Privacy Policy
Last Updated: August 19, 2026
MapJob (“MapJob,” “we,” “our,” or “us”) operates the job board platform at mapjob.io. This Privacy Policy explains how we collect, use, disclose, and protect information about you when you use our services. It also describes your rights and choices regarding your personal information.
By using MapJob, you agree to the practices described in this policy. If you do not agree, please do not use our services.
1. Information We Collect
We collect information you provide directly, information generated by your use of the platform, and limited information from third parties.
Information you provide
- Account information: name, email address, password (hashed), and account type (job seeker or employer).
- Seeker profile: resume, work history, skills, desired job type, location preferences, profile photo.
- Employer profile: company name, website, description, logo, billing contact information, and phone number (verified by SMS via Twilio for trust verification; stored encrypted at rest).
- Job postings: job title, description, location, compensation, requirements submitted by employers. MapJob also displays aggregated job listings sourced from authorized third-party APIs (see “Aggregated Job Content” below).
- Applications: cover letters, answers to screening questions, documents submitted when applying.
- Messages: content of messages exchanged between job seekers and employers through our platform.
- Support requests: information you provide when contacting our support team.
- Feedback: if you submit a note through the in-app feedback widget, we collect your message, the page you were on, your browser's user-agent string, and the email address and account type associated with your session. We use this to triage bug reports and product suggestions.
- Payment information: billing address and payment method details (processed by Stripe — we do not store raw card numbers).
Information generated automatically
- Usage data: pages visited, features used, search queries, job listings viewed, applications submitted, time on site.
- Device and browser: IP address, browser type and version, operating system, device identifiers, screen resolution.
- Location data: approximate location derived from IP address; precise location if you grant permission when using map features. When you browse the job map, your approximate viewport location is used to fetch nearby jobs. We do not permanently store your browsing location.
- Address lookups: when you type an address or place name into a search or address field, or place a pin on the map, we send that lookup to a third-party geocoding provider to resolve it into coordinates. What we send is the address or place text you type (or, for a map pin, the coordinates), where applicable a two-letter country filter, and in some cases an approximate location used to rank nearby results first — the center of the map area you are viewing when you search from the map, or the coordinates already on file for a company when you edit a company or job address. Your name, email address, and account identifier are never sent. Text lookups are cached under a one-way hash of what you typed, so the text itself is not retained in our cache keys: for up to 24 hours when you are searching or moving the map, and for up to 30 days when we verify an address you save to a profile, a job posting, or a company record. Map-pin lookups are cached under the pin’s coordinates rounded to about 11 meters, for up to 24 hours. The providers are listed under “Service providers” in section 4.
- Cookies and similar technologies: session identifiers and, if you opt in, analytics cookies. See our Cookie Policy for details.
- Log data: server logs including request timestamps, HTTP status codes, and referring URLs.
Aggregated job content
In addition to employer-submitted job postings, MapJob displays aggregated job listings sourced from authorized third-party APIs, including USAJobs (the federal government's official employment site) and JSearch via RapidAPI (which aggregates listings from sources such as LinkedIn, Indeed, and Glassdoor). This content is provided for informational purposes and is not user-generated. MapJob does not collect personal information from you in connection with displaying aggregated listings. However, if you click an external apply link on an aggregated listing, you will be redirected to a third-party website that is governed by its own privacy policy and data practices. MapJob is not responsible for the privacy practices of those external sites, and we encourage you to review their policies before submitting any personal information.
Information from third parties
- Stripe: payment confirmation and billing status after a transaction.
- Google (Sign in with Google): if you choose to sign in or sign up using Google, we receive your name, email address, Google account ID, and (if available on your Google profile) profile picture URL. We do not receive your Google password. Your use of Sign in with Google is also subject to Google's Privacy Policy.
- Email verification services: deliverability signals to confirm your email address is valid.
- Job aggregation APIs: MapJob receives job listing data (such as job titles, descriptions, locations, and employer names) from USAJobs and JSearch (via RapidAPI) to display aggregated listings. No personal information about you is shared with these providers as part of this data retrieval.
2. CCPA/CPRA Categories of Personal Information
For California residents, we collect the following statutory categories of personal information:
- Identifiers: real name, alias, email address, account username, IP address, device identifiers.
- Personal records: name, address, phone number, employment history, education history contained in resumes.
- Protected classification characteristics: we do not intentionally collect characteristics such as race, gender, age, or disability status. Seekers may voluntarily include such information in resumes or profiles; we do not use it for decision-making.
