Privacy Policy

Last updated: October 4, 2026

This policy explains how the BCIT Computing Club ("we", "us", "our") collects, uses, and protects personal information through our hackathon applications and management platform. It is written to meet our obligations under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and follows its ten fair information principles.

1. Accountability

The BCIT Computing Club is responsible for personal information under its control. Our privacy officer can be reached at [email protected] for any question, request, or complaint about this policy or our practices.

2. What we collect and why

We collect only what we need to run the hackathon:

  • Account information. Signing in (as currently handled via a 3rd party upstream provider) shares your name, email address, profile picture, and a stable account identifier with us (the openid email profile scopes). We use these to identify you across the platform. We never see your account password.
  • Application, RSVP, and Survey information. Answers you type into a hackathon application, rsvp, submission, or survey form, and any files you upload, so we can review your application and its associated details, ensure we are able to cater to any dietary or accessibility needs, and gather feedback.
  • Submission information. Details, links, and images you may publish for a project submission, so judges and attendees can review this info.
  • Event photographs. Photos taken at our events may show identifiable attendees and may be published in a public event gallery. See section 4.
  • Communication records. Emails you send us, and delivery records for emails we send you (recipient address, subject, delivery status).
  • Technical information. Signed cookies that keep you signed in, cookies used by our CTF lab features, and a browser-stored theme preference. Our upstream providers may also process and store (for a short period) standard request logs to operate and secure the services provided. Some of our upstream providers process request data (such as user agent headers, operating system, referrers, and page load metrics) to provide privacy friendly, aggregated analytics without using client side cookies or tracking individual visitors across sites.

Certain assets are loaded via various CDN (Content Delivery Network) providers, so your browser shares its IP address with those providers when loading pages.

3. Consent

By signing in, submitting an application, or publishing a submission you consent to the uses described here. You may withdraw consent at any time by emailing us, subject to legal or contractual restrictions; for example, we may reserve the right to keep a record needed to answer a dispute about a past event.

4. Event photographs

Photography at our venues is expected, and registering for an event acknowledges that event photos may be published. If you appear in a photo in the public gallery and would like it removed, you may email a request to us.

5. Who we share it with

We do not sell personal information. We share it only with hackathon organizers and developers, for the submissions they review; our service providers that operate the platform on our behalf (hosting, object storage, email delivery, edge network, CDN, analytics); our sign-in provider(s), within the scopes you approved. Providers may be subject to various laws in regard to information processed by us on their platforms.

6. Storage outside Canada

Our servers, object storage, and email infrastructure are located in the United States. Personal information stored there is subject to United States law, including lawful demands from United States authorities. We rely on contractual and technical safeguards to keep that information protected.

7. How long we keep your information

We retain personal information for as long as necessary to fulfill the purposes outlined in this policy or to comply with applicable legal obligations. Application and attendee records are retained for up to 24 months after the event ends to allow us to manage follow-up inquiries, review past submissions, and address any administrative or other disputes. After this period, records are either securely destroyed or permanently anonymized for historical reporting. Account details and uploaded files remain subject to deletion upon request.

8. Safeguards

All traffic is encrypted in transit, sessions are signed cookies, private uploads are never publicly addressable, and staff access is limited to people who need it and recorded in an append-only audit log.

9. Your rights

You may ask us what personal information we hold about you, request a copy, and ask us to correct anything inaccurate. We reserve the right to deny or limit access requests where permitted or required by law, such as where fulfilling the request would reveal personal information about a third party, compromise confidential information, or where the request is frivolous, vexatious, or otherwise exempt under PIPEDA. If we deny a request, we will explain the reason for the refusal in writing.

If you are not satisfied with our answer or response, you may complain to the Office of the Privacy Commissioner of Canada .

10. Children

The platform is intended for hackathon participants and is not directed at children under 13. We do not knowingly collect their personal information; if you believe we have, email us and we will delete it.

11. Changes to this policy

If our practices change we will update this page and revise the date above. Material changes to how we use personal information will only apply with your consent.

12. Contact

Technical information: [email protected]

All other inquiries: [email protected]

13. Statement on Ethical Hacking & Responsible Disclosure

At the BCIT Computing Club, we strongly believe that proactive collaboration is vital to cybersecurity. As AI-assisted development and rapid code generation becomes the norm, the risk of inadvertently introducing security vulnerabilities is higher than ever. By empowering white hats and security researchers through bug bounties and recognition, organizations foster a culture of continuous improvement, trust, and integrity. This ensures vulnerabilities are met with transparent resolution rather than exploitation. We stand firmly by these ethical defense practices as we wish to empower the next generation of developers to build safer, more resilient solutions.

If you believe you have discovered a potential security issue or vulnerability within any of our systems, we encourage responsible disclosure. Please reach out to our team through any of our official channels, including email or Discord, so we can work together to address it promptly.