SummerHacks
SummerHacksHacker Portal

SummerHacks Privacy Policy

Last updated August 6, 2026

This policy explains what the SummerHacks hacker portal (portal.summerhacks.ca) collects, how it's used, and who can see it. It covers the portal only - the sign-up flow before you're accepted runs on Devpost, a third-party platform with its own privacy practices.

SummerHacks (August 8–9, 2026, Stackt Market, Toronto) is organized by Open Skies Initiative. Questions about this policy can be directed to admin@openskiesinitiative.org.

1. Information we collect

We collect only what the portal needs to run sign-in, your profile, event check-in, and the Third Space Trek scavenger hunt.

Account & sign-in

  • Your email address, used to send a one-time sign-in code or link. We don't use passwords.

Profile

  • Full name, team name, school, program, and year of study, tracks you're interested in, and - if you choose to add one - a resume (either a pasted link or an uploaded PDF, stored privately).
  • A permanent, non-guessable ID tied to your account (derived from it, not personal information itself) that's embedded in your QR code and NFC tag for check-in.

RSVP

  • Whether you're attending, and whether you'll be arriving from downtown Toronto.

Event check-in

  • Which meals or registration checkpoints you've been checked into, when, and which staff member scanned you in.

Third Space Trek (optional)

  • If you join a team: your team's name and join code, who's on it, and any photos your team submits during the hunt. Photos are stripped of location metadata by your browser before upload where supported.

Demographic survey (optional, anonymous)

  • A short survey linked from the portal, hosted on Google Forms. It's anonymous by design and isn't connected to your portal account or email.

The Terms of Use mention dietary restrictions and accessibility needs collected "during registration." That collection happens on Devpost, at sign-up, before you have a portal account - the portal itself does not have fields for this and does not store it. If you have an accessibility or dietary need, please make sure it reaches us through registration or by emailing us directly.

2. How we use it
  • To run sign-in and keep your session secure.
  • To show your schedule, the venue map, and your own profile and check-in status.
  • To let volunteers confirm your identity at meals and registration by scanning your QR code or NFC tag.
  • To run the Third Space Trek, if you choose to take part.
  • To send event announcements to the portal and, where an announcement is marked for it, to our public Discord.

We do not use your data for advertising, and we do not sell it.

3. Who we share it with

We use a small number of service providers to run the portal. Each only receives what it needs to do its job:

  • Supabase — hosts our database, handles sign-in, sends sign-in emails, and stores uploaded files (resumes, Trek photos) in private storage.
  • Vercel — hosts the portal itself.
  • Google Forms — hosts the optional, anonymous demographic survey. If you take it, your responses go directly to Google Forms, not through the portal.
  • Discord — some announcements posted in the portal are also posted to our public Discord server. Those posts contain only the announcement text and event details, never your personal information.

Staff access

Volunteers and organizers can see hacker profiles as part of running the event - for example, to confirm your identity at check-in, or to look up your resume if you've uploaded one for our resume book. This access is limited to portal staff and is not the same as public visibility.

Sponsors

The portal itself does not currently export or share participant data with sponsors. If a sponsor resume book or booth-scan program is offered separately, it will be opt-in and described at the time.

4. Cookies and local storage

We use cookies and browser storage only to keep you signed in and remember small UI preferences. Nothing here is used for advertising or cross-site tracking, and we don't run analytics or error-tracking scripts on the portal.

  • Sign-in cookies, which keep you logged in and expire after a period of inactivity.
  • A dismissal flag for the demographic survey banner, cleared when you close your browser tab.
  • On staff devices only: which check-in event is currently selected, so volunteers don't have to reselect it between scans.
5. Data retention

Proposed retention periods below — pending organizer confirmation before this policy is finalized. The portal has no automatic deletion job today, so until this is confirmed and built, data is retained indefinitely.

  • Event data (profile, RSVP, check-in records, Trek submissions) — retained through the end of the year the event took place, then deleted, unless you ask us to delete it sooner.
  • Resumes — deleted within 90 days of the event unless you've separately opted into an ongoing resume book.
  • If your account is deleted, your profile, RSVP, and role records are removed immediately; any resume or Trek photo you uploaded is deleted separately by our team.
6. Your rights

You can review and update most of your profile information yourself from the portal at any time. For anything else - seeing a copy of your data, correcting it, or asking us to delete your account - email us and we'll handle it directly:

We don't yet have a self-serve export or delete-my-account button in the portal; requests made this way are handled manually by our team.

7. Security

Access to your data is restricted by row-level database policies, so hackers can only ever read and edit their own profile, and staff access is limited to what running the event requires. Resumes and Trek photos are stored in private, access-controlled storage - never publicly listed - and are only ever shared as short-lived links.

8. Changes to this policy

If we make a material change to this policy, we'll update the date at the top and ask you to review and accept it again the next time you sign in.

9. Contact