Candidate Privacy Notice
Last Updated: March 12, 2024
Thank you for choosing to learn more about the privacy policies of Cardlytics, Inc. (together, with its affiliates and subsidiaries, “Cardlytics”). Cardlytics knows that you care about how your personal information is used and shared. Privacy is not just a priority for Cardlytics, but an essential part of our business model.
This notice (“Candidate Privacy Notice”) provides information on how Cardlytics processes information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with you or your household (“Personal Information”) that is received in connection with your application to work at Cardlytics as an employee or a contractor or that is otherwise received or collected by Cardlytics in connection with its recruitment activities.
Note that, in connection with Cardlytics’ recruitment activities, Cardlytics may also collect information that cannot reasonably be linked to you, including de-identified, anonymized, and/or aggregated information, which is not considered personal information. This Candidate Privacy Notice does not apply to information that cannot reasonably be linked to you, including information that has been aggregated and anonymized such that it is no longer considered Personal Information under applicable data protection law
What information we collect about you
INFORMATION YOU PROVIDE
This policy covers the types of information, including Personal Information, that Cardlytics may receive directly from you (which may include sensitive personal information, depending on the jurisdiction where you reside) which may include the following:
Type of Information we Collect | Example |
---|---|
Contact Information | Name, postal address, email address, telephone number. |
Date of Birth | Date of Birth. |
Employment History | Copy of resume or CV, references from previous employers, cover letter, details of professional accomplishments and current or previous roles, LinkedIn profile URL, past payment pay slips to verify prior employment. |
Identity Verification Documents | Birth certificate or passport, state issued driver’s license, other identification, residence history. |
Information on Right to Work in Country of Hire | Copy of passport and/or other national identity documents, government identification number such as Social Security Number in the USA, work authorization documents, visas, I-9 documentation. |
Education History | Copy of education degrees or certificates obtained, university or other educational institution transcripts, and verification of membership in professional bodies. |
Preferences | Your preferences regarding being contacted in the future regarding other job positions, which may be of interest to you. |
National ID/Tax ID Number | Social Security Number, National Tax ID Number, or similar ID numbers. |
Demographic Information [optional] | Race/ethnicity, gender identity, disability, veteran status |
Any special needs or health condition and information relating to those accommodations | Auditory or visual assistance needs, disability accommodation needs. |
Any information on websites or social media profiles (whether professional or personal) that a candidate includes as part of their job application | LinkedIn Profile URL, Facebook URL, Twitter URL, GitHub URL, Design portfolio website. |
We may also collect any other Personal Information you chose to share with us in your resume or CV or during the interview process.
Regarding the collection of demographic information, candidates may optionally choose to self-identify their race/ethnicity, gender identity, and disability. These answers will help us evaluate our diversity and belonging efforts. You do not have to answer these questions—and if you do, your answers will not be linked to your name or job application, will not be visible to the hiring manager reviewing your application, and will in no way affect your job application
INFORMATION CARDLYTICS MAY BE COLLECTING FROM OTHER SOURCES
This policy covers the types of information, including Personal Information, about you that Cardlytics may receive from other sources (which may include sensitive personal information, depending on the jurisdiction where you reside) including:
Type of Information | Examples | Source |
---|---|---|
Background Check Information | Previous employment, extended education review, sanctions check, credit report, bankruptcy history, criminal history and public profiles (including any social media or other online platforms—whether professional or personal—where you have a profile that is publicly accessible). | Law enforcement agencies, educational institutions, third-party service providers, and social media or other online platforms where you have a publicly accessible profile. |
When voluntarily supplied to a third party by the Candidate, Contact Information, Employment History, Education History, Pay History | Candidate’s resume, recruiters’ notes from initial interview with a candidate. | Recruitment agencies |
Information that is publicly available, such as work experience information and other data online | Work experience information and other information, such as your activity on professional or personal social media accounts or other sites that are publicly accessible | Public-facing sites |
Referral information | If you're being referred, any information that the person referring you provides about you | Referrer |
External Career Site Cookies | Cookies are used to deliver functionality on our external career sites | Our external recruiting partners (including Workday, LinkedIn, and Gem) |
How do we use this information?
