Who we are#
Expanding Ranks is provided by Expanding Ranks LLC, a Kansas limited liability company with its registered office at 8715 W 81st Street, Overland Park, Kansas 66204, United States (“Expanding Ranks LLC,” “we,” “us,” or “our”).
This policy explains what information Expanding Ranks collects, why, and what happens to it. We wrote it to actually be read, so we have kept the sentences short and left out the parts that only exist to fill space. If a section does not apply to you, it says so.
If you have questions this page does not answer, write to the contact form on our Support page.
Two different people use this product, and we treat their data differently
This is the most important thing to understand about this policy, so we are putting it first.
Expanding Ranks is an applicant tracking system. A recruiting organization (our customer) subscribes to it and uses it to manage the people it is trying to hire (candidates). Those are two different groups of people, with two different relationships to Expanding Ranks LLC, and the law treats them differently.
Customer users. If you are a recruiter, hiring manager, or administrator who signs in to Expanding Ranks on behalf of your organization, Expanding Ranks LLC is the controller of your account data. That means we decide how your login, your preferences, and your usage of the product are handled, and this policy tells you how.
Candidates. If you are a job applicant or a person a recruiting organization is sourcing, your information is in Expanding Ranks because that organization put it there or connected an account that brought it in. For that data, Expanding Ranks LLC acts as a processor (service provider) working on the instructions of the recruiting organization, which is the controller. We do not decide why your data was collected or what it is used for. Your recruiting organization does. If you are a candidate and want to know what a specific organization is doing with your information, or want to exercise a right described in Section 8, the fastest path is to contact that organization directly. We will help them respond to you, and Section 8 explains how to reach us if you are not sure who to ask.
We are drawing this line at the start because a policy that blurs it tends to read as though we are building a database of candidates for our own purposes. We are not. We hold this data because our customers pay us to help them run their recruiting process, and only for that reason.
What we collect#
We break this out by source rather than writing “we may collect personal information,” because that sentence tells you nothing.
| Source | What is collected |
|---|---|
| Entered directly by the customer | Candidate name, contact details, resume or application materials, pipeline stage, and recruiter notes |
| Job boards and applicant sources the customer connects | Application records forwarded automatically from the customer's configured source, so nobody has to retype them |
| Microsoft 365, where a customer user connects it | Messages the user sends through Expanding Ranks. For messages the user receives, we read the sender's address, the conversation identifier, and the timestamp so we know a reply arrived. We do not retrieve or store the body, preview text, or attachments of any message. Calendar events the user creates, updates, or cancels through Expanding Ranks |
| Google Workspace, where a customer user connects it | Messages the user sends through Expanding Ranks. We do not request, retrieve, or store the content of any Google mail, and we do not read incoming Google mail at all. Calendar events the user creates, updates, or cancels through Expanding Ranks |
| Video conferencing (Zoom), where a customer connects it | A record that an interview occurred: who attended, when, and for how long. Where the meeting host recorded the session and the customer's organization has turned this on, the transcript of that recording. We never store the recording itself. It stays in the customer's own Zoom account |
| Telephony and text messaging, where a customer connects it | Records that a call or text occurred, and, where the customer's own phone system recorded the call, the transcript of it. We never store the recording itself. It stays in the customer's own phone system |
| Customer account administration | Billing contact information, subscription details, and support correspondence |
| The Expanding Ranks website | Standard web log data, and cookies as described under Cookies and website tracking below |
If a category above does not apply to a given customer, it is because that customer has not connected that account. Every connection in this table is opt-in. A customer who never connects a Zoom account generates no Zoom data in our system.
Cookies and website tracking
This website uses Cloudflare Web Analytics, and nothing else. It sets no cookie, it stores nothing on your device, and it does not follow you to other websites. It tells us how many people visited a page and roughly where in the world they came from. It cannot tell us who you are.
We do not use Google Analytics. We chose not to, because Google's terms let it process data in any country where Google or its suppliers have facilities, and we have promised our customers that we keep processing in the United States.
We do not use cookies to build advertising profiles. We do not sell or share information collected this way. If you join the waitlist, we keep the address you gave us, the time you sent it, and basic request details we use to spot abuse.
How we use it#
We use the information above to run the following features, each of which a customer has actively chosen to use:
- Present a recruiter's working list of candidates, ordered by who is owed a reply.
- Send outreach a recruiter has written or approved, from that recruiter's own connected account.
- Detect when a candidate has replied, so an in-progress follow-up sequence stops instead of continuing to message someone who already answered.
- Schedule, update, and cancel interviews on a recruiter's own calendar.
