🔒  Privacy First

Privacy Policy

We built Mailtohire to help you land jobs — not to profit from your data. Here's exactly what we collect, why, and what we never do.

Effective: January 1, 2025Governed by Indian LawNo ads. Ever.

Mailtohire is a job-search outreach platform that helps job seekers in India send personalised cold emails to HR professionals and companies directly from their own Gmail account. This Privacy Policy explains what personal data we collect, how we use it, and the choices you have. By using Mailtohire, you agree to the practices described here.

👁️
Section 01

Overview

Mailtohire is an early-stage product operated by an individual founder based in India. We do not currently operate as a registered legal entity. Once formally incorporated, this policy will be updated with the registered business details. For now, all data-related inquiries can be directed to the contact address at the bottom of this page.

We are committed to handling your information responsibly and in compliance with India's Information Technology Act, 2000, and its associated rules on privacy and sensitive personal data.

Short version: We collect only what's necessary to run the platform. We never sell your data. We never read your Gmail inbox. We never store your email passwords. You can delete your account and all associated data at any time.

📋
Section 02

Data We Collect

We collect information in three ways: what you provide directly, what Google shares with us during OAuth login, and what's generated automatically as you use the platform.

What you provide directly

  • Name, contact number, gender, and years of experience (from your profile)
  • LinkedIn URL, portfolio URL, and resume URL (public links only — we don't store the documents themselves)
  • Professional preferences: skills, roles, preferred cities, industries
  • Email template content that you write

What Google provides during sign-in

  • Your Google account name and profile photo
  • Your Google email address (used as your login identity)
  • OAuth access and refresh tokens — stored AES-256 encrypted; never in plain text

What's generated automatically

  • Coin transaction logs (credits and debits)
  • Campaign configuration and send statistics (how many sent, queued, failed)
  • Email send logs (timestamp, recipient type, template used, status) — recipient email addresses are masked in logs
  • Quick Send history (date, template used, masked recipient)

What we never collect

  • Your Gmail inbox, sent items, or any received emails
  • Credit card numbers, CVVs, or banking details (handled entirely by Razorpay)
  • Your Google account password
  • Device fingerprints, location data, or IP addresses for profiling
📧
Section 03

Gmail Access — How It Works

For Smart Campaigns (automated sending), Mailtohire requests one specific Gmail permission: gmail.send. This is a narrow, write-only scope that allows us to send emails on your behalf. It does not grant access to read, modify, or delete any messages in your inbox.

What we do with Gmail access

  • Compose and send outreach emails from your Gmail account, according to your campaign settings
  • Store your OAuth access and refresh tokens in our database — always AES-256 encrypted, never in plain text
  • Automatically refresh the access token before it expires, without requiring you to re-authenticate

What we never do with Gmail access

  • Read, scan, or analyse any emails in your inbox or sent folder
  • Use your Gmail for any purpose other than sending the emails you configured in Mailtohire
  • Share your Gmail tokens with any third party

You can revoke Gmail access at any time from your Profile page (Disconnect Gmail) or directly from your Google Account settings at myaccount.google.com. Revoking access will pause any active campaigns but will not affect your Mailtohire account or coin balance.

🗂️
Section 04

The HR Catalog

Mailtohire maintains a curated catalog of HR professionals, recruiters, and company career email addresses at Indian tech companies. This catalog is built and maintained manually by our team.

  • Catalog entries are sourced from publicly available professional information
  • Email addresses in the catalog are never shown in full to any user — they are masked in all UI views (e.g., pr******@razorpay.com)
  • Emails are only used server-side when sending your campaign or Quick Send message
  • Cooldown rules prevent any HR from being contacted more than once per platform-wide window, protecting both their inbox and your reputation

For HR professionals: If you are a recruiter or HR manager and wish to have your email address removed from the Mailtohire catalog, please contact us at abcd@gmail.com with the subject line "Catalog Removal Request". We will process your request within 7 business days.

💳
Section 05

Payments & Razorpay

All payment processing on Mailtohire is handled by Razorpay, a PCI-DSS compliant payment gateway. Mailtohire never sees, processes, or stores your credit card, debit card, UPI, or net banking credentials.

What Mailtohire stores after a completed transaction:

  • Razorpay order ID and payment ID (for reference and dispute resolution)
  • Transaction amount, currency (INR), and payment status
  • The plan purchased and coins credited

This information is retained to maintain your coin balance history and for accounting purposes. Razorpay's own privacy policy governs how they handle your payment credentials.

🍪
Section 06

Cookies & Tracking

Mailtohire uses exactly one cookie: a JWT authentication token stored as an httpOnly cookie. This cookie:

  • Is set when you sign in with Google and cleared when you sign out
  • Is marked httpOnly — it is not accessible to JavaScript and cannot be stolen by XSS attacks
  • Contains only your user ID and email — no sensitive personal data
  • Expires after 7 days, requiring you to sign in again
  • We do not use advertising cookies or tracking pixels
  • We do not use analytics cookies (Google Analytics, Mixpanel, etc.)
  • We do not serve ads or allow advertisers to place cookies on Mailtohire
🤝
Section 07

Data Sharing

We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:

  • Razorpay — receives transaction details to process your payment. Governed by their privacy policy.
  • Google — receives your OAuth tokens to authenticate login and send emails via the Gmail API.
  • Legal compliance — we may disclose data if required by Indian law, court order, or government authority, to the extent legally mandated.

No other third parties receive your personal data. We do not integrate with advertising networks, data brokers, or marketing platforms.

🗄️
Section 08

Data Retention

We retain your data for as long as your account is active. Specifically:

  • Your profile, templates, and campaign data are retained while your account exists
  • Payment and coin transaction records are retained for a minimum of 3 years for accounting and legal compliance purposes, even after account deletion
  • Email send logs are retained for 12 months, after which they are deleted
  • Gmail OAuth tokens are deleted immediately when you disconnect Gmail or delete your account
⚖️
Section 09

Your Rights

You have the following rights regarding your data on Mailtohire:

  • Access — request a copy of the personal data we hold about you
  • Correction — update or correct your profile information at any time from the Profile page
  • Deletion — request full account deletion by emailing us; we will delete all personal data except legally mandated records within 30 days
  • Gmail Revocation — disconnect Gmail access at any time from your Profile page, without deleting your account
  • Data Portability — request an export of your profile and template data

To exercise any of these rights, email us at abcd@gmail.com. We will respond within 30 days.

🔐
Section 10

Security

We take reasonable technical measures to protect your data:

  • Gmail OAuth tokens are encrypted using AES-256-CBC before storage — the encryption key is never stored in the database
  • All connections are HTTPS-only in production
  • JWT cookies are httpOnly and secure — resistant to XSS and CSRF
  • Database access is restricted to application servers; no public-facing database ports
  • Rate limiting is applied to all authentication endpoints

No system is 100% secure. If you discover a security vulnerability, please report it responsibly to abcd@gmail.com before public disclosure.

📝
Section 11

Changes to This Policy

We may update this Privacy Policy as the product evolves — for example, when we formally incorporate as a business entity. When we make material changes, we will update the effective date at the top of this page.

For significant changes that affect how we handle your data, we will notify you by email (to your Google account email) at least 7 days before the changes take effect. Continued use of Mailtohire after that date constitutes acceptance.

✉️
Section 12

Contact Us

For any privacy-related questions, data requests, or concerns, please reach out:

Get in touch

We typically respond within 2–3 business days. For account deletion or data export requests, please allow up to 30 days for processing.

✉️  abcd@gmail.com