Privacy Policy

Last updated September 3, 2026

Sortiva is an AI-powered hiring operations platform for home service trade businesses — HVAC, plumbing, electrical, restoration, roofing, painting, gutter repair, handyman and similar trades. This policy explains, in plain language, what information we collect, why we collect it, and what we do with it.

1. Who this policy covers

Two groups of people use Sortiva. Employers are the trade businesses that hold an account with us. Candidates and employees are the people those businesses hire or consider hiring. We handle candidate and employee information on behalf of the employer, who decides what to collect and how long to keep it.

2. Information candidates provide

When someone applies through a public Sortiva job link, the application form collects their name, phone number, optional email address, an optional free-text note, and an optional resume file. Resume files are stored in private cloud storage that only the employer who posted the job can access through short-lived, signed links. We also record which channel the application came from (for example a job board, a social post, or a QR code) so employers can see what is working.

3. AI phone screening and reference checks

Employers can ask Sortiva to place an automated outbound screening call to a candidate, or a reference-check call to a reference the candidate provided. These calls are placed through our voice provider, Bland AI. Depending on the call, the provider may create a recording and always produces a written transcript, which is returned to Sortiva and stored with the candidate record.

Transcripts are analyzed by an AI model to produce a structured summary and score — things like years of experience, licenses mentioned, availability, employment confirmation and rehire status. Calls are announced as automated at the start, and participants can decline or end the call at any time. Recording of calls is subject to applicable consent laws in the participant's jurisdiction; employers are responsible for using this feature lawfully.

4. Text messages

Sortiva sends and receives SMS messages for interview and reference scheduling — for example asking a candidate for their availability and reading the reply. Employees of Sortiva's business customers may also text the Sortiva number to submit time-off and scheduling requests. Message content, phone numbers and timestamps are stored so the employer has a record of the conversation. Standard carrier message and data rates may apply to recipients. Reply STOP to opt out at any time. See our SMS Terms & Conditions for full details.

5. Employer and employee information

We store the account and operational data employers enter, including:

  • Account details: name, work email, password credentials, and company profile.
  • Company setup: trade type, employee count, and hiring cost settings.
  • Job postings, requirements, and public application links.
  • Employee records and certification or license documents uploaded for renewal tracking, stored in private, owner-scoped cloud storage with expiration dates used to send reminder emails.

6. Site analytics

We collect standard, aggregate usage information such as page views, device and browser type, approximate location derived from IP address, and referring source. This is used to understand product usage and keep the service reliable. We do not sell personal information.

7. Who we share information with

We do not sell personal information and we do not share it for advertising. We share it only with the service providers below, and only with the specific data each one needs to do its job:

  • Supabase — our database, login system and file storage. It holds essentially all app data: employer accounts and passwords, company profiles, job postings, candidate and employee records, call transcripts and scores, messages, scheduling requests, and uploaded resume and certification files. Files are kept in private buckets and access is restricted by row-level security so an employer can only reach their own company's records.
  • Bland AI — our outbound automated voice/call provider. It receives the phone number of the candidate or reference being called, plus limited company and job context needed for the conversation script, and produces the call audio and written transcript, which are returned to Sortiva as applicable.
  • Twilio — our SMS delivery and routing provider. It receives the sender and recipient phone numbers, message content, and delivery/routing metadata needed to send and receive candidate, interview, reference, and employee scheduling messages. It processes that data only to provide messaging for Sortiva.
  • Google (Gemini models, accessed through the Lovable AI gateway) — our AI analysis provider. It receives call and reference transcripts, inbound scheduling text content, and the relevant job requirements, in order to produce the structured summaries, scores and extracted scheduling details you see in the app. Names and phone numbers may appear inside a transcript that is sent for analysis.
  • Google Calendar (optional) — If a company owner clicks "Connect Google Calendar" in Settings, Sortiva uses Google's Calendar API to create, update, and cancel that owner's own Sortiva interview events on their connected calendar. This connection is off by default and only activates when an owner explicitly connects it. Employee schedules are never written to an employer's calendar; employees receive their own private link and calendar file instead. Direct Google Calendar sync for employee schedules is not available in Sortiva today.
  • Jobber (shelved, not offered) — Sortiva is not affiliated with Jobber, has no Jobber Marketplace listing, and does not offer a Jobber connection today. It cannot be started from anywhere in the product, and no data is sent to or read from Jobber. If it is ever offered again, it will require an explicit authorization by a company owner and this policy will be updated first.
  • Resend — our email delivery provider. It receives the recipient email address and the content of the message: certification expiration reminders sent to employers, and messages an employer sends to a candidate through Sortiva.

Each provider processes this data only to deliver its part of the service. We may also disclose information if required by law, or as part of a business transfer, in which case this policy continues to apply to the transferred data.

