Privacy
This page describes, in plain language, the information ShadowMatch collects and how it is used during the pilot. It is written by the ShadowMatch team and has not been reviewed by a lawyer.
What we collect
- Account information — your email address and authentication credentials handled by our authentication provider, plus the name and role on your account.
- Student profile information — age, school or current status, education level, graduation year, ZIP code, career interests, a short bio, an optional phone number, and an optional LinkedIn or portfolio link.
- Business profile information — organization name, industry or role, city and ZIP code, description, requirements, dress code, minimum age, hosting limits, website, phone, primary contact name and email, timezone, and verification information.
- Applications, requests and messages — the opportunity requested, why the student is interested, what they hope to learn, request status history, cancellation or decline notes, reviews, and messages exchanged in the app.
- Uploaded documents — an optional student resume, optional business verification document, and any pre-visit form or waiver a business attaches to an opportunity. Private documents are stored with access controls and delivered through limited access mechanisms to permitted users.
- Support and reports — information submitted through the contact form or the "Report an issue" flow, plus internal status/notes used to review those submissions.
- Platform fee records — when an eligible shadow experience is completed, we may store the request, amount, currency, fee status, and payment-provider identifiers needed to track the student platform fee. Card details are not collected by the app while online payments are disabled; if checkout is enabled, payment-card processing is handled by the payment provider rather than stored directly in our application database.
- Technical data — standard information your browser and service providers use to operate the site, session data required to keep you signed in, and operational logs from hosting, database, email, and payment infrastructure as applicable.
Why we use it
We use this information to create and secure accounts, display relevant opportunities, let businesses evaluate applications, coordinate accepted visits, send transactional messages, review businesses before public publishing, track platform fee status, and investigate support requests or reports.
What is shared with other participants
When a student applies to an opportunity, that business can see the information needed to evaluate the request, including the student's name, age, school or current status, career interests, bio, application answers, and optional resume/profile link. A student's email address and phone number are not returned to the business while the request is pending or after it is declined; the owning business can retrieve a contact method only after that request is accepted.
When a business accepts a request, the accepted student can receive that opportunity's exact address or meeting link, arrival and parking instructions, day-of contact, and any required pre-visit form. Those details are restricted from public browsing and unrelated users. Authorized administrators and service providers may process them when necessary to operate, secure, troubleshoot, or support the platform.
Service providers
We use third-party providers to run the product, including hosting, managed database and authentication, private file storage, transactional email, and eventually payment processing when online checkout is enabled. They may process information on our behalf to provide those services under their own service terms and security practices.
What we do not do
We do not sell personal information to advertisers. We do not run advertising in the product or build advertising profiles from shadowing activity.
Retention and your choices
You can edit most profile information from your account and remove supported uploads such as a resume or business document. Some request, safety, support, billing, and audit history may be retained when needed to operate the service, keep accurate records, resolve disputes, or protect the platform.
To request access to your information, a correction, or deletion of your account, use the contact form. We may need to confirm the request through the account email or other reasonable account information before acting on it.
Minors
During the pilot, self-service student accounts are limited to people aged 18 and over. Broader student access should not launch until an appropriate guardian-consent approach is designed and implemented.