Reqstaq is a staffing CRM and applicant tracking system operated by WebGM, LLC, an Illinois limited liability company based in Chicago, Illinois ("Reqstaq", "we", "us"). This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and the choices you have.
We've tried to write this in plain English. If anything is unclear, email us at support@reqstaq.com.
Who this policy covers
Reqstaq is used by staffing and recruiting firms (each a "Customer"). Three groups of people are affected by how we handle data, and the rules differ for each.
Visitors and prospects
Anyone who browses reqstaq.com, requests a demo, or subscribes to our newsletter. We decide how this information is handled.
Account users
Employees and contractors of a Customer who have a Reqstaq login. We decide how your account and sign-in information is handled; your firm decides what you can do inside Reqstaq.
Candidates and contacts
People whose information a Customer puts into Reqstaq, or who provide it through a Customer's job application form or email — job seekers, placed workers, and people at the Customer's client companies. We call this Customer Data.
The Customer decides what Customer Data goes into Reqstaq, who at their firm can see it, and how long it stays. We process it only on the Customer's instructions and under our agreement with them. In privacy-law terms, the Customer is the "business" or "controller" and we are the "service provider" or "processor."
If you are a candidate or contact and want to know what a staffing firm holds about you, or want it corrected or deleted, contact that firm. We will help them respond, but we don't act on Customer Data without their direction except where the law requires it. If you don't know which firm to contact, email us and we'll try to route you.
1 Information we collect
Visitors and prospects
- What you give us: name, work email, phone, company, and anything you write in a contact or demo request form.
- Automatically: IP address, browser and device type, pages viewed, referring page, and — if you arrive from one of our ads — the ad click identifier (Google's GCLID or Microsoft's MSCLKID). See Section 6 for details.
Account users
- Profile: name, work email, optional phone, job title, role and permissions, and the firm you belong to.
- Sign-in and activity records: sign-in times, IP address, an approximate location derived from your IP address (country and region), browser and device, and an audit trail of actions you take in the platform. Your firm's administrators can view these records and may restrict sign-ins from certain countries or from anonymizing networks (VPNs, proxies, Tor). We keep these records for security and to help your firm meet its own obligations.
- Connected mailbox: if you connect a Google or Microsoft account to send email from Reqstaq, see Section 3.
- Sign-in providers: if you sign in with Google, Microsoft, or Apple, we receive the name and email address on that account and a provider-specific user ID so we can recognize you next time. Apple lets you hide your email address; if you do, we store the relay address Apple gives us and use it to reach you.
- Mobile app: if you use the Reqstaq iOS app and turn on notifications, we store the device token Apple issues so we can deliver them. The app does not collect your device's advertising identifier, contacts, location, or photos beyond the files you choose to attach.
- Billing contacts: for the person who manages the subscription — name, email, billing address, and payment details. Card numbers are handled by our payment processor, Stripe; we store the card brand, last four digits, and expiry only.
- Support: what you send us through the in-app support center or by email, including attachments.
Customer Data (candidates and contacts)
Customers choose what to enter. Typically this includes:
- Contact details, work history, resumes and other documents, skills, availability, and compensation or pay-rate information for candidates.
- Names, titles, and contact details of people at client companies.
- Job orders, submittals, interviews, placements, timesheets, and the fees and commissions that flow from them.
- Notes, tasks, and tracked email conversations (see Section 2).
Some Customer Data comes directly from candidates and contacts rather than from the Customer. We collect it on the Customer's behalf and handle it the same way:
- Job applications: what a person enters on a Customer's job application form — name, email, phone, resume, and anything else they choose to add.
- Email consent records: when a person agrees to receive email from a Customer, or unsubscribes, we record their email address, what they chose, when, and how — the application form or the email preferences page. When a person makes the choice themselves, we also keep their IP address and their browser's user agent as evidence, and — for agreements given on the application form — the form they responded to and the wording they were shown. When someone on the Customer's team unsubscribes a person, we record which team member did so. See Section 3.
We do not require Customers to collect sensitive categories of information, but they may choose to record things like work authorization status, EEO self-identification, or background-check outcomes. The Customer is responsible for having the right to collect and store that information.
