This policy explains what personal data SourcingNav processes, why, who it is shared with, how long it is kept, and the rights you have over it. It covers two groups of people: recruiters who hold accounts, and candidates whose information is processed by those recruiters.
SourcingNav is operated by Jason Shotwell (sole proprietor). For candidate data entered or sourced by a recruiter, that recruiter is the controller and SourcingNav acts as a processor on their behalf. For account and billing data we are the controller. Contact: hello@sourcingnav.com.
| Category | Examples | Where it comes from |
|---|---|---|
| Professional profile | Name, public profile URL, headline, employer, job title, location, skills | Public web search results; the public profile page a recruiter opens |
| Application data | Résumé, cover letter, email, phone, work authorisation and export-control answers | Submitted by the candidate through a job posting |
| Voluntary self-identification | Gender, race/ethnicity, veteran and disability status | Optional, candidate-provided, opt-in only |
| Contact data | Work email, verification status | Self-published sources and licensed lookup providers, on an explicit recruiter action |
| Engagement records | Messages sent, replies, opens, clicks, interview notes, scores and decisions | Generated by use of the Service |
| Account data | Recruiter name, email, settings, usage counts | Provided by the recruiter |
The SourcingNav Chrome extension is a window onto a recruiter's own SourcingNav account, shown beside a public profile page in their browser. It reads the visible name, headline, location, current employer, experience text and photo address of the one profile the recruiter is viewing, only when the recruiter clicks in the panel, and sends that to the recruiter's SourcingNav account at sourcingnav.com and nowhere else. It does not crawl, does not run in the background, does not read any other page, and does not read or require LinkedIn Recruiter. The only thing it stores in the browser is the recruiter's own SourcingNav session token, saved when they click Connect in Settings and removable by uninstalling the extension. Everything it saves is processed under this policy exactly as if the recruiter had typed it into sourcingnav.com. It is installed from the Chrome Web Store, where its permissions are listed and justified; when the recruiter uses LinkedIn’s own Save to PDF, the extension notices that one download finishing and names it in the panel, and reads nothing else from the browser.
SourcingNav is a high-risk AI system under the EU AI Act (Annex III, employment). It ranks and scores candidates against a role and can suggest that someone is passed over. Two things are always true:
We do not infer protected characteristics, and we do not use them as inputs to scoring.
We do not sell personal data and we do not share it for cross-context behavioural advertising. Candidate records are never pooled across recruiter accounts. We use these categories of processor:
| Purpose | Providers | What they receive |
|---|---|---|
| Hosting and database | Vercel, Turso | Service data at rest and in transit |
| Email delivery | Resend; your own Outlook or Gmail if connected | Message content and recipient address |
| AI inference | Anthropic, Together.ai, OpenAI, Groq | Job and profile text for parsing, scoring and drafting |
| Public web search | Serper (Google), SerpApi, Perplexity, Tavily | Query strings only — job titles, skills, place names. No candidate record, score or decision is ever sent to a search provider. |
| Contact lookup | Hunter, SignalHire | Name, employer and profile URL, on an explicit recruiter action |
We may also disclose data where required by law, or in connection with a merger or sale of assets, in which case this policy continues to apply.
Processing takes place primarily in the United States. Where data is transferred out of the EEA or UK, we rely on Standard Contractual Clauses and equivalent safeguards with our processors.
| Data | Retention |
|---|---|
| Candidates in an active pipeline | While the search is open |
| Candidates on a closed search, not placed | 2 years, then anonymised |
| Placed candidates | 7 years, then anonymised |
| Captured public profile pages | 3 years, then deleted |
| Location cache | 45 days |
| Automated-decision audit records | 7 years (hashes, not résumé text) |
| Recruiter account | While active; 90 days after a deletion request |
Retention windows are enforced by an automated sweep, not by policy alone. A verified deletion request overrides all of the above except records we are legally required to keep.
Depending on where you live you may have the right to access, correct, delete, port, restrict or object to processing, and to withdraw consent. California residents additionally have rights to know, delete, correct, and to opt out of sale or sharing — we do not sell or share personal data, and we honour Delete Act (SB 362) style requests. You will not be discriminated against for exercising any right.
Use sourcingnav.com/privacy-request, or email hello@sourcingnav.com. We verify by email before acting. If you are in the EEA or UK you may also complain to your local supervisory authority.
Access requires authentication; API keys are stored hashed and are read-limited by default; outbound links and webhooks are signature-verified; opt-outs are enforced before every send and every contact lookup. No system is perfectly secure, and we do not claim otherwise.
The Service is not directed to anyone under 16 and we do not knowingly process their data.
We will post changes here with a new effective date and, for material changes affecting account holders, notify by email.