Privacy Policy
Last updated July 8, 2026
Your Organization("we") is a student organization; where it is affiliated with a school, it operates independently of that institution. This policy explains what personal data our member portal collects, why, and the choices you have. Contact for anything privacy-related: contact@example.com.
What we collect
| Category | Examples |
|---|---|
| Account data | Name, email address, role (member/exec/super admin), account status, and how you signed in (email + password, or Google). |
| Profile data | Major, graduation year, career interest, company, LinkedIn, phone (if provided), committee. |
| Activity data | Attendance check-ins, points ledger, standing, module progress, assignment submissions, quiz attempts and scores. |
| Communications | Inbox messages and replies, notifications, announcement read status, and your email notification preferences. |
| Files | Documents uploaded by execs or submitted by you (e.g., stock pitch memos, models), plus file metadata. |
| Calendar data | Club events you can see, and personal events you create (visible only to you). |
| Security data | Authentication and session information used to keep your account signed in securely. We never see or store your password — it is handled by our authentication provider. |
| Technical data | Standard server logs, security audit records of sensitive admin actions, rate-limit counters, and error/diagnostic reports used to fix bugs. |
| Cookies | Essential authentication/session cookies only — see the Cookie Notice. |
Why we collect it
- Operating the club: attendance, points and standing, learning modules, grading, events, recruiting.
- Communication between members and the officer team, including email notifications you can turn on or off.
- Security: protecting accounts, managing secure sessions, and investigating misuse.
Accounts & sign-in
You can sign in with an email and password or with Google. New accounts are not active automatically — they are created in a pending state, and an officer reviews and approves each request before the portal opens. Accounts can also be marked active, alumni (limited read-only access), suspended, or declined. We never see or store your password; if you sign in with Google, we receive only your name and email from Google to identify your account.
Email communications
The portal can send you email: announcements posted by the officer team and an optional weekly digest of unread messages and recently graded work. You can turn these off at any time from your account settings or the unsubscribe link in any such email. Essential account emails — password resets and security notices — are required to use the portal and cannot be turned off. Email is delivered through our email provider (listed below).
Our commitments
- We do not sell personal data. Ever.
- No ads and no behavioral ad tracking.
- Member profiles are not publicly indexed — the portal is login-only and hidden from search engines.
- Messages and files are not shared outside the organization except with the service providers below or where required for legal or security reasons.
- Officers can see operational data (attendance, submissions, grades, points) only for organization purposes; private messages are visible only to their participants.
- Passwords are handled by our authentication provider (Supabase Auth); we never store raw passwords.
- Sensitive admin actions (role changes, grading, point adjustments, file deletions) are logged.
Service providers
The portal runs on third-party infrastructure that processes data on our behalf, each under its own security and privacy terms. We do not grant any of them rights to use member data for their own purposes:
- Supabase — database, authentication, and file storage.
- Netlify — web hosting and delivery.
- Google — only if you choose to sign in with Google; it verifies your identity and returns your name and email.
- Resend — delivers the announcement and weekly-digest emails described above.
- Sentry — collects error and diagnostic reports so we can find and fix bugs.
Retention
| Record | Kept for |
|---|---|
| Rejected/withdrawn applications | 6 months after the recruiting cycle ends, then deleted. |
| Attendance records | 1 year, then deleted or anonymized. |
| Assignment submissions & quiz attempts | 1 year after the semester ends. |
| Messages | Until your account is deleted. |
| Account & profile data | Until you leave the organization, plus up to 90 days for wind-down. |
| Alumni profiles | Basic name/role retained for club history; personal fields scrubbed on request. |
| Error/diagnostic logs | Kept short-term (about 90 days) by our monitoring provider, then discarded. |
Published retention windows are enforced by scheduled deletion jobs. Verified privacy requests can trigger earlier export, correction, or erasure.
Your rights
You can request access to, correction of, export of, or deletion of your personal data at any time by emailing contact@example.com. We aim to respond within 30 days. If you leave the organization, you can ask for your profile to be scrubbed beyond the basic membership record.
Changes
If this policy changes materially, we will update the date above and ask members to re-acknowledge it at their next sign-in.