Seventh Jobs is a job board for Seventh-day Adventist schools, hospitals, conferences and ministries. It is operated by [Legal entity name] (“we”, “us”). This policy explains what information we collect, why, who else handles it, and how long we keep it.
Last updated: [Privacy policy last updated (Month Year)]. If we make a material change we'll update this date and email people who have a confirmed job alert or an employer account (see Changes to this policy).
The short version
- Job seekers don't need an account. If you sign up for job alerts, we keep your email address and the search you asked for until you unsubscribe.
- Jobs you save are kept in your own browser, not on our servers. If you ask us to email you that list, we send it once and don't keep your address.
- Employers sign in with a one-time code or link sent to their email. There are no passwords.
- Payments are handled by Stripe. We never see or store your card number.
- We measure how the site is used with PostHog in a cookieless mode: no cookies, no identifiers stored in your browser, and no profile of you. We don't use advertising or social-media trackers, and we don't sell personal information.
- We use an AI model (Google Gemini) to read public job postings. It reads the posting, not you, and we don't use AI to rank, score, screen or make decisions about job seekers (see How we use AI below).
- You can ask to see, correct or delete your information, or opt out of anything we do, at any time (see Your choices and requests).
- Where we need to recognize repeat requests to stop abuse, we use a scrambled, one-way code made from your IP address (a keyed hash), not the address itself.
Information we collect
If you're looking for a job
- Browsing. You can search and read listings without an account, and we set no cookies while you do. When a listing is viewed or its apply button is clicked, we add one to that listing's daily view or click count. The counts aren't linked to you; the view total is shown on the listing.
- Usage analytics. We also send PostHog, our analytics provider, the pages you view and a few actions on them (a search and its filters, a listing viewed, apply, share or save clicked, an alert created), with the browser type, screen size, referring site and the country and region your IP address points to. PostHog counts visitors with a hash of your IP address and browser that changes daily and can't be turned back into either; it stores no cookie or identifier in your browser, keeps no profile of you, and discards the address itself. We never send it your email address, the text you type into forms, or where an application goes.
- Saved jobs. When you save a job, the list of jobs you saved (each job's ID number, title and employer, so a job that has closed can still be listed by name) is kept in your browser's local storage on your device, not on our servers and not in a cookie. To show your Saved jobs page, your browser sends us the listings' ID numbers so we can look them up; we don't record them or link them to you. Removing a job, or clearing this site's data in your browser, deletes it from the list.
- Emailing your saved jobs. If you ask us to email you your saved jobs, we use the email address you enter to send that one email, through our email provider, and then discard it. We don't keep the address or the list, and we don't sign you up for anything. To limit abuse, we count requests using keyed hashes of your IP address and of the email address (see Technical information below).
- Applying. Applications go to the employer, not to us. The apply button either sends you to the employer's own website or shows you the employer's email address. We never receive your application or résumé; what you send an employer is covered by the employer's own privacy practices.
- Job alerts. Your email address, the search you saved (keywords, field, state, remote or on-site, job type, Adventist membership and employer), how often you want emails (daily or weekly), and when you confirmed and were last emailed. We send a confirmation email first and send no alerts until you confirm; when you confirm, we also keep the version of the signup wording you were shown and a keyed hash of your IP address, as a record that you agreed. If your alert uses the Adventist membership, visa sponsorship or language choices, we save them only if you tick a separate consent box (see Sensitive information below), and we keep when you did. If you sign up again for an alert you already have, we email you to say so instead of adding a second one; switching an alert between daily and weekly also needs a click in an email we send.
- Reporting a listing. The reason you choose, anything you type in the details box, and keyed hashes of your IP address and of your network (the address with its last part dropped) so we can tell separate reports apart and limit abuse. The form also runs the Cloudflare Turnstile bot check. Please don't include personal information in the details.
If you post jobs
- Your account. Your email address. You sign in with a one-time code or link we email you. Our sign-in provider (Supabase) keeps a record of sign-in sessions, which can include an IP address and browser type.
- Your organization. Its name, type, website, city and state, description, and the work email domains of the people who created or claimed it (we use email domains to connect colleagues to their organization and to confirm who may claim it). We also keep who belongs to the organization and their role, invitations (the invited email address, until they expire after 14 days), and requests to join with any note the requester wrote for the owner. When someone claims an organization we keep their email address and the role they gave us; when someone asks our team to review who manages an organization, we keep their email address and note. Notes a creator gives us to verify a new organization, and our staff's notes about how it was verified, are kept too.
