Privacy Policy
Sift Human Resources (“Sift HR,” “Sift,” “we,” “us,” or “our”) respects the privacy of visitors, clients, prospective clients, and individuals whose information may be processed in connection with our services.
This Privacy Policy describes how we collect, use, disclose, and protect personal information through sifthr.com (the “Website”), our accounts and online services, communications with us, and the professional services we provide.
Our Website and services are intended primarily for organizations and individuals acting on behalf of organizations.
Information We Collect
The information we collect depends on how you interact with Sift.
Information You Provide Directly
We may collect information you provide through the Website, an account, an order, correspondence, or an engagement, including:
- name;
- email address;
- telephone number;
- organization and job-related information;
- billing and mailing information;
- account information;
- order and transaction information;
- information included in contact forms, emails, or other communications; and
- other information you choose to provide to us.
Payment-card information is generally provided directly to our third-party payment processors rather than stored by Sift.
Client and Engagement Information
Clients may provide information necessary or useful for Sift to perform professional services. Depending on the engagement, this may include:
- job descriptions and job requirements;
- interview, assessment, or hiring materials;
- candidate, employee, or participant information;
- assessment results;
- performance evaluation information;
- employment or organizational data;
- survey or research data; and
- other materials supplied by a client.
Clients are responsible for having the appropriate rights, permissions, notices, and consents necessary to provide this information to Sift.
Clients should not provide Social Security numbers, financial-account information, medical information, or other highly sensitive personal information unless it is reasonably necessary for the engagement and Sift has requested or agreed to receive it.
Information Collected Automatically
When you use the Website, we and our service providers may automatically collect information such as:
- IP address or approximate location derived from it;
- browser and device type;
- operating system;
- referring website or source;
- pages visited;
- date, time, and duration of visits;
- interactions with Website content;
- device, cookie, or similar identifiers;
- advertising or attribution information; and
- diagnostic, security, and usage information.
Some of this information is collected through cookies, pixels, tags, and similar technologies as described below.
How We Use Information
We may use personal information to:
- provide, administer, and support our products and services;
- communicate with clients and prospective clients;
- respond to inquiries;
- establish and manage accounts;
- process orders and transactions;
- perform consulting, assessment, research, analytical, and project work;
- administer or support assessments and related systems;
- provide reports, recommendations, analyses, and deliverables;
- understand and improve our Website, products, methods, and services;
- measure Website usage, referrals, marketing, and communications;
- maintain records of transactions and engagements;
- protect the security and integrity of our Website, accounts, and systems;
- prevent fraud, abuse, and unauthorized activity;
- comply with legal, tax, accounting, and regulatory obligations;
- establish, exercise, or defend legal rights; and
- send business or marketing communications where permitted by law.
You may unsubscribe from promotional emails using the unsubscribe mechanism included in those communications.
Client Data and Our Role
The role Sift plays with respect to personal information depends on the context.
For information collected through our own Website, accounts, marketing, communications, and business operations, Sift generally determines why and how that information is processed.
When Sift processes candidate, employee, assessment, performance, or other personal information on behalf of a client, the client may determine the purposes for which that information is processed and Sift may act as a service provider or processor on the client’s behalf.
Where applicable, the client’s own privacy notices, policies, permissions, and legal obligations govern its collection and use of that information.
Sift does not make employment decisions on behalf of clients merely by processing assessment, performance, candidate, or employee information. Clients remain responsible for determining how information provided through Sift’s products and services is interpreted and used.
De-Identified and Aggregated Information
Sift may create information, analyses, statistics, findings, benchmarks, models, insights, or other results derived from information processed in connection with our services that have been aggregated, de-identified, or otherwise processed so that they do not reasonably identify an individual or client.
We may retain and use such information for research, benchmarking, validation, development and improvement of methods and services, teaching, publication, presentations, professional activities, and other analytical or business purposes.
We will not attempt to re-identify individuals from information used in this manner.
These uses are subject to applicable law and any specific written agreement governing an engagement.
Cookies and Similar Technologies
We use cookies and similar technologies to operate the Website, remember preferences, maintain security, understand Website usage, measure traffic and referral sources, support transactions, measure marketing effectiveness, and provide other Website functionality.
We use CookieYes to provide cookie notices, manage visitor cookie preferences, and maintain records of consent.
