Meritto — Privacy Policy

Last updated: 17 September 2026 · Effective: 17 September 2026

This Privacy Policy describes how Meritto ("Meritto", "we") collects, uses, shares, and safeguards personal information when you use the Meritto Platform.

1. Data We Collect

1.1 Information You Provide

1.2 Information Collected Automatically

1.3 Information from Third Parties

1.4 Information We Derive for Matching

2. How We Use Your Data

PurposeLegal basis
Operate the Platform, compute karma scores, surface candidates to recruiters Performance of contract
Match seekers to recruiters' requirements by automated analysis of profile, résumé and requirement text, and tell recruiters when new candidates match Performance of contract
Measure and improve match quality using search logs and recruiter feedback Legitimate interest
Detect and prevent cheating, fraud, or platform abuse Legitimate interest
Send transactional notifications (interview reminders, test results) Performance of contract
Send product updates and beta announcements Consent — opt-out anytime
Comply with legal obligations (tax, audit, statutory requests) Legal obligation

2.1 Automated Matching

Meritto ranks candidates for a recruiter's requirement automatically, by comparing the meaning of the requirement with each seeker's search profile, and shows a match percentage and the requirement's words that appear in the profile. This ranking is an aid to the recruiter: Meritto does not make hiring decisions and does not reject anyone automatically. Recruiters decide whom to contact, and you decide whether to share your contact details. Turning off "Open to work" removes you from every search and shortlist.

3. How We Share Your Data

We do not sell your personal data.

4. Data Retention

5. Your Rights

Subject to applicable law, you have the right to:

To exercise any of these rights, email [email protected].

6. Security

We use TLS in transit and AES-256 at rest, role-based access controls, and continuous monitoring on our hosting infrastructure. While no system is impervious, we apply industry-standard safeguards and notify affected users of any material data breach within 72 hours of discovery, where required by law.

7. Cookies

We use first-party cookies and similar technologies to keep you signed in, remember preferences, and measure aggregate usage. You can clear cookies from your browser settings at any time; some features will require re-authentication after doing so.

8. Children

Meritto is not intended for use by anyone under 18. We do not knowingly collect data from minors. If you believe a minor has provided us data, please contact [email protected] and we will delete it promptly.

9. International Transfers

Our infrastructure is primarily hosted in the Asia-Pacific (ap-south-1) region. Where we transfer data outside India for processing by service providers, we rely on the EU Standard Contractual Clauses and equivalent safeguards under applicable law. Text sent to Voyage AI for matching (section 3) may be processed outside India, including in the United States, and is not retained by Voyage AI after processing.

10. Changes

We will post material changes to this Policy at least 14 days before they take effect, via email and an in-app banner. The "Last updated" date at the top reflects the most recent revision.

11. Contact

For privacy questions, data-subject requests, or to reach our Data Protection Officer, email [email protected].