About Crooter
Crooter is a recruitment operating system used by professional recruitment consultancies to manage candidates, clients, vacancies, communications and placements in a single, secure workspace. Crooter is operated from the United Kingdom and provided to business customers (the “Customer”) under a subscription or commercial agreement.
This policy describes the personal data we process as a data controller for our website visitors, applicants and prospects, and as a data processor on behalf of our Customers for the data they place into the Crooter platform.
What data we collect
We collect only the data needed to operate the service and support our users:
- Account data — name, work email, profile photo, role, organisation and authentication identifiers.
- Candidate data uploaded or captured by recruiters — contact details, CVs, public LinkedIn information, qualification notes and status.
- Client and contact data — company names, hiring contacts and commercial context entered by recruiters.
- Communication data from integrations the user explicitly authorises — message metadata, email content, call records and meeting notes.
- Usage and device data — log events, IP address, browser type and product analytics required to keep the service reliable and secure.
Why we collect it
We process personal data to:
- Provide, secure and improve the Crooter platform.
- Authenticate users and protect accounts from misuse.
- Enable communications, scheduling and reporting features.
- Comply with our legal, tax and contractual obligations.
We do not sell personal data, we do not use customer data to train third-party AI models, and we do not share data with advertisers.
Authentication
Crooter supports email/password sign-in and federated sign-in with providers such as Google and Microsoft. We store the minimum identity information needed to verify a user (such as a verified email address and provider user ID). Passwords, when used, are never stored in plain text.
Candidate data
Recruiters using Crooter on behalf of their organisation are responsible for ensuring they have a lawful basis to process candidate data, that candidates are informed about how their data is used, and that records are kept accurate and up to date.
Crooter provides tooling to honour candidate rights, including export, update and deletion. Where a candidate contacts us directly, we will route the request to the relevant Customer who controls that record.
Client data
Information about client companies and their hiring contacts is processed to enable the recruitment relationship. Access is restricted to authorised users within the Customer’s workspace, governed by role-based permissions.
Communication data
Crooter consolidates messages, calls and meetings into a unified inbox. Content sent through Crooter is stored to provide reply, search and audit functionality. Access is limited to participants and administrators within the user’s workspace, subject to role permissions.
Email integrations (Gmail & Outlook)
When a user connects their Gmail or Microsoft Outlook account, they are redirected to Google or Microsoft to grant explicit consent. Crooter only accesses the scopes the user has authorised, which are limited to reading and sending messages on their behalf and maintaining metadata needed to display conversation threads.
OAuth tokens are stored encrypted at rest. Users can disconnect an account at any time from Settings → Communication Setup, which immediately revokes Crooter’s access and removes the stored tokens. Crooter’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
WhatsApp integration
Where a Customer enables the WhatsApp Business integration, Crooter exchanges messages on the Customer’s behalf using the credentials they configure. Message content is stored to power the inbox and audit log. Customers are responsible for obtaining the consents required by WhatsApp’s Business Messaging Policy before initiating conversations.
Future communication providers
As Crooter adds support for additional channels (such as SMS, telephony, LinkedIn messaging and calendar providers), the same principles apply: integrations are opt-in, scopes are limited to what the feature needs, tokens are encrypted, and users can disconnect at any time.
Security
Production data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Access to production systems is restricted, logged and reviewed. Detailed controls are described on our Security page.
Data retention
Personal data is retained for as long as the Customer’s workspace remains active and for a limited period afterwards to honour legal and audit obligations. Customers may request export or deletion of their workspace data at any time. Backups are rotated and deleted on a defined schedule.
GDPR & international transfers
Crooter processes personal data in accordance with the UK GDPR and EU GDPR. Where data is transferred outside the UK or EEA, we rely on appropriate safeguards such as the UK International Data Transfer Addendum or the EU Standard Contractual Clauses with our sub-processors.
Your rights
You have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure, subject to legal and contractual obligations.
- Object to or restrict certain processing.
- Receive a portable copy of the data you provided.
- Lodge a complaint with the UK Information Commissioner’s Office.
Contact
For privacy questions or to exercise any of the rights above, contact privacy@crooter.co.uk. We aim to respond within 30 days.
