Legal
Privacy Policy
How First Shift collects, uses, and protects your information — and the rights you have over it.
Last updated: 23 September 2026
Introduction
First Shift is provided by Arbeo ("we", "us"), part of the Dazlab group, which operates the Arbeo hiring platform. Arbeo and First Shift are two brands of the same service, and this policy applies to both. It explains what personal information we handle, how we use it, who we share it with, and the rights you have.
It applies to firstshift.jobs, the First Shift application, employer careers pages and application forms, and the candidate portal (together, "the Service"). It sits alongside our Terms of Use and Data Processing Agreement.
We are based in Australia and comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). The Service is hosted in the United States, and we also follow the US state privacy laws that apply to us and to the employers we serve.
1. Quick summary
- First Shift is AI-assisted hiring software (an applicant tracking system) for employers, mainly US home care agencies. Our customers are the employers.
- If you applied for a job, the employer you applied to controls your application. Questions and requests about it go to them first (see §2).
- AI helps employers review applications, but a person at the employer makes every hiring decision.
- We don't sell personal information, and we don't use customer or candidate data to train AI models.
- We use a small number of service providers ("sub-processors"), listed in §7.
2. The two roles we play
- When the data is about our customers (the names, emails and logins of employer staff, billing details, and how the account uses the Service) we are the controller, and this policy governs it.
- When the data is about candidates (people who apply to an employer through the Service) the employer is the controller, and we are its processor. Under California law the employer is the "business" and we are its "service provider". We handle candidate data only to provide the Service to that employer and on its instructions, as set out in our DPA.
If you are a candidate and ask us about your application, we will direct you to the employer, and help them respond. You can also use the candidate portal yourself (see §10).
3. What we collect
About customers (employer staff)
- Account and contact details: name, work email, phone, agency name, role, and the agency's postal address.
- Subscription and billing details. Card payments are handled by Stripe; we don't store full card numbers.
- Usage and device data: log data, IP address, browser type, and the features used.
About candidates, on the employer's behalf
- Contact details and work history.
- Résumé and cover-letter files, and applications an employer forwards to us from Indeed.
- Answers to the employer's screening questions, including credential facts such as a state registry number, background-check date, CPR/first-aid expiry, driver's licence, insured vehicle, a work-authorization answer, and availability.
- The transcript of the AI intake chat, if you use it.
- AI-generated summaries, match scores and advisory flags (see §5).
- The employer's notes and status changes on your application.
What we don't collect. We do not ask for, or infer, protected characteristics such as age, race, sex, disability, national origin or religion. Tuberculosis (TB) test dates are collected only after a conditional job offer, by the employer, and are hidden from pre-offer views.
About website visitors
- Anything you submit in a form (name, email, agency, message), with the page that referred you and any campaign tags on the link you arrived through.
4. How we use information
- Provide the Service: publish jobs, receive and organise applications, run the intake chat, schedule interviews, and send emails on the employer's behalf.
- Run AI features the employer has enabled (see §5).
- Support, secure and improve the Service: respond to requests, prevent abuse, debug, and understand how employer staff use the product.
- Communicate with customers: service messages, and marketing you can opt out of at any time.
- Meet legal obligations, including keeping records employment law requires.
We use candidate data only for the employer's hiring process. We don't use it for our own marketing or sell it to anyone.
5. AI in hiring
The Service uses AI to read résumés, run the intake chat, summarise applications and score them against the job's requirements, flag possible gaps for a recruiter to check, and power recruiter search and an assistant. Candidates see a notice about this before the application form, at the start of the intake chat and on the careers page.
- AI output is advisory. It helps a recruiter, but a human at the employer makes every hiring decision.
- Protected characteristics are off-limits. The AI is instructed not to infer age, race, sex, disability, national origin or similar characteristics, and recruiter searches for protected characteristics are blocked.
- Employers can switch AI screening off for any job. Candidates who prefer not to use the AI chat can use the standard form or email the employer, and can ask the employer how their application will be reviewed.
