LoopXJobs Map
We were selected by The Founding Co(backed by residency) for their first cohortView announcement →

Privacy Policy

Last updated: June 30, 2026

Redstring Technologies Private Limited ("Redstring," "we," "us," or "our") operates the website redstring.co.in (the "Landing Page") and the AI-powered hiring platform LoopX accessible at loopx.redstring.co.in (the "Platform"). This Privacy Policy describes how we collect, use, disclose, store, and protect personal information when you visit our Landing Page or use the Platform. This policy is drafted in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") of India and other applicable laws.

1. Information We Collect

1.1 Information You Provide Directly

  • Account Information: Name, email address, password (hashed), role (Founder, Recruiter, Hiring Manager, etc.), and company details during onboarding.
  • Candidate Information: When candidates submit applications through career pages or public forms — name, email, phone, resume, portfolio links, work experience, education, skills, availability, salary expectations, video responses, and answers to application form questions.
  • Communication Data: Messages sent through the in-app inbox, email broadcasts, and email replies — including message content, attachments (images, PDFs, documents), and metadata (sender, recipient, timestamp).
  • Career Page Data: Branding preferences, custom domain settings, social links, and page content configured by workspace owners.
  • Newsletter & Lead Forms: Email addresses and optionally name/company submitted through newsletter signup or free tools (Hiring Playbook, Hiring Planner, Waitlist).

1.2 Information Collected Automatically

  • Device & Browser Information: IP address, browser type and version, operating system, device type, screen resolution, and language preferences.
  • Usage Data: Pages visited, time spent on pages, click patterns, navigation paths, feature usage, and interaction events within the Platform.
  • Cookies & Tracking Technologies: We use essential cookies for authentication and session management (e.g., httpOnly session cookies with 7-day TTL). We use functional cookies to remember user preferences (theme, layout). We do not use advertising cookies or third-party tracking pixels. See Section 9 for full details on cookies.

1.3 Information from Connected Third-Party Accounts

  • Google OAuth: Email address, display name, and Google profile picture when you sign up or log in with Google.
  • Gmail Integration: When recruiters connect their Gmail inbox to LoopX, we access email headers (From, Subject), email body text, Gmail message/thread IDs, timestamps, and attachment indicators. Binary attachment files are not downloaded or stored — only a boolean flag indicating the presence of attachments is recorded.
  • ContactOut: Candidate profiles, LinkedIn enrichment data, and email addresses sourced through ContactOut integration for talent sourcing.

2. How We Use Your Information

We process personal information for the following purposes:

  • Platform Operations: Providing, maintaining, and improving the LoopX platform, including account management, authentication, and customer support.
  • Hiring & Recruitment: Processing candidate applications, AI-powered screening and match scoring, resume parsing, pipeline management, and communication between recruiters and candidates.
  • Email & Communication: Sending transactional emails (OTP verification, magic links, notifications, workspace invitations), email broadcasts, and email-chat bridging messages.
  • AI Processing: Analyzing resumes, application responses, and email content using AI models (via Groq API) to generate match scores, highlights, summaries, semantic embeddings, form suggestions, and hiring insights. AI requests are processed over HTTPS and are not retained by the AI provider beyond the request completion.
  • Analytics & Improvement: Tracking platform usage patterns to improve features, fix bugs, and enhance user experience. No analytics data is shared with third-party analytics services (Segment, Mixpanel, etc.).
  • Security & Fraud Prevention: Detecting unauthorized access, preventing abuse, enforcing rate limits, and maintaining platform integrity.
  • Legal Compliance: Complying with applicable laws, regulations, legal processes, and enforcing our agreements.

3. How We Share Your Information

3.1 Third-Party Service Providers

  • Groq API: Sender name/email, subject, email body text (limited to 2000 characters for classification, 800 for reply drafting), form responses, and job descriptions for AI processing. Groq does not retain data beyond request completion.
  • Google (Gmail API & OAuth): OAuth access/refresh tokens (stored encrypted), email messages for inbox sync, and reply emails. Tokens are encrypted at rest in a Postgres vault using encryption keys.
  • Resend: Transactional emails, broadcast campaigns, and email tracking (open/click/bounce/complaint webhooks).
  • Cloudinary: Uploaded files — resumes, images, logos, video responses, audio files, and document attachments.
  • ContactOut: Candidate sourcing queries and enriched candidate profile data.
  • Redis: Workspace and user identifiers for background job queue management (transient — removed on job completion).

