Privacy Policy
Last updated: March 10, 2026 · Effective: March 10, 2026
This Privacy Policy describes how LevelHire (“LevelHire,” “we,” “us,” or “our”) collects, uses, stores, and discloses your personal information. It applies to our website at https://levelhire.ai and our platform at app.levelhire.ai (collectively, the “Services”).
Scope of this Policy
LevelHire operates under the laws of Mexico (Federal Law on Protection of Personal Data Held by Private Parties — Ley Federal de Protección de Datos Personales en Posesión de los Particulares, “LFPDPPP”) and the laws of the United States, including the California Consumer Privacy Act (“CCPA”) and other applicable state and federal privacy regulations. Where requirements differ, we apply the higher standard of protection.
1. Data Controller / Responsible Party
The data controller (“Responsable” under LFPDPPP) responsible for your personal data is:
LevelHire
Email: hello@levelhire.ai
Website: https://levelhire.ai
For privacy inquiries: privacy@levelhire.ai
2. Personal Data We Collect
We collect the following categories of personal data (“datos personales”):
Identification data
Full name, email address, job title, company name, LinkedIn profile URL.
Account data
Password (hashed), plan tier, billing information (processed by our payment provider; we do not store full card numbers), invoice history.
Candidate evaluation data
Challenge responses, keystroke timing patterns, pause intervals, revision behavior, AI-generated scores, verdicts, and onboarding predictions. This data is generated and stored on behalf of our business customers (see Section 10).
Usage and technical data
IP address, browser type, operating system, referring URLs, pages visited, session duration, crash reports, and feature usage metrics.
Communications data
Emails, support tickets, and chat messages you send us.
Cookies and tracking data
See Section 9 for our full Cookies Policy.
We do not collect sensitive personal data (“datos personales sensibles” under LFPDPPP) such as racial or ethnic origin, health or genetic data, religious or political beliefs, or biometric identifiers, unless you explicitly provide them.
3. How We Collect Personal Data
- Directly from you — when you register, complete an evaluation, contact support, or fill out a form.
- Automatically — through cookies, pixel tags, and server logs when you use our Services.
- From third parties — from payment processors (e.g., Stripe) and identity/authentication providers when you use social login.
- From our customers — business customers may submit your email to invite you to complete a candidate evaluation.
4. Purposes of Processing (“Finalidades del Tratamiento”)
We process your personal data for the following purposes:
Service delivery
Primary / NecesariaTo create and manage your account, process payments, and provide the LevelHire platform.
Candidate evaluation
Primary / NecesariaTo generate context-driven challenges, capture behavioral signals, and produce AI verdicts on behalf of our business customers.
Security & fraud prevention
Primary / NecesariaTo detect abuse, unauthorized access, and fraudulent transactions.
Customer support
Primary / NecesariaTo respond to your inquiries and resolve disputes.
Legal compliance
Primary / NecesariaTo comply with applicable laws, court orders, and regulatory obligations in Mexico and the United States.
Product improvement
Secondary / SecundariaTo analyze usage patterns and improve platform features. Performed on aggregated, de-identified data where possible.
Marketing communications
Secondary / Secundaria (opt-in)To send you newsletters, product announcements, and promotional offers — with your consent where required.
Under LFPDPPP, you may object to secondary purposes (“finalidades secundarias”) at any time by contacting privacy@levelhire.ai. Objecting to secondary purposes will not affect your use of the platform.
5. Legal Basis for Processing
- Contract performance — processing necessary to provide the Services you have subscribed to.
- Consent (“consentimiento”) — where we send marketing communications or collect non-essential cookies.
- Legitimate interests (“interés legítimo”) — for fraud prevention, security monitoring, and aggregate analytics.
- Legal obligation (“obligación legal”) — where required by Mexican or US law (e.g., tax records, court orders).
6. Your Rights (ARCO + US Rights)
You have the following rights regarding your personal data:
Access (Acceso)
Request a copy of the personal data we hold about you.
