Privacy Policy
This Privacy Policy explains what personal information OneTwoLoop LLC (“OneTwoLoop,” “we,” “us,” or “our”) collects when you use onetwoloop.com and our related services, why we collect it, who we share it with, and the choices you have. OneTwoLoop LLC, a Wyoming limited liability company, operates onetwoloop.com. By using the site, you agree to the practices described here.
If you have questions about this policy or your data, contact us at hello@onetwoloop.com.
1. Introduction and Acceptance
OneTwoLoop is a free Chicago software jobs board and newsletter. Some features are open to anyone; others require you to sign in with GitHub. This policy applies to information we collect through the website, the sign-in flow, job postings, applications, the newsletter, and email we send you. It does not cover third-party websites we link to, which have their own policies.
2. Information We Collect
2.1 Information You Provide Directly
Depending on how you use the site, you may provide:
- Email address. Collected when you subscribe to the newsletter, sign in with GitHub, post a role (as the poster contact), or request a company analytics report.
- Name. First and last name entered during onboarding.
- GitHub profile data. When you sign in with GitHub, we receive your GitHub username, display name, avatar image, and the email associated with your GitHub account.
- Location. A self-selected city. This is a dropdown choice, not device GPS or precise location.
- Professional profile. LinkedIn profile URL, a resume PDF you choose to upload, and public GitHub repositories you choose to import (name, description, links, and topics).
- Career preferences. Disciplines, specialities, work type, seniority, hiring intent, and whether you need visa sponsorship.
- Discovery source. How you found the site, including any free-text answer you provide.
- Self-attestations. Work history, self-rated skills and supporting evidence, external links, and any explanation you give about a sparse GitHub profile.
- Job applications. A cover note plus a snapshot of your display name, GitHub username, email, profile URL, and the job you applied to.
- Mission submissions. A submission URL.
- Expressions of interest. When you express interest in a role, a snapshot of your name, GitHub username, profile URL, and email.
- Intro chat messages. The body of messages you send through the intro chat. Contact details such as emails, phone numbers, and URLs are stripped by our server before a message is stored.
- Assessment attempts. Scores, feedback, and timestamps from any assessment you take, plus your rating-consent choices and consent timestamp.
2.2 Company and Poster Information
When someone posts a role, we collect the company name, job title, job description link, discipline, work type, poster contact email, hiring stage, notes, a summary of the job description, salary range, and visa-sponsorship details. Job listings are submitted for review before they appear.
2.3 Automatically Collected Information
When you visit the site we collect standard technical and usage data, including pages viewed, clicks and interactions, scroll depth, engagement time, referrer, the URL path, and device and session identifiers. See Section 6 for details on analytics.
2.4 GitHub Sign-In
We use GitHub OAuth for sign-in. We do not collect or store passwords. GitHub tells us the account email, username, display name, and avatar tied to the GitHub account you authorize. Your use of GitHub is governed by GitHub’s own privacy policy.
2.5 Information We Do Not Collect
- We do not collect or store passwords.
- We do not collect payment-card or billing details on the site. If a paid job listing is offered, payment happens off-site through a link we email you; no card or CVV fields exist on the site.
- We do not store your IP address in our database. IP addresses are used only briefly in memory for rate limiting and are not written to our records. Your IP is still visible to the third parties listed in Section 5 as a normal part of loading their content.
- We do not collect phone numbers, and our chat pipeline actively removes phone numbers before storing a message.
- We do not collect precise geolocation. Browser geolocation is blocked by our permissions policy.
3. How We Use Your Information
We use the information above to:
- Provide, operate, and improve the jobs board, profiles, applications, and newsletter.
- Authenticate you and maintain your session.
- Match engineers and roles, and surface relevant listings.
- Send transactional messages such as newsletter confirmations, job-posting confirmations, and report magic-links.
- Notify our team about new signups, pending or live job postings, and expressions of interest.
- Understand how the site is used through aggregate analytics.
- Protect the site against abuse, spam, and unauthorized access.
- Comply with legal obligations.
4. Listing Corrections and People Named in Postings
4.1 Employer Listing Corrections
If you represent a company and a listing about your company is inaccurate or should be removed, email hello@onetwoloop.com and we will review and correct or remove it.
4.2 People Named in a Posting
If you are named in a role posting or other submitted content and want that reference corrected or removed, contact us at the same address. We do not sell personal data and we are not a consumer reporting agency.