- Attach a completed interview, call, or text exchange to the right candidate record automatically, so nobody has to log it by hand.
- Produce a customer's own reporting on its own recruiting activity.
- Operate, secure, and support the product, including responding to support requests and detecting abuse.
What we do not do with it:
- We do not sell personal information.
- Mobile information collected for text messaging is never shared or sold to third parties or affiliates for marketing or promotional purposes.
- We do not use customer data or candidate data to train general-purpose machine learning or artificial intelligence models.
- We do not use data from a connected mailbox, calendar, meeting account, or telephony account for advertising, and we do not transfer it to anyone for advertising purposes.
- We do not read message content beyond what is needed for the specific feature the customer enabled, and for several integrations described below, we structurally cannot see message content at all because we never request it.
- We do not make automated hiring decisions. Expanding Ranks may surface and order candidates using signals the customer configures, but it does not reject, exclude, or hide a candidate from human review. A person at the customer organization makes the hiring decision.
- We do not share candidate data between customers. Each customer's data is kept separate.
- We do not use information purchased, rented, or gathered about a candidate from anyone other than that candidate to score, rank, or evaluate their fit for a role. That kind of information may only be used to locate a candidate and connect them to the right recruiter or opening. See Candidate data and your rights for more detail.
Google user data#
Reviewers, auditors, and frankly anyone who cares about this should not have to hunt for what a specific vendor connection does. Each one is described on its own here.
Expanding Ranks connects to a recruiter's own Google account, with that person's consent, so a recruiter can send candidate outreach from their own Gmail address through the product and manage interviews on their own Google Calendar. We request send-only access to Gmail. We do not request, and structurally cannot obtain, read access to any Google mail. We do not know what a candidate's reply says unless the recruiter reads it themselves in Gmail; Expanding Ranks never sees it.
Limited Use disclosure. Expanding Ranks' use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes adheres to the Google User Data Policy, including the Limited Use requirements. In practice, this means: we use Google data only to provide the outreach and calendar features described above, we do not transfer it except as necessary to provide those features or as this policy otherwise describes, we do not allow anyone at Expanding Ranks LLC to read it except where you have given specific consent, for security investigations, or where the law requires it, and we do not use it to train generalized AI or machine learning models.
Microsoft 365 data#
Expanding Ranks connects to a recruiter's own Microsoft 365 mailbox and calendar, with that person's consent and their organization's approval. It sends outreach the recruiter has composed or approved, and it reads limited information about the mail the recruiter receives to detect a candidate reply. That read access returns only the sender's address, the conversation identifier, and the timestamp. It is built to exclude the message body, preview text, and attachments, so the content of what a candidate wrote is never retrieved by Expanding Ranks and never stored on our systems. We use the same account to create, update, and cancel interview events on the recruiter's own calendar. We do not access any mailbox or calendar other than the signed-in user's own, and access ends when that user's access to their own account ends.
Zoom data#
Where a customer connects a Zoom account, Expanding Ranks records that a scheduled interview happened: the participants, the start time, and the duration, so that fact is attached to the right candidate automatically. Transcript capture is off by default. A customer's organization must affirmatively turn it on before Expanding Ranks retrieves the transcript of any Zoom recording. Expanding Ranks does not schedule, host, or join meetings on a user's behalf. We do not access Zoom chat messages, contacts, phone records, or billing information.
We never store the recording itself. Not by default, not as a paid option, not for any customer, at any time. The recording lives in the customer's own Zoom account, for as long as that customer's own Zoom administrator has set it to live there. We cannot make that window longer, and we cannot make it shorter.
Playing a recording back does not mean we hold one. When someone plays an interview back inside Expanding Ranks, we check that they are allowed to see that candidate's record, write a log entry recording who played what and when, fetch the recording from Zoom at that moment using the customer's own connection, and stream it to them. The Zoom credential doing the fetching never reaches the browser. That is the whole reason we built it this way instead of handing out a direct Zoom link: a Zoom credential sitting in a web page would reach the customer's entire Zoom account, not one recording. The recording's bytes exist on our side only inside that single request, in memory, and they are gone the moment it ends. Nothing is written to a disk we control.
We do analyze what was said, and here is what that means. Where a customer turns conversation review on, we produce a transcript and analyze it to give that customer results about its own recruiting: a searchable record of the conversation, and review of how that customer's own recruiters ran it against a script that customer wrote. Those results belong to that customer. We do not use conversation content to train general-purpose machine learning or artificial intelligence models, we do not share it between customers, and we do not use it for advertising.
