Privacy policy
HumanSourcer collects very little, and this page lists all of it. If something isn't described here, the site doesn't collect it.
Last updated .
1. Scope
This policy covers humansourcer.com and the forms and links on it. HumanSourcer is the controller of the data described below.
It does not cover the companies listed in the directory. Once you follow an apply link you are on that provider's own site, under their privacy policy, and HumanSourcer has no visibility into or control over what they collect.
2. What is collected
There are four things, and this is the complete list.
- Your email address, if you give it. Submitting the roles-digest form or the HumanSourcer Prep waitlist stores your address and the path of the page you submitted from. The path shows which pages readers find worth subscribing from; it is not linked to anything you do afterwards.
- What you write in a request form. Two forms ask for more than an address. The research-access form stores your institution and a description of what you are studying, both optional. The provider form stores the company you are writing about, which of four things you are asking for, a feed or API URL if you give one, and any message you write. Both are free-text fields you fill in yourself, kept only to answer you - so put nothing in them you would not want stored. A feed or API URL submitted through that form is never fetched automatically; it is read by a person before anything is done with it.
- Outbound clicks on apply links. Apply links pass through a redirect on this domain, which records the provider, the role, the destination URL, the page you clicked from, the referring URL, and the browser identifier (“user agent”) sent with every HTTP request. No IP address is stored. The user agent is recorded for one purpose: automated crawlers follow apply links across thousands of role pages, and without separating them the counts describe robots rather than people. It marks a click automated or not, and nothing else.
- Page views. Counted cookielessly and first-party, served from this domain. No cookie is set, no identifier is stored, and no data is sent to a third-party analytics host.
No account system exists, so there are no usernames, passwords, profiles, or payment details to collect. No special-category data is collected, and none is requested anywhere on the site.
3. Why, and on what legal basis
If you are in the UK or EEA, the lawful bases under Article 6 of the UK/EU GDPR are:
- Consent - for the roles digest and the waitlist. You opt in by submitting the form, and you can withdraw at any time by unsubscribing or emailing the address below. Withdrawing does not affect anything done before you withdrew.
- Taking steps at your request - for the research-access and provider forms. Both exist to answer a question you asked, so what you submit is kept and used for that and nothing else. Neither one subscribes you to the roles digest.
- Legitimate interests - for click counts and page views, in order to understand which pages are useful and to distinguish automated traffic from human traffic. The data is aggregate and carries no identifier pointing back to a person, so the impact on your privacy is minimal.
4. Cookies
This site sets no cookies. There are no advertising cookies, no analytics cookies, no cross-site trackers, no advertising or social pixels, and no fingerprinting. That is why you are not shown a cookie banner - there is nothing to consent to.
5. Who else processes it
Three processors, all acting only on instructions and only to run the service: Vercel (hosting and the cookieless page counting), Supabase (the database holding the email addresses, form submissions and click counts), and Kit (kit.com, which sends the roles digest).
Kit receives your email address if you submit the roles digest, the course waitlist, or the research-access form, so that mail can be sent to you. It does not receive submissions from the provider form, and it never receives the free-text content of any form - only the address itself.
Nothing is sold, rented, or shared for anyone else's marketing, and email addresses are never passed to the providers listed in the directory. Data may be disclosed if required by law.
If another processor is added, it will be named here in the same change that ships it.
All three processors operate infrastructure in multiple countries, so data may be processed outside the UK/EEA under the transfer safeguards in their own terms.
6. How long it is kept
Email addresses are kept until you unsubscribe or ask for removal, and are deleted on request. Research-access and provider-form submissions are kept while the request is open and for as long as the resulting correspondence is useful, and are also deleted on request. Click and page-view records are kept as an ongoing measure of what readers find useful; they carry no identifier that points back to a person and are not deleted individually, because there is no key by which to find yours.
7. Your rights
If you are in the UK or EEA you have the right to access, correct, delete, restrict, or object to the processing of your data, and to data portability. Where processing rests on consent, you can withdraw it at any time. You also have the right to complain to your supervisory authority - in the UK, the Information Commissioner's Office.
If you are a California resident you have the right to know what is collected, to delete it, to correct it, and to opt out of sale or sharing. HumanSourcer does not sell or share personal information, as those terms are defined by the CCPA/CPRA, and does not use it for cross-context behavioural advertising. Exercising any of these rights will never result in worse treatment.
To exercise any of them, email privacy@humansourcer.com from the address you signed up with. That address is the only identifier stored, so nothing further is needed to locate the record - and no request is refused for lack of an account, because there are no accounts.
8. Children
This site is aimed at people looking for paid work and is not directed at children. Data is not knowingly collected from anyone under 16. If you believe a child has submitted an email address, write to the address above and it will be deleted.
9. Security
The site is served over HTTPS, and stored data sits behind the access controls of the processors named above. No method of transmission or storage is completely secure, and the honest framing is that the best protection here is how little is collected: an email address and a set of click counts, with no passwords, payment details, or IP addresses to lose.
10. Changes to this policy
Any change to what is collected, why, or who processes it ships in the same change as the feature causing it, with the date at the top updated. Material changes affecting subscribers will be sent to the digest list rather than only posted here.
11. Contact
Questions, requests, and corrections: privacy@humansourcer.com.
HumanSourcer is an independent directory and is not affiliated with any provider listed on it. How the site is funded, and what it measures, is set out in full on how we make money.