Our Website uses or may use technologies associated with services including:
- Google Analytics, including through ExactMetrics;
- WordPress, WooCommerce, Jetpack, and related Automattic services;
- Sourcebuster or similar referral and attribution functionality;
- Mailchimp and Mailchimp for WooCommerce;
- Stripe and other payment-related services;
- Meta Pixel;
- LinkedIn Insight Tag; and
- CookieYes.
The specific cookies and similar technologies used on the Website, their purposes, categories, and retention periods may change as Website functionality changes. Current information about these cookies is available through the CookieYes consent-preferences interface on the Website.
Except for cookies that are necessary to operate the Website or provide requested functionality, visitors can accept, reject, or customize optional cookies through the CookieYes consent interface and can revisit their preferences using the consent-preferences control displayed on the Website.
Disabling certain cookies may affect Website functionality.
Analytics
We use analytics technologies to understand how visitors find and use the Website and to improve Website performance, content, and services.
These technologies may collect information such as pages viewed, referral sources, interactions, device information, browser information, approximate location, and cookie or similar identifiers.
Google Analytics and other optional analytics technologies are used subject to applicable consent choices and privacy requirements.
Advertising, Conversion Tracking, and Audience Measurement
We use or may use advertising and measurement technologies identified above to understand the effectiveness of our marketing, measure conversions, understand how visitors interact with the Website, and create or measure audiences for advertising.
These technologies may collect or receive information such as:
- pages and URLs visited;
- referring pages;
- timestamps;
- IP address;
- browser and device characteristics;
- cookie, advertising, or similar identifiers; and
- interactions with Website content, links, buttons, or forms.
Advertising and measurement providers may process information received through these technologies according to their own privacy policies and applicable agreements. These technologies may allow Sift to measure advertising effectiveness or show advertisements to audiences based on prior interactions with the Website.
Where consent is required, these technologies are intended to operate subject to the visitor’s choices through our cookie-consent system.
Sift does not intend to transmit candidate assessment results, employee performance data, client-provided employment information, or similar client engagement data to advertising platforms for advertising purposes.
Email and Marketing Services
We may use services such as Mailchimp to manage email communications, marketing campaigns, and related Website or transaction activity.
Information associated with an order, account, subscription, communication, or Website interaction may be transmitted to such providers as reasonably necessary to provide these functions.
You may unsubscribe from promotional email communications at any time using the unsubscribe mechanism provided in the message.
Payments and Transactions
We use third-party providers, including Stripe and WooCommerce-related services, to facilitate purchases and payments.
Payment processors may collect payment-card details, billing information, transaction information, device information, and fraud-prevention information directly.
Sift generally does not receive or store complete payment-card numbers.
Payment and transaction providers process information according to their own privacy practices and applicable agreements.
PXT Select™ and Other Third-Party Assessment Services
Sift may provide or support assessments, software, reports, or related services supplied by third parties, including PXT Select™.
When a client or individual uses a third-party assessment platform, information may also be collected and processed by the provider of that platform under its own privacy terms and contractual arrangements.
Sift may access or use assessment information as reasonably necessary to provide services, support clients, prepare reports or recommendations, perform agreed analyses, conduct authorized research or validation work, or otherwise fulfill an engagement.
How We Disclose Information
We may disclose personal information to:
- hosting, technology, infrastructure, and security providers;
- Website, analytics, attribution, and measurement providers;
- advertising and marketing providers;
- payment and transaction processors;
- email and communications providers;
- assessment publishers and platform providers;
- professional advisers such as accountants, attorneys, or consultants;
- contractors or service providers assisting Sift in performing an engagement;
- governmental authorities or other parties when required by law or legal process; and
- a successor or potential successor in connection with a merger, acquisition, financing, restructuring, or sale of all or part of Sift’s business.
We seek to limit disclosures to those reasonably necessary for the applicable purpose and use contractual or other safeguards where appropriate.
Sale, Sharing, and Targeted Advertising
Sift does not sell personal information for monetary compensation.
We may disclose Website activity or related information to analytics, advertising, and measurement providers such as Meta, LinkedIn, Google, and similar providers for purposes including analytics, advertising measurement, conversion tracking, audience creation, and retargeting.
Certain privacy laws may characterize some advertising-related disclosures as a “sale,” “sharing,” or use for targeted advertising even when no money is exchanged.