3.2 What We Do NOT Share

  • No analytics or tracking services (Segment, Mixpanel, etc.)
  • No advertising networks or data brokers
  • No social media platforms
  • No third-party cookies or tracking pixels in emails

3.3 Legal Disclosure

We may disclose personal information if required by law, regulation, legal process, or government request, or to protect the rights, property, or safety of Redstring, our users, or the public.

4. Data Retention

We retain personal information only as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are as follows:

  • Active Account Data: Retained for the duration of your active account and for up to 30 days after account deletion to facilitate recovery.
  • Email Contents & Metadata: Incoming cold emails synced via Gmail are retained for the duration of your active Gmail connection and for 90 days after disconnection, after which they are permanently deleted from our systems.
  • Resumes & Uploaded Documents: Retained for the duration of the associated candidate record in the hiring pipeline, and for up to 1 year after the last activity on the record, unless earlier deletion is requested.
  • Candidate Application Data: Retained for the duration of the associated job posting and for 1 year after the job posting is closed or archived, unless earlier deletion is requested.
  • Inactive Accounts: Accounts with no login activity for 24 consecutive months are considered inactive. We will send a notification email 30 days before scheduled deletion. If no response is received, the account and associated personal data will be permanently deleted.
  • OAuth Tokens: Encrypted tokens are retained while the Gmail connection is active and are permanently deleted within 24 hours of disconnection.
  • Background Job Data (Redis): Automatically pruned — 50 completed jobs and 200 failed jobs retained.
  • Newsletter Signups: Email addresses are retained until you unsubscribe or request deletion.

Backup & Recovery Retention

We maintain encrypted backups of our databases for disaster recovery. When you request deletion of your personal data, it will be removed from our primary systems within 72 hours. Backup copies are overwritten on a rolling 30-day cycle. During this period, your deleted data may exist only in encrypted backup storage and is not accessible or usable in the Platform.

5. Your Rights Under the DPDP Act

In accordance with the Digital Personal Data Protection Act, 2023, and applicable data protection laws, you have the following rights regarding your personal data:

5.1 Right to Access Your Data

You may request a copy of all personal data we hold about you by contacting us at the email address provided in Section 11. We will respond to your request within 30 days and provide your data in a structured, commonly used, and machine-readable format.

5.2 Right to Correct Your Data

You may update or correct your personal information directly through your account settings within the Platform. For corrections that cannot be made through self-service, you may submit a request by contacting us at the email address in Section 11.

5.3 Right to Delete Your Data

You may request deletion of your personal data by contacting us or by deleting your account through the Platform settings. Upon receiving a verified deletion request, we will permanently delete your personal data from our primary systems within 72 hours and from backup storage within 30 days, except where retention is required by applicable law.

5.4 Right to Withdraw Consent

Where our processing of your data is based on your consent (e.g., Gmail inbox connection, newsletter subscription), you may withdraw your consent at any time by disconnecting the integration through Platform settings or by unsubscribing from the newsletter. Withdrawal of consent will not affect the lawfulness of processing carried out prior to withdrawal.

5.5 Right to Object to Marketing Communications

You may opt out of marketing and promotional communications at any time by clicking the "unsubscribe" link in any marketing email, updating your communication preferences in account settings, or contacting us directly. Transactional communications (security alerts, account verification, service notifications) cannot be opted out of as they are necessary for Platform operations.

5.6 Right to Nominate a Representative

In accordance with the DPDP Act, you have the right to nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.

5.7 Right to Grievance Redressal

If you believe your data protection rights have been violated, you may file a grievance with us. We will acknowledge your complaint within 3 business days and resolve it within 30 days. If you are unsatisfied with our resolution, you may appeal to the Data Protection Board of India established under the DPDP Act.

