Privacy
The site. workable.w4dev.com is a static site hosted on Cloudflare Pages. Cloudflare keeps its own server logs for security and performance, under Cloudflare's privacy policy. It uses Google Analytics to understand traffic in aggregate — pages viewed and where visitors came from, which involves an analytics cookie shared with the other w4dev.com sites. We look at counts and trends, never at you, and no data is sold or shared. No other tracking runs.
The plugin. Workable Jobs for WordPress runs on your own WordPress site and stores its settings in your own database. It talks to three outside parties. First, your own Workable account: it reads your public jobs feed to build the job list, and once you add a Workable API token it reads each job's application form and creates a candidate on your account when someone applies — it never looks candidates up. Second, when you configure Cloudflare Turnstile or Google reCAPTCHA for spam protection, the job page loads that provider's script in the visitor's browser, and the plugin calls that provider's verify endpoint when the form is submitted. Third, the w4dev.com license and update server (https://w4dev.com/wp-json/wp-repo/v3/): on each check it receives your site's URL, WordPress version, PHP version, admin name and email, plus how many jobs are active, the applications mode, whether the sitemap and schema features are on, and which captcha provider (if any) is configured — used to check your license and deliver updates. Applications submitted on your site go straight to Workable and are not stored by the plugin. If you turn on the optional application log, it keeps the job, the result, the Workable candidate id and a shortened visitor IP for your last 50 attempts, visible to administrators only.
Contact. Questions: [email protected]