Full legal draft
Privacy Policy
This Privacy Policy explains how the operator of Papa ʻOihana collects, uses, discloses, retains, and protects personal information when people use the platform, its community job boards, and related services.
← Return to the privacy summary
Contents
- Scope and who we are
- Information we collect
- Sources of information
- How we use information
- Opportunity recommendations
- Cookies and similar technologies
- How we disclose information
- Public and third-party information
- Retention and deletion
- Security
- Your choices and privacy rights
- Regional and jurisdiction-specific rights
- Children and minors
- International use and transfers
- Changes to this Policy
- Contact us
1. Scope and who we are
This Policy applies to Papa ʻOihana websites, tenant or community job boards, account areas, application workflows, emails, and other services that link to it (collectively, the “Service”). “Papa ʻOihana,” “we,” “us,” and “our” mean the platform operator. Community boards and employers that use the Service are separate organizations and may have their own privacy notices and legal obligations.
This Policy does not govern an employer’s independent use of application information after it receives that information through the Service, an external application site, or any third-party service. Review the employer’s and community board’s notices before submitting information. If a board-specific notice conflicts with this Policy about a board’s independent processing, that notice governs the board’s processing to the extent permitted by law.
2. Information we collect
Account and identity information
We collect names, email addresses, password credentials in protected form, email-verification status, account images if supplied, account roles, memberships, invitations, and account creation and update timestamps. We also maintain session records such as session tokens, expiration times, IP addresses, and browser or device user-agent data.
Candidate and application information
Candidate data may include phone number, location, professional headline, biography, skills, résumé and document files, cover letters, community-connection responses, availability, saved opportunities, saved searches, notification preferences, application drafts, submitted applications, application status, employer notes, and relevant timestamps and consent records.
Employer, board, and listing information
We collect employer organization profiles, contact details, websites, organization types, locations, logos, employer and board membership records, invitations, job drafts and listings, review notes, publication decisions, board settings, domains, themes, homepage content, and retention settings. Information intentionally included in public employer profiles and published job listings is public.
Communications, operational, and security information
We process verification, password-reset, invitation, job-alert, and application-notification delivery records; support requests; audit events; moderation actions; rate-limit outcomes; security events; error and diagnostic logs; upload metadata; file type and size; checksums when available; object-storage keys; and deletion, retention, legal-hold, and recovery records.
Please do not submit government identification numbers, financial account information, health information, or other highly sensitive data unless a specific field clearly requests it and the information is necessary and lawful for that purpose.
3. Sources of information
We receive information:
- directly from candidates, employers, board members, administrators, and other users;
- from activity within the Service, including account, session, application, search, alert, moderation, and audit events;
- from organizations that invite or authorize a person to use an employer or board workspace;
- from public job, organization, and board content supplied by participating organizations; and
- from infrastructure and security providers that help deliver, protect, and diagnose the Service.
4. How we use information
We use personal information to:
- create, verify, secure, and administer accounts and role-based access;
- operate community boards, employer workspaces, job listings, saved searches, alerts, candidate profiles, and application workflows;
- deliver application materials to authorized employer or board users and communicate application status or next steps;
- send requested service messages, account messages, invitations, and job-alert digests;
- provide optional, explainable opportunity recommendations;
- review employers and listings, moderate content, enforce rules, prevent fraud and abuse, and protect users and the Service;
- maintain audit records, investigate errors, monitor reliability, restore service, and improve features and accessibility;
- honor access, correction, deletion, retention, and legal-hold requirements; and
- comply with law, legal process, and enforceable governmental requests and establish, exercise, or defend legal claims.
Where a law requires a legal basis, we rely as appropriate on performance of a contract, consent, compliance with legal obligations, and legitimate interests such as operating, securing, and improving the Service. A user may withdraw consent where processing depends on consent, without affecting earlier lawful processing.
5. Opportunity recommendations
Signed-in candidates may opt in to deterministic, rules-based opportunity recommendations. The current model compares candidate skills, professional headline, biography, location, and saved searches with public job content, category, location, workplace type, and publication date. Recommendation cards show a match score and plain-language reasons.
Recommendations are off by default. Candidates can disable them in profile settings and can always browse the complete, unfiltered board. Saved and already-applied-to opportunities may be omitted from the recommendation module. Recency alone is not treated as a useful match.
The model does not use names, email addresses, phone numbers, résumé contents, protected characteristics, application answers, application status, prior employer decisions, or inferred protected traits. Recommendation scores are not shown to employers or used to determine application eligibility, rank candidates for employers, reject an applicant, or make a hiring decision.
7. How we disclose information
We may disclose information to:
- Authorized users. Candidates can access their own records. Authorized employer and board members can access records needed for their roles, including relevant applications and moderation records.
