1. Information We Collect
At H1BIndex, we strictly minimize the data we collect. We only gather information that is fundamentally necessary to secure your account and operate your private Data Vault. We collect:
- Account Credentials: Your email address and a cryptographically hashed version of your password. We never see or store your password in plain text.
- Vault Interactions: The specific employers, job titles, law firms, and geographic markets you actively save to your personal dashboard.
- Security & Telemetry Data: Your masked IP address (via Cloudflare) strictly utilized by our backend rate-limiter to prevent brute-force attacks and automated scraping.
2. How We Use Your Information
Your personal data is utilized exclusively for the operational integrity of the H1BIndex platform. We use your email to authenticate your identity, send password recovery links, and verify account creation. Your Vault interactions are stored as isolated metadata arrays to populate your custom Bento dashboard.
We do not use your saved watchlist data to build advertising profiles, nor do we track your web activity outside of the H1BIndex ecosystem.
3. Zero-Sale Policy & Third-Party Sharing
H1BIndex explicitly guarantees that we do not and will never sell your personal information or your private Vault history to corporate HR departments, external employers, or third-party data brokers.
We only share necessary functional data with our secure enterprise infrastructure partners, including our Web Application Firewall (Cloudflare) to block malicious traffic, and our secure SMTP provider (Brevo) to dispatch essential authentication emails. We may also disclose data if strictly required to do so by a verified law enforcement subpoena or federal mandate.
4. Your Privacy Rights & "The Danger Zone"
In accordance with global privacy frameworks (including GDPR and CCPA), you maintain absolute autonomy over your personal data. You have the right to request access to the data we hold, request corrections, or mandate complete erasure.
To honor your "Right to be Forgotten," we have engineered an automated Danger Zone within your Account Settings. Executing an account deletion through this portal will permanently and irreversibly wipe your credentials, email address, and all saved Vault arrays from our database. This action requires no manual approval from our staff.