Legal
Privacy Policy
What Campus collects, why, who can see it, and how long we keep it. Campus carries no advertising, sells no personal data, and takes no payment for placement, so this policy is short on exceptions.
Last updated 29 August 2026
1. In short
Campus connects verified university students with local employers who have been reviewed and approved by an administrator. This policy explains what we do with personal information along the way.
- Students register with a university email address ending in .edu and confirm it through a link that expires after 24 hours.
- A new profile is invisible. Nothing reaches an employer until the student turns visibility on, and it can be turned off again at any time.
- Employers never see a student’s email address or phone number. Outreach is relayed by Campus.
- We ask for a ZIP code, not a precise location, and resolve it to the published centre point of that ZIP for distance search.
- We show students who viewed their profile, because a search that is invisible to the person being searched is not a fair one.
- No advertising, no trackers, no analytics cookies, no data broker, no sale of personal data, no paid placement. The one request that leaves Campus is the Google Fonts stylesheet, described in section 9.
Your use of Campus is also governed by the Terms of Service.
2. What we collect
Account information
Your email address, a bcrypt hash of your password (never the password itself), the role your account holds, its status, when you confirmed your address, and when the account was created. For students the address must end in .edu; that is how we know you are a student, and it is the only credential Campus asks for.
Student profile
What you enter as you build your profile: your name; an optional phone number; your ZIP code and preferred search radius; your university, college, major and minor; graduation month and year; work authorisation; the kind of availability you are looking for and hours per week; optional certifications and a LinkedIn address; the skills you tag; the courses you list; and each project you add, with its title, course context, description, kind of experience, and any external link.
Every field beyond your name and email is yours to leave blank — a sparser profile simply matches fewer searches.
Employer information
Company name and website, contact name and job title, phone number, industry, and a short note about hiring intent. We also store the result of two automated checks run at registration: whether the contact email domain matches the company website, and whether that website responds. Both are review signals for an administrator, not automated rejections. Approval decisions, who made them, and any reason given are recorded, as is the plan the employer account is on and how many outreach messages it has sent in the current period.
Activity on the platform
Which approved employer opened which student profile and when; shortlist entries, their pipeline stage, and the employer’s private notes; outreach messages and replies; saved searches and their filters; and the notifications generated from all of the above. Profile views and outreach are logged deliberately, so that students can see who has been looking.
Endorsements
When a student requests a coursework endorsement we store the name and email address the student gives for the endorser, the course concerned, a single-use token, and whether the endorser confirmed or declined. Endorsers do not create an account and we ask them for nothing else.
Technical and security information
A server-side session record in our database. One is created on your very first page view, before you sign in and whether or not you ever do, because every page carries a form-protection token that is kept in the session. The record holds the session identifier, its expiry, that token, and — once you sign in — who you are signed in as. IP addresses are processed by the rate limiters that protect signup, login, and verification resends. If someone attempts to register a student account with a non-.edu address, we record the address, the IP, and the reason, as an abuse signal. Our servers also keep ordinary operational logs.
Campus does not run analytics software, advertising tags, session recording, or fingerprinting, and it does not build behavioural profiles.
3. Location and ZIP codes
Proximity is central to Campus, so we need a rough idea of where you are — but only a rough one. You give a ZIP code. We look that ZIP code up in a table of published centroids and store the latitude and longitude of the centre of the ZIP area against your profile. Distance search then measures from that centre point.
Campus does not collect precise location. We do not use your device’s GPS, we never ask the browser for your position, we do not store a street address, and we do not derive location from your IP address for search. Two students in the same ZIP code are, to Campus, in exactly the same place. Employers see distance and locality, not a pin on a map.
4. How we use it
- To run your account — creating it, confirming your address, signing you in, resetting your password, and keeping you signed in.
- To make fit searchable — matching your structured profile against an approved employer’s filters for skills, major, graduation year, availability, and distance.
- To connect people — relaying employer outreach to you by email, carrying your replies back, and handling endorsement requests you initiate.
- To keep you informed — in-app notifications, saved-search alerts for employers, and a weekly summary of activity on your profile.
- To show you who is looking — the viewer history on your dashboard, which you can switch off.
- To review employers — presenting an application, and its automated checks, to an administrator for a decision.
- To protect the service — the session and form-protection token that guard every form, rate limiting, abuse logging, fraud signals, and an administrative audit trail.
- To report at the campus level — producing aggregate counts for a university’s career centre, described in section 6.
We do not use your information to train machine-learning models, to build advertising audiences, or for any purpose incompatible with the ones above.
5. Lawful basis
Where data protection law requires us to identify a basis for processing, these are the ones we rely on.
