Privacy Policy
What Served collects, why it collects it, who can see it, and what you can do about it.
We will never sell your data. Period. We’re not sell-outs, and we’re not about to start.
Served was built by someone who spent years behind the bar — not by a data broker. Your information exists here to help you find work, hire good people, and build a hospitality community that actually respects the people in it. That’s it.
Who we are
Served is operated by Served LLC, based in Michigan. If you have any questions about this policy or how your data is handled, reach out any time at support@served.life.
What we collect
To make Served work, we collect:
- Account information — your email address and a password. The password is held by our authentication provider as a one-way hash; nobody at Served can read it. If you use a Google account to sign in, we receive the email address on it and no password at all.
- Profile information — your name, headline, bio, job history, skills, years of experience, availability, and similar details you choose to share.
- Photos and media — profile photos, portfolio and work images, and photos of a venue you manage.
- Resumes — if you choose to upload one.
- Location, in two separate forms. A town-sized location you type on your profile, which is shown with it. And, if you turn on distance matching, a precise address you give for that purpose, which we convert into map coordinates and store apart from your profile. Nobody else ever sees the precise one — not another member, not an employer holding your application, not an administrator. Only a distance calculated from it can reach anyone else.
- Venue information — the venues you create or are invited to help run, who is on the team, what each person is allowed to do, and invitations sent and accepted.
- Jobs, applications, and hiring — roles posted, applications sent and withdrawn, and the stage a candidate has reached: shortlisted, interviewing, offered, hired, or passed.
- What an employer records about a candidate — saved candidates, a status, and one private note per candidate, written by that employer and readable only by them.
- What you post — feed posts, comments, likes, saves, follows, reposts, and Heard discussions and replies, together with who posted them and when.
- Messages — conversations you have with other users through Served, whether each message has been read, and interview requests sent inside a conversation.
- Notifications and email preferences — what you have been notified about, what you have seen, and which classes of email you have turned off.
- Safety records — reports you file, reports other people file about your content or account, the outcome a moderator reached, and any appeal you send.
- Account standing — whether an account is active, deactivated, suspended, or banned, the reason recorded, and when a suspension ends.
- Account and payment information — for employers subscribing to hiring features, payment is processed securely through Stripe. Card details are entered on Stripe’s own hosted pages and never touch Served: we hold the Stripe customer and subscription identifiers, whether the subscription is active, and the dates of the current period.
- Basic technical and operational information — server logs carrying a request identifier, and audit records of account actions such as signing in, changing a password, or deactivating. These record the action, its outcome, and an identifier; they deliberately contain no password, no token, and no message content. To slow down password guessing we also keep a short-lived count of recent sign-in attempts, stored against a one-way hash of the address rather than the address itself.
Nearly all of it comes from you. The rest comes from other people using Served — an employer’s note about you, a report somebody files, a message somebody sends you — and from the services listed below doing their jobs.
Sensitive information
Some of what Served handles counts as sensitive personal informationunder state privacy laws, and it gets stricter treatment:
- Precise location. The matching address and its coordinates are the clearest example. We only collect them if you turn distance matching on, we use them for nothing else, we never sell or share them, and you can remove them at any time.
- Anything sensitive you choose to write. A profile, a post, or a message is free text, and what you put in it is up to you. We do not ask for your race, health, religion, immigration status, union membership, or sexual orientation, we do not have fields for them, and we do not infer them.
- Your right-to-work confirmation is a yes-or-no answer you give when you sign up. We do not collect documents proving it — an employer handles that directly with you.
We do not sell sensitive information, use it for advertising, or use it to profile you for anything with a legal or similarly significant effect.
How we use it
We use your information to:
- Let workers and employers find and connect with each other
- Power features like saved candidates, job matching, distance search, and messaging
- Send the notifications and emails your account and your preferences call for
- Keep the community safe: screen what is posted, act on reports, and handle appeals
- Process employer subscription payments (via Stripe)
- Improve Served and fix problems
- Communicate with you about your account or important updates
- Meet a legal obligation, or respond to a valid legal request
We do not make decisions with legal or similarly significant effects about you by automated means. The one place a machine decides anything is content moderation, which has its own section below and always has a person at the end of an appeal.
Who can see what
Visibility is enforced by the database itself, not only by what the interface chooses to show, and it is covered by automated tests. In short:
- Your profile — signed-in members. If you turn on the public preview, a limited version can also be seen by anyone, including search engines.
- Your precise matching address — nobody but you. Others may see a distance calculated from it.
- Your resume — only an employer you applied to, for as long as that application gives them a reason to read it. The permission is recorded, scoped to that purpose, and can be revoked; links to the file itself are short-lived.
- An employer’s note about you — that employer only.
- Messages — the people in the conversation. Where a conversation is with a venue rather than a person, everyone on that venue’s team who is entitled to reply can read it.
- Posts, comments, and Heard discussions — the community, and anyone at all where a post has a shared public link. Treat them as public writing.
- Venue pages — public, including to search engines, once published.
- Reported content and account records — Served administrators, for moderation and support.
Automated review of what you post
Public content — feed posts, Heard discussions, and replies — is checked by an automated moderation service (OpenAI) before it appears. The text is sent to that service, which returns category scores; those scores decide whether the post publishes, waits for a person, or is refused.
- Private messages are never sent to it. Neither are resumes, profiles, or any file you upload.
- Images are not machine-checked at all. A post carrying a picture goes to a person instead.
- If something you wrote is hidden or refused, you are told, and you can appeal to a human moderator.
How ranking and matching work
Served orders things for you. Roles you might want are inserted into your feed, job results are sorted by relevance and distance, and candidate lists are ordered for employers. The inputs are ordinary and few: what you put on your profile, the filters in front of you, distance if you enabled it, and how recent something is.