If a customer's Zoom administrator removes Expanding Ranks from their Zoom account, that is the step that ends our access, and it ends it at Zoom. Zoom decides whether a credential it once gave us still works, so removing the app in Zoom's own settings settles it, and it does not depend on us at all. On our side we mark that connection dead and stop using it. We will not tell you the credential is destroyed at that same moment, because we cannot yet prove it. Our half of that is a request into somebody else's system, and a request can fail without the person who pressed Disconnect ever seeing it fail. We would rather point you at the step that works than make a promise we cannot check. We will say so here the day our own side of it completes and verifies itself. There is more on this under Retention and deletion. There is no recording on our side for any of this to reach, because we never stored one; the recording stays in the customer's own Zoom account and is removed there. Disconnecting does not delete the meeting records and transcripts we already had. A meeting that happened is part of the candidate's history and stays, on the retention schedule described below. If you want a specific interview's record and transcript removed, a customer can delete it directly from the candidate's record at any time, with or without disconnecting Zoom. Separately, and at any time, a customer can delete a single interview's record and transcript from a candidate's record without disconnecting Zoom entirely.
Phone and messaging data#
Where a customer connects its own phone system, Expanding Ranks records that a call or text happened and attaches that record to the candidate it belongs to. Where the customer's own system recorded the call, we retrieve a transcript of it. The customer owns its phone numbers and its carrier relationships. Expanding Ranks LLC is not a telephone service provider or a text messaging provider, and each customer is responsible for its own consent practices and its own registration of its messaging programs with the carriers, as required by applicable telecommunications rules. We process the records that connection produces. We do not originate a call or a text to a candidate on our own account, ever. Candidate outreach rides the customer's own number under the customer's own registration, and that is a deliberate boundary rather than a limitation.
We do operate one phone number of our own, and it is a support line for our own customers. You can call 844-777-2657 or text 844-777-2657, one toll-free number for both, published on our Support page. The text line only ever answers. You text us, a person reads it and replies, and we do not text anyone who has not texted us first. There is no list, no marketing, and no number taken from a web form, a bought list, or a third party for messaging. Sign-in codes are the only other thing that number will ever be used for, if you choose a text message as your second factor for signing in. Reply STOP to stop and HELP for help. Message and data rates may apply. What we keep is the message itself and the number it came from, handled under this policy like any other support conversation, and our Text Message Terms set out the rest.
If you call or text that line, here is where it goes. A telephone company carries the call or the message, the same way one carries any call, and our own provider keeps the voicemail recording and the text so that we can read it and reply. So a voicemail you leave us is held by us and by that provider, not only by us. We use it to answer you and for nothing else. We do not add you to a list, we do not sell it, and we do not use it for marketing. If you would rather not leave a recording at all, the contact form on our Support page reaches the same people and creates no recording. This is our own line and it is separate from anything described above about a customer's phone system: the calls and texts here are between you and Expanding Ranks.
We never store the call recording itself. It stays in the customer's own phone system, on that system's own clock. Some phone systems hold a recording for a fixed number of days and give nobody, including their own customer, a way to extend it. Playback works the way it does for Zoom: we fetch the recording from the customer's phone system at the moment someone plays it, and we keep no copy. Where a customer has turned conversation review on, we analyze call transcripts for the same purpose and on the same terms described in the Zoom section above.
Consent records and opting out. Where a candidate is texted through Expanding Ranks, the recruiting organization is the one that obtained permission to contact that number and the one that holds the record of it. We are saying that plainly rather than claiming a consent ledger of our own, because we do not have one yet. What we do keep is the record that you asked to stop. If you receive a text through Expanding Ranks and do not want to be contacted again, reply STOP and you will not be texted again. Reply HELP for assistance. We record that you opted out, and that record stops the recruiting organization that texted you from texting that number again. It covers every campaign that organization runs through us, not only the campaign that reached you. It is recorded against the phone number you replied from, and it is not tied to an email address. So if that same organization also emails you and you want the email to stop as well, say so to that organization directly, or write to us through the contact form on our Support page and we will pass it on.
Two limits on that, and we would rather you read them here than find out the hard way. The record belongs to the organization that texted you. It does not reach a different organization that also uses Expanding Ranks. If two companies are both recruiting you, telling one to stop does not tell the other, because those are separate records held by separate companies and neither can see the other. And we hold it for as long as that organization's account with us exists. When that account closes and its data is deleted, the record of your opt-out is deleted along with it. We keep that record for one thing, which is refusing to send. It is not a profile, it is not shared, and it is not used for anything else.
