Privacy Policy
Last updated: August 2026
This describes what RemoteHire.ph collects, why, who else sees it, and how long we keep it. It is written to be read rather than to be survived, and everything in it is what the product actually does today.
Who is responsible
RemoteHire.ph is operated from the Netherlands and is the controller of the personal data described here. The quickest way to reach a person about anything on this page, including any of the rights below, is support@remotehire.ph or the contact page, which reaches the same inbox.
Why we are allowed to hold it
Under the GDPR every use of personal data needs a lawful basis. Ours are these, and nothing here is done on the basis of consent except where it says so.
| What for | On what basis |
|---|---|
| Your account, your profile, messages, offers, contracts, hours and invoices | Performing the contract you have with us when you use the service |
| Identity verification, tool certifications and phone confirmation | Performing that contract: they are features you ask for, and the whole product is built on the ID check |
| Moderation, abuse prevention and security logging | Our legitimate interest in a platform where people can trust who they are talking to, and yours in the same |
| Counting views, searches and page visits to understand what the product is missing | Our legitimate interest in improving it. Nothing here is used for advertising |
| Marketing email | Consent, which you give when you leave the setting on and withdraw by switching it off or unsubscribing |
| Payment and accounting records | A legal obligation. Tax law sets how long these are kept, not us |
What a freelancer profile shows publicly
Photo, your first name (never your surname), headline, bio, age (never the date of birth), gender, province, hourly rate, hours a week, rated skills, tools and industries, languages, work and education history without the organisation names, portfolio media, and which platforms you have links on. That is a public, indexable page, and it is meant to be.
Your bio is your own free text and is public as written. Somebody who writes their city into it has published their city; the content rules ban contact details, not places.
Identity documents
Government IDs and verification selfies go to a private storage bucket that only you and an administrator can read. They are never shown on your profile or to clients. The images are deleted 30 days after a verified review and 90 days after a rejected one; the record that a review happened, and when, is kept.
What the review records
When a person on our team reviews your government ID we record the review date, who reviewed it, how long they spent, whether the photograph came from a camera or an upload, and which of five checks they confirmed: that the face on the ID is the face in the selfie, that the document looks intact and unedited, that the name matches your profile, that the date of birth matches, and that the document has not expired. All five have to be confirmed before a profile is marked verified.
Nothing off the document itself is recorded. Not its type, not its number, not the authority that issued it, not its expiry date, and not your name as printed on it. Between 14 August and 2 September 2026 the first four of those could be recorded and the number was stored only as a one-way fingerprint; everything recorded in that period was deleted on 2 September 2026, in the database and in our internal log. Subscribed clients see the review date and nothing else about it.
Phone confirmation
If you confirm your phone number, we store the number and the confirmation date. Subscribed clients can see the date, never the number. Codes are stored only as a one-way hash, expire after ten minutes, and are deleted 90 days after an unsuccessful attempt. Changing your number clears the confirmation.
Tool certifications
If you ask to be certified in a tool, we keep what you send us: the link or file you submit, a screen recording, your screenshots, and your two written answers. We keep them to review the task and to check the credential if it is ever questioned. They are never published and never shown to clients, who see only that you hold the credential, the date, and that it was earned by a practical task reviewed by a person.
The screen recording is deleted 30 days after we decide, automatically. The rest is kept for as long as you hold the credential, because a credential with no surviving evidence cannot be checked. If a submission is declined for an integrity reason we keep the record of that decision, and you are told the outcome without the detail.
Relationship and invoice records
We count the offers, engagements and invoices recorded here into totals, durations and per-currency amounts shown to subscribed clients, without ever naming the other party.
Contracts you sign
When you sign a contract here we record the name you typed, the exact time, the IP address and browser you signed from, and whether your identity had been verified against a government ID at that moment. That record is part of the signed document and cannot be changed afterwards, by you, by the other party or by us. Both of you keep access to it, including after a subscription ends.
Each signed version carries a code printed on the document. Anyone holding the document can check that code at /verify-contract, which shows the times it was signed and whether each identity was verified, and never shows either of your names.
Activity logging
For security and moderation we keep an append-only log of account activity: sign-ins, changes to your data, administrative actions, and with each of those the IP address and browser your request came from. It is used to investigate abuse and to answer “who changed this”, not for advertising.
Job post view counts
We count how many different people look at each job post, so the client who posted it can see whether anyone read it. Only that client sees the number, and it is a count and nothing else: it never says who looked.
If you were signed in we record your account id against that post for that day, so a second look on the same day is not counted twice. If you were not signed in we record no address at all, only a one-way scrambled value that includes the date, which means it cannot be turned back into an address and cannot be used to recognise you tomorrow. Job owners, administrators and search engine crawlers are not counted.
Profile and video views
When a freelancer profile is opened we record which profile it was, when, and your account id if you were signed in. It feeds one number: the view count the freelancer sees on their own dashboard. That number is a count and nothing else, and the person viewed is never shown who looked. The same applies to video intros. A freelancer opening their own profile is not counted.
Where things came from, on Deep Check
If you are a freelancer, the Deep Check page a subscribed client can open about you shows, for two kinds of record, the country the record came from and part of the internet address behind it: the address you confirmed your phone number from, and the distinct addresses you have signed in from over the last ninety days.
