Privacy Policy
1. Introduction
Welcome to Task Fills ("Company," "we," "our," or "us"). This Privacy Policy explains how we collect, use, store, and share your personal information when you use our platform, website, mobile applications, and related services (collectively, the "Services"). We respect your privacy and are committed to protecting your personal data. We comply with global data protection laws, including:
- GDPR (General Data Protection Regulation) – European Union (EU) & UK - Provides individuals with enhanced rights over their personal data and imposes strict obligations on organizations processing that data.
- CCPA/CPRA (California Consumer Privacy Act/California Privacy Rights Act) – USA - Grants California residents specific rights regarding their personal information and imposes transparency requirements on businesses.
- PIPEDA (Personal Information Protection and Electronic Documents Act) – Canada - Governs how private sector organizations collect, use, and disclose personal information in commercial activities.
- PDPA (Personal Data Protection Act) – Singapore - Requires organizations to obtain consent before collecting personal data and governs data protection obligations.
- PIPL (Personal Information Protection Law) – China - Regulates personal information processing activities and provides individuals with rights concerning their personal information.
- POPIA (Protection of Personal Information Act) – South Africa - Promotes the protection of personal information processed by public and private bodies and establishes minimum requirements for data processing.
- Other applicable laws across Asia, Africa, the Middle East, and North America - Including but not limited to Japan's APPI, South Korea's PIPA, Brazil's LGPD, and UAE's PDPL.
By using Task Fills, you consent to the collection and use of your data as described in this policy. This Privacy Policy applies to all users of our Services, including job seekers, employers, recruiters, and visitors to our platform. If you do not agree with this Privacy Policy, please do not access or use our Services.
2. Information We Collect
We collect the following categories of personal information to provide and improve our Services:
(A) Personal Identifiers:
- Full Name, Date of Birth, Gender - Used to create and personalize your account
- Contact Information (Phone, Email, Address) - Used for account communications, verifications, and job matching
- Profile Photo (optional) - Used to personalize your profile for employers
- User Account Credentials - Used to secure and authenticate your account access
(B) Professional Information:
- Skills, Work Experience, Employment History - Used to match you with relevant job opportunities
- Resume, CV, Cover Letters - Shared with potential employers with your consent
- Professional Certifications, Educational Background - Used to verify qualifications and improve job matching
- Job Preferences, Salary Expectations, Work Availability - Used to find suitable positions matching your criteria
- Professional References - Processed only with your explicit permission and the consent of your references
(C) Government Identifiers (if required by law or for verification):
- National ID, Passport, Social Security Number - Used for identity verification and background checks (where legally required)
- Work Authorization Documents - Used to verify eligibility to work in specific regions
- Tax Identification Information - Used for compliance with applicable tax laws and regulations
- Driver's License (for certain positions) - Used when required for specific job functions
(D) Financial Data (for payment processing):
- Bank Account Details - Securely stored for payment processing using encryption
- Payment Card Information - Processed via PCI DSS-compliant vendors (e.g., Stripe, PayPal) and not stored directly on our servers
- Billing Address, Tax Information - Used for payment processing and tax reporting purposes
- Transaction History - Maintained for accounting, auditing, and user service purposes
(E) Platform Usage Data:
- IP Address, Device Information - Used for security, fraud prevention, and service optimization
- Geolocation Data - Used for job matching based on proximity and location preferences
- Browsing History, Search Queries - Used to improve search relevance and job recommendations
- App Usage Patterns, Feature Interactions - Used to enhance user experience and platform functionality
- Communication Records - Stored to facilitate dispute resolution and customer support
3. How We Use Your Data
We use your personal data for the following legitimate purposes:
- Providing Core Services: Matching job seekers with employers, facilitating job applications, enabling communication between parties, and optimizing job recommendations based on your profile, experience, and preferences.
- Identity Verification & Security: Preventing fraud, verifying user identities, protecting against malicious activity, securing account access, and ensuring compliance with applicable employment and verification laws.
- Payment Processing: Facilitating secure payments between users, processing subscription fees, managing refunds or disputes, and generating necessary financial records in compliance with accounting standards.
- Marketing & Communication: Sending promotional emails, job alerts, platform updates, and newsletters relevant to your interests. All marketing communications include clear opt-out options and are sent only with proper consent in accordance with applicable laws.
- Platform Improvement: Analyzing user behavior and feedback to enhance our services, fix technical issues, develop new features, and optimize user experience through A/B testing and analytics.
- Customer Support: Addressing user inquiries, providing technical assistance, resolving disputes, and maintaining communication records for quality assurance.
- Legal & Regulatory Compliance: Adhering to GDPR, CCPA, PIPEDA, and other applicable laws, responding to legal requests from authorities when legally required, and maintaining necessary documentation for compliance audits.
