Security & privacy

How Notice Tracking handles your candidate data.

Notice Tracking asks for the fewest candidate fields a notice needs, keeps each customer's workspace separate from every other, and preserves a record of what happened.

Data minimization

The application is designed for candidate name, email, jurisdiction, job reference, linked hiring tool, notice status, and delivery events. It excludes resumes, Social Security numbers, demographic data, assessment scores, interview notes, background checks, and medical data.

Workspace separation

Customer records are tenant-scoped. Application access checks and database policies are designed to limit records to authorized members of the relevant customer workspace.

Access controls

Roles control access to sensitive actions. Owners and administrators can enable multi-factor authentication. Billing actions are restricted to the workspace owner.

Record integrity

Notice, delivery, consent, and audit events are designed as append-only application records. The application distinguishes a send/provider-accept response from later delivery or failure events.

Controlled sends

A notice cannot be sent from an unapproved template version. Template approval requires a recorded attorney review; customers remain responsible for their approved language and legal decisions.

Protected integrations

Outbound-provider and billing webhooks are validated before the application processes them. Sensitive service credentials are kept server-side rather than exposed in the browser.

What this page covers

The product controls in place today. It describes what is built, not an independent audit or a full security assessment. For security, privacy or data-handling questions, contact Notice Tracking. Please do not put candidate records or other sensitive information into the forms on this marketing site.

Legal documents

The current public terms, privacy, processing and retention documents.

Review the workflow before sharing data.

We can walk through your notice process, the data fields involved and what you need to export, without you sending us a single candidate file.