Who We Are
security'26 is an internal club operations platform used to manage volunteers, attendance, meeting records, and WhatsApp reminders.
Information We Collect
- Account identifiers, such as username, email address, display name, and login session data.
- Volunteer and member records, such as name, phone number, gender, branch, participation details, attendance status, flags, and notes entered by authorized users.
- Meeting and attendance data, including meeting title, host, venue, time, attendance records, and action history.
- WhatsApp automation data, including selected recipients, approved template names, message status, delivery failures, and webhook events received from Meta.
- Security and diagnostic data, including IP address, request metadata, Turnstile verification result, server logs, and error logs.
How We Use Information
- To authenticate authorized users and protect platform access.
- To maintain volunteer records, attendance records, dashboards, flags, and meeting history.
- To send operational WhatsApp template messages selected by authorized users.
- To keep audit logs, prevent abuse, troubleshoot errors, and improve reliability.
- To comply with applicable obligations and respond to lawful requests.
How We Share Information
We do not sell personal information. Information may be processed by service providers used to run the platform, including Firebase, Cloudflare Turnstile, and Meta WhatsApp Cloud API. These providers process data only as needed to provide authentication, security, database, messaging, logging, or infrastructure services.
Data Retention
Records are retained while needed for club operations, auditability, dispute handling, security, and compliance. Administrators should delete or anonymize data when it is no longer needed.
Your Choices
Members may request access, correction, or deletion of their information by contacting the club administrator. Some information may be retained when needed for security, legal, or operational records.
Security
We use authenticated sessions, server-side secret handling, HTTPS hosting, bot checks, rate limits, and restricted API endpoints. No system is perfectly secure, so administrators must protect credentials, review access, and report suspected incidents promptly.
Contact
For privacy requests or questions, contact the security'26 administrator responsible for this deployment.