Privacy Policy
This Privacy Policy explains what personal information OneTwoLoop LLC (“OneTwoLoop,” “we,” “us,” or “our”) collects when you use onetwoloop.com and our related services, why we collect it, who we disclose it to, and the choices you have. OneTwoLoop LLC operates onetwoloop.com.
If you have questions about this policy or your data, contact us at hello@onetwoloop.com.
1. Introduction and Acceptance
OneTwoLoop is a community for engineers by engineers. Some features are open to anyone; others require you to sign in with GitHub. This policy applies to information we collect through the website, sign-in, profiles, job postings, applications, candidate introductions, partner hiring workspaces, build inquiries, the newsletter, and email we send you. It does not cover third-party websites we link to, which have their own policies.
2. Information We Collect
2.1 Information You Provide Directly
Depending on how you use the site, you may provide:
- Email address. Collected when you subscribe to the newsletter, sign in with GitHub, post a role, request a company analytics report, submit a build inquiry, or participate in a candidate introduction.
- Name. First and last name entered during onboarding.
- GitHub profile data. When you sign in with GitHub, we receive your GitHub username, display name, avatar image, and the email associated with your GitHub account.
- Location. A self-selected city. This is a dropdown choice, not device GPS or precise location.
- Professional profile. LinkedIn profile URL, a resume PDF you choose to upload, and public GitHub repositories you choose to import (name, description, links, and topics).
- Career preferences. Disciplines, specialities, work type, seniority, hiring intent, and whether you need visa sponsorship.
- Discovery source. How you found the site, including any free-text answer you provide.
- Self-attestations. Work history, self-rated skills and supporting evidence, external links, and any explanation you give about a sparse GitHub profile.
- Job applications. A cover note plus a snapshot of your display name, GitHub username, email, profile URL, and the job you applied to.
- Application fit analyses. Advisory role-match scores, reasoning, matched signals, gaps, confidence, and related timestamps generated from the role and the profile, project, application, and assessment information available to us. These analyses support internal review and do not automatically reject an application or make an employer’s final hiring decision.
- Mission submissions. A submission URL.
- Build inquiries. Your name, email, whether you are building for a business, yourself, or a client, an optional company, client, or project name, an optional role, your working-budget range, preferred kickoff date, requested outcome, referral and campaign attribution, and the versions, document checksum, and server timestamp associated with your acceptance of the Build Inquiry Terms.
- Expressions of interest. When you express interest in a role, a snapshot of your name, GitHub username, profile URL, and email.
- Introduction requests and consent. When a company asks to meet you, we record the company and opportunity, the requester, the information proposed for disclosure, your approval or decline, and related timestamps and delivery status. We disclose your identity and contact information to that company only after you approve that specific introduction.
- Intro chat messages. The body of messages you send through the intro chat. Contact details such as emails, phone numbers, and URLs are stripped by our server before a message is stored.
- Assessment attempts. Scores, feedback, and timestamps from any assessment you take, plus your rating-consent choices and consent timestamp.
2.2 Company and Poster Information
When someone posts a role or uses a partner hiring workspace, we may collect the company name, job title, job description link, discipline, work type, poster or requester contact information, hiring stage, internal notes, a summary of the job description, salary range, visa-sponsorship details, introduction requests, and related activity. Job listings are reviewed before they appear.
2.3 Automatically Collected Information
When you visit the site we collect standard technical and usage data, including pages viewed, clicks and interactions, scroll depth, engagement time, referrer, the URL path, and device and session identifiers. See Section 6 for details on analytics.
2.4 GitHub Sign-In
We use GitHub OAuth for sign-in. We do not collect or store passwords. GitHub tells us the account email, username, display name, and avatar tied to the GitHub account you authorize. Your use of GitHub is governed by GitHub’s own privacy policy.
2.5 Information We Do Not Collect
- We do not collect or store passwords.
- We do not collect payment-card or billing details on the site. If a paid job listing is offered, payment happens off-site through a link we email you; no card or CVV fields exist on the site.
- We do not request a phone number as a standalone profile field, and our chat pipeline removes phone numbers before storing a message. An uploaded resume or other file may still contain contact information you chose to include in that file.
3. How We Use Your Information
We use the information above to:
- Provide, operate, and improve the jobs board, profiles, applications, and newsletter.
- Evaluate build inquiries, communicate with requesters, and prepare possible scopes and project agreements.
- Authenticate you and maintain your session.
- Match engineers and roles, and surface relevant listings.
- Generate advisory candidate-role fit analyses for internal review. These analyses do not automatically reject a candidate or make an employer’s final hiring decision.
- Facilitate candidate-request and candidate-approved introductions with employers and hiring partners.
- Send transactional messages such as newsletter confirmations, job-posting confirmations, and report magic-links.
