Account and consent data: email address, Google account identifier when Google sign-in is used, account role, selected data region, self-declared residence country, terms-acceptance and privacy-policy acknowledgment records, authentication attempts, session identifiers, and login results. Only when trusted edge verification is configured and available, we may also record a network-derived signup-country signal and the associated policy epoch. That signal may be unavailable and is not treated as nationality or proof of residence.
Candidate data: work history and evidence summaries, capabilities, supported outcomes, target work, location region, work arrangement, availability, compensation expectations, aspirations, preferences, constraints, and information you choose to submit during hiring requests and contact sharing.
Company data: company name, work-email domain, optional website, company region, representative contact details, the account user's confirmation that they may act for their own company, hiring briefs and expected outcomes, work location, compensation range, requirements, and information submitted through requests and contact sharing. When limited B2B preview or testing is explicitly enabled, this may also include seller offerings, private buyer sourcing briefs, commercial and delivery conditions, and evidence. Agency business verification does not request or collect client-mandate, client-consent, delegation, or per-role authority evidence.
Company billing data: selected plan, checkout and subscription identifiers, payment status, amount, currency, tax and invoice metadata, billing contact, and provider event history. Payment-card or bank-account details entered in Creem checkout are collected by Creem and are not stored by Veilink.
Generated and operational data: structured individual and hiring records and, where limited B2B testing is enabled, offering and sourcing records; embeddings and relevance signals; closed clarification questions and answers; summaries; drafts; workflow status; consent and contact-sharing history; connected AI metadata; request logs; device or browser metadata; errors; abuse-prevention signals; and monitoring records.