← 返回首页

PRIVACY

Privacy Policy · 隐私政策

我们使用必要的账号和活动记录提供登录、报名及集章服务。相机扫码在本机处理,活动地图不读取你的实时位置。你可在 App 中删除账号,或通过下方邮箱联系;完整政策见以下英文正文。

Effective and last updated: September 23, 2026

1. Who we are and what this policy covers

GT CSSA operates the GTCSSA campus activity service in Georgia, United States. This policy explains how we handle personal information through the GTCSSA mobile application and gtcssa.org, together called the “Service.” References to “we,” “us,” and “our” mean the GT CSSA team responsible for this Service.

“Personal information” means information that identifies you or can reasonably be connected to you. An “account” is your GTCSSA sign-in account. “Service providers” are the organizations that supply hosting, database, authentication, update delivery, maps, or other infrastructure described below.

For privacy questions or requests, contact hjh604@outlook.com.

2. Account and technical information

When you sign in, we receive and store your account identifier, name, email address, email verification status, and profile image when supplied by your sign-in provider. Google or Apple also supplies provider-specific account identifiers and authentication data, such as identity tokens. Apple may provide a private relay email address instead of your usual address. The information available depends on the provider and your choices.

We store necessary OAuth authorization credentials to maintain linked sign-in accounts and support authorization revocation. Stored access and refresh tokens are encrypted. Existing email-and-password accounts use password hashes; we do not store their passwords in plain text. We do not receive your Google or Apple account password.

The authentication service records sessions, session identifiers, creation and expiration times, and, when available, the IP address and browser or device information supplied in the request’s user-agent header. Hosting and infrastructure providers also process network requests, request times, URLs, response status, and operational or error logs to deliver and secure the Service. An IP address may indicate an approximate location; it is not a GPS reading.

If you contact us, we receive the email address, message, attachments, and other information you choose to provide. Please avoid sending passwords, authorization tokens, or another participant’s private information.

3. Activity records and staff access

We link activity registrations to your account and the relevant event. For stamp activities, we store the stations you have completed, collection times, and a random personal inspection code. We also store GT CSSA membership and assigned roles to determine access to staff tools.

Staff with inspection permission can submit your inspection code to view your name, registration status, and stamp progress for the associated event. Staff with member-management permission can view member names, email addresses, and roles and manage permitted role assignments. Tag-writing staff can obtain station tag content; that permission does not by itself grant access to participant records. Access depends on the permissions assigned to the staff account.

Published event descriptions, schedules, venue locations, and external registration links are public. We do not publish participants’ account information or personal stamp records as a public attendee list. Keep your personal inspection code private except when presenting it to authorized event staff.

4. How we use information

We use this information to authenticate users, maintain accounts and sessions, register participants, validate activity tags, record and display stamp progress, prevent duplicate stamps, check staff permissions, administer events, and process account deletion. Technical information helps us deliver compatible app updates, troubleshoot failures, and protect the Service. We use support correspondence to investigate and respond to your request.

The current Service does not run advertising, advertising tracking, marketing analytics, marketing email campaigns, SMS messaging, or payment processing. We do not sell personal information or share it for targeted advertising.

5. Necessary cookies and device storage

The website uses necessary authentication and security cookies to keep you signed in and complete secure sign-in redirects. These may last for the session or until their configured expiration. Blocking or clearing them can prevent sign-in or end your session.

The app uses the operating system’s secure storage through SecureStore for sign-in credentials and pending sign-in recovery information. It also keeps local interface preferences, temporary activity data, and downloaded app updates as needed to operate. Sign-out and successful account deletion clear the app’s user query cache and sign-in state. They do not necessarily erase unrelated downloaded update files or information independently retained by your operating system.

We do not use advertising cookies or web beacons in the current Service. Google, Apple, and other external services may use their own cookies or storage when you interact with them, under their own policies.

6. Camera, NFC, clipboard, and optional device features

The QR scanner requests camera access when you choose to use it. QR decoding takes place on the device. This feature does not record audio or upload camera images or video. A decoded inspection code is sent to our server when an authorized staff member requests the participant’s progress. A code can also be entered manually.

NFC tools read activity tags and allow authorized staff to write station tags. Tag identifiers such as a UID, technology information, raw records, and scan diagnostics are processed locally by these tools and are not automatically uploaded to our activity backend. To look up a station or collect a stamp, the app submits the station’s tag token with the applicable account session. Opening a tag’s website link also sends that token as part of the requested URL. A station tag contains no participant account or sign-in credential.

If you choose to copy NFC diagnostics, the app places those details in your device clipboard. If you then paste or share them, they are disclosed to the destination you choose.