- Notify our team about new signups, pending or live job postings, and expressions of interest.
- Understand how the site is used through aggregate analytics.
- Protect the site against abuse, spam, and unauthorized access.
- Comply with legal obligations.
4. Listing Corrections and People Named in Postings
4.1 Employer Listing Corrections
If you represent a company and a listing about your company is inaccurate or should be removed, email hello@onetwoloop.com and we will review and correct or remove it.
4.2 People Named in a Posting
If you are named in a role posting or other submitted content and want that reference corrected or removed, contact us at the same address.
5. Third-Party Service Providers
We disclose personal information to service providers and other recipients only as reasonably necessary to operate the service, follow your instructions, protect OneTwoLoop and its users, or comply with law. Recipient categories include:
- Infrastructure providers that host the site and provide databases, authentication, file storage, security, and content delivery.
- Analytics providers that help us measure performance, understand use, and review masked session replays as described in Section 6.
- Communication providers that deliver transactional messages and newsletters and manage delivery, bounce, complaint, and suppression records.
- Payment providers that process off-site invoices or payment links for paid services.
- Content, job-data, and evaluation providers that support job ingestion, description processing, maps, fonts, other public-facing content, and advisory role matching based on submitted profile, project, application, and assessment information.
- Employers and hiring partners when you direct us to apply, express interest, or approve a specific introduction. An introduction approval identifies what will be shared before disclosure.
- Professional advisers, authorities, and transaction counterparties when reasonably necessary for legal, security, compliance, financing, or corporate-transaction purposes.
We do not sell personal information or share it for cross-context behavioral advertising.
6. Cookies, Analytics, and Tracking
We use browser storage, scripts, pixels, and similar technologies to operate the service and understand how it is used. These technologies may collect or derive pages and URLs viewed, referrer, clicks, scrolls, interaction and engagement timing, performance data, browser and device information, network information, and device or session identifiers.
- Product analytics. We measure pageviews, navigation, interactions, scroll depth, engagement, and performance and associate those events with device, session, and, after sign-in, account identifiers.
- Session replay. Some public pages use session replay to help us diagnose usability and performance issues. Form inputs are configured to be masked, sensitive or private forms are excluded from recording, and authentication tokens and URL fragments are filtered before analytics events are sent.
- Listing views. We record which role a signed-in user or anonymous session viewed, together with a user or session identifier and timestamp.
- Browser storage. We use localStorage and sessionStorage for authentication, analytics state, and preferences such as remembering a page or pending role selection.
We do not use this information for cross-site advertising or retargeting. Because we do not track your activity across unrelated sites for advertising, browser “Do Not Track” signals do not change our practices. You can limit nonessential analytics through browser controls, script blocking, or clearing browser storage, although doing so may affect some features.
7. Newsletter and Email Choices
Newsletter enrollment occurs when you submit a newsletter form or when an account-registration screen clearly states that newsletter enrollment is included. We store your email, subscription status, and signup source. Marketing emails identify the sender and include an unsubscribe method. You can unsubscribe at any time using that method or the unsubscribe page. Transactional messages, such as a job-posting confirmation, secure sign-in link, candidate-introduction request, or report link you requested, are sent as part of the service.
8. Data Retention
We keep personal information for as long as your account or subscription is active and as long as needed for the purposes described in this policy, then delete or anonymize it, unless a longer period is required by law. You can remove uploaded resumes and imported projects from your profile. To request deletion of other data, contact us at hello@onetwoloop.com.
9. Security
We use reputable infrastructure providers and standard safeguards, including access controls, transport encryption, and rate limiting, to protect your information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Children’s Privacy
The site is not directed to children. It is intended for people who are at least 18 years old, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us and we will delete it.
11. Your Privacy Rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. To exercise these rights, email hello@onetwoloop.com. We will verify your request and respond as required by law. We will not discriminate against you for exercising these rights.
12. California Privacy Rights (CCPA/CPRA)
Where California privacy law applies, California residents may have rights to know, access, delete, and correct personal information and to opt out of its sale or sharing. We do not sell personal information or share it for cross-context behavioral advertising. You may submit a request, including through an authorized agent, by contacting hello@onetwoloop.com.
13. International Data Transfers
We operate from the United States, and information may be processed in the United States and other countries where our service providers operate. Privacy protections in those countries may differ from those where you live. Where required, we use an appropriate legal mechanism for international transfers.
14. Business Transfers
If OneTwoLoop is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its business or assets, personal information may be reviewed, disclosed, or transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.
15. Changes to This Policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be highlighted on the site. Your continued use of the site after an update means you accept the revised policy.
16. Contact
Questions, requests, or complaints about this policy can be sent to hello@onetwoloop.com. Our mailing address is OneTwoLoop LLC, 215 N Peoria St, Floor 8, Chicago, IL 60607.