- Service providers. Cloudflare provides hosting, content delivery, security, rate limiting, email delivery, and object storage. Neon provides the application database. These providers process information to perform services for the platform.
- Participating organizations. When a candidate applies, the application is made available to the relevant employer and, where authorized, the community board. Information submitted to an external application link is governed by that recipient.
- Legal and safety recipients. We may disclose information when reasonably necessary to comply with law or legal process, protect rights or safety, investigate misuse, or enforce agreements.
- Transaction recipients. If the Service or its operator is reorganized, merged, financed, or transferred, information may be disclosed subject to appropriate confidentiality and legal protections.
- At your direction. We may disclose information when a user requests or consents to the disclosure.
We do not sell personal information. We do not provide employers with private candidate information unless the candidate submits an application or otherwise directs or authorizes the disclosure.
8. Public and third-party information
Published job listings, employer profiles, community-board content, logos, and other information designated as public can be viewed and copied by anyone. Do not place private personal information in public fields. Links to employer sites or external application services are provided for convenience; their privacy practices, security, content, and availability are controlled by those third parties.
9. Retention and deletion
We retain information for the time needed to provide the Service, comply with legal and contractual obligations, resolve disputes, maintain security and auditability, and enforce agreements. Retention can vary by community board and record type.
- Pending or unsubmitted uploads are generally eligible for deletion after 30 days under the default board setting.
- Abandoned draft applications are generally eligible for deletion after 90 days under the default board setting.
- Submitted hiring records may be retained indefinitely by default unless a board selects a finite retention period or law requires otherwise.
- Account-deletion requests remove private stored documents and non-required profile data, revoke sessions and linked accounts, and anonymize retained identifiers, subject to any configured grace period.
- Active legal holds suspend deletion for the records within the hold until an authorized administrator releases it.
- Non-sensitive audit, security, backup, and legal records may remain after deletion or anonymization when necessary for integrity, recovery, compliance, or legal claims.
Deletion from active systems may not immediately remove information from encrypted backups or provider systems that expire on their normal cycle. Public content may remain in third-party caches or copies beyond our control. Where an employer independently retains an application, contact that employer about its copy.
10. Security
We use administrative, technical, and organizational measures designed to protect information, including encrypted network transport, protected credentials, role-based authorization, private object storage, secure session cookies, email verification, rate limiting, bot protection, audit logging, environment separation, monitoring, and database recovery procedures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Users must protect their credentials, use unique passwords, sign out from shared devices, and promptly report suspected unauthorized access. If a security incident requires notice, we will provide notice as required by applicable law.
11. Your choices and privacy rights
Depending on the Service and applicable law, users may:
- review and update profile and account information;
- enable or disable opportunity recommendations;
- change or disable saved-search email alerts;
- withdraw an application when the workflow permits, without requiring an employer to erase a lawfully retained copy;
- request access, correction, deletion, restriction, portability, or objection where provided by law; and
- request account deletion or cancel a pending deletion request before processing, where the interface permits.
Submit a request using the contact information below. We may need to verify identity and authority before acting. We may deny or limit a request where permitted by law, including when records must be retained for security, legal obligations, disputes, or the rights of others. We will explain an applicable denial and any appeal method required by law.
12. Regional and jurisdiction-specific rights
Privacy rights differ by location. Where applicable law grants rights concerning access, correction, deletion, portability, restriction, objection, consent withdrawal, or appeal, we will honor verified requests subject to lawful exceptions. Authorized agents may submit a request when local law permits and appropriate proof of authority is provided. We will not unlawfully discriminate against a person for exercising a privacy right.
As currently configured, we do not sell personal information or share it for cross-context behavioral advertising, and we do not use candidate recommendations to make decisions producing legal or similarly significant effects. If these practices change, we will update this Policy and provide any notices or choices required by law.
13. Children and minors
The Service is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If we learn that such information was collected, we will take appropriate steps to delete it. A parent or guardian who believes a child supplied information should contact us. Minors who may lawfully seek work must use the Service only with any consent or supervision required by law.
14. International use and transfers
The Service is operated from the United States and is primarily intended for opportunities connected with Hawaiʻi communities. If a person uses the Service from another country or territory, information may be transferred to and processed in the United States and other places where service providers operate. Where required, we will use lawful transfer mechanisms and safeguards.
15. Changes to this Policy
We may update this Policy to reflect changes in the Service, law, or data practices. We will post the revised version with a new “Last updated” date and provide additional notice when required. Material changes apply prospectively unless law permits otherwise.
16. Contact us
Contact the Papa ʻOihana platform operator with privacy questions, rights requests, accessibility needs related to this Policy, or security concerns:
Papa ʻOihana PrivacyEmail: onaepuni@kanaeokana.net
Do not send passwords, résumé files, government identifiers, or other sensitive documents by ordinary email. We may provide a safer method if supporting information is required.
Last updated August 25, 2026.