We do not collect, scan, or analyze biometric identifiers (fingerprints, voiceprints, face geometry, and the like).
2 Email tracking
Customers can have Reqstaq keep a record of email between their team and their candidates and contacts. This section describes exactly what we keep, what we throw away, and what we do with it. It applies only when a Customer turns the feature on.
How mail reaches us
Email tracking works by journaling. The Customer's administrator configures their mail system (for example, Google Workspace or Microsoft 365) to send a copy of the team's mail to an address we operate. We do not sign into anyone's mailbox and we have no ongoing access to it. Everything below describes what happens to those copies.
What we store, and what we don't
- We store a message only when at least one of the Customer's team and at least one candidate or contact in the Customer's account is on it.
- Everything else — internal mail between colleagues, personal mail, anything with no matching record — is counted and discarded, unless one of the options below says otherwise. Its content never reaches our storage or our logs. We keep only a count.
- We delete the raw email as soon as processing finishes. The retained copy is the parsed message (headers, body, attachments) linked to the matching records.
- Blocked senders. A Customer can block an address or an entire domain. Mail from a blocked sender is never matched to a candidate or contact. When a blocked sender is the only person outside the team on a message, we count it and discard it.
- Bounces. When a message a team member sent can't be delivered, we record the address it failed to reach and a plain-language reason. If the bounce relates to a conversation we already store, we attach it there with no subject, body, or attachments.
- Out-of-office and "no longer with the company" replies are stored on the conversation, shown in grey, and don't count as contact with the person.
- Resume address. Mail a team member sends to the Customer's resume address is kept at their request, whoever it was originally from and even when it is entirely internal.
- Forwarding address. A message forwarded to the Customer's forwarding address is kept when a candidate or contact in the account is on it. We only accept forwards that the sending mail system reports as authenticated and that come from an address we already know as one of the team.
- Excluding a person. A Customer administrator can exclude any team member from tracking. Mail to or from an excluded user is discarded regardless of who else is on it.
Optional capture features
Each of these is off until a Customer administrator turns it on.
- Learn addresses from replies. A reply from an address we don't recognize on a conversation we already track is kept on that conversation, along with the addresses and display names of everyone on it we don't recognize (up to five per message). Each is offered to the team as a possible new address for the record. Nothing is added to a record until someone accepts it; dismissing a suggestion leaves the message where it is. Suggestions kept while this was on remain until the conversation they came from is deleted.
- Hold unmatched resumes. A resume emailed to the team that we can't match to a candidate is held for 14 days so the recipient can act on it. We hold the sender's address and name, the subject, and up to five resume files — never the message body. The hold is deleted after 14 days, or immediately if someone ignores it or blocks the sender. Creating a candidate from it removes the held message and the file becomes the candidate's own file.
- Watch words. When a Customer lists watch words or phrases, we check the subject and plain-text body of every email a candidate or contact sends the team against them. A match places a flag on the message, shows it on a Watch list visible to every team member who can see email, and emails the record's owner the phrase that matched. Checking starts from the day a phrase is added; we never go back over mail already received.
- AI features. When enabled, we send the subject and plain-text body of tracked messages to Anthropic, PBC to produce thread summaries, catch-up notes, reply drafts, and intent labels. We never send attachments, and we never send another Customer's mail. Anthropic processes this under its commercial API terms, which prohibit it from using the content to train its models. What comes back is stored in Reqstaq: a label lives on the message and is deleted with it; a catch-up note lives on the candidate or contact and is deleted with them; a thread summary lives on the conversation. Turning the feature off stops new processing; it does not remove what was already generated. Customers can delete generated content by deleting the underlying records.
What happens to stored email later
- Deleting a candidate or contact deletes the emails linked only to them, usually within a day. An email stays if another candidate or contact on the same conversation is still linked to it.
- Files saved from an email onto a record become ordinary record files and remain if the email is later deleted.
- Logging an email as a note saves a second copy of that excerpt as a note on the record. The copy follows the rules for notes: anyone who can see the record's notes can read it, it is indexed for search, and it stays until the note is deleted.