4. Data Sharing & Third Parties
We do not sell your personal data. However, we share data with the following categories of recipients, always maintaining appropriate data protection safeguards:
- Employers & Clients: We share your professional information (resume, skills, experience) only when you apply for a specific position or when a job match is made with your explicit consent. Employers receive only the information necessary for hiring decisions.
- Payment Processors: We use industry-standard payment processors (e.g., Stripe, PayPal) that are PCI DSS Compliant. These processors receive transaction data necessary to process payments but do not use this data for their own purposes beyond providing payment services.
- Cloud Service Providers: We use secure cloud infrastructure providers to host our platform and store data with appropriate security measures, including encryption and access controls.
- Analytics & Marketing Tools: We use analytics providers to improve our services and marketing tools to optimize our communications. These providers process anonymized or pseudonymized data where possible and are bound by strict data processing agreements.
- Customer Support Platforms: Support inquiries may be handled through third-party ticketing systems that maintain the confidentiality and security of your communications.
- Legal Authorities: We may disclose information if required by law, court order, or governmental regulation, or to protect our rights, property, or safety.
- Corporate Transactions: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity with the same level of protection and subject to the same privacy policy.
All third-party service providers are carefully selected and contractually obligated to ensure the security and confidentiality of your personal data.
5. Data Retention & Security
We retain your personal data only for as long as necessary for the purposes set out in this policy, to fulfill legal obligations, or to protect our legitimate business interests. Our specific retention practices include:
- Active Accounts: We retain your data for as long as your account remains active, allowing you to access and use our services.
- Inactive Accounts: If your account becomes inactive for 12 consecutive months, we will notify you before archiving or anonymizing your personal data.
- Post-Termination: Upon account termination, essential information may be retained for specific periods to comply with legal obligations (typically 2-7 years depending on the type of data and applicable laws).
- Anonymized Data: We may retain anonymized data (stripped of personal identifiers) indefinitely for statistical and analytical purposes.
We implement robust technical and organizational security measures, including:
- End-to-End Encryption: For sensitive data transmission and storage, protecting your information from unauthorized access.
- Multi-Factor Authentication (MFA): Available for all user accounts to prevent unauthorized access even if passwords are compromised.
- Regular Security Audits: Conducted by internal teams and external security specialists to identify and address potential vulnerabilities.
- Access Controls: Strict employee access limitations based on need-to-know principles and role-based permissions.
- Data Backup: Regular backups with encryption to prevent data loss while maintaining confidentiality.
- Incident Response Plan: Comprehensive procedures to detect, respond to, and recover from security incidents, including data breach notification protocols.
- Staff Training: Regular privacy and security training for all staff members who process personal data.
Despite these measures, no method of transmission over the Internet or electronic storage is 100% secure. We strive to use commercially acceptable means to protect your personal data but cannot guarantee absolute security.
6. Your Rights & Choices
Depending on your location, you may have various rights regarding your personal data. We honor these rights regardless of your location, subject to applicable legal limitations:
- Right to Access: You can request copies of your personal data that we hold (GDPR, CCPA, PIPEDA, PIPL).
- Right to Data Portability: You can request your data in a structured, commonly used format that can be transferred to another service provider (GDPR, CCPA).
- Right to Delete/Erasure: You can request deletion of your personal data under certain circumstances (CCPA "right to delete", GDPR "right to be forgotten", POPIA).
- Right to Correct/Rectification: You can request correction of inaccurate or incomplete personal data (GDPR, PIPL, PDPA).
- Right to Restrict Processing: You can request temporary or permanent limitations on how we use your data (GDPR, PDPA, POPIA).
- Right to Object: You can object to processing based on legitimate interests, direct marketing, or research/statistical purposes (GDPR).
- Right to Opt-Out of Sale/Sharing: You can direct us not to share your information with third parties (CCPA).
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights (CCPA).
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw your consent at any time (GDPR, PIPL, POPIA).
To exercise any of these rights, you can:
- Manage many privacy settings directly through your account dashboard
- Submit a data request by emailing privacy@taskfills.com
- Contact our Data Protection Officer at dpo@taskfills.com
We will respond to all legitimate requests within 30 days, or sooner where required by law. In certain cases, we may ask for additional information to verify your identity before processing your request.
7. Cross-Border Data Transfers
Task Fills operates globally, which means your personal data may be transferred to, stored, and processed in countries outside your country of residence. If you are located outside the United States, your data may be transferred to and stored in the USA, EU, or other jurisdictions where we or our service providers operate.
We implement appropriate safeguards to ensure that your personal data receives an adequate level of protection, regardless of where it is processed:
- Standard Contractual Clauses (SCCs): For EU & UK data transfers to countries without an adequacy decision, we incorporate European Commission-approved SCCs into our agreements with data processors and controllers.