- Performance of a contract — everything needed to give you the service you signed up for: your account, your profile, search, outreach, and transactional email.
- Legitimate interests — keeping Campus safe and working: rate limiting, abuse and audit logs, employer vetting signals, and preventing fraud and misuse. We balance these against your interests and keep the data involved minimal.
- Consent — the choices that are yours alone: switching your profile visible, creating a public portfolio link, nominating an endorser, and filling in optional fields. You can withdraw any of these at any time by reversing the action.
- Legal obligation — responding to valid legal process and meeting obligations that apply to us.
6. Who can see your information
Approved employers
Only employers an administrator has approved can search, and only while your visibility is switched on. They see your profile as you built it: name, university, college, major, graduation, availability, skills, coursework and endorsement status, projects, certifications, any LinkedIn address you added, and your locality and distance from their search point. They do not see your email address or your phone number. When an employer sends outreach, Campus delivers it to your address on their behalf; they only learn how to reach you directly if you choose to tell them.
Anyone holding your share link
If you create a public portfolio link, anyone with that address can view the portfolio without signing in. The link is a long random token, is not listed anywhere, and stops working the moment you revoke it. It works independently of your visibility setting: hiding your profile from employer search does not disable a link you have already created, and revoking the link is what stops it.
Endorsers you nominate
An endorser receives your name and the course you asked them to confirm, and nothing else.
Career centre staff
Staff accounts linked to a university see aggregate statistics for that university only — how many students have registered, how many have completed a profile, how many are visible, how many outreach messages those students have received in total, the most common majors, and the most common skills. They do not have access to individual profiles, messages, or contact details through this dashboard.
Administrators
Administrators review employer applications and respond to reports about accounts. To do that they can open an individual student profile, and they can flag an account for review; a flag records the reason, who raised it, and when, and stays on the account until it is resolved. Administrative actions — approvals, rejections, flags, and changes to an employer’s plan — are recorded in an audit log with the administrator’s identity and the time.
Service providers
Campus runs on a small number of providers acting on our instructions: the hosting provider that runs the application and its PostgreSQL database, and the email provider that delivers our transactional mail. Loading our typeface also sends a request to Google — see section 9.
Others
We may disclose information if we are legally required to, or where it is necessary to protect someone’s safety or to investigate a serious breach of our terms. If Campus is ever transferred to another operator, information transfers with it, and we will tell you before that happens.
We do not sell personal data. We do not share it with advertisers, data brokers, or recruiters other than the approved employers you have made yourself visible to, and no one can pay for access or placement.
7. Email we send
Campus sends email only in response to something happening on your account: confirming your address, resetting your password, telling an employer the outcome of their application, relaying outreach and replies, asking an endorser to confirm a course, alerting an employer that a saved search has new matches, and a weekly summary of activity on your profile.
There is no marketing list, no newsletter, and no promotional mail. Our messages contain no tracking pixels and we do not measure whether you opened them.
Every message above is a service email tied to your account. Campus has no unsubscribe link and no notification settings — there is no such preference in the product, and we would rather tell you that than offer a switch that does not exist. What works instead is removing whatever generates the mail. An employer stops saved-search alerts by deleting the saved search. A student’s weekly summary is sent only in a week when an employer actually opened your profile or sent you a message, so switching your visibility off stops the activity and the summary that reports it, along with any further outreach. Closing your account stops everything, and you can ask us to close it at privacy@campus.hiretahoe.com.
8. Cookies and local storage
Campus sets one cookie, and it is set on your very first visit — before you sign in, and whether or not you ever do. Every form on Campus carries a token proving the form came from us (CSRF protection); that token is held in a server-side session, and this cookie is what points at the session. Once you sign in, the same session carries your login state as well, and signing out destroys it. It is the only cookie we set, so it is the only entry you will find for this site in your browser’s cookie list.
The cookie itself holds an opaque session identifier and nothing else — the
token, your login state, and the expiry all live in our database, not in your
browser. It is marked httpOnly
so scripts cannot read it, secure so it
travels only over HTTPS in production, and
sameSite=strict so it is not sent from other
sites. It expires seven days after it is issued.
We also store one value in your browser’s local storage:
campus-theme, which remembers whether you
chose the light or dark theme. It never leaves your browser and is not sent to us.
Clearing site data removes it and returns the theme to its default.
There are no analytics cookies, advertising cookies, third-party trackers, tracking pixels, or fingerprinting scripts on Campus — which is why you are not being asked to dismiss a consent banner.
9. Google Fonts
Campus is set in IBM Plex, which we load from Google Fonts. Every page therefore
asks your browser to fetch a stylesheet from
fonts.googleapis.com and the font files
themselves from fonts.gstatic.com.
