Last updated: October 4, 2026
This policy explains how the BCIT Computing Club ("we", "us", "our") collects, uses, and protects personal information through our hackathon applications and management platform. It is written to meet our obligations under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and follows its ten fair information principles.
The BCIT Computing Club is responsible for personal information under its control. Our privacy officer can be reached at [email protected] for any question, request, or complaint about this policy or our practices.
We collect only what we need to run the hackathon:
openid email profile scopes). We use these to identify you across the
platform. We never see your account password.
Certain assets are loaded via various CDN (Content Delivery Network) providers, so your browser shares its IP address with those providers when loading pages.
By signing in, submitting an application, or publishing a submission you consent to the uses described here. You may withdraw consent at any time by emailing us, subject to legal or contractual restrictions; for example, we may reserve the right to keep a record needed to answer a dispute about a past event.
Photography at our venues is expected, and registering for an event acknowledges that event photos may be published. If you appear in a photo in the public gallery and would like it removed, you may email a request to us.
We do not sell personal information. We share it only with hackathon organizers and developers, for the submissions they review; our service providers that operate the platform on our behalf (hosting, object storage, email delivery, edge network, CDN, analytics); our sign-in provider(s), within the scopes you approved. Providers may be subject to various laws in regard to information processed by us on their platforms.
Our servers, object storage, and email infrastructure are located in the United States. Personal information stored there is subject to United States law, including lawful demands from United States authorities. We rely on contractual and technical safeguards to keep that information protected.
We retain personal information for as long as necessary to fulfill the purposes outlined in this policy or to comply with applicable legal obligations. Application and attendee records are retained for up to 24 months after the event ends to allow us to manage follow-up inquiries, review past submissions, and address any administrative or other disputes. After this period, records are either securely destroyed or permanently anonymized for historical reporting. Account details and uploaded files remain subject to deletion upon request.
All traffic is encrypted in transit, sessions are signed cookies, private uploads are never publicly addressable, and staff access is limited to people who need it and recorded in an append-only audit log.
You may ask us what personal information we hold about you, request a copy, and ask us to correct anything inaccurate. We reserve the right to deny or limit access requests where permitted or required by law, such as where fulfilling the request would reveal personal information about a third party, compromise confidential information, or where the request is frivolous, vexatious, or otherwise exempt under PIPEDA. If we deny a request, we will explain the reason for the refusal in writing.
If you are not satisfied with our answer or response, you may complain to the Office of the Privacy Commissioner of Canada .
The platform is intended for hackathon participants and is not directed at children under 13. We do not knowingly collect their personal information; if you believe we have, email us and we will delete it.
If our practices change we will update this page and revise the date above. Material changes to how we use personal information will only apply with your consent.
Technical information: [email protected]
All other inquiries: [email protected]
At the BCIT Computing Club, we strongly believe that proactive collaboration is vital to cybersecurity. As AI-assisted development and rapid code generation becomes the norm, the risk of inadvertently introducing security vulnerabilities is higher than ever. By empowering white hats and security researchers through bug bounties and recognition, organizations foster a culture of continuous improvement, trust, and integrity. This ensures vulnerabilities are met with transparent resolution rather than exploitation. We stand firmly by these ethical defense practices as we wish to empower the next generation of developers to build safer, more resilient solutions.
If you believe you have discovered a potential security issue or vulnerability within any of our systems, we encourage responsible disclosure. Please reach out to our team through any of our official channels, including email or Discord, so we can work together to address it promptly.