Rectification (Rectificación)
Request correction of inaccurate or incomplete data.
Cancellation / Deletion (Cancelación)
Request deletion of your personal data, subject to legal retention obligations.
Opposition (Oposición)
Object to specific uses of your data, including marketing communications.
Data Portability (US/CCPA)
Receive your data in a structured, machine-readable format.
Opt-out of sale (CCPA)
LevelHire does not sell personal data. You have the right to confirm this at any time.
Non-discrimination (CCPA)
We will not discriminate against you for exercising your privacy rights.
Revoke consent
Withdraw consent for secondary purposes or marketing at any time.
How to exercise your rights
Submit a written request to privacy@levelhire.ai with subject line “ARCO Request” or “Privacy Rights Request.” We will respond within 20 business days (LFPDPPP) or 45 calendar days (CCPA), as applicable. We may request identity verification before processing your request.
7. Data Sharing and Third Parties
We do not sell your personal data. We may share it with:
- Service providers (“encargados”) — cloud hosting (AWS/GCP), payment processing (Stripe), email delivery (e.g., Postmark), error monitoring — all bound by data processing agreements.
- Business customers — if you complete a candidate evaluation, results are shared with the company that invited you.
- Legal and regulatory authorities — when required by law, court order, or to protect our legal rights.
- Business transfers — in connection with a merger, acquisition, or sale of assets, with prior notice to affected users.
8. International Data Transfers
LevelHire processes data on servers located in the United States and may transfer data across borders. When transferring personal data of Mexican residents outside Mexico, we ensure appropriate safeguards are in place as required by LFPDPPP, including contractual clauses with data recipients. When transferring data from the US, we comply with applicable state and federal requirements.
9. Cookies Policy
We use the following types of cookies:
Strictly necessary
Session management, authentication, and security tokens. Cannot be disabled.
Functional
Language preferences and UI settings.
Analytics
Aggregate usage data to improve the platform (e.g., page views, feature adoption).
Marketing
Only placed with your explicit consent. Used to measure campaign effectiveness.
You can manage cookie preferences through your browser settings or by contacting us. Disabling optional cookies will not affect core platform functionality.
10. Business Customers and Candidate Data
LevelHire business customers (hiring companies) act as independent data controllers for the candidate data they collect through our platform. LevelHire acts as a data processor (“encargado”) on their behalf. If you are a job candidate who participated in a LevelHire evaluation, your rights regarding that evaluation data should be directed to the company that invited you. We will assist in facilitating such requests upon verified instruction from the business customer.
11. Data Retention (“Conservación de Datos”)
We retain personal data for as long as necessary to fulfill the purposes described in this Policy, subject to legal, accounting, and regulatory obligations:
- Account data: retained while your account is active and for 3 years after closure.
- Candidate evaluation data: retained for 24 months after evaluation completion, or until deletion is requested.
- Financial/billing records: 5 years (as required under Mexican tax law and US regulations).
- Communication logs: 2 years.
After retention periods expire, data is securely deleted or irreversibly anonymized.
12. Data Security (“Medidas de Seguridad”)
We implement appropriate technical and organizational security measures including encryption in transit (TLS 1.2+) and at rest (AES-256), access controls, regular security audits, and employee training. In the event of a personal data breach that affects your rights and freedoms, we will notify you and relevant authorities within the timeframes required by applicable law (72 hours under applicable regulations). Visit our Security page for details.
13. Children’s Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us at privacy@levelhire.ai and we will promptly delete it.
14. Supervisory Authorities
If you are not satisfied with how we handle your privacy request, you have the right to file a complaint with the relevant supervisory authority:
- Mexico: Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI) — www.inai.org.mx
- United States (California): California Privacy Protection Agency (CPPA) — cppa.ca.gov
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by posting the updated policy on this page with a revised “Last updated” date, and where required by law, by sending a direct notice to registered users. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
16. Contact
For any privacy-related questions, requests, or complaints, please contact us: