01 Overview
Crimson Talent LLC ("Crimson Talent," "we," "us," or "our") is a Delaware-registered employment agency that operates a recruiting and staffing practice across the United States. We are the data controller for the personal information described in this Privacy Policy.
This Privacy Policy explains what personal information we collect from candidates, clients, and visitors to our website (crimsontalent.com), why we collect it, how we use and share it, and the rights you have over it. It applies to all individuals interacting with us, whether through our website, email, telephone, or in-person at any of our nine US offices.
We comply with applicable US federal law (including Title VII, the ADA, and the FCRA where applicable), state law (including California’s CCPA/CPRA, Virginia’s VCDPA, Colorado’s CPA, and Connecticut’s CTDPA), and SOC 2 Type II controls. California residents should also review our dedicated Your Privacy Choices page.
@crimsontalent.com.
02 Information we collect
2.1 — Information you give us directly
When you apply, submit your résumé, attend a consultation, or otherwise interact with us, we collect:
- Identifiers such as your full name, postal address, phone number, and email address;
- Professional and employment-related information including résumé/CV, work history, education, certifications, licenses, references, current and target compensation, work authorization status, and notice period;
- Information about your job preferences (industry, geography, remote/hybrid/on-site, seniority);
- Communications and notes we record during our discussions with you;
- Information you share voluntarily for diversity-equity-inclusion analytics, where you have explicitly opted in.
2.2 — Information we receive from third parties
With your consent (and only where lawful), we may receive information from:
- Professional networking platforms such as LinkedIn, where your profile is publicly available;
- References and previous employers you have authorized us to contact;
- Background-check vendors (FCRA-compliant) when a client’s offer is contingent on a check;
- Our clients, when they refer you to us or share search-specific feedback;
- Publicly available sources such as company websites, news articles, and regulatory filings.
2.3 — Information we collect automatically
When you visit our website, we collect certain technical information automatically through cookies and similar technologies: IP address, browser type and version, operating system, device identifiers, referring/exit pages, click-through patterns, and time on page. See Section 9 for details.
2.4 — Sensitive personal information
We avoid collecting sensitive personal information (as defined by US state laws) wherever possible. We will only request such information — for example, Social Security Number for FCRA-compliant background checks — with your explicit consent and only when strictly necessary for a specific search you are actively engaged in. We never request banking details, government-issued ID scans, or payment information.
03 How we use information
We process personal information for the following purposes:
- Search delivery: matching candidates to suitable open roles and presenting qualified candidates to clients;
- Communication: contacting candidates about opportunities, scheduling interviews, and providing updates on active engagements;
- Client engagement: fulfilling our contractual obligations to our retained-search and direct-hire clients;
- Quality & compliance: internal audits, ensuring fair-hiring practices, complying with EEO and state employment laws;
- Aggregate analytics: understanding placement trends, time-to-hire benchmarks, and salary ranges — always in de-identified form;
- Marketing: sending career-relevant communications and market updates (you can unsubscribe at any time);
- Security: preventing fraud and impersonation (see our team directory for verified contacts).
04 Sharing & disclosure
We do not sell personal information. We never have and we never will. We disclose personal information only as follows:
- To client employers with whom we are conducting a search, only after you have given us informed consent to be presented for a specific opportunity;
- To service providers bound by written confidentiality and data-processing agreements: applicant-tracking system (Greenhouse), email infrastructure (Google Workspace), background-check vendors (Checkr), payment processors (Stripe, for client billing only), and cloud hosting (AWS us-east-1, SOC 2-compliant);
- To professional advisors such as our attorneys, accountants, and auditors when required for the conduct of our business;
- To law enforcement when compelled by a valid subpoena, court order, or warrant under US law;
- In a corporate transaction — if Crimson Talent LLC is acquired or merged, we will provide notice before personal information is transferred and becomes subject to a different privacy policy.
