The short version
- We collect your email and what you bought. We use it to give you what you bought and to tell you about updates.
- We do not run third-party advertising trackers. There is no Facebook Pixel here.
- We use Stripe for payment (your card never touches our servers), Plausible for privacy-respecting analytics, and Resend for transactional email.
- You can ask us to delete your account and everything we have on you, at any time, by emailing hello@humanresourcely.com.
What we collect
From you, directly
- Email address (sign-in, transactional email, list opt-in).
- Name and optional company name (account profile only).
- Payment method (handled by Stripe — we never see your full card number; we store the last four digits and the brand for receipts).
- What you've purchased and downloaded.
Automatically
- Aggregated, privacy-respecting analytics via Plausible — pageviews, source, country. No cookies, no device fingerprinting, no individual tracking.
- Server logs (IP address, user agent) retained for 30 days for security.
What we don't collect
- Third-party advertising identifiers, Facebook Pixel, Google Ads conversion data.
- Cross-site tracking cookies.
- Device fingerprinting.
- The contents of documents you've edited locally.
Who we share with
Only with the providers we need to deliver the service. Each has its own privacy policy, which you can review:
- Stripe — payment processing.
- Resend — transactional email (receipts, magic links) and the optional newsletter.
- Neon — our Postgres database host (US region).
- Cloudflare R2 — paid document storage with signed-URL access.
- Vercel — hosting and content delivery.
- Plausible Analytics — privacy-respecting analytics (EU-hosted).
We do not sell your data. We do not share your data for advertising. We do not give your data to data brokers.
How long we keep it
- Account and purchase records: for the life of your account plus 7 years for tax.
- Server logs: 30 days.
- Newsletter/list data: until you unsubscribe or we close the list.
Your rights
You can ask us at any time to:
- Show you everything we hold about you.
- Correct anything that's wrong.
- Delete your account and all associated data.
- Export your data in a portable format.
- Stop sending you marketing email.
Email hello@humanresourcely.com with the subject "Privacy request". We respond within 14 days.
GDPR and CCPA
If you are in the EU/UK, your data is processed under GDPR and our lawful basis is contract (delivering the service you paid for) and legitimate interest (security, analytics). If you are in California, you have the CCPA rights of access, deletion, and opt-out of "sale" — we do not sell data, so the opt-out is automatic.
Changes to this policy
We update this page when something material changes. The "last updated" date at the top is the source of truth. Substantial changes are emailed to account holders.