8. Google Workspace API data and Limited Use

Sortiva’s use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Sortiva requests Google Calendar permission only for the Calendar functionality actually implemented and authorized by the signed-in user: creating, updating, and cancelling that user's Sortiva interview events. Sortiva does not read or use unrelated Calendar events, even where the granted OAuth scope would technically permit broader access; use is limited to the authorized Sortiva functionality above. Employee schedules are delivered by private link and standards-based calendar file, not direct Google Calendar sync.

Tokens and event identifiers. When a user connects Google Calendar, Sortiva stores the Google access and refresh tokens plus the identifiers of the calendar events Sortiva created. Tokens are needed to keep the authorized connection working without asking the user to sign in repeatedly, and event identifiers are needed to update or cancel the correct event later. Both are held server-side only and are never exposed to the browser or to another company. Access and refresh tokens are stored only while the connection is active and are deleted when the connection is disconnected or the account is deleted. Identifiers of Sortiva-created events may remain in the related Sortiva interview or technical records after a disconnect so Sortiva can keep its own history of what it scheduled; those identifiers are removed together with those records, or on account deletion, under the retention controls described in this policy.

Your controls. Disconnecting Google Calendar in Sortiva's Settings deletes the stored access and refresh tokens and stops all Calendar access; you can also revoke access directly in your Google Account settings. Deleting a Sortiva account removes the stored tokens and the Sortiva records that hold Sortiva-created event identifiers. Google Calendar events Sortiva previously created may remain in your Google Calendar after a disconnect, since Sortiva can no longer reach them, and you can delete them yourself in Google Calendar. You can also email us to request deletion.

The current employer connection manages only that employer's own Sortiva-created interview events. Employee schedules are delivered by private link and standards-based calendar file; Sortiva does not offer employee Google Calendar authorization.

Sortiva does not use, transfer, sell, or allow raw or derived Google Workspace API user data to be used to create, train, or improve generalized, non-personalized, foundational, or cross-user artificial intelligence or machine learning models. This restriction also applies to Google Workspace data that has been aggregated, anonymized, or otherwise derived. Google Workspace API data is never sent to our AI analysis provider.

Sortiva does not use Google Workspace API data for advertising, marketing profiles, data brokerage, creditworthiness, or lending decisions. Access is limited to providing the user-facing Calendar functionality the user authorized, and Google Workspace API data is not transferred to any other service provider.

9. Mobile information and SMS opt-in data

Sortiva does not share mobile information or SMS opt-in data with third parties or affiliates for marketing or promotional purposes. Text-message opt-in and consent data is shared only with messaging service providers and aggregators, such as Twilio, as necessary to operate the SMS program; they may not use it for their own marketing.

10. Employer-configured integrations and background checks

An employer can send their own Sortiva data to an address they control, or read it with a read-only API key they create in Settings. Those feeds carry a limited summary only — for example a name, role, job title, credential expiration date or approved shift count. They never carry resumes, uploaded documents, call recordings, transcripts or draft schedules. Nothing is sent anywhere until an employer sets up a destination themselves, and they can pause or delete it at any time.

Sortiva has no official app, partnership, certification or approved listing with any other software vendor. Any connection an employer builds with these tools is their own integration, and the receiving system's handling of that data is governed by that system's terms and privacy policy, not ours.

Sortiva does not run background checks. It does not order a check, contact a screening provider, receive a report, or store any result. Employers use their own provider and remain responsible for FCRA disclosure, authorization and adverse-action obligations. Sortiva stores only a workflow marker showing where the employer left off.

11. How we use information

We use the information above to run the service: to deliver applications to the right employer, to screen and score candidates, to schedule interviews, to track certification expirations and send reminders, to calculate dashboard metrics, and to support, secure and improve the product.

12. Data retention and security

Candidate, employee and company data is retained while the employer's account is active, and deleted or anonymized on request or within a reasonable period after account closure. Access is restricted by row-level security rules so an employer can only see their own company's records. Files are held in private buckets and served only through expiring signed links. No system is perfectly secure, but we take reasonable technical and organizational measures to protect the data we hold.

13. Your choices and rights

Candidates and employees may request access to, correction of, or deletion of their information by contacting us or the employer who collected it. Employers can delete jobs, candidates, employees and uploaded documents from within the app. Depending on where you live, you may have additional rights under applicable privacy law.

14. Data deletion and account closure

You can permanently delete your account and all associated data at any time, yourself, from Settings — open the Security section and use "Delete Account & All Data" in the Danger Zone.

This action is immediate and irreversible. It removes your company profile and settings, every job posting and application link, every candidate record along with screenings, transcripts and messages, every employee record and certification, all uploaded resumes and certification documents, and your own login account. There is no recovery afterwards and we cannot restore deleted data.

If you would rather not do it yourself, email connect@sortiva.studio and we will delete your account and data for you.

15. Children

Sortiva is not intended for anyone under 16, and we do not knowingly collect information from children.

16. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected in the "last updated" date above, and continued use of Sortiva after an update means you accept the revised policy.

17. Contact

For privacy questions or requests, email connect@sortiva.studio.

Questions? Email us at connect@sortiva.studio.