05 Legal bases for processing
We process personal information on the following legal bases under US state privacy law:
- Consent — when you actively submit your information for a specific search or sign up for our market updates;
- Performance of a contract — to fulfill our engagement letter with the client and our placement obligations with you;
- Legitimate interest — for fraud prevention, security monitoring, and internal quality assurance, balanced against your rights and interests;
- Compliance with legal obligation — for tax reporting, EEO record-keeping, and regulatory audits.
06 Data retention
We retain candidate personal information for as long as is reasonably necessary to provide our services, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention windows:
| Data category | Retention period |
|---|---|
| Active candidate profile | Indefinitely while you remain available for searches |
| Inactive candidate (no engagement in 36 months) | Anonymized within 6 months unless you request earlier deletion |
| Placed candidate records | 7 years post-placement (EEO & client-audit compliance) |
| Communications & notes | 4 years from last interaction |
| Background-check data (FCRA) | 5 years from check completion, then destroyed |
| Website analytics | 26 months (Google Analytics default) |
You may request earlier deletion at any time using the contact details in Section 13, subject to any legal hold or contractual obligation requiring continued retention.
07 Security measures
We maintain administrative, technical, and physical safeguards designed to protect personal information against accidental loss, unauthorized access, alteration, or disclosure. Our program includes:
- SOC 2 Type II certification (audited annually by an AICPA-accredited firm);
- Encryption in transit (TLS 1.3) and at rest (AES-256);
- Access controls based on least-privilege principles, with MFA required for all employees;
- Annual security training for all team members, including phishing awareness;
- Incident response plan with notification within 72 hours of any confirmed breach affecting your personal data;
- Background-checked employees with confidentiality agreements covering candidate data.
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security but we work diligently to apply industry-standard protections.
08 Your rights
Depending on your state of residence, you have the right to:
- Access the personal information we hold about you;
- Correct inaccuracies in your information;
- Delete your information (subject to retention obligations above);
- Port your data to another service in machine-readable format;
- Opt out of marketing communications at any time;
- Withdraw consent for ongoing search engagements;
- Non-discrimination — we will not retaliate or refuse service for exercising any of these rights.
California residents have additional CCPA/CPRA rights; see our Your Privacy Choices page. To exercise any right, email privacy@crimsontalent.com. We will respond within 30 days (45 days for California requests).
09 Cookies & tracking
Our website uses the following categories of cookies:
- Strictly necessary — session and security cookies that cannot be turned off;
- Analytics — Google Analytics 4 for understanding aggregate site usage (IP anonymization enabled);
- Functional — remembers your preferences (e.g. cookie banner acknowledgment);
- Marketing — only used with your explicit opt-in via our cookie banner.
You can manage your preferences at any time through your browser settings or by clicking "Manage Preferences" in our cookie banner. We honor the Global Privacy Control (GPC) signal as an opt-out request.
10 Children’s privacy
Our services are intended exclusively for adults (18 years and older) seeking employment opportunities. We do not knowingly collect personal information from children under 18. If we learn we have collected information from a child, we will delete it promptly. Contact privacy@crimsontalent.com if you believe a minor has provided information to us.
11 International transfers
Crimson Talent is a US-based company and all primary data processing occurs within the United States. If you are located outside the US and submit information to us, you are consenting to the transfer of your data to the US for processing. We rely on appropriate safeguards including Standard Contractual Clauses where required by the laws of your country of residence (e.g. EU/UK GDPR).
12 Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Effective" date at the top of this page;
- Notify candidates with an active engagement via email at least 30 days before the change takes effect;
- Post a prominent notice on our website for at least 30 days;
- Maintain prior versions on request for transparency.
13 Contact us
For any questions about this Privacy Policy or to exercise your data-protection rights, please contact our Privacy team:
Crimson Talent LLC · Attn: Privacy Officer
1345 Avenue of the Americas, 33rd Floor
New York, NY 10105
Email: privacy@crimsontalent.com
Toll-free: +1 (888) 472-7466
Response time: 30 days (45 days for California CCPA/CPRA requests)
If you believe we have not adequately addressed your concern, you may also contact your state Attorney General’s office or, for California residents, the California Privacy Protection Agency at cppa.ca.gov.