TALENTGO PRIVACY
Privacy Policy
This policy explains the information TalentGo handles for its current website and service marketplace, why it is used, and which information may be visible to other people.
1. Scope
This policy covers TalentGo accounts, Personal and Business onboarding, provider profiles and services, service requests and responses, contextual text chat, in-app notifications, security-phone verification and related website operations.
2. Information TalentGo handles
The information handled depends on the features you choose to use.
- Account information such as email address, authentication state and account identifiers.
- Profile, provider service, portfolio, experience, coverage, public contact and publication information you submit.
- Organisation, membership, role, Business Profile and bounded audit information needed to establish who acted and with what authority.
- Service requests, broad location and service choices, provider matches and responses, shortlist and selection state, text conversations, read state and notifications.
- Encrypted Malaysian security-phone information, verification state, masked phone display and security/anti-abuse results. Passwords and OTPs must not be placed in public content.
- Operational metadata such as timestamps, request outcomes, session/security information and bounded logs needed to run and protect the service.
3. Why TalentGo uses information
TalentGo uses information only for current product, authority, communication and security purposes.
- Create and secure accounts and provide the features you request.
- Resolve ownership, active organisation membership and action-specific permission at server and database boundaries.
- Publish eligible profiles and services, support discovery, match eligible providers to requests and maintain marketplace lifecycle state.
- Verify security phones, prevent abuse, diagnose failures and preserve bounded security and authority evidence.
- Deliver account messages and private in-app notifications connected to real marketplace activity.
4. Public and private information
TalentGo separates public discovery information from private account, security and marketplace information.
- Published provider and Business Profile fields are public only after the relevant publication rules pass.
- Draft profiles, account identifiers, organisation membership records and internal audit information are not public profile fields.
- Provider opportunities use a bounded view of an eligible request and do not expose a customer’s private email, security phone, user identifier or exact address.
- Contextual text conversations and notifications are private to authorised participants and recipients.
- A private security phone is separate from public contact choices and is never copied automatically into a public profile.
5. Cookies and browser storage
TalentGo uses essential cookies or similar browser storage for authenticated sessions, language and navigation context, email cooldown and security flows, and abuse prevention.
TalentGo does not currently maintain a separate Cookie Policy. This section is the current notice for the website’s essential cookie and browser-storage use.
- Authentication storage keeps you signed in and protects account routes.
- Language and navigation state help preserve the EN or MS journey you selected.
- Security providers may use browser signals needed to detect automated abuse and verify legitimate requests.
6. Service providers
TalentGo uses service providers for defined technical functions. Current architecture includes the following categories and platforms.
- Vercel for application hosting/runtime and Supabase for authentication, database and storage services.
- Cloudflare Turnstile for abuse challenges.
- Mocean for Malaysian security-phone verification and SMS delivery.
- Supabase authentication email flows and the configured email-delivery infrastructure used for TalentGo account messages.
7. Retention
Retention depends on the record type and lifecycle. Account, marketplace, security and authority records may remain while needed to operate and protect TalentGo, preserve marketplace state, and maintain bounded audit history.
TalentGo does not currently promise one fixed retention period for every category. Replaced or revoked security evidence and audit records may outlast the visible profile or current status when the security or authority contract requires that history.
8. Your choices
Current product controls determine what you publish and which contact information you choose to make public.
- Keep eligible profiles and services in draft, publish them, or unpublish them through the available controls.
- Choose public contact channels separately from your private security phone.
- Use available profile, service, Business Profile and request controls to correct or remove content where its lifecycle permits. Some security and audit records are intentionally not editable through normal product flows.
9. Data protection
TalentGo uses server-side authentication and authority checks, database row-level security, narrow privileged functions, encrypted security-phone storage and bounded public projections to protect information.
- Browser-supplied ownership, organisation role and verification claims are not treated as authority.
- Sensitive values such as passwords, OTPs, full security-phone numbers and server credentials must not be exposed in public or browser payloads.
- No internet service can promise absolute security. TalentGo’s controls reduce risk but do not make unauthorised access impossible.