The address is always shown partly, never in full, and it is our administrators only who can see the whole of it. The country is worked out from the address at the moment the page is opened, by an IP-to-country lookup service, and is not stored. No count of sessions, no times of day and no pattern of any kind is shown. We draw no conclusion from any of it and neither should anyone else: shared offices, households and mobile networks routinely put two people on one address.
Signed-in devices
For each browser or phone signed in to your account we store the address it connected from, the browser it identifies itself as, when it signed in and when it was last used. You can read all of it, for your own account only, under Settings, and sign any of them out from there. It exists so that you can tell whether somebody else is signed in as you, which is the only thing it is used for: nobody else sees it, and it feeds no other feature.
When a session ends the record is kept for up to ninety days so that signing a device out leaves a trail, and then deleted. The approximate location beside each device is worked out from the address at the moment you look at the page, by an IP-to-country lookup service, and is never stored.
Searches
When a search or a filter returns results we record what was searched for, which filters were set, how many results came back, and your account id if you were signed in. We use it to understand what people are looking for and, more usefully, what they look for and do not find.
It is never shown to anyone outside our own administrators, and even there it is only ever aggregated: there is no way for anybody to see one person’s searches, including us.
Email delivery and link checks
We record whether email we send you arrives or bounces, so that we notice when our own delivery is failing. We also periodically try the links on profiles and record whether they opened. Neither is shown to clients.
Contacting us
If you write to us through the contact form we store your name, email address, the company you gave if you gave one, your message, the IP address and browser the message came from, and your account id if you were signed in. The IP address and browser are there to keep the form from being used for abuse. Only administrators can read what you sent, and we keep it for two years, after which it is deleted along with the rest of that period’s records. Ask us to delete it sooner and we will.
Who else sees your data
These are our processors. Each holds data only to do the job named beside it, on our instructions, under a data-processing agreement.
| What they do | What for |
|---|---|
| A database, authentication and file-storage provider | Everything you enter lives here |
| A hosting and content-delivery provider | Serving the site, and counting page views without cookies or anything stored on your device |
| Stripe | Payments. Card details reach Stripe and never reach us |
| An email delivery provider | Sending email, and telling us whether it arrived |
| Google Analytics | Counting visits and which pages are read. Audience measurement, never advertising |
| An error-monitoring provider | Recording errors so we can fix them. It sees the page and the fault, not what you typed |
| An IP-to-country lookup service | Turning an address into a country or a time zone at the moment a page is opened. Nothing is stored |
We do not sell personal data, we do not run advertising trackers, and nothing here is shared with anybody else except where the law requires it.
Where your data is
Some of these providers process data outside the European Economic Area, including in the United States. Where that happens it is covered by the European Commission’s standard contractual clauses, which is the mechanism we rely on.
Freelancers here are in the Philippines and clients are anywhere, so a working relationship on this platform necessarily involves data crossing borders. That is the product rather than a side effect, and it is what you are agreeing to by using it.
How long we keep it
| What | How long |
|---|---|
| Records of changes to data | 2 years |
| Sign-ins and other security events | 5 years, because they are what an argument about account access turns on |
| Profile views, video views, searches | 1 year |
| Job post view records | 2 years |
| Contact-form messages | 2 years |
| Unsuccessful phone confirmation attempts | 90 days |
| Records of two accounts sharing a document or a number | 2 years |
| Ended device sessions | 90 days after last use |
| Certification screen recordings | 30 days after the decision, automatically |
| Certification uploads never submitted | 14 days |
| ID document images | 30 days after a verified review, 90 after a rejected one |
| Contracts, invoices and timesheets | While the accounts they belong to exist, because they are financial and legal records |
Deletion happens on a periodic manual run rather than automatically, except where the table says otherwise, which means a record may outlive its period by a few weeks before the next run reaches it. Ask us to delete your account and we delete it and its data.
Decisions about you
Nothing here is decided about you automatically. The profile score is computed and shown, and it is not a decision about a person: it changes what a freelancer can apply to and nothing that a human has not set the rules for. Every moderation call, every ID verdict and every certification decision is made by a person on our team.
Your rights
You can edit almost everything from your account at any time. Name, date of birth and gender lock once your ID is verified, because the check is against those details; an administrator can correct them, with the reason recorded. Beyond that, the law gives you these, and you exercise any of them by writing to support@remotehire.ph:
- Access: a copy of what we hold about you.
- Rectification: correcting anything wrong.
- Erasure: deleting your account and its data. Some records survive where the law requires it, such as accounting records.
- Restriction: asking us to stop using something while a question about it is resolved.
- Portability: a machine-readable copy of what you gave us.
- Objection: objecting to anything we do on the basis of a legitimate interest, including the counting described above.
- Withdrawing consent: for marketing email, at any time, from your settings or the unsubscribe link. It does not affect anything sent before.
We answer within a month. If we need longer we tell you why, and we never charge for it.
If you think we have got it wrong
Tell us first, because most of it we can fix the same day. You also have the right to complain to a data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl); if you are a freelancer in the Philippines you can also raise it with the National Privacy Commission (privacy.gov.ph). You do not have to go through us first.
Changes to this policy
When we change something material we update the date at the top and, where it affects what happens to your data, tell you in the product. We do not quietly rewrite this page.