- Your listings. What you post, including the application link or email address. Listings are public: the application email address is shown to anyone who clicks to reveal it. We also keep each listing's daily view and apply-click counts, and a record of the statements you confirm when you publish (such as that the pay range is a good-faith estimate or the religious-preference statement): the wording shown, who confirmed it and when, and a snapshot of the pay, benefits and membership fields at that moment.
- Payments. When your organization first pays, Stripe creates a customer record with your organization's name and the email address of its owner (or yours, if it has no owner with one); if the owner changes, we update it. We keep Stripe's reference numbers, what was bought, the amount, its status (for example, paid, processing, refunded or disputed) and dates, that billing email address, and your plan's status and renewal date. If you delete a draft that was paid for and refunded, we keep its payment record and title. Card and bank details go directly to Stripe.
- Email preferences. Whether you want the weekly summary email.
From public sources
We collect job postings from the public careers pages of Adventist employers (how our crawler works), and we search the web to find more employers. A posting can include contact details the employer published, such as a hiring contact's email address. The collector also keeps a fingerprint of each page it has read (not the page text) so it can skip pages that haven't changed.
Technical information
Like any website, our hosting provider receives standard request information, such as your IP address, browser type and the pages you request, and may keep it in its logs. Our analytics provider receives the same for the pages and actions it measures, keeps only the country and region, and discards the address (see Usage analytics above). We use your IP address briefly to limit how often the same network can sign in, report listings, sign up for alerts, email a saved-jobs list or add to listing view counts. What we store, or send to our rate-limiting provider, is a keyed hash of the address, never the address itself.
How we use it
- To run the job board: show listings, send you to employers, and let employers post and manage jobs.
- To send email you asked for or that your account needs: job alerts, a one-time email of your saved jobs, sign-in codes, and notices about your organization and listings (for example, published, expiring soon, expired, verification decisions, team invitations and join requests, and an optional weekly summary).
- To verify that organizations are who they say they are before their listings go public.
- To prevent spam and abuse: rate limits, a bot check on sign-in, and listing reports.
- To take payments and issue refunds.
- To tell search engines when public listing pages are published or taken down.
- To understand how the site is used in aggregate (which searches, pages and listings people use, and from where) so we can improve it.
We don't sell or rent personal information, and we don't use it for advertising. In the last 12 months we have not sold or shared personal information. We don't sell sensitive information.
Categories of information at a glance
| Category | Source | Why we use it | Who receives it |
|---|---|---|---|
| Email address | You (job alerts, employer sign-in, privacy requests, the one-time saved-jobs email) | Send what you asked for; sign you in; answer you | Supabase, Resend |
| Search choices saved with an alert | You (keywords, field, state, ZIP code, job type, employer, and the optional choices described under Sensitive information) | Pick the jobs to email you | Supabase |
| IP address and device details | Your browser, on every request | Run and secure the site; limit abuse; count visits. We store only a keyed hash of the IP address | Vercel, Upstash (hash only), Cloudflare Turnstile, PostHog (country and region kept) |
| Pages viewed, searches and clicks | Your browser | Understand how the site is used, in aggregate; count views of each listing | PostHog, Supabase (counts not linked to you) |
| Approximate location | Country and region from your IP address; a ZIP code only if you give one | Usage reports; distance search and alerts if you give a ZIP code | PostHog, Supabase |
| Employer account, organization and payment records | Employers (and Stripe, for payment status) | Run employer accounts, verify organizations, take payments, issue refunds | Supabase, Stripe, Resend |
| Job postings, which can include a hiring contact's name and email | Public careers pages, employers, our staff | Show listings | Supabase, GitHub (runs the collector), Google Gemini (posting text) |
| Information about religion, immigration status or ethnicity | You, only if you tick the consent box on a job alert that uses Adventist membership, visa sponsorship or language | Pick the jobs to email you | Supabase. Never sold or shared |
We don't collect Social Security numbers, government ID numbers, bank account numbers, health information or passwords. We don't sell personal information or share it for advertising, and we have not done so in the last 12 months. We use sensitive information only for the job alerts you asked for.
Do Not Track, Global Privacy Control and other sites
- Do Not Track. Our analytics uses no cookies or identifiers and doesn't track you across other websites, so the site works the same whether or not your browser sends a Do Not Track signal.