Notice to your staff
Most workplaces are required to tell staff that work email is being recorded, and some jurisdictions require consent. This is the Customer's obligation, not ours. Check what applies to you before enabling email tracking.
3 Sending email from Reqstaq
Account users can optionally connect their own Google Workspace or Microsoft 365 mailbox so that email composed in Reqstaq is sent from their real work address. This is a per-user choice; no one else at the firm can connect your mailbox for you.
How it works
- You connect through Google's or Microsoft's sign-in screen. We never see or store your password. Your provider gives us a token that lets us send mail on your behalf, and nothing else.
- Permissions we request. From Google:
gmail.send(send mail as you) and your basic account email address so we know which mailbox is connected. From Microsoft:Mail.Send,User.Read(your basic profile), andoffline_access(so you don't have to reconnect every hour). These are send-only permissions. They do not let us read your inbox, your sent folder, your contacts, or your calendar. - When we use the permission. Only when you compose a message or campaign in Reqstaq and choose to send it or schedule it to be sent later. We do not send anything on your behalf that you didn't write or approve.
- What we keep. A copy of each message you send — recipients, subject, body, attachments — and its delivery status, attached to the candidate or contact's record under the same rules as email tracking. Your provider also places the message in your own sent folder as usual, so your firm's normal mail retention applies too.
- What we don't do. We don't insert open-tracking pixels, rewrite links to track clicks, or add hidden recipients. We don't use the connection to import or read existing mail.
- Token storage. Tokens are encrypted at rest with a key separate from the database, and are used only to send mail as described here.
- Disconnecting. You can disconnect at any time under your Reqstaq profile settings, which deletes the token. You can also revoke Reqstaq's access from your Google Account permissions page or your Microsoft account's app permissions page; either way, sending stops immediately. Removing your Reqstaq user account also deletes the token. Messages already sent remain on the records they were sent from, under the Customer's control.
Campaigns and email consent
A campaign is one personalized email sent to each person in a group or list, from the sender's connected mailbox. Campaigns go only to people who have agreed to receive email from the Customer.
- Only the person can agree. A candidate or contact agrees by ticking an unticked box on the Customer's job application form, or by choosing to keep receiving emails on the email preferences page. The Customer's team cannot record consent for anyone.
- Checked at send time. Each campaign email is checked against the person's current choice at the moment it is sent. Anyone who hasn't agreed or has since unsubscribed is skipped.
- Unsubscribing. Every campaign email includes an unsubscribe link in its footer and
List-Unsubscribeheaders that let the person's email program unsubscribe them in one click. The Customer's team can also unsubscribe a person, and can undo only an unsubscribe their team made. Unsubscribing stops all email sent through Reqstaq to that address, including one-to-one email from a team member. - One consent per firm. Consent is recorded per Customer and per email address. Agreeing to hear from one staffing firm does not let any other Customer email that person.
Google API Services
Reqstaq's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we:
- use Google user data only to provide and improve the email-sending feature you connected it for;
- do not transfer it to third parties except as needed to provide that feature, to comply with law, or as part of a merger or acquisition with notice to you;
- do not use it for advertising of any kind;
- do not allow humans to read it except with your consent, for security or abuse investigation, to comply with law, or where the data has been aggregated and anonymized; and
- do not use it to develop, improve, or train generalized AI or machine-learning models.
Microsoft identity platform
Our use of Microsoft account data is governed by Microsoft's terms for applications on the Microsoft identity platform. Your organization's Microsoft 365 administrator may need to approve Reqstaq before you can connect, and may revoke access for the whole organization at any time.
4 How we use information
We use the information described above to:
- Run Reqstaq — create and secure accounts, store and display Customer Data, match tracked email to records, send mail and campaigns you compose, record email consent and unsubscribes, and run the features Customers enable.
- Search candidates by meaning — when improved candidate search is on for a Customer's account, we turn each candidate's work history (titles, skills, education, employers and job descriptions) and each keyword search into numeric embeddings, using a model that runs on our own servers. No third party receives this text, and names, contact details, notes and résumé files are never included. A candidate's embeddings are deleted with the candidate.
