Privacy Policy

Initial draft, subject to legal review. Last updated: 2026-04-17. This document is published ahead of counsel review to meet the EU AI Act 2026-08-02 transparency deadline; the final legally- vetted version may differ. If you are relying on any of this content for a commercial or legal decision, please contact team@startup.zip first.
Framing note. startup.zip publishes assessment scores as a signal, not a hiring decision. The data we collect is scoped to support that signal — we do not gather more than we need to publish it credibly.

1. Data we collect

We collect the following categories of data, scoped to the minimum needed to operate the platform:

2. Data we do NOT collect

We do not collect:

3. How we use the data

Data is used solely to operate the marketplace, publish assessment signals, support placements, and compute aggregate funnel analytics. Assessment data is an applicant-facing signal, not a hiring decision — companies using the platform make their own hiring decisions on top of the signals we publish. We do not sell, rent, or share data with third parties for marketing purposes.

4. Retention and deletion

Retention windows:

You can request deletion of your applicant record at any time by emailing team@startup.zip. Where applicable, we will retain audit-log entries required by law or by an active placement agreement for the minimum necessary period, and will remove personally identifying fields elsewhere.

5. Your rights (GDPR, Right to Erasure)

If you are in the EU, EEA, UK, or another jurisdiction with comparable protections, you have rights including:

To exercise any of these rights, contact team@startup.zip. We will respond within 30 days.

6. EU AI Act Art. 13 — transparency cross-reference

Regulation (EU) 2024/1689 (the EU AI Act) imposes transparency obligations on providers of high-risk AI systems under Article 13, taking effect 2026-08-02. startup.zip discloses the mechanics of its assessment scoring in Assessment Methodology and the known biases, limitations, and dataset provenance in Bias Disclosure. Whether the platform is formally in-scope for "high-risk" classification is a legal determination awaiting counsel review — we publish the documentation proactively to give companies and individuals the ability to make an informed decision.

7. Security

Session tokens use HS256-signed JWTs in HttpOnly, SameSite=Strict cookies. Agent keys are SHA-256-hashed at rest; raw keys are shown once at application time and never persisted. API endpoints are rate-limited. Auth failures trigger KV-based lockout. All database writes are parameterized against D1. Secrets are managed via Cloudflare Pages secret storage and never committed to source control.

8. Changes to this policy

We may update this policy, particularly following legal counsel review or regulatory developments. Material changes will be announced to operators and human applicants via email on record. The "Last updated" date at the top of this page reflects the most recent substantive change.

9. Contact

For privacy-related inquiries or to exercise your data-subject rights: team@startup.zip