- No training. We use Google (Gemini) and OpenAI through their business APIs, whose terms exclude using our customers' data to train their models. We don't use customer or candidate data to train AI models either.
- Connected AI tools. An employer can connect its own AI assistant (for example, Claude) to its account through our read-only connector. When it does, candidate data is disclosed to that assistant at the employer's direction and under the employer's own agreement with that provider.
6. Emails to candidates
Emails about an application (confirmation, interview scheduling, status updates) are part of the hiring process and are not marketing. Bulk or promotional emails an employer sends through the Service carry an unsubscribe link and the employer's postal address, and we honour unsubscribes.
7. Sub-processors
Each provider below is bound by contract to protect personal information and use it only to provide its service to us.
| Sub-processor | Purpose | Region |
|---|---|---|
| Google Cloud (Cloud Run, Cloud Storage, Gemini API) | Application hosting, document storage, AI features | United States |
| OpenAI (API) | AI features (intake chat, recruiter assistant) | United States |
| Neon | Database hosting (Postgres) | United States |
| Resend | Sending email, and receiving forwarded application emails | United States |
| Stripe | Subscription billing for customers | United States |
| PostHog | Product analytics about employer staff only, never candidate data | United States |
We will update this list, with notice, before adding or replacing a sub-processor.
10. How long we keep it
- Candidate data is kept for the retention period the employer chooses in its settings, from 1 to 10 years. The default is 4 years from the application date, which covers the US federal minimum of one year for hiring records and California's four-year rule for records of automated decisions. After that, applications and their files are deleted automatically.
- Candidate deletion requests. Signed in to the candidate portal, you can download your data and ask for your applications to be deleted. Deletion happens after a 30-day grace period, during which you can cancel it; after that it is permanent. An employer may be required by law to keep some records, and can tell you if so.
- Customer account data is kept while the account is active. After closure, we delete or de-identify it within a reasonable period, except what we must keep by law (for example, tax records).
- Backups age out on a rolling schedule after deletion.
11. Security
We use encryption in transit and at rest; keep candidate documents in a private storage bucket, available only through short-lived signed links; isolate each employer's data from every other employer's; rate-limit the Service; and limit staff access to those who need it. We don't currently hold a SOC 2 or similar certification. No system is perfectly secure, but we work to keep risks low and to respond quickly if something goes wrong (§14).
12. Your rights
You can ask us to access, correct or delete personal information we hold about you as a controller, and we will respond within a reasonable time after verifying your identity. We don't charge for access requests.
If you are a candidate, the employer controls your application. Contact them, or use the candidate portal; we will refer requests we receive to the employer and help them respond.
US state privacy rights. Depending on where you live (including California), you may have the right to know what personal information is collected about you, to access, correct or delete it, and to opt out of its sale or sharing. We don't sell or share it. We won't treat you differently for exercising these rights. An authorised agent can make a request for you with your written permission.
If you have a concern, contact us first (§15). If you're not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC), or to the privacy regulator where you live.
13. Where the Service is offered, and overseas processing
The Service is intended for employers in the United States and Australia. It is not directed at the EU, the EEA or the UK. Your information is stored and processed in the United States. Because we are an Australian company, our staff may access it from Australia. We take reasonable steps under APP 8 to make sure every provider that handles it protects it consistently with this policy.
14. Data breaches
If a breach affects an employer's data, we notify that employer without undue delay, and within 48 hours of confirming it, with what we know. We notify affected individuals and regulators as required by Australia's Notifiable Data Breaches scheme and applicable US state breach-notification laws, working with the employer where it is the controller.
15. Contact
Privacy questions, requests or complaints: privacy@firstshift.jobs. General support: hello@firstshift.jobs.
Arbeo, 1/680 Coleridge Road, Bateau Bay NSW 2261, Australia.
16. Children
The Service is not directed at children, and we do not knowingly collect personal information from anyone under 16.
17. Changes to this policy
We may update this policy from time to time. The current version is always on this page, with the date at the top. For material changes we will take reasonable steps to let customers know in advance.
Free tools