- Keep the service secure — detect and investigate suspicious sign-ins, enforce Customer-configured access restrictions, prevent abuse, and maintain audit trails.
- Support you — answer questions and resolve problems, which may require a member of our team to view Customer Data at your request.
- Bill you — process payments, send invoices, and manage subscriptions.
- Communicate about the service — send notices about outages, security, changes to features or terms, and other administrative messages. You can't opt out of these while you have an account.
- Market Reqstaq — send product news and offers to prospects and to account users who haven't opted out. Every marketing email has an unsubscribe link.
- Improve the product — analyze how the platform is used, in aggregate, to decide what to build and fix.
- Meet legal obligations — respond to lawful requests, enforce our agreements, and protect the rights and safety of Reqstaq, our Customers, and others.
What we don't do
- We do not sell personal information.
- We do not use Customer Data to advertise to anyone, or to build profiles for advertising.
- We do not use Customer Data to train AI models, and our AI vendor is contractually barred from doing so.
- We do not show ads inside Reqstaq.
- We do not access Customer Data except to provide the service, to support a Customer at their request, to investigate security or abuse, or as the law requires.
7 How long we keep information
| Information | Retention |
|---|---|
| Customer Data | For as long as the Customer keeps the record and maintains an active account. Records the Customer deletes are removed immediately from the application; associated emails within about a day. |
| Raw inbound email (journaled copies) | Deleted as soon as processing completes — typically within minutes. |
| Discarded email (no match) | Content is never stored. Only a count is kept. |
| Held unmatched resumes | 14 days, or sooner if actioned. |
| Learned-address suggestions | Until the conversation they came from is deleted. |
| AI-generated summaries, notes, and labels | Deleted with the message, record, or conversation they belong to. |
| Email consent and unsubscribe records | Until the Customer closes its account. These records are not deleted when the Customer deletes a candidate or contact, so that an unsubscribe continues to be honored if the person is added again. |
| Connected-mailbox tokens | Until you disconnect, revoke access, or your user account is removed. |
| After a Customer closes its account | All Customer Data is deleted within 30 days of termination. Customers can export their data before closing. |
| Backups | Encrypted backups roll off within 30 days of the data being deleted from the live system. |
| Sign-in and audit logs | 12 months, or longer if a Customer's agreement requires it. |
| Support tickets | For the life of the account plus 12 months. |
| Billing records | Seven years, for tax and accounting purposes. |
| Mobile device tokens | Until you sign out of the iOS app, delete your user account, or Apple reports the token invalid. |
| Prospect and marketing contacts | Until you unsubscribe or 24 months after your last interaction with us. |
| Website analytics | Indefinitely. |
We may keep information longer where the law requires it, where it is needed to resolve a dispute or enforce an agreement, or in de-identified form.
8 Security
- Encryption. All traffic to and from Reqstaq is encrypted in transit (TLS 1.2 or higher). Databases, file storage, and backups are encrypted at rest. Connected-mailbox tokens and other credentials are additionally encrypted at the application level.
- Tenant isolation. Each Customer's data is logically separated. Every query is scoped to the Customer's account, and file access requires an authenticated, account-scoped request.
- Access controls. Customers manage who can see what through roles and permissions, including a restricted "Secure" role that only account Owners can grant. Sign-in records and location-based restrictions are available to every Customer.
- Our own access. Reqstaq is run by a small team. Access to production systems is limited to those who need it to operate the service, is logged, and is protected by multi-factor authentication. We look at Customer Data only to support you at your request, to investigate a security or abuse issue, or as the law requires.
- Vendors. We assess the security practices of the providers listed in Section 5 and require them by contract to protect the data they handle.
- Incidents. If we learn of a breach affecting personal information, we will notify affected Customers without unreasonable delay, consistent with the Illinois Personal Information Protection Act and our agreements, and will provide the information Customers need to meet their own notification obligations.
No system is perfectly secure. We use commercially reasonable safeguards, but we cannot guarantee that information will never be accessed, disclosed, or destroyed without authorization.