- Commercial information: credits purchased, transaction history, billing records.
- Internet or other electronic network activity: browsing and search history within the platform, interactions with job listings.
- Geolocation data: approximate location (IP-based) and precise location (if granted by device permission).
- Professional or employment-related information: job history, skills, job preferences, application materials.
- Inferences: job category preferences and geographic search patterns derived from usage.
- Sensitive personal information: account login credentials (password hash); precise geolocation if granted. We do not use sensitive personal information to infer characteristics about you or for purposes beyond providing the service.
3. How We Use Your Information
- Providing the service: displaying job listings on the map, routing applications to employers, enabling employer–seeker messaging, managing credits and billing.
- Account management: creating and maintaining your account, verifying your identity, enabling two-factor authentication.
- Communications: sending transactional emails (application confirmations, messages, password resets) and, unless you opt out, onboarding tips, product updates, and job alerts. Every such email includes a one-click unsubscribe link, and you can manage categories at any time from your email preferences page.
- Safety and fraud prevention: detecting fake listings, abusive accounts, and fraudulent payment activity.
- Security, logging, and abuse prevention: we record IP addresses, user-agent strings, and request metadata in server logs and security audit records to detect and prevent fraud, brute-force attacks, abusive behavior, and unauthorized access. Security audit records of administrative actions are retained for up to two years. These records are not used for marketing or for inferring characteristics about you.
- Analytics and improvement: understanding how people use the platform so we can improve features and fix bugs. Third-party analytics tools are only loaded if you opt in to analytics cookies. Separately, we keep first-party records of searches run on the platform — the search terms (after removing anything that looks like an email address or phone number), the filters applied, and the number of results — to improve search quality and find gaps in job coverage. These search records are linked to your account only if you have opted in to analytics cookies; if you have not opted in, or your browser sends a Do Not Track or Global Privacy Control signal, they are stored without any user identifier.
- Legal compliance: complying with applicable laws, responding to lawful requests from government authorities, and enforcing our Terms of Use.
- Billing and payments: processing credit purchases, issuing refunds, and resolving disputes through Stripe.
4. How We Share Your Information
We do not sell your personal information. We share information only as described below.
- Employers and job seekers (MapJob Apply): when a seeker applies to a job via MapJob Apply, the application is submitted directly on the platform with one click using the seeker's saved profile. The following information is shared with the relevant employer: your name, email address, resume, and application message. Employers may only use this data to evaluate you for the posted position. For jobs that link to an external website or applicant tracking system, your data is submitted to that third party and is subject to their privacy practices. Employer company profiles and job listings are visible to seekers. Messages are shared between the parties to the conversation.
- Resume visibility: your resume is only visible to employers who receive your applications. If you opt in to the talent CRM browse feature, employers with active accounts may also browse your profile and resume. You can opt out of talent CRM browse at any time in your account settings.
- Service providers: we use third-party vendors to operate the platform. Each vendor processes data on our behalf under contractual obligations limiting their use, and is subject to its own privacy policy:
- Stripe — payment processing and billing (stripe.com/privacy).
- Amazon Web Services (AWS): hosting, S3 file storage for resumes and uploads, and Amazon SES for transactional email delivery (aws.amazon.com/privacy).
- Vercel — web hosting and edge delivery; processes IP addresses and request metadata (vercel.com/legal/privacy-policy).
- Vercel Analytics & Speed Insights — aggregated, privacy-friendly usage analytics and page-performance telemetry. Only loaded after you opt in via the cookie banner or our Cookie Preferences page. Processes a per-visit pseudonymous identifier, page URL, referrer, country (derived from IP, IP itself is not stored), and basic device/browser metadata. Same privacy policy as Vercel above.
- PostHog — product analytics (funnel, retention, feature usage) used to understand how the platform is being used so we can improve it. Only loaded after you opt in via the cookie banner or our Cookie Preferences page. Processes a pseudonymous user identifier, the events you trigger (page views, signups, applications), page URL, referrer, and basic device/browser metadata. We do not send your email address or resume content to PostHog (posthog.com/privacy).
- Neon (Databricks) — managed PostgreSQL database (databricks.com/legal/privacynotice).
- Upstash, Inc. — managed Redis hosting: session storage, caching, and rate-limit counters (upstash.com/trust/privacy.pdf).