6. Data Storage & Cross-Border Transfers

Your personal information may be processed and stored on servers located in countries outside your jurisdiction. Our infrastructure providers (MongoDB Atlas, Cloudinary, Google Cloud, Vercel) operate data centers globally. We ensure that all transfers are protected by appropriate security measures, including encryption in transit (TLS 1.2+) and at rest (AES-256 encryption), and that our third-party service providers maintain adequate data protection standards consistent with the requirements of the DPDP Act.

7. Children's Privacy

The Platform is not directed at individuals under the age of 18. We take reasonable measures to protect the privacy and security of all users, including minors, and apply the same security safeguards to information provided by young users as we do to information provided by adults. We do not knowingly collect personal data from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information promptly. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at the address in Section 11.

8. Data Security

  • Encryption at Rest: OAuth tokens are encrypted in a Postgres vault using encryption keys. Databases are encrypted at rest via provider-level encryption.
  • Encryption in Transit: All data is transmitted over HTTPS (TLS 1.2+). API routes require authenticated sessions (cookie-based with httpOnly and sameSite flags).
  • No Plaintext Passwords: Passwords are never stored in plaintext; they are hashed using industry-standard algorithms.
  • Workspace Isolation: All data queries are scoped by workspace ID, ensuring data separation between organizations.
  • Access Controls: Role-based access control (RBAC) with Owner and Member roles and 16 granular permissions. All API routes require authentication.
  • CORS Restrictions: API access is restricted to configured frontend origins.
  • Rate Limiting: Sensitive endpoints are rate-limited to prevent abuse.
  • Secure Invitations: Workspace invitation tokens are SHA-256 hashed with 7-day expiry.

9. Cookies & Tracking Technologies

We use the following categories of cookies and similar technologies on our Landing Page and Platform:

9.1 Essential Cookies (Required)

These cookies are necessary for the Platform to function. They include session cookies (httpOnly, sameSite, 7-day TTL) for authentication, CSRF protection tokens, and load-balancing cookies. These cannot be disabled as the Platform will not function without them.

9.2 Functional Cookies

These cookies remember your preferences and settings, such as your selected theme (light/dark mode), layout preferences, and language. They enhance your experience but are not strictly required for Platform operation.

9.3 Third-Party Cookies

We do not use third-party advertising cookies, analytics tracking cookies (such as those from Google Analytics, Facebook Pixel, or similar services), or tracking pixels in our emails. If we introduce any third-party cookies in the future, we will update this policy accordingly and seek your consent where required.

9.4 Managing Cookies

You can manage or delete cookies through your browser settings. Most browsers allow you to refuse or delete cookies. Please note that disabling essential cookies may affect the functionality of the Platform. For more information about cookies and how to manage them, visit allaboutcookies.org.

9.5 Do Not Track

Some browsers support a "Do Not Track" (DNT) feature that signals to websites that you do not want to be tracked. Since we do not use tracking cookies or analytics services, DNT signals do not change our data practices, but we respect your preference.

9.6 Local Storage & Similar Technologies

We may use browser local storage to store non-sensitive preferences (theme, recently viewed items, UI state) and client-side application data. This data is not transmitted to our servers and can be cleared through your browser settings.

10. Data Breach Notification

In the event of a personal data breach that is likely to result in harm to any data principal, we will notify the affected individuals and the Data Protection Board of India without unreasonable delay, in accordance with the requirements of the DPDP Act. Our notification will include the nature of the breach, the personal data affected, the likely consequences, and the measures we have taken or propose to take to address the breach.

11. How to Contact Us

For any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:

Redstring Technologies Private Limited

Email: founders@redstring.co.in

Website: redstring.co.in

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date and, for significant changes, by sending a notification to the email address associated with your account. We encourage you to review this policy periodically.

Hiring doesn‘t have to be boring, let‘s make it fun with us!

Backed byThe Founding Co

Tools

Hiring PlannerHiring Playbook

Company

FAQAboutBlogPlaybooks & GuidesJobs Map

Built For Founders

A private community where founders exchange ideas, share experiences, and help each other build better companies. Each Application Handpicked by our Founder!

Privacy policy·Terms and conditions