Privacy Policy
Effective Date: August 16, 2025
Welcome to Shortlst. We value your trust and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and protect information across our services worldwide. It is designed to comply with global privacy frameworks including the GDPR (EU/UK),CCPA (California), Singapore PDPA, and India'sDigital Personal Data Protection Act (DPDP Act), 2023.
1. Information We Collect
We collect information in the following ways:
- Account Information: Name, email, phone number, organization, role, login credentials.
- Candidate Data: Resume, interview responses, voice/video recordings, assessments, and performance data.
- Usage Data: Log files, IP address, device identifiers, browser type, operating system, and activity within the platform.
- Cookies & Tracking: Session cookies, analytics tools, and similar technologies to improve service performance.
- Payment Information: Processed securely by third-party payment providers; we do not store sensitive payment card details.
2. How We Use Information
We process personal data to:
- Provide and improve our services.
- Match candidates with job opportunities and generate analysis for recruiters.
- Facilitate communication between candidates and recruiters.
- Personalize user experience and develop new features.
- Ensure security, prevent fraud, and comply with legal obligations.
3. Legal Basis for Processing
Depending on your location, we rely on:
- Consent (e.g., for cookies, optional data fields).
- Contractual necessity (to deliver services).
- Legitimate interests (platform improvement, fraud prevention).
- Legal obligations (to comply with applicable laws).
4. AI Voice Interviews — Recording and Processing
Shortlst conducts AI-powered voice interviews. When you participate in an interview session, the following applies:
- Both parties are recorded. Each interview session is recorded as a stereo audio file. The left channel captures the AI interviewer's synthesized voice; the right channel captures the candidate's microphone audio. Both tracks are stored together.
- Speech-to-text transcription. Candidate audio is transcribed in real time using Deepgram's speech recognition service. Transcripts are stored and used to generate evaluation reports.
- AI evaluation. Interview transcripts are processed by Anthropic's Claude AI to produce scoring, assessments, and recommendations for recruiters.
- Candidate notification. Recruiters are required to inform candidates that the interview is conducted by an AI, that audio is recorded, and that the recording is used for evaluation before the session begins.
- Recording storage. Recordings are stored securely in cloud storage. Access is limited to the recruiting organization that initiated the interview.
5. Sharing of Information and Subprocessors
We may share your data with:
- Employers/Recruiters using Shortlst to assess candidates.
- Service providers (cloud hosting, analytics, payment processors) bound by confidentiality.
- Legal authorities if required by law.
- Business transfers in case of mergers, acquisitions, or restructuring.
We never sell your personal data.
We rely on the following key subprocessors to deliver the Service:
- Supabase — database and file storage (candidate data, recordings, interview results).
- Deepgram — real-time speech-to-text transcription and AI text-to-speech synthesis.
- Anthropic (Claude) — large language model inference for interview conduct and post-interview evaluation.
- Daily.co — WebRTC transport for real-time audio communication during interview sessions.
- Stripe — payment processing (we do not store card details).
Each subprocessor is bound by data processing agreements and appropriate security obligations. Data transfers to subprocessors outside India or the EEA are made under appropriate safeguards (Standard Contractual Clauses or equivalent).
6. International Data Transfers
We operate globally. Data may be transferred to and processed in countries outside your own. We ensure appropriate safeguards such as Standard Contractual Clauses (SCCs)or equivalent mechanisms for cross-border transfers.
7. Data Retention
- Candidate interview recordings and transcripts: Retained for 12 months from the date of the interview unless the recruiting organization or the candidate requests earlier deletion.
- Candidate profile and assessment data: Retained for 12 months from last activity or until deletion is requested.
- Account data: Retained as long as the account is active, then for up to 90 days after closure for recovery purposes.
- Legal/transactional records: Retained as required by applicable law (typically 7 years for financial records).
Candidates may request deletion of their interview recording and associated data at any time by contacting us at help@shortlst.com. We will process deletion requests within 30 days, subject to any legal retention obligations.
Depending on your jurisdiction, you may have rights to:
- Access, rectify, or delete your data.
- Restrict or object to processing.
- Data portability.
- Withdraw consent (where applicable).
- Lodge complaints with supervisory authorities.
- Request deletion of your interview recording and associated data (see Section 7).
9. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Interview recordings are stored encrypted at rest and transmitted over encrypted connections. Access is restricted to authorized personnel and the recruiting organization. However, no method of transmission over the internet is 100% secure.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top.
11. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: help@shortlst.com
Address: Hitech City, Hyderabad, Telangana, India