Privacy Policy
Plain-language description of what data HackathonHost collects, who we share it with, and what you can do about it.
Last updated ·On this page
01.Who we are
HackathonHost is an event-management platform for hackathons and game jams. The product is delivered as a web app at app.hackathonhost.com and as an iOS companion app.
For privacy questions, email contact@hackathonhost.com — we read every message.
02.What we collect, and why
The data we hold falls into four buckets:
1. Host account data
When you sign up as a host you give us a display name, username, email, phone number, and optionally a company name. We use these to authenticate you, send you account notifications, and to display your name to your event participants. Your password is stored only as a bcrypt hash — we never see or store it in plaintext.
2. Event data
Anything you put into the platform to run your event — team rosters, jury accounts, scoring criteria, agenda items, sponsor info, sample event data — is stored against your host account. Other hosts on the platform never see it; only you and the people you invite (jury, organizers, mentors) can access it through their role-scoped logins.
3. Participant data
When teams or individuals register for an event through your public link, we collect the fields you configured (typically name, date of birth, government CIF, email, phone, role, prior experience, and any custom questions you added). This data belongs to the host who created the event — we process it on your behalf as a data processor, on the terms set out in our Data Processing Agreement. Participants can ask you, the host, to remove their data; you can do this from the Registrations and Teams pages of the admin dashboard, and they can also self-serve through links in their confirmation and notice emails.
4. Usage and support data
Standard request logs (IP, user-agent, timestamps) for security and rate-limiting, plus any messages and attachments you send through the in-app Support ticket system. We do not run third-party analytics, tracking pixels, advertising SDKs, or session-replay tools on the app or this site.
03.Who else touches your data
We use a small number of named vendors to run the service. Each one only sees the slice of data they need to do their job.
- Railway — hosting for the web app and database. EU / US infrastructure.
- Resend — outgoing transactional email (registration confirmations, results, broadcasts you send, contact form messages). Resend sees recipient addresses and message contents. Hosts who configure their own SMTP server instead route those same emails through their chosen provider rather than Resend.
- Sentry — error monitoring. When something breaks, Sentry receives the technical details of the error (stack trace, request path, timestamps) so we can fix it. It is not analytics or session-replay, but an error report can incidentally include limited personal data such as an email in a request.
- Google & Apple — identity providers for the optional “Continue with Google” and “Sign in with Apple” buttons. If you use them to sign in, the provider verifies your identity and shares your email and name with us. If you sign up with an email and password instead, neither is involved.
- Polar & RevenueCat — payment processors for event credits. Polar handles web checkout and RevenueCat handles in-app purchases on iOS; both process your card details directly, and we only receive a record of the purchase (amount, status, your account ID).
- Apple Push Notification Service — for iOS push notifications when you opt in.
We do not sell or rent personal data to anyone. We do not share it for advertising or profiling. If we ever need to disclose data in response to a lawful legal request, we'll narrow it as much as we can and notify affected users where the law allows.
04.The iOS app specifically
The HackathonHost iOS app is a wrapper around the same web app, with a few native integrations:
- Face ID / Touch ID — optional. If you enable biometric sign-in, your auth token is stored in the iOS Keychain and unlocked locally by your biometrics. The biometric data itself never leaves your device; Apple's Secure Enclave handles it.
- Camera — only accessed when you actively pick "Take photo" for an avatar, team logo, or certificate upload. We don't run the camera in the background.
- Push notifications — opt-in. Used to alert you to incoming registrations, scoring milestones, and scheduled reveals on events you participate in.
- Haptics, share sheet, network status — UX polish. No data leaves your device through these.
06.How long we keep things
We keep your account and event data for as long as your host account is active. When you delete your account from Settings → Security, we cascade-delete every event you own, all teams, all jury accounts, all participant registrations under those events, and the associated email and billing logs.
Automatic anonymization. Even while your account stays open, personal data belonging to participants and event staff (jury, mentors, guests) for events that ended more than 12 months ago is automatically anonymized. The aggregate records — team counts, scores, statistics — stay intact, but names, contact details, dates of birth, and ID numbers are stripped out, so we don't hold personal data long after an event is over.
If off-site database backups are enabled, a copy of data can persist in those backups for a short rolling window (typically up to two weeks) before the backup ages out and is removed. Where configured, those backups are encrypted at rest.
07.Your rights
You can access, export, correct, or delete your data at any time from inside the app:
- Access / export — Events > Export Bundle gives you an XLSX with every team, score, jury comment, and agenda item for an event.
- Correct — Settings → Profile for account fields; the relevant admin page for event content.
- Delete — Settings → Security → Delete account permanently removes everything you own.
For requests that can't be handled in-app (e.g. participants asking to be removed when their host hasn't responded), write to contact@hackathonhost.com — we'll act within 30 days.
08.Children
HackathonHost is not directed at children under 13. We don't knowingly collect personal data from anyone under 13. If a host's event allows minors to register, the host is responsible for collecting parental consent where their local law requires it.
09.Changes to this policy
We'll update this page if our practices change. The "Last updated" date at the bottom always reflects the current version. Material changes (new sub-processors, new data categories) will also be announced inside the app to active hosts.