.
- Legal requirements: we may disclose information if required by law, court order, or regulatory authority; to protect the rights, property, or safety of MapJob, our users, or the public; or to detect and prevent fraud.
- Business transfers: if MapJob is acquired or merged, personal information may be transferred as part of that transaction. We will notify you before your data is subject to a different privacy policy.
- With your consent: for any other sharing not described here, we will obtain your explicit consent.
5. Data Retention
- Active accounts: we retain your information for as long as your account is active.
- Closed accounts: after account deletion, we delete or anonymize personal data within 90 days, except where we are required to retain it for legal, compliance, or dispute resolution purposes (typically up to 7 years for financial records). After account deletion we retain anonymized transactional and financial records (amounts, dates, and payment references — no personal data) as required for legal, tax, and dispute purposes.
- Job postings: expired job listings are archived and removed from public view, but retained for up to 2 years for analytics and dispute resolution.
- Messages: platform messages are retained with the related job application and are permanently deleted together with the job posting, two years after the posting is archived. Conversations tied to a posting that is still live remain available for as long as that posting exists.
- Resumes and uploads: files in S3 are deleted when you remove them from your profile or delete your account.
- Search records: the first-party search records described in “Analytics and improvement” above are retained as aggregate product telemetry. Any link between a search record and your account is removed when your account is deleted.
- Feedback: notes submitted through the in-app feedback widget are retained so we can act on them; the link to your account and your email address are removed when your account is deleted.
- Logs: server access logs are retained for 90 days.
6. Your Rights and Choices
Depending on where you live, you may have the following rights regarding your personal information. California residents have additional rights under CCPA/CPRA — see our Privacy Choices page for a dedicated interface.
- Access: request a copy of the personal information we hold about you.
- Correction: request that we correct inaccurate personal information.
- Deletion: request deletion of your personal information, subject to certain exceptions.
- Portability: receive a copy of your personal information by request (email support@mapjob.io) in a machine-readable JSON format, within 45 days of a verified request.
- Opt-out of sale/sharing: we do not sell personal information. If this changes, you will have the right to opt out.
- Limit use of sensitive personal information: you can limit our use of sensitive personal information to purposes necessary to provide the service.
- Non-discrimination: we will not discriminate against you for exercising any privacy right.
- Marketing opt-out: you can unsubscribe from marketing emails at any time using the unsubscribe link in the email or by contacting us.
- Cookie preferences: manage your cookie choices via our Cookie Preferences page.
To exercise any right, submit a request at support@mapjob.io or via our Privacy Choices page. We will verify your identity before processing requests and respond within 45 days (extendable by an additional 45 days with notice for complex requests).
7. State-Specific Privacy Rights
In addition to California (CCPA/CPRA), residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states with comprehensive privacy laws have rights to access, correct, delete, and port their personal data, and to opt out of targeted advertising and profiling that produces legal or similarly significant effects. We do not engage in targeted advertising based on personal data purchased from third parties, and we do not make automated decisions that produce legal or similarly significant effects. To exercise any state privacy right, contact us at support@mapjob.io.
8. Children's Privacy (COPPA)
MapJob is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us at support@mapjob.io and we will delete it promptly. Users must be at least 16 years old to create an account.
9. Security
We implement appropriate technical and organizational measures to protect your personal information, including TLS encryption in transit, encrypted storage at rest, hashed passwords, access controls, and regular security reviews. No system is completely secure. If you discover a security vulnerability, please report it to security@mapjob.io. See our Security page for details.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and, where required, regulatory authorities within the timeframes required by applicable law.
10. International Transfers
MapJob is operated in the United States. If you access our platform from outside the US, your information will be transferred to and processed in the United States. We use service providers (AWS, Stripe, etc.) that may process data in multiple countries. We rely on their standard contractual clauses and data processing agreements to ensure adequate protection for cross-border transfers.
11. Do Not Track
We honor the Do Not Track (“DNT”) browser signal. If your browser has DNT enabled, we will not run optional analytics cookies even if you previously opted in. We do not use cross-site tracking.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (to the address on your account) and post the updated policy with a new “Last Updated” date. Your continued use of the platform after the effective date of the updated policy constitutes acceptance of the changes.
13. Contact Us
MapJob is operated by MapJob LLC, 82 Wendell Ave, Suite 100, Pittsfield, MA 01201, USA.
For privacy-related questions, requests, or complaints, contact us at:
Email: support@mapjob.io
Subject line: Privacy Request
You also have the right to lodge a complaint with your state's Attorney General or applicable data protection authority.