Mobile information collected for text messaging is not shared or sold to third parties or affiliates for marketing or promotional purposes. That covers your phone number, the record that consent was given to contact it, and the record that you asked us to stop. Our Text Message Terms set out who sends these messages, how often they arrive, and how to stop them.
Candidate data and your rights#
If you are a customer user, you can request correction or deletion of your own account information by writing to the contact form on our Support page.
If you are a candidate, your data belongs to the recruiting organization that is the controller for it. The fastest way to have it corrected or deleted is to contact that organization directly. If you are not sure which organization that is, or you would prefer to route the request through us, write to the contact form on our Support page and tell us as much as you can (your name, the organization you believe holds your information, and how you applied or were contacted). We will identify the responsible customer and pass your request to them, and we will assist that customer in responding to you as required by applicable law. We do not have the authority to unilaterally delete a candidate's data outside the customer's instruction, except where the law requires otherwise.
One thing we cannot delete, because we never had it. If your request covers a recording of a call or an interview, that recording is not ours. It sits in the recruiting organization's own phone system or meeting account, and only that organization can remove it there. On the customer's instruction we will delete our transcript and our record of the conversation, and we will pass the rest of your request to the organization that holds the audio, but we cannot reach it ourselves.
Depending on where you live, you may have rights to know what personal information we or our customers hold about you, to correct it, to delete it, to receive a copy of it, and to object to or limit certain uses of it. Some state and national privacy laws give these rights directly to you; others route them through the controller, which for candidate data is the recruiting organization rather than Expanding Ranks LLC.
We do not sell personal information and we do not use it for cross-context behavioral advertising, so there is no “opt out of sale or sharing” mechanism to operate, because nothing here is sold or shared in that sense.
If a right applicable to you is not addressed above, write to the contact form on our Support page and we will tell you how to exercise it, including routing your request to the correct controller where that applies.
A note on where your information comes from, and what it can and cannot be used for. Sometimes a recruiting organization finds a candidate through a source Expanding Ranks LLC did not create, for example a purchased contact list, a data enrichment service, or information gathered from a public source rather than given to the organization directly. Information that reached us that way may be used only to locate you and connect you with the right recruiter or opening. It cannot be used to score, rank, rate, or judge your fit for a role, and it can never cause you to be left out of a recruiter's view. Only information you gave the recruiting organization yourself, for the specific application or hiring process it relates to, can ever factor into how a candidate is ordered or evaluated.
Retention and deletion#
We keep different categories of information for different lengths of time, matched to why we are keeping it:
| Category | Retention |
|---|---|
| Audit and security event records (who did what, and when) | 7 years |
| Access and read logs (records of who viewed a candidate record) | 4 years |
| Screening-related records (candidate signals, responses, and scoring history) | 4 years. This is a recordkeeping period, not a preference of ours: California's employment recordkeeping rule (Cal. Gov. Code 12946) requires records of this kind to exist for four years. The federal floor (29 CFR 1602.14) is one year, and where both apply the longer one governs |
| Activity records (calls, texts, emails, and interview occurrences logged to a candidate) | For as long as the candidate record they are attached to exists |
| Call and meeting recordings | We never store them, so there is no window of ours for one to sit in. The recording stays in the customer's own meeting platform or phone system, for however long that customer's own administrator has set it to stay there |
| Call and meeting transcripts | 90 days from the day we receive the transcript, on its own clock, independent of the customer's subscription |
| Customer account and billing data | For the life of the customer's subscription, plus what is needed for tax and accounting records |
When a customer's subscription ends, the customer can export its entire dataset, in one action, at any time during the 30 days after termination. Once that 30-day export window closes, we delete the customer's data from our active systems within an additional 30 days, subject to internal review. 60 days in total. Disconnecting a specific integration (for example, unlinking a Zoom account) stops Expanding Ranks from using that connection; data already brought into Expanding Ranks before the disconnection is retained under the schedule above unless the customer separately deletes it.
On disconnecting an integration, the short version is not the honest one, so here is the longer one. Disconnecting marks that connection dead on our side and stops the product using it. It is not proof that the access itself is gone. A connection's credential is not something we keep in our own database, and whether it still works is decided at the provider rather than here. Our request to take it down there runs against somebody else's system, and it can fail quietly. A subscription a provider already set up for us can also keep running until it expires on that provider's own clock. So if you want access ended for certain, remove Expanding Ranks in the provider's own settings too. In Zoom that is App Marketplace, then Manage, then Installed Apps. In Microsoft 365 or Google Workspace it is the admin console, or your own account's third-party access settings. In a phone system it is wherever that system lists connected applications. That is the step that reliably ends it, because the provider is the one that decides whether a credential still works. We will say so here the day our own teardown completes, verifies itself, and tells you when it could not.