9 Your rights and choices
If you are an account user
- Your profile. Update your name, phone, and preferences in your Reqstaq settings.
- Email tracking. Ask your firm's administrator to exclude you from tracking.
- Connected mailbox. Disconnect at any time in your settings, or revoke access from your Google or Microsoft account.
- Sign-in providers. Signing in with your email and password instead of a provider is always available; use "Forgot password" to set one.
- Notifications. Turn iOS notifications off in Settings → Notifications. Signing out of the app deletes the device token.
- Marketing. Click unsubscribe in any marketing email. You'll still receive service notices.
- Your user account. Delete it at any time from Profile → Delete my account, on the web or in the iOS app. This removes your profile, sign-in identities, device tokens, and API tokens. Records your firm holds about candidates and contacts belong to your firm and stay with it. If you own your firm's account and other members still belong to it, transfer ownership first; if you believe your firm won't act, contact us.
If you are a candidate or contact
The staffing firm that entered your information decides how it is used and is the right party to contact about access, correction, or deletion. If you contact us instead, we will forward your request to the firm and help them respond. We will not disclose which firm holds your data without their agreement, but we will make sure your request reaches them.
You control whether a staffing firm may send you campaign emails through Reqstaq. You can withdraw your agreement at any time using the unsubscribe link in any campaign email or your email program's unsubscribe button, and change your mind again from the same email preferences page. A firm can unsubscribe you on your behalf, but only you can agree to receive campaigns.
US state privacy rights
Depending on where you live, you may have the right to:
- know what personal information we hold about you and receive a copy;
- correct inaccurate information;
- delete your information;
- opt out of the sale or sharing of personal information and of targeted advertising (we don't sell; see Section 6 regarding advertising measurement); and
- not be discriminated against for exercising these rights.
To exercise them, email support@reqstaq.com with "Privacy request" in the subject line. We will verify your identity — usually by confirming control of the email address associated with your information — and respond within the time the applicable law allows (generally 45 days). If we deny a request, we will explain why and how to appeal. You may authorize an agent to act for you; we'll ask for proof of authorization.
Requests about Customer Data will be forwarded to the relevant Customer as described above.
Outside the United States
Reqstaq is hosted in the United States and is built for US staffing firms. If you access it from elsewhere, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country.
If the GDPR or UK GDPR applies to you: we act as a controller for visitor, prospect, and account-user information, and as a processor of Customer Data on our Customers' behalf. Our legal bases are performance of a contract (providing the service), legitimate interests (security, product improvement, B2B marketing), consent (where we ask for it), and legal obligation. You have the rights to access, rectify, erase, restrict, port, and object, and to lodge a complaint with your local supervisory authority. Customers who need a data processing agreement can request one at support@reqstaq.com.
10 Customers' responsibilities
Because Customers control what goes into Reqstaq, they are responsible for:
- having a lawful basis and any required consent to collect and store candidate and contact information;
- giving candidates and contacts any privacy notice the law requires;
- complying with the laws that apply to the email they send, including CAN-SPAM, for one-to-one email as well as campaigns — Reqstaq requires consent before sending a campaign, but does not decide whether an individual message is lawful;
- notifying their own staff that work email is being recorded before enabling email tracking, and obtaining consent where required;
- configuring roles, permissions, and retention appropriately for their business; and
- responding to rights requests from the people whose data they hold.
Our agreement with each Customer sets out these responsibilities and our commitments as their service provider in more detail.
11 Children
Reqstaq is a business tool. Account users must be at least 18. Our website and services are not directed at children under 13 and we do not knowingly collect information from them; if we learn we have, we will delete it. Customers may occasionally hold information about candidates aged 16 or 17 for employment purposes; that information is Customer Data under the Customer's control.
12 Changes to this policy
When we change this policy we will update the date at the top. For material changes, we will email Customer account owners and post an in-app notice at least 14 days before the change takes effect, unless a shorter period is required to comply with law or protect the service. Continued use after the effective date means you accept the updated policy.
13 Contact us
Chicago, Illinois 60614
Privacy questions and requests
support@reqstaq.com
General support
reqstaq.com/help