
Privacy across the Product Foundry marketplace.
Product Foundry separates public previews from private company, talent, billing, contract, verification, AI-review, and administrator records. Access is limited by role, ownership, consent, and workflow stage.
Last updated: August 12, 2026
Draft notice
These plain-language beta terms describe the current Product Foundry workflow. They remain subject to applicable agreements and should be reviewed by qualified Canadian legal counsel before being treated as final legal terms.
Information we may collect
- • Account, identity, contact, company, team, and authentication information.
- • Company profiles, business needs, briefs, uploaded source files, structured fields, budgets, timelines, and workflow decisions.
- • Talent profiles, resumes, experience, skills, proof points, portfolio links, availability, compensation expectations, preferences, credentials, and verification submissions.
- • Shortlists, introductions, messages, interviews, contracts, payments, milestones, notifications, feedback, outcomes, support requests, and audit history.
- • Technical information such as session, security, device, log, rate-limit, cookie, and diagnostic events.
Why information is used
- • To create and secure accounts, verify access, and enforce company, talent, and administrator permissions.
- • To structure and version briefs, assess readiness, support matching, prepare approved shortlists, coordinate consent-based introductions, and show journey status.
- • To support interviews, contracts, Stripe payments, Talent Pro, notifications, engagement tracking, feedback, calibration review, support, and fraud or abuse prevention.
- • To produce privacy-safe internal operational reporting and improve Product Foundry services.
AI-assisted processing
FoundryAI may process limited, task-relevant information to structure briefs, parse resumes, assess readiness, prepare explanations, answer authorized Ask Foundry questions, or support other disclosed workflows. Product Foundry limits context where practical, treats retrieved content as untrusted, records material AI activity, and keeps human review in sensitive decisions. AI providers may process submitted data as service providers under their applicable terms and configuration.
Semantic matching consent
Semantic matching uses minimized role information and, for talent, only eligible profile information covered by explicit consent. Private verification evidence is excluded. Talent can grant or withdraw semantic-processing consent through the supported workflow. Withdrawal prevents future generation or persistence where technically possible, but cannot recall a provider request that already began.
Public previews and contact release
- • Public talent cards are anonymized and omit private contact, resume, credential, verification, and administrator information.
- • Public opportunity previews omit confidential company information and are limited to approved, shareable details.
- • Contact information is released only after a valid approved shortlist-based request, talent consent, required administrator approval, and resolution of blocking conditions.
- • Private decline reasons, internal notes, hidden weights, raw prompts, and sensitive verification information are not shared across parties by default.
Service providers and disclosures
Product Foundry may use service providers for hosting, database and authentication, AI, email, security, file handling, analytics, and payment processing. Information is shared only as reasonably needed for the disclosed service, to comply with law, protect rights or safety, investigate abuse, or complete an authorized transaction. Product Foundry does not promise that every provider stores data only in Canada.
Retention, accuracy, and user choices
- • Information is retained only as long as reasonably required for the identified purpose, legal obligations, dispute handling, security, auditability, or active marketplace workflows.
- • Users should keep their information accurate and may use available profile or workspace controls to update it.
- • Users may request access, correction, or deletion through the Contact page, subject to legal exceptions, transaction records, security needs, and records that must be preserved.
- • Withdrawing optional consent may limit AI-assisted or matching functionality but does not erase completed audit, contract, payment, or legal records that Product Foundry must retain.
Security and access control
Product Foundry uses server-side authorization, Supabase row-level security where applicable, private storage patterns, role-scoped administrator permissions, signed payment webhooks, input validation, rate limits, and audit records. No system is perfectly secure, and users should protect credentials and report suspected misuse promptly.
Foundry Insights
Foundry Insights is an internal administrator reporting surface built from aggregated operational records. It suppresses groups below the configured privacy threshold and does not return individual identifiers, emails, notes, or individual budget values. Marketplace-wide personal analytics are not exposed to company or talent users through this feature.
Questions and complaints
Privacy questions, access or correction requests, consent concerns, and complaints can be submitted through the Product Foundry Contact page. Please provide enough information to identify the relevant account or workflow without sending passwords, payment-card details, or unnecessary sensitive information.