This Privacy Policy explains how HardworkingPH ("HardworkingPH", "we", "our", or "us") collects, uses, shares, and protects your personal information when you use our website and services (the "Platform"). By using the Platform you consent to this policy.
1. Information we collect
We collect the following categories of information:
- Account information — name, email address, password (hashed), role (Worker or Employer), and profile picture.
- Worker profile information — headline, bio, hourly rate, skills, work experience, certifications, resume/CV, portfolio items, location, hours of availability, and verification documents you upload.
- Employer information — company name, billing details, job descriptions, and team-member email addresses you invite.
- Payment information — handled by third-party providers (PayPal, Stripe, Wise, GCash, Maya, etc.). HardworkingPH does not store full card numbers; we store provider tokens, transaction IDs, and high-level metadata required for accounting and dispute handling.
- Communications — messages exchanged between Workers and Employers on the Platform, support tickets, and emails to/from us.
- Usage data — pages viewed, features used, search queries, IP address, browser and device information, and approximate location derived from IP.
- Time-tracking and screenshots — if you opt in to TimeProf, our desktop time-tracking tool, we collect activity samples and screenshots you and your Employer have agreed to capture.
2. How we use information
- To operate and improve the Platform and provide the services you request.
- To match Workers with relevant jobs, and Employers with relevant candidates, using our matching and ranking algorithms.
- To process payments, calculate fees, issue invoices, and handle disputes and refunds.
- To send transactional messages (account, job, payment, security notifications) and, with your consent, marketing communications.
- To prevent fraud and abuse: detect fake profiles, bulk-invite spam, payment fraud, and other policy violations.
- To comply with legal obligations, tax reporting, and law-enforcement requests.
3. Legal bases for processing (EU/UK users)
Where the GDPR applies, we process your data under the following legal bases: (a) performance of a contract — to provide the services you sign up for; (b) legitimate interests — to improve, secure, and market the Platform; (c) consent — for optional analytics, marketing emails, and screenshot capture; (d) legal obligation — for tax, accounting, and law-enforcement requests.
4. Sharing of information
We share information only as follows:
- Between users — your public profile (Worker) or job posts and company details (Employer) are visible to other Platform users and indexed by search engines unless you opt out. Messages are visible to the parties in the conversation and to HardworkingPH staff who handle support and disputes.
- Service providers — payment processors (PayPal, Stripe, Wise, GCash, Maya), email delivery (SMTP providers), analytics (Google Analytics, with IP anonymization), customer support, hosting (DigitalOcean), and AI providers (Anthropic Claude, OpenAI) we use to power features like job description suggestions and resume parsing.
- Legal and safety — when required by law, court order, valid legal process, or to protect the rights, property, or safety of HardworkingPH, our users, or the public.
- Business transfers — if HardworkingPH is acquired, merged, or reorganized, your information may be transferred as part of that transaction. We will notify you and provide opt-out options where required.
We do not sell your personal information.
5. International transfers
HardworkingPH is operated from the Philippines and uses service providers in the United States, the European Union, and elsewhere. By using the Platform you understand that your information may be transferred to and processed in countries other than your own. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.
6. Data retention
We retain personal information for as long as your account is active and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements. Financial transaction records are typically retained for at least seven years for tax and accounting purposes. You can request deletion of your account at any time (see Section 8).
7. Cookies and tracking
We use cookies and similar technologies for: keeping you signed in (essential), remembering preferences (functional), measuring usage and improving the Platform (analytics), and attributing referrals from marketing campaigns. You can disable non-essential cookies in your browser settings; some features may not work correctly. We do not use third-party advertising cookies.
8. Your rights
Depending on your location, you have some or all of these rights:
- Access — request a copy of the personal information we hold about you.
- Correction — fix inaccurate or outdated information; most fields are editable directly in your profile settings.
- Deletion — request that we delete your account and associated data, subject to legal retention requirements (e.g., financial records).
- Portability — receive your data in a structured, machine-readable format.
- Objection / restriction — object to or limit certain processing, such as marketing or analytics.
- Withdraw consent — where processing is based on consent, you can withdraw it at any time without affecting prior lawful processing.
- Lodge a complaint — with your local data-protection authority (e.g., the Philippine National Privacy Commission, or your EU member-state authority).
To exercise any of these rights, use the contact page or email [email protected]. We respond within 30 days.
9. California residents (CCPA/CPRA)
If you reside in California, you have rights similar to those described above, including the right to know what personal information we collect and how we use it, the right to delete (subject to exceptions), the right to correct, and the right to limit the use of sensitive personal information. We do not "sell" or "share" personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.
10. Security
We use industry-standard technical and organizational measures to protect your information: TLS encryption in transit, hashed passwords, scoped access controls, and audit logging. No system is perfectly secure; if you suspect unauthorized access to your account, contact us immediately.
11. Children
The Platform is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under 18. If we learn that we have done so, we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced via email or an in-product notice with at least 14 days' notice. The "Last updated" date at the top of this page reflects the current version.
13. Contact
Questions, complaints, or rights requests? Use our contact page or email [email protected].
Not legal advice. This policy is provided in good faith and aims to be readable. It does not replace tailored legal counsel — if you operate at scale or handle sensitive data, please review with a qualified attorney and your local data-protection authority.