Privacy Policy
Last updated 19 September 2026
This document is specific to the Hack League platform at hack-league.startglobal.org. It supplements the START Global privacy policy. Where the two conflict for this platform, this document prevails.
1. About this policy
This policy covers the Hack League platform and the events, products, and services offered through or in connection with Hack League. Hack League is a START Global programme, so the general START Global privacy policy linked above also applies. This page explains how we use data specifically for Hack League.
START Global, Unterstrasse 6, 9000 St. Gallen, Switzerland, is the controller responsible for that data. You can reach us at info@startglobal.org or find our full details in the imprint. START chapters run their local events on our behalf and under our instructions.
We follow the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU General Data Protection Regulation (GDPR). An event or another START Global service may also have its own privacy notice. Section 5 is the specific notice for Hack League leaderboards.
2. What we collect
We collect the information you give us and the data created when you use Hack League:
- Account and sign-in details: your email address and the basic identity details returned by Google or GitHub if you use either to sign in. You can also use an email magic link or a passkey. We do not use passwords.
- Profile details: your display name, handle, home chapter, and any avatar, LinkedIn profile, or GitHub profile you add.
- Event details: your registration, application answers and uploads (such as a CV), RSVP and check-in status, skills, preferred role, experience, languages, and whether you are looking for a team.
- Teams and submissions: your event teams, join requests and invites, case choices, and the content and files your team submits.
- Jury and season records: jury allocations and decisions, results, placements, points, rankings, and event wins.
- Messages and preferences: in-app messages and broadcasts, your notification choices, and your browser's push endpoint, keys, and user-agent string if you enable push.
- Consent records: what you agreed to or withdrew, which version of the event terms applied, and when you made or withdrew that choice.
- Technical and audit data: IP addresses, request details, error reports, and a record of administrative actions, including who acted, when, and for which chapter. Audit records cannot be changed or deleted.
3. Why we use it
- To provide Hack League: this includes accounts, applications, teams, cases, submissions, judging, and results. We need this to fulfil our contract with you or take steps you ask for before entering one (Art. 6(1)(b) GDPR).
- To keep the platform safe and reliable: this includes preventing abuse, keeping audit records, and sending essential updates about deadlines, decisions, locks, and results. We rely on our legitimate interests (Art. 6(1)(f) GDPR). These are service messages, not marketing, and you cannot opt out of them.
- To run the leaderboards: we publish names and rankings because they are part of the competition. We rely on our contract with you and our legitimate interest in running a fair, comparable league (Art. 6(1)(b) and (f) GDPR). Section 5 explains this in more detail.
- When you choose to share more: we ask for consent before listing you in an event directory, sharing your profile with a case partner, or sending optional email or push notifications (Art. 6(1)(a) GDPR). We ask separately for each purpose. Any future event invitations or START Global newsletter would also need their own separate consents.
- To meet our legal obligations where required (Art. 6(1)(c) GDPR).
Consent is optional and separate from accepting the terms or this policy. We ask for each consent again for every event. You can change directory and notification choices in your account settings. To withdraw another consent, email us. Withdrawal only affects what we do from that point onward.
4. Who can see what
The event participant directory is opt-in. If you turn it on, other participants in that event can see your event profile; you can turn it off again at any time. Your teammates can see their team's submission, jurors can see submissions assigned to them, and organisers can see participants and submissions for their event. We share your profile or CV with a case partner only if you consent. You can withdraw that consent by emailing us.
5. Leaderboards
If you earn points at a league event, you currently appear on the leaderboard. There is no separate opt-out. If you do not want to be listed, contact us before the event so we can explain your options.
- Individual leaderboard: your display name, avatar (if set), home chapter, points, rank, number of scoring events, and event wins. We never show your email address, application answers, or submissions there.
- Audience: anyone signed in to Hack League, across every chapter. Avatar files use public links, so someone with the link can load the image without signing in. We will tell you before making a leaderboard public without sign-in.
- Retention: leaderboards remain available during their season and afterwards in the archive of past seasons. If you object to being named, contact us. We keep the underlying points to preserve the season results and will explain what removing your name means for your entry.
Supabase stores the leaderboard data and avatars. Cloudflare delivers the platform and currently caches leaderboard results for 20 seconds. Sections 7 and 8 explain these providers and international transfers.
