How we store and protect your data
You are trusting us with candidates, contact details and financial information. Here is plainly what we do to protect it — and what we don't claim.
Last updated 2 September 2026
Keeping data private between organisations
The most important protection on a marketplace is that one organisation can never see another’s data. We enforce that at the database itself, not only in application code:
- Database-level row security. Each organisation’s records are separated by row-level security enforced by the database, so a query can only ever return the data the signed-in organisation is entitled to.
- A candidate is shared only with the employer of the role they were submitted to. They are never visible to other recruiters on the marketplace.
- Role-based access control. Within an organisation, a person only reaches what their role permits.
Securing accounts
- Two-factor authentication is required — a second factor is asked for at sign-in, so a leaked password alone cannot open an account.
- Passwords are hashed with Argon2id and never stored in a readable form. We cannot see your password.
- Rate limiting on sign-in and password reset blocks automated guessing.
Encryption and infrastructure
- Encryption in transit. All traffic to the platform runs over HTTPS/TLS.
- Encryption at rest is provided by our managed database and file-storage providers.
- Automated backups with point-in-time recovery, so data can be restored after an incident or mistake.
- An append-only audit log of significant actions — who did what, and when.
Payments and financial data
We do not store card numbers or bank-account credentials on our own systems. Payment and payout details are handled by established, PCI-compliant payment providers, and money movement is reconciled against those providers rather than run through our servers.
Your data, your rights
You can ask us what personal data we hold and why, correct it, or have it deleted, wherever you are and whether or not you hold an account. The full detail — including retention periods and how long a submission record is kept for ownership and dispute purposes — is in our Privacy Policy. To raise a request, email support@estaffinginc.com.
Still stuck? Email support@estaffinginc.com.