- Meilisearch — full-text search indexing of job listings (meilisearch.com/privacy-policy).
- Twilio — SMS delivery for phone number verification; processes phone numbers (twilio.com/legal/privacy).
- Cloudflare Turnstile — bot protection on authentication and form submissions; processes IP addresses and browser fingerprint signals (cloudflare.com/privacypolicy).
- Sentry — error monitoring and performance tracing; may capture user identifiers, IP addresses, and request metadata embedded in stack traces (sentry.io/privacy).
- MapTiler — map tile delivery for the job map, and address search and autocomplete; processes IP addresses, the address or place text you type, and the approximate location described under “Address lookups” in section 1 (maptiler.com/privacy-policy).
- Geoapify — geocoding provider; processes IP addresses, the address or place text you type, and the approximate location described above. Geoapify handles the map-pin address lookup and the verification of addresses you save to a profile, a job posting, or a company record — including a home address on a seeker profile. Which of Geoapify or MapTiler answers a typed address search is set by a server configuration setting and can change without a code release, so both are named here (geoapify.com/privacy-policy).
- OpenStreetMap Foundation (Nominatim) — standby geocoder. When the provider that would normally answer is unavailable, not configured, or unable to resolve an address, the same lookup is sent to the OpenStreetMap Foundation's Nominatim service instead, so that address search, the map-pin address lookup, and address verification on job postings and profiles keep working. This affects any address you type into MapJob, including a home address you enter on your seeker profile (osmfoundation.org/wiki/Privacy_Policy).
- USAJobs API — source of federal government job listings; no personal information about you is shared with USAJobs as part of this retrieval (usajobs.gov/Help/privacy).
- JSearch via RapidAPI — aggregated third-party job listings; no personal information about you is shared with RapidAPI as part of this retrieval (rapidapi.com/privacy).
- Adzuna — aggregated third-party job listings; no personal information about you is shared with Adzuna as part of this retrieval (adzuna.com/privacy-policy).
- Analytics providers: if you opt in to analytics cookies, aggregate and pseudonymous usage data may be shared with analytics tools.
- Legal requirements: we may disclose information if required by law, court order, or regulatory authority; to protect the rights, property, or safety of MapJob, our users, or the public; or to detect and prevent fraud.
- Business transfers: if MapJob is acquired or merged, personal information may be transferred as part of that transaction. We will notify you before your data is subject to a different privacy policy.
- With your consent: for any other sharing not described here, we will obtain your explicit consent.
5. Data Retention
- Active accounts: we retain your information for as long as your account is active.
- Closed accounts: after account deletion, we delete or anonymize personal data from our live systems within 90 days, except where we are required to retain it for legal, compliance, or dispute resolution purposes (typically up to 7 years for financial records). After account deletion we retain anonymized transactional and financial records (amounts, dates, and payment references — no personal data) as required for legal, tax, and dispute purposes. Copies held in backups and database history are covered separately below.
- Job postings: expired job listings are archived and removed from public view, but retained for up to 2 years for analytics and dispute resolution.
- Messages: platform messages are retained with the related job application and are permanently deleted together with the job posting, two years after the posting is archived. Conversations tied to a posting that is still live remain available for as long as that posting exists.
- Resumes and uploads: files in S3 are deleted when you remove them from your profile or delete your account.
- Search records: the first-party search records described in “Analytics and improvement” above are retained as aggregate product telemetry. Any link between a search record and your account is removed when your account is deleted.
- Feedback: notes submitted through the in-app feedback widget are retained so we can act on them; the link to your account and your email address are removed when your account is deleted.
- Platform usage records: we keep first-party records of in-product events — job listings viewed, apply clicks, and similar interactions — which power the statistics employers see for their own listings and our own product metrics. These records are retained for as long as the job listing they relate to exists: a listing is permanently deleted two years after it is archived and its usage records are deleted with it, as they are if the employer's company record is removed. A listing that is never archived has no separate time limit. Independently of that, the link to your account is removed when your account is deleted, leaving an event with no user identifier.
- Security and sign-in audit records: we keep a record of sign-ins, authentication attempts, and comparable security-relevant actions on an account. These records store a one-way hash of the IP address rather than the address itself, and are retained indefinitely for security, fraud, and dispute investigation. They survive account deletion, at which point the account they reference has already been de-identified. (This is separate from the administrative audit records described in section 3.)