In the table below we explain the business purposes for which Cardlytics processes your Personal Information, what information is processed, and the lawful basis Cardlytics relies on to do so (to the extent applicable law requires a lawful basis to process Personal Information).
Types of Information | How we use it | Legal Justification (where applicable) |
---|---|---|
Contact Information, Information on Right to Work in Country of Hire, Preferences. | To communicate with you during the recruitment process | Pre-contractual necessity; Legitimate interest in communicating with potential candidates. |
Contact Information, Information on Right to Work in Country of Hire, Preferences. | To communicate with you in relation to open positions which may be of interest to you | Legitimate interest in communicating new opportunities to potential candidates. |
Contact Information | To arrange to send a laptop to a candidate prior to their first day | Legitimate interest in providing prospective employees with essential work equipment to carry out their duties. |
Contact Information, Employment History, Information on Right to Work in Country of Hire, Education History | To evaluate your attributes, qualifications and skills to determine if you are eligible for the role | Legitimate interest in determining the skills and qualifications of a candidate. |
Contact Information, Employment History, Information on Right to Work in Country of Hire, Education History | To prepare for interviews or screening discussions | Legitimate interest in identifying candidates qualified for open roles. |
Contact Information, Identity Verification Documents, Date of Birth, National ID/Tax ID Number, Education History, and any information or activity on social media profiles (whether professional or personal) that are publicly accessible | To conduct a background check where lawful to do so and where we have concluded that such checks are relevant to the role at issue | Legitimate interests (or consent to the extent legally required) |
Information on Right to Work in Country of Hire. | To verify employment authorization/eligibility in the country of hire | Compliance with a legal obligation (i.e., to ensure an employee has the right to work under applicable laws) |
Personal information Cardlytics processes as listed herein | To facilitate internal research, analysis, internal reporting, including research/analysis/reporting in relation to diversity and inclusion, business talent needs, business planning, and improving recruitment processes | Legitimate interest (or consent to the extent legally required). |
Demographic Information | To evaluate our diversity and belonging efforts | Legitimate interest (or consent to the extent legally required). |
When and whom we share your information with
Cardlytics uses a number of third-party tools and service providers to help us operate and carry out the business purposes listed above. We may share your Personal Information with those service providers to support these efforts, as well as with other third parties, all in accordance with applicable law. For example, we may share your Personal Information with:
Entity Type | Purpose | Types of Data |
---|---|---|
Other Entities of Cardlytics | To provide services and support across the Cardlytics group for recruitment and onboarding purposes. | Contact Information, Right to Work in Country of Hire |
Workday | When you apply for a position, refer a candidate, or are being considered for a role at Cardlytics, your information is stored in Workday, in accordance with Cardlytics’ Candidate Privacy Policy. We use this information to evaluate your candidacy for the posted position. We also store this information, and may use it in relation to future positions to which you apply, or which we believe may be relevant to you given your background. | Contact Information, Employment History, Information on Right to Work in the Country of Hire, Education History, Potential of salary expectations, Reference notes, Interview notes, and Job application history (internal/external applicants). |
To source candidates. We use this information to evaluate your candidacy for the posted position. We also store this information, and may use it in relation to future positions to which you apply, or which we believe may be relevant to you given your background. | Contact Information, Employment History, Information on Right to Work in Country of Hire, Education History | |
DocuSign | To collect e-signatures for offers of employment/employment agreement for candidates. | Contact information (Name, email, mailing address) |
DocuSign | To collect e-signatures for offers of employment/employment agreement for candidates. | Contact information (Name, email, mailing address) |
Other Third Parties | For example, we may share your information with regulators, law enforcement, or other government agencies in response to legal requests, we may share your information with civil litigants pursuant to court orders, or we may share your information with others to protect the rights, property and safety of our company, our employees, or others, including to prevent death or imminent bodily harm. For instance, we may share your information with law enforcement in emergency situations where we learn that a person’s life is at risk. | Contact Information, Employment History, Education History, and other information described in the “Information Cardlytics May Collect About You” Section above |
Other Third Party Service Providers | To source talent, engage candidates, to evaluate candidates, to communicate about candidates as they progress through our recruiting process, and to otherwise manage our recruiting operations. | Contact Information (Name), application information (such as resume or cover letter), Employment History, Information on Right to Work in Country of Hire, Education History, Potential of salary expectations, Reference notes, Interview notes, and Job Application History |
When we share your information with third party service providers, we ensure, both technically and contractually, that they will protect your information like we do.