- Served does not decide who gets hired, interviewed, or rejected. A person at the venue does that. We do not score you, rank you against other candidates for an employer’s decision, or produce any assessment of your suitability.
- Served is not a background-check or screening service and is not a consumer reporting agency. What an employer sees is what you published, plus what you sent them. We do not assemble reports about you from outside sources.
- If an employer uses its own tools on top of what Served shows it, that is theirs to disclose and account for, not ours to answer for.
What we do not do
- We do not sell your personal data to third parties. Not to advertisers, not to data brokers, not to anyone. Full stop.
- We do not use your data to serve you third-party ads.
- We do not run advertising or analytics trackers on this site. There is no ad network, no social pixel, and no third-party analytics script anywhere in the application.
- We do not read your private messages, except where a report or a legal duty requires it.
Who we share it with
We only share data with the services that help Served actually function:
- Supabase — the database, sign-in, and file storage behind the app. This is where your account, profile, messages, and uploads live.
- Vercel — hosting for the application itself.
- Stripe — payment processing for employer subscriptions. Stripe holds the card details; we do not.
- Resend — delivery of the emails we send you, so it handles your email address and the contents of those messages.
- OpenAI — automated moderation of public posts and discussions, as described above. Text only.
- Google Maps Geocoding — turning a typed address into map coordinates for distance matching. The lookup is made by our server, so your device never contacts Google for it, and no account information goes with it.
If required by law, we may disclose information to comply with a valid legal request. If Served is ever sold or merged, account data may transfer with the business — and this policy, or one at least as protective, goes with it.
We do not share your information with any other third party for marketing or resale purposes.
One more route worth naming plainly: employers are independent businesses. When you apply for a role, what you send — your profile, your resume, your messages — is in that employer’s hands, and how they handle it is governed by their own obligations as well as ours.
Cookies, Do Not Track, and opt-out signals
Served sets the cookies it needs to keep you signed in and to keep forms secure. There are no advertising cookies and no third-party tracking cookies. Clearing them signs you out; nothing else about your account changes.
Some browsers send a Do Not Track signal, and some send a Global Privacy Control signal, which several state laws treat as a binding request not to sell or share personal information. Served does not track you across other websites and does not sell or share your information, so there is nothing for either signal to switch off — we treat every visitor as though the signal were already on. If that ever changes, this page changes first.
How long we keep it
- While your account exists, we keep what your account needs to work.
- Deactivating hides your profile and takes your listings out of circulation. It does not erase your account, and it is reversible — that is the point of it.
- Deletion removes your account and the personal content attached to it. Ask us and we will do it.
- Some records outlive the account, deliberately. Moderation outcomes, reports, appeals, account-standing history, audit records of account actions, and payment records are kept so that a ban cannot be erased by re-registering, so a report you filed does not vanish from under the person acting on it, and so we can meet tax and legal obligations. They are kept no longer than those purposes need.
- Messages you sent to somebody else stay in their conversation, in the same way a sent email stays in the recipient’s inbox.
- Sign-in attempt counters are short-lived and hold no address.
Your choices
- You can edit or delete most of your profile information directly in the app at any time
- You can turn off classes of email in your settings, or from the unsubscribe link in the message itself. Messages we have to send you — password resets, security notices, and anything about your subscription — keep coming while your account is open, because they are how the account itself works.
- You can deactivate your account yourself, and reactivate it later
- You can appeal a moderation decision, and a person will read it
- You can request a copy of your data, or request that we delete your account and associated data, by emailing support@served.life
- If you’re a Michigan resident or a resident of a state with its own privacy law (like California’s CCPA), you may have additional rights — to know what we hold, to correct it, to delete it, to take it elsewhere, and not to be treated worse for asking. Email us and we’ll help sort out what applies to you. We will never charge you or degrade your account for exercising a privacy right.
How to make a request, and what happens next
Email support@served.life from the address on your account and say what you want — a copy of your data, a correction, deletion, or a question about any of this. Someone acting for you (an authorised agent) can ask on your behalf, with proof that you asked them to.
- We will confirm it is you before we hand anything over or delete anything, usually by checking that the request comes from your account’s email address. That is a protection for you, not an obstacle.
- We answer within 45 days, and tell you if we need longer.
- If we say no, we say why, and you can appeal by replying to that answer. An appeal goes to someone who did not make the first decision, and we will write back with the outcome and, where your state provides one, how to complain to your Attorney General.
- There is no charge, and asking changes nothing about how your account is treated.
Some things we may have to keep even after a deletion request — a moderation record, a payment record, something a law requires. If that happens we will tell you what was kept and why.
How it is protected
Traffic is encrypted in transit. Access rules are enforced inside the database rather than only in the interface, so a request that should not see something is refused at the source and not merely hidden from view. Resumes and private media sit in private storage reached only through short-lived signed links. No card details are stored by Served at all. No system is perfectly secure, and we will tell you promptly if something happens that affects you.
Where your data is held
Served and its providers operate in the United States, and that is where your information is stored and processed. If you use Served from elsewhere, you are sending your information to the US.
Age, and children
Served is for adults: you must be 18 or older to have an account. We do not knowingly collect information from anyone under 18, and if we learn that we have, we delete it and close the account. A parent or guardian who believes their child has an account can email support@served.life and we will remove it.
Changes to this policy
If we materially change how we handle your data, we’ll update this page and the “Last updated” date above. If the change is significant, we’ll try to let you know directly through the app.
Contact
Questions, concerns, or just want to yell at us (nicely) about something? Email support@served.life.