The app includes native support for location, notifications, calendar, and media-library features, but the current Service does not use those capabilities to collect GPS location, register push-notification tokens, read your calendar, or access your photo library. Their inclusion does not grant permission or turn on collection. If a future feature needs such access, we will explain its purpose and request the relevant system permission when needed.

7. Maps and external activity links

Activity maps use the venue coordinates provided by event organizers. They do not request or display your live GPS location. The website’s management map requests map tiles from OpenStreetMap. Supported app screens may display Apple Maps or Google Maps, depending on platform and configuration. These providers receive network and map requests, which may include your IP address, technical device information, and the map area being viewed, even though we do not collect your live location.

Choosing directions opens an external map service. Some activities also link to an external booking or registration provider, such as SignUpGenius. We do not automatically pass your GTCSSA account details to those booking or map services. They receive ordinary connection information and anything you separately provide or authorize there. Registering inside GTCSSA does not complete an external reservation, and deleting your GTCSSA account does not cancel an external booking. Review the destination’s privacy policy before providing information.

8. App updates and diagnostics

We use Expo’s update service to download compatible app code and assets. The app requires a successful compatible update before its first normal use and checks for later updates. Update requests can include your IP address, operating-system platform, runtime version, current or embedded update identifiers, and an EAS-Client-ID. This client ID is a random identifier persisted for an app installation, not a hardware serial number.

The update system may also send startup or update-failure diagnostics, including information about a previous fatal startup error on Android. These identifiers and diagnostics support compatible update delivery and recovery.

9. Service providers and disclosures

We use Vercel to host the website and backend, Supabase to host the application database, Expo for app updates, and Google and Apple for sign-in and supported map features. Web maps use OpenStreetMap tile services. Providers process the information necessary for their respective functions; using one provider does not mean every provider receives all account or activity data. Support messages are also handled by the email service used for our contact address.

You can read the providers’ policies: Vercel, Supabase, Expo, Google, Apple, and OpenStreetMap Foundation. Those policies describe their own processing and do not replace our responsibility for the GTCSSA Service.

In addition to the staff access and service providers described above, we may disclose information when you direct us to do so, when legally required, or where reasonably necessary to investigate misuse, protect people and accounts, or address a security incident. We limit such disclosures to the information relevant to the purpose.

10. Retention and processing locations

We keep information only for as long as needed for the purposes described here, including your account, activity history, support requests, security, and applicable legal obligations. Records may be removed when no longer needed or when you successfully delete your account. Different categories of data and providers may have different retention schedules.

Deletion from the active application database does not immediately erase every provider log, backup, or support email. Residual copies may remain under provider backup and log-retention processes or where a limited retention obligation applies. Contact us if you need details about a particular category of information.

Our team operates in Georgia, United States. Service providers may process or store information elsewhere in the United States or in other countries. Privacy laws and protections can differ from those where you live.

11. Your choices and account deletion

You can manage device permissions in your system settings, clear website cookies, sign out, and choose whether to use optional scanners or external links. Withholding necessary account information or cookies may prevent account-based features from working.

To permanently delete your account, open “账号与设置” (Account and Settings) in the app and choose “删除我的账号” (Delete my account). Enter the current account’s email address to confirm. You may need to sign in again or, for an email-and-password account, supply your password. After deletion completes, the operational application database removes your account, linked authentication records, sessions, membership, registrations, stamps, and personal inspection codes. For linked Apple accounts, the deletion flow requests revocation of stored Apple authorization credentials. If that step fails, deletion may require a retry.

This is deletion of the GTCSSA account, not merely deactivation. It does not delete public events or station information, your Google or Apple account, or information held independently by external booking providers. Signing in again creates a new GTCSSA account without restoring the deleted personal activity history.

See the account deletion instructions. If you cannot access the app, or want to request access, correction, or deletion of your information, email hjh604@outlook.com. We may ask for information needed to verify that the account belongs to you. Do not email passwords or authorization tokens. We will explain any applicable limits to a request.

12. Security

We use reasonable safeguards, including HTTPS connections, password hashing, encryption of stored OAuth access and refresh tokens, secure device storage for app credentials, and server-side permission checks. No internet transmission or storage system can be guaranteed completely secure. Protect your sign-in accounts and personal inspection code, and contact us if you suspect unauthorized access.

13. Children

The Service is intended for campus activities and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided such information, please contact us so we can investigate and remove it as appropriate.

14. Changes and contact

We may update this policy as the Service changes. We will post the revised policy here and update the date above. For material changes, we will provide an appropriate notice through the Service. New uses requiring permission will be explained before that permission is requested.

Contact GT CSSA about this policy or your information at hjh604@outlook.com. General help is available on our support page.

Adapted from the FreePrivacyPolicy generator and revised to reflect this Service.