Cardlytics does not sell the Personal Information of candidates, nor do we share it for purposes of cross-context behavioral advertising.
Information For UK Candidates Regarding International Transfers
Cardlytics has employees and contractors working around the world, including in the UK. If you have applied for a position in the UK, your Personal Information is controlled by the Cardlytics entity you applied for a position with (which in that instance would be Cardlytics UK Limited). Your information may be sent to other Cardlytics locations and to service providers who may be located in other regions, including the United States (where we are headquartered). For example, we may transfer your data to the United States so that we can process all of our candidate information centrally, or to otherwise facilitate the recruitment and onboarding process. When we send your information across borders, we take steps to protect your information and do so in accordance with UK law, including utilizing appropriate safeguards such as the Standard Contractual Clauses when necessary
How long we retain your Personal Information
We store your Personal Information for as long as necessary for the purposes outlined in this privacy policy, including to fulfill our contractual obligations to you, to comply with our legal obligations and where it is in our legitimate interests to do so. When we have no ongoing legitimate business purpose to process your information, we will either delete or anonymize it.
Data Security
We have, and require the service providers with whom we may disclose Personal Information to have, administrative, technical, and physical safeguards in place in our respective physical facilities and in our respective computer systems, databases, and communications networks that are reasonably designed to protect information contained within such systems from loss, misuse, and alteration. The measures we use may include storing Personal Information on secured servers, transmitting Personal Information using encryption technologies, and auditing and reviewing our data collection and storage practices. In addition, we limit access to Personal Information to those employees, agents, contractors, and other third parties that have a legitimate business need for such access.
Notice to UK, and California Candidates
If you reside in the UK or California, (depending on which region you reside in), you may have one or more of the following rights:
to correct, update, and request access to your Personal Information and information about our processing of your Personal Information;
request that we cease or suspend the processing your Personal Information;
request that we delete your Personal Information;
request that we restrict our processing of your Personal Information (including limiting the use of sensitive Personal Information, as applicable);
and to object to certain processing activities (e.g. automated decision making, etc.);
If you create a Workday account in connection with your application to Cardlytics, you may be able to exercise some of the above rights directly through your Workday account.
When Cardlytics has obtained your consent to process your Personal Information, under applicable law, your consent may be withdrawn at any time with future effect. If this applies and you withdraw consent, it will not invalidate (1) the lawfulness of any processing Cardlytics conducted prior to the withdrawal, or (2) Cardlytics’ continued processing of some or all of your Personal Information under other legal bases, where applicable.
Please note that we may need to verify your identity before facilitating or enabling you to exercise your rights regarding Personal Information, and thus may request certain information from you when you submit any such requests. Under some applicable laws, you may also submit Personal Information requests through an authorized agent, in which case, we may request further information to verify the authenticity of the request and the agent’s authorization to act on your behalf
Changes to Cardlytics’ Candidate Privacy Notice
We may change Cardlytics’ Candidate Privacy Notice from time to time. We will post any changes to the Candidate Privacy Notice on this page. The last updated date of this Candidate Privacy Notice is identified at the top of this page.
How to Contact Us
If you have any questions about how we use or process your information, or if you would like to exercise your Personal Information rights (where applicable), please contact candidate-privacy@cardlytics.com