5. Third-Party Service Providers
We share data with a small set of processors that help us run the service. Loading their content may expose your IP address to them.
- Supabase. Our primary data processor for database, authentication, file storage (including uploaded resumes), edge functions, and realtime features.
- GitHub. OAuth sign-in and public-repository import; provides your email, username, name, and avatar.
- PostHog (US cloud). Product analytics, delivered through a first-party reverse proxy, plus limited masked session recording as described in Section 6.
- Vercel. Hosting, cookieless web analytics, and edge middleware.
- Resend (with Svix webhooks). Transactional and newsletter email delivery, including bounce and complaint suppression.
- Anthropic (Claude). Parsing job descriptions and, for administrative use only, analyzing ticker images.
- Google Gemini. Ticker image analysis for administrative and scheduled tasks only.
- CARTO, Google Fonts, jsDelivr, and unpkg. Map tiles, web fonts, and content-delivery assets. Loading these exposes your IP address to those providers.
- Greenhouse. Server-side fetching of public job-description content; no visitor personal data is sent.
- Cloudflare Worker. Sends intro-request notifications to our team.
- Stripe. Processes any off-site payment link we email for a paid job listing. No card fields are collected on the site.
We do not sell your personal data, and we do not share it with advertising networks or data brokers.
6. Cookies, Analytics, and Tracking
We do not set first-party HTTP tracking cookies. Our analytics rely on browser storage and cookieless beacons.
- PostHog. Captures pageviews, page-leave events, autocaptured clicks and inputs, web vitals, scroll depth, engagement events, and named product events, along with device and session identifiers. Its state is stored in your browser’s localStorage, and traffic is routed through a first-party proxy path.
- Session recording. Session recording is enabled only on the newsletter page. All inputs are masked, and a filter strips authentication tokens and URL fragments before events are sent. This is not sitewide keystroke capture.
- Vercel Web Analytics. Cookieless pageview measurement. For job pages, we store a normalized path, a session or device identifier, and a timestamp.
- Listing views. We record which job a signed-in user or anonymous session viewed, keyed to a user or session identifier plus the job.
- Browser storage. We use localStorage and sessionStorage for analytics state, your authentication session, and small preferences such as remembering a page or a pending job selection.
We do not use Google Analytics, advertising pixels, retargeting, or cross-site tracking cookies. You can limit analytics by using your browser’s privacy controls, blocking scripts, or clearing localStorage at any time.
7. Newsletter and Email Choices
The newsletter is opt-in. When you subscribe, we store your email, subscription status, and the source of the signup. Every newsletter email includes a one-click unsubscribe link and our postal address. You can unsubscribe at any time using that link or the unsubscribe page. Transactional messages, such as a job-posting confirmation or a report link you requested, are sent as part of the service.
8. Data Retention
We keep personal information for as long as your account or subscription is active and as long as needed for the purposes described in this policy, then delete or anonymize it, unless a longer period is required by law. You can remove uploaded resumes and imported projects from your profile. To request deletion of other data, contact us at hello@onetwoloop.com.
9. Security
We use reputable infrastructure providers and standard safeguards, including access controls, transport encryption, and rate limiting, to protect your information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Children’s Privacy
The site is not directed to children. It is intended for people who are at least 18 years old, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us and we will delete it.
11. Your Privacy Rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. To exercise these rights, email hello@onetwoloop.com. We will verify your request and respond as required by law. We will not discriminate against you for exercising these rights.
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request access to and deletion of it, and to correct inaccurate information. You also have the right to opt out of the sale or sharing of personal information. We do not sell or share your personal information as those terms are defined under California law. You may exercise your rights by contacting hello@onetwoloop.com, and you may use an authorized agent to submit a request.
13. International Data Transfers
We operate from the United States, and our providers are primarily based in the United States. If you access the site from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country. By using the site, you consent to this transfer.
14. Business Transfers
If OneTwoLoop is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will continue to protect it consistent with this policy and will note any change in ownership that materially affects it.
15. Changes to This Policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be highlighted on the site. Your continued use of the site after an update means you accept the revised policy.
16. Contact
Questions, requests, or complaints about this policy can be sent to hello@onetwoloop.com. Our mailing address is OneTwoLoop LLC, 215 N Peoria St, Floor 8, Chicago, IL 60607.