Privacy Policy

Last updated: September 20, 2026

1. Who we are

This GPOA (General Plan of Action) Schedule Tracker is an internal, invite-only tool operated by FIT iTamaraws Esports Club ("the Club," "we," "us") for its own officers and administrators. It is not a public product and is not available to the general public.

2. What we collect

We only collect the information needed to run the Club's internal event planning:

  • Account information: first name, last name, student number, and a password (stored as a salted hash, never in plain text). We do not collect or store your email address — a non-personal placeholder address is generated internally only to satisfy our authentication system's technical requirements and is never displayed or emailed.
  • Officer records (if you are added as an officer): position, committee, contact details, and Officer Information Sheet (OIS) details you or an admin provide (year level, program, address, birthdate, emergency contact).
  • Class schedule (COR) data: weekly class time blocks, used only to compute officer availability for events.
  • Event data: titles, dates, times, locations, descriptions, and links to documents you choose to attach (e.g. a Google Drive link).
  • Basic usage analytics: aggregated, cookie-free page-view analytics (see our Cookie Policy) used only to understand overall usage of this internal tool.

3. How we use it

Data is used exclusively to run the calendar and officer directory: scheduling events, checking officer availability against class schedules, and managing who has admin access. We do not sell, rent, or use your data for advertising, and we do not share it with third parties except the infrastructure providers described below.

4. Third-party processors

We use Vercel for hosting and privacy-friendly analytics, and Neon for database hosting. These providers process data on our behalf under their own security and privacy commitments. If you attach a repository link (e.g. Google Drive) to an event, opening or previewing it may load content directly from Google, subject to Google's own privacy policy.

5. Your rights

You may ask an administrator to review, correct, or delete your account or officer record at any time. Denied access requests have their student number retained on a blacklist solely to prevent repeat requests; you can request its removal from an administrator.

6. Data retention

We keep account and officer data for as long as you are (or may become) an active officer or admin, and delete it when an administrator removes your record. Session cookies expire automatically and are cleared when you sign out.

7. Security

Passwords are hashed, all traffic is served over HTTPS, and access to officer and event data requires an approved account. Only the site's founding administrator (super admin) can approve new admins.

8. Applicable law

This policy is intended to comply with the Philippine Data Privacy Act of 2012 and its Implementing Rules and Regulations. If members outside the Philippines use this tool, we also aim to follow general good-practice principles found in comparable frameworks (e.g. GDPR, CCPA), though this is an internal club tool rather than a commercial data controller.

9. Contact

Questions about this policy can be directed to a current Club administrator.