- Global Privacy Control. We don't sell personal information or share it for advertising, so there is nothing for the signal to opt you out of, and the site works the same whether or not your browser sends it.
- Other parties and other sites. No other party collects personal information about your activity on other websites through ours: our analytics and email providers don't, and the site shows no ads or social-media widgets.
How we use AI
We use an AI model (Google's Gemini) to read public job postings and pick out details such as the title, location, education, experience, languages and visa sponsorship. It reads the posting, not you. We don't use AI to rank, score, screen or make decisions about job seekers or applicants, and we never send job seekers' email addresses, alerts or searches to it. Details read this way on listings collected from careers pages can be incomplete or wrong, so check the employer's original posting; you can report a wrong detail with the report button on the listing.
We don't use personal information to train AI models. We send the text of public job postings, careers pages and employer websites to Google's Gemini API to extract listing details. We currently use Google's free Gemini API tier, under which Google may use what we send to improve its products and machine-learning models, and human reviewers may read it. Postings can include a hiring contact's name and email address that the employer published. We intend to move to Google's paid terms, which don't allow that use, and will update this page when we do.
Sensitive information
We don't ask for information about your health, race, sexuality, citizenship or immigration status, precise location or age. Two search choices could still reveal something like that when saved with your email address in a job alert: Adventist membership (religious beliefs), visa sponsorship (immigration status) and language (ethnicity). On a job alert we save them only if you tick a separate, unchecked box agreeing to it; without it, the alert can't keep those choices. We keep when you agreed, use these choices only to pick the jobs to email you, and never sell or share them. You can withdraw your agreement at any time with the unsubscribe link in any alert, which deletes the alert. Searching the site with these filters, without creating an alert, isn't stored by us with anything that identifies you, and our analytics records only that a filter was used, not its value.
Cookies
- Sign-in cookies. When an employer signs in, our sign-in provider (Supabase) sets session cookies that keep you signed in. They can't be read by scripts on the page.
- A short-lived message cookie. After some actions in the employer dashboard, a cookie carries an error message to the next page. It expires after five minutes.
- Bot check. The sign-in page and the report form use Cloudflare Turnstile to check that you're a person. It runs in your browser and may collect information about your device and browser; see Cloudflare's privacy policy.
- Stripe. Checkout and the billing portal are Stripe's own pages and use Stripe's cookies.
- Analytics: no cookie and no storage. Our analytics runs in a cookieless mode and writes nothing to your browser.
- Saved jobs (local storage, not a cookie). Your saved jobs are stored in your browser's local storage for this site. It stays on your device, isn't sent with requests, and is kept until you remove the jobs or clear this site's data.
- Sign-in in progress (session storage, not a cookie). After you ask for a sign-in code, the sign-in page remembers the email address it went to in this browser tab, so reloading the page returns you to the code step. It isn't sent anywhere, is forgotten when you close the tab, and is ignored after 15 minutes.
We don't use analytics, advertising or social-media cookies or trackers.
Who else handles your information
We use these service providers. Each receives only what it needs for its job:
- Supabase: our database and employer sign-in. It stores the information described above.
- Vercel: hosts the website and runs our scheduled jobs, so it handles every request to the site.
- Stripe: payments, invoices and the billing portal (your organization's name, your email, your payment details and any billing details you enter there).
- Resend: delivers our email (your email address and the message, including a saved-jobs list you ask us to send). Resend also tells us when an email to your address bounces permanently or is marked as spam; we then delete that address's job alerts.
- Upstash: rate-limit counters, keyed by hashed IP addresses, hashed email addresses or account IDs.
- Cloudflare: the Turnstile bot check on the sign-in page and the report form.
- PostHog (hosted in the United States): usage analytics as described above — page views and a few actions, with the browser type, screen size, referring site, and the country and region derived from your IP address, which it then discards. Requests to it go through our own web address, so it sets no cookie and receives no page content, email address or application link.
- Google, and search engines that use IndexNow (such as Bing): the web addresses of public listing pages when they're published or taken down. No personal information.
- Google (Gemini API): the text of public web pages we collect or evaluate (careers pages, employer websites found by search, or postings our staff paste in), so its AI model can pick out listing details such as the title and location, and judge whether a page belongs to an Adventist employer. We don't send job seekers' information to Google for this. What Google may do with that text depends on the API terms we are on; see How we use AI.
- Brave Search: web searches we run to find employers. No personal information.
- GitHub: runs the program that collects job postings from careers pages, which reads and writes listing and organization information in our database. It also stores our nightly database backups (encrypted before upload), which contain the information described above.