6. Cookies
We use only the cookies needed to sign you in, keep your session active, and remember your active chapter. We do not use advertising cookies, third-party analytics, or tracking pixels on this platform.
The aftermovie on our home page loads nothing from YouTube until you press play: the still image you see beforehand is served by us. If you press play, YouTube sets its own storage in your browser. Section 7 explains what YouTube receives.
7. Who we share data with
We do not sell your data. START Global runs the platform and gives people access only to what they need for their role. Chapter teams can access data for their own chapter and events, but not other chapters. Jurors see only their assigned submissions. The Hack League board and league team can access the data needed to approve events and manage seasons, points, and rankings, but do not have full account or contact data by default. Platform administrators have wider access where needed for support, security, administration, or compliance.
Event and case partners receive only the information needed for their part of an event and only where we have a legal basis, such as your consent. Chapters and partners do not receive your full account or data from other events unless the law requires it, the platform cannot operate without it, or we have clearly told you otherwise.
We also use these service providers, which process data for us under contract:
- Supabase for the database, authentication, and file storage.
- Cloudflare for hosting and edge caching.
- Resend for service and notification emails.
- Sentry (EU region) for error monitoring and diagnostics.
- Google and GitHub if you choose either provider to sign in.
- YouTube (Google) if you press play on the aftermovie. It then receives your IP address, your browser and device details, and the address of the page you played it from. We embed it in no-cookie mode, which switches off ad personalisation, and it loads only on that press.
- Browser push services such as Google, Mozilla, Apple, or Microsoft if you enable push notifications.
8. International transfers
Some providers process data outside Switzerland and the EEA. We cover those transfers with an adequacy decision or safeguards such as the EU Standard Contractual Clauses. Contact us if you would like details of those safeguards.
9. How long we keep data
- Account and profile: while your account is active, and for seven days after you close it.
- Applications and registrations: for the life of the event. We keep rejected applications for six months after the decision unless you agreed to a longer period.
- Teams, cases, and submissions: for the event and its season.
- Jury records: until results are confirmed and any dispute period has passed.
- Points and rankings: for the season and its archive. Point records cannot be edited or deleted; corrections are recorded as new reversing entries.
- Consent records: long enough to show when consent was given or withdrawn, including any applicable limitation period.
- Notifications and preferences: we keep notification records while we need them to provide the service. We keep your preference records while your account is active so we can remember your choices. We remove push subscription details when you turn browser push off, revoke the subscription, or the subscription stops working.
- Audit records: as needed to protect the integrity of the platform. They cannot be changed or deleted.
- Technical and diagnostic data: for a short period under the retention settings of the providers in section 7.
We delete or anonymise personal data when we no longer need it, unless the law requires us to keep it. You can close your account yourself, from the danger zone at the bottom of your profile page. Sign-in stops working immediately, and seven days later we anonymise your account and profile data: your name, headline, photo, email address, and social links are removed, and your event profiles, notification preferences, push subscriptions, and notification history are deleted. The seven-day wait is there so a request made by mistake, or by somebody else with access to your account, can still be undone: email info@startglobal.org within that period and we will reverse it.
Competition records that cannot be removed stay in place without your name attached: points, rankings, and audit entries, along with consent records and the submissions and shared work that belong to your teams rather than to you alone. You cannot close your account while you are on a team in an event whose results are not yet confirmed, because doing so would strand your team; the profile page names the event and when it ends.
10. Your rights
Depending on the FADP and GDPR rules that apply, you can ask for access to your data or ask us to correct, delete, or restrict it. You may also object to processing, ask for a portable copy, or withdraw consent. Email info@startglobal.org to make a request.
You may also complain to a data protection authority: the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, or the authority in your country of residence in the EU.
11. Security
Database security rules limit access to the people and roles described above. Accounts are personal and must not be shared. We encrypt connections to the platform and store uploaded files in encrypted storage. Chapters and partners must report any data protection or security incident to START Global without delay.
12. Changes
We may update this policy. The date at the top shows the latest revision, and we will highlight material changes on the platform.
13. Contact
Questions about this policy or your data can be sent to info@startglobal.org.