Those requests go to Google, not to us, and Google receives your IP address along with them, together with the usual request information such as your browser and operating system and the page that referred the request. That processing is governed by Google’s own privacy policy. We do not use Google Analytics, Google advertising products, or Google sign-in, and no other third-party request is made by our pages: everything else — stylesheets, scripts, icons, images — is served from Campus.
If you would prefer to avoid the request entirely, blocking those two domains only changes the typeface: the site falls back to a system font stack and works exactly as before.
10. How long we keep it
- Account and profile — for as long as your account exists. If it is left unverified and unused, we may remove it.
- Verification and password-reset tokens — stored only as a SHA-256 digest, valid for 24 hours, usable once, and invalidated when a newer one is issued.
- Sessions — up to seven days, or until you sign out. Expired rows are cleared from the session table.
- Profile views, outreach, replies, shortlists, saved searches, notifications, endorsements — kept while your account exists, so that your viewer history and message history stay complete.
- Employer applications and administrative audit records — kept as a record of review decisions, including after an account closes.
- Abuse and rate-limit records — kept only as long as they remain useful as a security signal.
- Backups — routine encrypted backups may hold deleted data for a short period before they roll off.
When an account is deleted, the deletion cascades through the database: the student profile, its skills, coursework, projects, shortlist entries, outreach and replies, profile views, notifications, saved searches, endorsement requests, and any administrative flag raised against the account go with it.
11. Security
- Passwords are hashed with bcrypt at a deliberately slow work factor. They are never stored or logged in readable form.
- Verification and reset links are 256 bits of random data emailed once; only their SHA-256 digest is stored, so a copy of the database cannot be used to take over an account.
- Sessions are held server-side in PostgreSQL. The browser holds only an opaque identifier in an httpOnly, secure, sameSite=strict cookie.
- Every form that changes state carries a CSRF token that is checked on the server.
- Signup, login, and verification resends are rate limited, with an additional per-account cooldown so that one address cannot be mail-bombed from many IPs.
- Signup and password-reset responses are deliberately identical whether or not an account exists, so they cannot be used to discover who has one.
- Administrative actions are written to an audit log, and employer registrations are checked for domain mismatch and unreachable websites.
- Traffic is served over HTTPS.
No service can promise perfect security. If you believe you have found a vulnerability, please tell us at privacy@campus.hiretahoe.com before disclosing it publicly, and we will work with you.
12. Your choices and rights
Controls in the product
- Visibility — off until you turn it on, and off again the moment you switch it back. While it is off, no employer search can reach you.
- Viewer history — choose whether your dashboard shows you which employers opened your profile.
- Share link — create one when you want it, revoke it when you do not.
- Correction — almost everything on your profile can be edited in place, at any time.
Rights you can exercise by writing to us
Depending on where you live you may have the right to access the personal information we hold about you, to have it corrected, to have it deleted, to receive a portable copy, to object to or restrict certain processing, and not to be discriminated against for exercising any of these. We extend all of them to every Campus user, wherever you are.
Write to privacy@campus.hiretahoe.com from the address on your account and tell us what you want. We will confirm receipt, may need to verify who you are, and aim to respond within 30 days. Access and export requests are answered with a machine-readable copy of your profile and account records. There is no charge.
If you are in the UK, the EU, or another region with a data protection authority, you also have the right to complain to it. We would rather you came to us first.
13. Age and children
Campus is built for university students and for employer representatives acting in a professional capacity. It is not directed to children, we do not knowingly collect personal information from anyone under 16, and holding an account requires you to be at least 16.
If you believe someone under 16 has registered, tell us at privacy@campus.hiretahoe.com and we will remove the account and its data.
14. International transfers
Campus is operated from, and its database and email delivery are hosted in, the United States. If you use Campus from outside the United States, your information is transferred there and processed under United States law, which may not offer the same protections as your own.
The Google Fonts request described in section 9 is served from a global network, so it may be handled outside your country as well. Where a transfer requires a legal safeguard — for example the European Commission’s Standard Contractual Clauses — we put an appropriate one in place with the provider concerned.
15. Changes to this policy
As Campus changes, this policy will change with it. We update the “last updated” date at the top of the page whenever we revise it, and if a change materially affects how we use your information we will tell you by email or in the product before it takes effect. Older versions are available on request.
16. Contact
Privacy questions, access, correction, export, and deletion requests, and security reports: privacy@campus.hiretahoe.com.
Questions about the agreement itself, or reports of misuse: legal@campus.hiretahoe.com. See the Terms of Service for the rules that govern the service.