We may also share information when the law requires it, to protect people or the service from harm or fraud, or as part of a sale or reorganization of our business. These providers may process information in the United States and in other countries where they operate. Each is bound by its own terms or data processing agreement with us as a processor or service provider.
How long we keep it
- Saved jobs: in your browser only, until you remove them. A saved-jobs list you email yourself: not kept after it's sent.
- Job alerts: until you unsubscribe, or until email to your address bounces permanently or is marked as spam. Alerts that are never confirmed are deleted after 7 days.
- Records of which emails we sent to which address (kept so no one gets the same email twice): deleted after 180 days.
- Job-alert consent records (the signup wording version, the keyed IP hash from confirmation, and the date you agreed to save the choices described under Sensitive information): kept inside the alert and deleted with it.
- Rate-limit counters: expire on their own, within about two days at most.
- Daily view and apply-click counts for listings: deleted after 13 months.
- Logs of payment notifications from Stripe: deleted after 90 days. Logs of the web searches we run to find employers: deleted after 90 days. Logs of our job-collection runs: deleted after 365 days. The collector's page fingerprints: deleted after 90 days without being read again.
- Employer accounts, organizations and listings: while the account or organization exists. Closed listings leave the public site 30 days after they close but stay in the employer's dashboard.
- Listing reports: the reason, details and date are kept as moderation history. The keyed hashes of the reporter's IP address and network are removed 12 months after the report.
- Records of our staff's moderation and billing actions, and their notes on how an organization was verified: kept without a fixed end date, as an audit trail for moderation decisions, refunds and billing or fraud disputes. They contain no job-seeker information.
- Privacy requests you send us, and our answers: kept for 24 months after we answer, so we can show we answered.
- Sign-in codes and links expire shortly after we send them. Sign-in session records are kept by Supabase while your account exists.
- Payment records: kept for as long as we need them for accounting, tax and legal purposes.
- Backups: an encrypted copy of our database is made every night and kept for 90 days (as GitHub Actions artifacts), so information deleted from the site can remain in a backup until the backup itself is deleted.
Your choices and requests
- Every job alert email has an unsubscribe link. Unsubscribing deletes the alert; the same page can delete every alert for your address at once.
- You can remove saved jobs on the Saved jobs page at any time, or clear them all by clearing this site's data in your browser.
- Employers can turn off the weekly summary email in their dashboard settings, and can edit their organization and listings at any time.
Your rights. Wherever you live, you can ask us to show you what personal information we hold about you, give you a copy, correct it, delete it (including your employer account), or opt you out of any sale or sharing of it, and you can appeal our answer. Several states (for example California, Colorado, Connecticut, Nevada, Texas and Virginia) give residents rights like these; we offer them to everyone. We won't treat you worse for asking. You can use an authorized person to ask for you; we may ask them for proof.
- How to ask. Use the form at Your privacy choices and requests or email hello@seventhjobs.com. We reply to the email address you gave, which is how we check the request is yours. We'll tell you if we need to keep anything (for example, payment records) and why.
- How fast. We confirm your request within 10 business days and answer within 45 days of receiving it. If we need longer we may extend once by 45 days and will tell you why.
- Appeals. If we decline all or part of a request, reply to our answer to appeal. We respond within 60 days and explain the result. If you're still not satisfied you can contact your state attorney general.
- Nevada. Nevada residents: we don't sell covered information. hello@seventhjobs.com is our designated address for requests under Nevada law, and we answer within the same times.
Security
The site is served over HTTPS, employer sign-in uses one-time codes instead of passwords, sign-in cookies can't be read by page scripts, and IP addresses are hashed before our app stores them. Account and billing records are visible only to members of the organization they belong to and to our staff. No system is perfectly secure, so please email us if you find a problem.
Children
Seventh Jobs is meant for adults looking for work and the employers hiring them, and is intended for people 16 or older. It isn't directed to children under 13, and we don't knowingly collect information from anyone under 16. If you think a child has given us information, email hello@seventhjobs.com and we'll delete it.
Changes to this policy
If we change this policy, we'll post the new version here and update the date at the top. For a material change we'll also email people who have a confirmed job alert and the people with an employer account, before it takes effect where we can.
Contact
[Legal entity name], [Mailing address]. Email: hello@seventhjobs.com (privacy questions and requests, including our designated address for Nevada residents). You can also use the privacy requests form.
