Scalemaker HRis

Privacy policy

Effective October 7, 2026. This policy describes the Scalemaker HRis product of Scalemaker HR, operated by Stacey Kay.

Who we are

Scalemaker HRis is an HR information system and applicant tracking system. Scalemaker HR provides it to employer clients. Those employers use it for their own people and hiring. Applicants use the public career and application pages to apply for a job at one of those employers. Employees and other client users sign in to the product.

In this policy, “we” means Scalemaker HR. The employer you apply to, or work for, is a separate organization. That employer decides how to use the HR and recruiting records it keeps in the product.

Information from applicants

When you apply for a job, we collect the information you submit on that application. That can include your name, email, phone number, and home address; a resume; why you are interested, when you can start, and desired pay; work authorization and whether you need sponsorship; whether you know someone at the employer; how you heard about the job; a portfolio or LinkedIn link; work history, education, and certifications; and answers to questions the employer added to that job.

The application can also include a voluntary self-identification for equal employment purposes: gender, ethnicity, veteran status, and disability status. That response is stored separately from the rest of the application so it is not part of the ordinary hiring packet.

If the employer invites you to schedule an interview or sends an offer, we store the scheduling details and your response, such as a chosen time, or an acceptance, decline, or request to discuss the terms, including a note and a typed name when you accept.

A resume you upload from this computer, or a file you choose from Google Drive, is saved as the resume on your application. We may read the file in the browser flow to suggest name, email, phone, address, work history, and education. You can edit those fields before you submit. Some employers ask you to confirm that the resume does not include certain personal details before it is saved.

Google user data

Scalemaker HRis’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

The only Google scope we request is https://www.googleapis.com/auth/drive.file (drive.file). We request it only when you choose “Upload from Google Drive” on an application form. Google Identity Services and the Google Picker run in your browser. You sign in with your own Google account and pick a file. drive.file lets the page open the file you pick. It does not give us access to the rest of your Drive.

We use that file solely to attach it as the resume on your application. A PDF, Word (.docx), or text file is downloaded as itself. A Google Doc is exported as a PDF in your browser, because a Google Doc has no file bytes of its own. The downloaded or exported file then follows the same path as a resume you chose from your computer. We do not use the file for anything else.

The Google access token stays in your browser. It is used only to open the picker and to download the one file you picked. It is not sent to Scalemaker servers, and we do not store Google access tokens or refresh tokens. We do not keep a live connection to your Google account after the download. The original file remains in your Drive. What we store is a copy saved as your application resume.

We do not sell Google user data. We do not use Google user data for advertising, for credit decisions, or to train a general-purpose model. We do not transfer Google user data except as needed to provide the service: the resume copy is stored and shown to the employer you applied to, and to Scalemaker HR staff who operate the service for that employer. We may also disclose information if the law requires it, or to protect the security of the service. People at that employer, and Scalemaker HR staff supporting that employer, may read the resume because you picked the file and submitted the application. They do not receive access to the rest of your Google account.

You can revoke Scalemaker HRis at myaccount.google.com/permissions. Revoking access stops future use of the Drive permission. It does not delete a resume already saved on an application. To ask about that file, email staceykay@scalemakerhr.com.

Information from employees and client users

Signed-in users have an account: name, email, a password stored as a bcrypt hash, and, when turned on, an authenticator-app second factor. The authenticator secret is encrypted. A sign-in creates a session cookie. Sessions end after a period of inactivity chosen by the employer (15, 30, or 60 minutes; 30 is the default) and also end 12 hours after sign-in.

The employee record can include name and contact details, job, department, manager, work location, employment type, start and end dates, status, and an employee number. It can also include pay (salary or hourly rate and pay frequency), time-off balances and requests, timeclock punches, documents, onboarding tasks, performance notes and goals, equipment, messages, and benefit information the employer records in the product. The product does not connect to an insurance carrier.

Employers on a full file can also store a Social Security number, date of birth, home address, and emergency contact. Those employers can collect Form I-9 information, including the last four digits of the Social Security number, date of birth, citizenship or immigration status, and identity and work-authorization document numbers, and Form W-4 information, including the full Social Security number and withholding choices. Employers on a soft file do not collect Social Security number, date of birth, home address, or emergency contact on the employee profile, and do not use Form I-9 or Form W-4 in this product.

An employer can export records from the product, including a payroll census with name, work email, employee number, pay, status, job title, and department, for the employer’s own payroll process.

How we use information

We use this information to provide Scalemaker HRis: to receive and show applications, to keep the employer’s HR records, to run sign-in and permissions, and to send email the product initiates about applications, interviews, offers, account access, and messages when those features are used. We do not sell personal information. We do not use it for advertising.

How we share information

We share information with the employer client the record belongs to, and with Scalemaker HR staff who operate the service for that employer. Employees can see their own record in the signed-in self-service pages, within the limits of that employer’s file.

We use service providers to host the application, store files such as resumes and documents, and send email. They process information on our instructions to provide the service. The application is hosted on Vercel. We do not authorize those providers to use the information for their own advertising.

We may disclose information if the law requires it, to protect the security of the service, or if Scalemaker HR is involved in a merger or similar business transfer. We do not transfer Google user data except as described in the Google user data section.

Cookies

Signed-in use stores a session cookie. A few other cookies remember session state, such as whether a user is viewing their own record. Public career and application pages do not require an account. We do not use advertising cookies, and we do not use a third-party analytics tracker on these pages.

How long we keep information

Application and employee records are kept while the employer client uses the service and as needed for that employer’s HR and recruiting records. We do not delete an application on a fixed timer.

When the product collects a Form I-9, it is kept until the later of three years after the first day of employment or one year after employment ends, plus a 30-day buffer, and then removed. If there is no end date, that timer does not start. A signed Form W-4 is marked to be kept at least four years. The product does not delete that form automatically when the date passes.

Deletion and other requests

To ask us to delete, correct, or provide a copy of your information, email staceykay@scalemakerhr.com. Include the employer and the email you used, and say what you want. Some records belong to the employer client or have to be kept for a legal reason, including I-9 and W-4 records described above. If we cannot delete something, we will tell you why.

Security

Access to signed-in records is limited by role. Employees reach their own record. Employer users reach their company. Scalemaker HR access follows the role assigned to that person. Passwords are stored as bcrypt hashes, not as plain text. Authenticator secrets are encrypted. Session cookies are signed and expire as described above. The hosted service is served over HTTPS. No method of storage or transmission is perfect.

Children

Scalemaker HRis is not directed to children under 13, and we do not knowingly collect personal information from children under 13. The people who use it are job applicants and workforce users of an employer client. If you believe we have information from a child under 13, email staceykay@scalemakerhr.com and we will delete it.

Changes

We may update this policy. The new version will be posted on this page, and the effective date at the top will change. Continued use of Scalemaker HRis after the update means the new policy applies.

Contact

Scalemaker HR
Stacey Kay
staceykay@scalemakerhr.com