Certain privacy laws apply only to organizations that meet specified statutory thresholds. If and to the extent an applicable privacy law applies to Sift and provides a right to opt out of such processing, we will provide and honor the choices required by that law.
Visitors may also control optional analytics and advertising technologies through our CookieYes consent interface.
Do Not Track and Privacy Signals
Third-party analytics and advertising providers may collect information about visitors’ online activities over time and across different websites or online services when their technologies are enabled on the Website.
Some browsers offer a legacy “Do Not Track” (“DNT”) setting. Because there is no universally adopted standard for interpreting DNT signals, the Website does not currently respond separately to DNT signals. Visitors can instead manage optional Website tracking through our CookieYes consent controls.
Where applicable law requires Sift to recognize a legally valid universal opt-out preference signal, such as Global Privacy Control, for processing in which Sift engages, Sift will honor that signal as required by law.
Legal Bases for Processing in the EEA and UK
Where the General Data Protection Regulation, UK GDPR, or similar law applies, our legal bases for processing personal information may include:
- performance of a contract or steps requested before entering into a contract;
- our legitimate interests in operating, securing, and improving our business and services;
- consent;
- compliance with legal obligations; and
- establishment, exercise, or defense of legal claims.
Where processing is based on consent, you may withdraw that consent at any time without affecting processing that occurred before withdrawal.
Privacy Rights
Depending on where you reside, the nature of our relationship with you, and the laws applicable to Sift’s processing of your information, you may have rights concerning your personal information, including rights to:
- request access to or information about personal information we maintain;
- request correction of inaccurate information;
- request deletion of certain information;
- obtain a portable copy of certain information;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent;
- opt out of certain sales, sharing, targeted advertising, or profiling where applicable;
- limit certain uses of sensitive personal information where applicable; and
- appeal a decision regarding a privacy request where applicable law provides that right.
Not every right listed above applies in every jurisdiction or to every organization. We will honor privacy rights to the extent required by applicable law.
You may submit a privacy request by contacting compliance@sifthr.com.
We may take reasonable steps to verify your identity and authority before fulfilling a request. An authorized agent may submit a request where permitted by applicable law.
We will not unlawfully discriminate against an individual for exercising applicable privacy rights.
If Sift is processing personal information solely on behalf of a client, we may direct a request to that client or assist the client in responding as appropriate.
Residents of the European Economic Area or United Kingdom may also have the right to lodge a complaint with the applicable data protection authority.
Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected or processed, taking into account the nature of the information, the applicable relationship or engagement, legal and accounting requirements, dispute-resolution needs, and legitimate business and recordkeeping purposes.
For example:
- account and transaction records may be retained for the life of the account and applicable legal, tax, accounting, and recordkeeping periods;
- engagement information may be retained during the engagement and for a reasonable period afterward for support, recordkeeping, professional, analytical, legal, and business purposes;
- inquiries and correspondence may be retained as reasonably necessary to respond and maintain business records;
- cookie and analytics information is retained according to the settings and retention periods applicable to the relevant technology; and
- properly aggregated or de-identified information may be retained for longer periods, including indefinitely, when it no longer reasonably identifies an individual or client.
We delete, aggregate, or de-identify information when it is no longer reasonably necessary, subject to applicable legal and operational requirements.
Security
We use reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, loss, or misuse.
No Internet transmission, storage system, or security measure can guarantee absolute security.
Third-party platforms and service providers maintain their own security measures and are responsible for systems under their control.
International Processing
Sift and its service providers may process information in the United States and other jurisdictions.
Where applicable law requires protections for international transfers of personal information, we use appropriate contractual or other legally recognized safeguards as applicable.
Third-Party Websites and Services
The Website may contain links to third-party websites, assessment systems, social-media services, or other resources.
Sift does not control the privacy or security practices of those third parties. Visiting or using a third-party site is subject to that provider’s own terms and privacy practices.
Children’s Privacy
The Website and Sift’s services are intended for business and professional use and are not directed to children.
We do not knowingly collect personal information directly through the Website from children under 13. If we learn that such information has been collected inappropriately, we will take reasonable steps to delete it.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, technologies, legal obligations, or privacy practices.
A revised Privacy Policy becomes effective when posted unless otherwise stated. The effective date below identifies the current version.
Contact Us
Questions, concerns, or privacy requests may be directed to:
Sift Human Resources
California, United States
compliance@sifthr.com
Effective: August 29, 2026