The 60 days does not override the table above, and on one row the difference is years rather than days. Candidate screening records are kept for four years, not sixty days. California's employment recordkeeping rule (Cal. Gov. Code 12946) requires records of that kind to exist for four years, and deleting them when a customer leaves would destroy evidence that customer may be the one required to produce. The federal floor (29 CFR 1602.14) is one year. They are different obligations, and where both apply the longer one governs. Anywhere the table gives a longer period than sixty days, the table is what happens.
On the 60-day deletion itself, one thing we would rather you read here than find out later. Deletion at the end of that window is started by us and needs a second approval, and there is no scheduled process that starts it automatically on day sixty. A clock that depends on somebody remembering is not a clock, so we will not state it as an unconditional promise until the process that runs it exists.
Where a legal hold, audit requirement, or an active dispute applies to specific records, we may retain them beyond these windows for as long as that requirement applies, and we will tell the affected customer when that happens.
A legal hold cannot reach a recording, and we would rather you read that here than discover it during a dispute. A hold placed with us marks what we actually have: the interview or call record, the transcript past its 90 days, the review attached to it, and the audit trail. What a hold with us is, stated plainly: it is a commitment by people, not a lock in the software. We mark the records and we do not delete them. But an authorized user in your own organization who deletes a record while a hold is open will succeed, because the product does not yet stop them. So if you need records preserved, tell your own people too. We will say so here the day that changes. It has no reach into the customer's own meeting platform or phone system. We cannot pause that provider's deletion clock and we cannot outlive it. Once the provider has deleted a recording, it is gone, and we have nothing to produce. If a customer needs recordings to last longer, that is a setting and a plan on the system that made the recording, arranged with that provider's own administrator. It is not something we can sell or do on their behalf, at any price.
Security#
We use industry-standard measures to protect the information in Expanding Ranks, including encryption of data in transit and at rest, isolation of each customer's data from every other customer's, and access controls that limit who inside Expanding Ranks LLC can reach production data. Access to sensitive systems requires authentication through our identity provider, and we log access to candidate records as described in Section 10.
We do not currently hold SOC 2, ISO 27001, or any other third-party security certification, and no independent penetration test of Expanding Ranks has been completed as of the effective date of this policy. We are not claiming either here, and we will update this section if that changes. No system is perfectly secure, and if we ever learn of an incident affecting your information, we will notify affected customers and individuals as required by applicable law.
If you believe you have found a security vulnerability in Expanding Ranks, please write to the contact form on our Support page. Our full disclosure policy is at expandingranks.com/security.
International transfers and children#
Expanding Ranks processes and stores data in the United States. We do not currently offer Expanding Ranks to customers established outside the United States, and we do not knowingly hold data about candidates located outside it. On those facts no international transfer of your account data takes place, and no transfer mechanism is needed. Rather than attach one that does not apply, we have said so.
If that changes, and you are established outside the United States or tell us you will be processing data about people in a place that restricts transfers, we will agree an appropriate transfer mechanism with you in writing before that processing starts, and we will tell you honestly whether we are ready rather than sign something we cannot operate. Your account data is stored in the United States. Neon, the vendor that holds it, is configured to a United States region, and Neon itself runs on Amazon Web Services in an Amazon data center in Ohio. We hold no Amazon account that any of this runs in. Requests to our site first pass through Cloudflare, our security and traffic layer, which runs a global network and does not store your data. A vendor that cannot commit to storing your data in the United States is not one we will use without agreeing a transfer mechanism first.
Expanding Ranks is a business tool used by recruiting organizations and is not directed to children. We do not knowingly collect personal information through the product from anyone under the age of 16 in connection with a customer's own account. Because candidate data is supplied by our customers rather than collected directly from the public, we rely on our customers to apply their own legal obligations regarding the recruitment of minors where that applies to their hiring.
Changes to this policy#
We will post any change to this policy on this page and update the “last updated” date above. Where a change is significant, particularly a change to how we use data obtained through a connected Google or Microsoft account, we will notify affected customers directly and, where required, obtain renewed consent before the new use begins.
Contact us#
Expanding Ranks LLC
8715 W 81st Street
Overland Park, Kansas 66204
United States
Privacy questions and candidate requests: the contact form on our Support page
General support: the contact form on our Support page
Security: the contact form on our Support page
Web: https://expandingranks.com