- Profile-view records: when an employer views your seeker profile we record that view, so we can show you who has viewed you and detect abuse of employer browsing. To make that abuse detection possible the record also includes a one-way hash of the IP address of the employer who viewed you and their browser user agent. These records are retained for as long as your account exists and are deleted with it; there is no separate time limit while the account is open.
- Logs: server access logs are retained for 90 days.
- Backups and database history: the retention periods above describe our live systems. Copies of data can persist after that in routine backups and in our database provider's point-in-time recovery history, which are used only to restore the service after a failure or data-loss incident and are not consulted for any other purpose. These copies expire on their own schedule rather than on request: point-in-time database history currently expires after 24 hours, and the nightly database archive we hold in cloud object storage is moved to cold storage after 30 days and deleted after 365 days. A restore is a whole-database event, so a restore performed after a deletion could reintroduce information that had already been deleted; these copies are never used to answer an access, correction, or deletion request.
6. Your Rights and Choices
Depending on where you live, you may have the following rights regarding your personal information. California residents have additional rights under CCPA/CPRA — see our Privacy Choices page for a dedicated interface.
- Access: request a copy of the personal information we hold about you.
- Correction: request that we correct inaccurate personal information.
- Deletion: request deletion of your personal information, subject to certain exceptions.
- Portability: receive a copy of your personal information by request (email support@mapjob.io) in a machine-readable JSON format, within 45 days of a verified request.
- Opt-out of sale/sharing: we do not sell personal information. If this changes, you will have the right to opt out.
- Limit use of sensitive personal information: you can limit our use of sensitive personal information to purposes necessary to provide the service.
- Non-discrimination: we will not discriminate against you for exercising any privacy right.
- Marketing opt-out: you can unsubscribe from marketing emails at any time using the unsubscribe link in the email or by contacting us.
- Cookie preferences: manage your cookie choices via our Cookie Preferences page.
To exercise any right, submit a request at support@mapjob.io or via our Privacy Choices page. We will verify your identity before processing requests and respond within 45 days (extendable by an additional 45 days with notice for complex requests).
7. State-Specific Privacy Rights
In addition to California (CCPA/CPRA), residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states with comprehensive privacy laws have rights to access, correct, delete, and port their personal data, and to opt out of targeted advertising and profiling that produces legal or similarly significant effects. We do not engage in targeted advertising based on personal data purchased from third parties, and we do not make automated decisions that produce legal or similarly significant effects. To exercise any state privacy right, contact us at support@mapjob.io.
8. Children's Privacy (COPPA)
MapJob is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us at support@mapjob.io and we will delete it promptly. Users must be at least 16 years old to create an account.
9. Security
We implement appropriate technical and organizational measures to protect your personal information, including TLS encryption in transit, encrypted storage at rest, hashed passwords, access controls, and regular security reviews. No system is completely secure. If you discover a security vulnerability, please report it to security@mapjob.io. See our Security page for details.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and, where required, regulatory authorities within the timeframes required by applicable law.
10. International Transfers
MapJob is operated in the United States. If you access our platform from outside the US, your information will be transferred to and processed in the United States. We use service providers (AWS, Stripe, etc.) that may process data in multiple countries. We rely on their standard contractual clauses and data processing agreements to ensure adequate protection for cross-border transfers.
11. Do Not Track and Global Privacy Control
We honor the Do Not Track (“DNT”) and Global Privacy Control (“GPC”) signals sent by your browser. If either signal is enabled, we will not load optional analytics or performance cookies, and the analytics your browser would otherwise send us — page views, funnel events and the like — are refused at our servers and not stored at all, even if you previously opted in to those categories. Search records created while either signal is set are stored without any account identifier. Records we create in order to run the service — for example that you applied to a particular job, which the employer sees in their applicant list — are still recorded against your account, because they are part of carrying out the action you asked for rather than analytics. Both signals are recognized in your browser and on our servers. These signals take priority over your cookie consent selection. We do not use cross-site tracking. The same statement appears in our Cookie Policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (to the address on your account) and post the updated policy with a new “Last Updated” date. Your continued use of the platform after the effective date of the updated policy constitutes acceptance of the changes.
13. Contact Us
MapJob is operated by MapJob LLC, 82 Wendell Ave, Suite 100, Pittsfield, MA 01201, USA.
For privacy-related questions, requests, or complaints, contact us at:
Email: support@mapjob.io
Subject line: Privacy Request
You also have the right to lodge a complaint with your state's Attorney General or applicable data protection authority.