- Binding Corporate Rules (BCRs): Where applicable, we may rely on BCRs approved by relevant data protection authorities for intra-group transfers.
- Data Processing Agreements: We ensure that all third-party service providers are contractually bound to protect data according to the standards required by applicable law.
- Privacy Shield: For historical data transfers, we may continue to honor Privacy Shield principles although we no longer rely on this mechanism for new transfers.
- Data Localization: In some regions (such as China under PIPL and Russia under their Data Localization Law), we may maintain local data storage to comply with data localization requirements.
- Regional Infrastructure: Where required by law or technical necessity, we may process certain data within specific regions to optimize service performance and ensure compliance.
By using our Services, you acknowledge these international transfers. However, we will always ensure that these transfers comply with applicable data protection laws and that appropriate safeguards are in place to protect your information.
8. Cookies & Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience on our platform. These technologies help us understand how users interact with our Services and allow us to improve functionality.
We use these technologies for the following purposes:
- Essential Cookies: Necessary for the operation of our platform, including user authentication, security measures, and basic functionality (these cannot be disabled).
- Preference Cookies: Remember your settings and preferences to personalize your experience (language preferences, location settings).
- Analytics Cookies: Help us understand how visitors interact with our platform by collecting anonymized information about usage patterns, popular features, and potential issues.
- Marketing Cookies: Used to deliver relevant advertisements and track the effectiveness of our marketing campaigns (only with your consent in regions where required).
- Third-Party Cookies: Set by our partners for analytics, advertising, or social media integration (managed according to their respective privacy policies).
Cookie Management:
- You can manage cookie preferences via your browser settings by adjusting permissions for cookies or using private/incognito browsing mode.
- Our Cookie Management Tool allows you to selectively enable or disable non-essential cookies when you visit our site.
- For EU/UK users, we present a cookie consent banner on first visit in compliance with the ePrivacy Directive.
- Opting out of cookies may impact certain functionalities but will not prevent you from using essential features of our platform.
We also employ other tracking technologies, including web beacons, pixels, and local storage, which operate similarly to cookies to enhance user experience and platform functionality.
9. Marketing Communications
We may send you marketing emails about our services, job opportunities, and platform updates that we believe may interest you. Our marketing practices comply with all applicable laws, including:
- Consent-Based Marketing: In regions requiring explicit consent (such as the EU under GDPR), we only send marketing communications after obtaining your clear, affirmative consent.
- Opt-Out Mechanism: All marketing communications include a prominent, easy-to-use unsubscribe link that immediately processes your request to stop receiving such communications.
- Preference Center: You can manage your communication preferences through your account settings, selecting which types of messages you wish to receive.
- CAN-SPAM Compliance: Our email marketing adheres to the US CAN-SPAM Act requirements, including accurate sender information, clear subject lines, and physical business address in emails.
- Service Announcements: We may send essential service-related announcements (such as security alerts or major platform changes) even if you've opted out of marketing communications.
If you receive unwanted communications from us, you can:
- Click the "unsubscribe" link at the bottom of any marketing email
- Adjust your preferences in your account settings
- Contact us directly at privacy@taskfills.com
We respect your communication preferences and will process opt-out requests promptly, typically within 10 business days or less.
10. Updates to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, services, or applicable laws. When we make changes:
- Notice of Changes: Significant changes will be communicated to you via email and/or prominent notice on our platform before changes take effect.
- Prior Versions: We maintain archives of previous privacy policies for your reference.
- Effective Date: The revised policy will include an updated effective date at the top of the document.
- Consent: Where required by law, we may seek your explicit consent to new processing activities or significant policy changes.
We encourage you to review our Privacy Policy whenever you access our Services to stay informed about our information practices. Your continued use of our Services after we post changes constitutes your acceptance of the revised terms, where permitted by applicable law.
11. Children's Privacy
Our Services are not directed to individuals under the age of 16, or the applicable age of digital consent in your jurisdiction. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information without appropriate parental consent, please contact us at privacy@taskfills.com. If we become aware that we have collected personal information from children without verification of parental consent, we will take steps to remove that information from our servers.
12. Contact Us
For any privacy-related inquiries or to exercise your data rights, please contact us through one of these channels:
- Email: privacy@taskfills.com (for general privacy inquiries)
- Data Subject Requests: dsr@taskfills.com (for formal data subject requests)
- Web Form: Available through our Contact Us page
If you are in the EU/UK and have unresolved concerns, you have the right to complain to your local data protection authority.
This Privacy Policy ensures compliance with GDPR, CCPA, PCI DSS, PIPEDA, PIPL, PDPA, and other global privacy laws.
By using Task Fills, you acknowledge and agree to this Privacy Policy.