Categories of Personal Information We Collect
Layover collects the following categories of personal information from Candidates, Managers, and Recruiters.
Categories collected
- Identifiers — legal name, email address, residential city/state, account ID, IP address, and device identifiers.
- Professional and Employment Information — prior employer name(s), job title(s), employment dates, departure status (RIF, voluntary, involuntary), and the contact information of any verifying Manager.
- Performance Evaluation Information — Manager Attestation ratings and commentary, HRIS-derived performance scores, milestone descriptions, and tenure metadata.
- Identity Verification Information — government-issued photo identification and selfie/biometric template, collected and processed by Didit, our identity verification partner. Layover does not retain biometric data; see § 3.
- Document Hashes — SHA-256 cryptographic hashes of uploaded employment documents. Raw documents are not retained; see § 2.
- Payment Information — payment card details, billing address, and transaction records, collected and processed directly by Stripe. Layover does not store payment card numbers.
- Usage Information — pages visited, features used, timestamps, error logs, and rate-limit signals.
Sources
Personal information is collected from: (a) the Candidate, (b) the verifying Manager, (c) the Recruiter, (d) third-party identity verification (Didit), and (e) automated system logs.
The Zero-Retention Doctrine
Layover operates as a cryptographic verification engine, not a data storage facility. When a Candidate uploads foundational employment documents, Layover executes a strict 8-Second Zero Retention Policy.
Processing
The system verifies the document, logs the mathematical proof via SHA-256 hash into our Cryptographic Ledger, and immediately burns the raw files.
Storage
We do not retain, host, or store raw, unredacted personnel files on our servers. The mint is the moment original documents leave Layover’s infrastructure.
Identity Verification (KYC/AML)
To enforce our audit-grade standards, Layover requires all Candidates to independently verify their legal identity before their public record goes live.
How verification works
- Layover utilizes the Didit API to conduct KYC/AML Document and Selfie Verification.
- Layover does not store biometric data locally; identity authentication is handled securely via Didit webhooks post-Stripe checkout. Refer to Didit’s privacy policy for their retention practices.
Third-Party Processors
Layover relies on the following third-party service providers to operate the platform. Each processor handles personal information only as necessary to provide its specific service and is bound by its own privacy and security commitments.
Data Anonymization & Private Flight Protocol
Layover utilizes a dual-sided privacy architecture to protect Personally Identifiable Information (PII).
Candidate Protection
If a Candidate engages “Private Flight” or Stealth Mode, Layover blurs visual assets and replaces the candidate’s legal name with a mathematically generated Passenger Alias (e.g., CLR-X79BQ). All public routing utilizes an anonymous UUID stealth_token to defend against Open Source Intelligence (OSINT) reverse-searching.
Recruiter Protection
Verified Corporate Recruiters utilizing the Private Flight protocol will have their specific name and LinkedIn profile masked behind a generic “Verified Corporate Recruiter” alias during initial outreach.
Data Disclosure (The Two-Key Protocol)
Layover does not sell Candidate data to third-party marketing brokers. Candidate data is strictly gated and governed by the Candidate’s configured Access Protocols.
How disclosure works
A Candidate’s unredacted Verified Performance Record is only unsealed and disclosed to a Recruiter upon (a) explicit authorization from the Candidate (Manual Clearance), or (b) the Candidate’s pre-authorized settings triggering a secure decryption event (Auto-Clearance).
No Sale or Sharing for Cross-Context Behavioral Advertising
As defined under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), Layover does not sell personal information and does not share personal information for cross-context behavioral advertising.
Retention Schedule
The duration Layover (or its processors) retains each category of data. Where a processor sets the retention (e.g., Sentry), Layover honors the processor’s policy as published.
Your Rights
Layover honors the following rights for all users, with additional protections for California residents as required by the CCPA and CPRA.
Rights available to you
- Right to Access — you may request a copy of the personal information Layover holds about you.
- Right to Deletion — you may request deletion of your personal information, subject to the legal-records retention obligations described in the Retention Schedule.
- Right to Correction — you may request correction of inaccurate personal information.
- Right to Portability — you may request a machine-readable copy of your personal information for transfer to another service.
- Right to Non-Discrimination — Layover will not deny services, charge different prices, or provide a different level of quality because you exercised any of these rights.
How to exercise these rights
Send a request to privacy@layover.id with the subject line “Privacy Request.” Layover will respond within forty-five (45) days of receipt, with the possibility of a one-time extension of up to forty-five (45) additional days where reasonably necessary, as permitted under the California Consumer Privacy Act.
To verify your identity for a rights request, Layover may require you to confirm specific account details (such as your registered email address and account creation date). Where applicable, you may designate an authorized agent to make a request on your behalf.
Updates to This Policy
Layover may update this Privacy Policy from time to time. Material changes will be communicated to your registered account email at least thirty (30) days in advance of the effective date. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
Questions about this Privacy Policy? Reach us at privacy@layover.id.
