Privacy Policy
Effective and last updated October 1, 2026
This policy explains what personal data HackHoster collects when you use hackhoster.org, why we collect it, who can see it, how long we keep it, and the choices you have. We collect only what we need to run hackathons on the platform.
The short version
- We collect your account details, your date of birth (to check your age), the profile you write, and what you do on HackHoster, like joining hackathons and submitting projects.
- When you register for a hackathon, its organizer receives your name, handle, email address, team, and submission.
- Your email address and date of birth are never public. Projects become public only after a hackathon announces its winners.
- We don’t sell personal data, don’t show ads, and don’t use advertising or analytics trackers.
- You can edit your profile, change email settings, and ask us to delete your account at any time.
- Users must be 13 or older. Teens get extra protections by default.
This summary helps you read the document; the full text below is what applies.
1. Who we are
HackHoster is operated by its owner, an individual operating HackHoster as a sole proprietorship, in the United States. We are responsible for (the “controller” of) the personal data described here. Contact us about privacy at legal@hackhoster.org.
This policy covers hackhoster.org and the emails we send. It doesn’t cover how hackathon organizers use the data they receive from us (they have their own practices, see section 6) or other websites you reach through links on HackHoster.
2. What we collect
Data you give us
- Account: your email address and password (if you sign up with email; the password is handled by Google Firebase Authentication and we never see it), and whether you signed up mainly to build or to organize.
- Age check: your date of birth and, if you are 13 to 17, your confirmation that a parent or guardian gave permission. We use these to enforce our age rules. They are never shown publicly.
- Profile: display name, handle, avatar, bio, country, links (website, LinkedIn, X), skills, and interests.
- Hackathon activity: registrations, answers to an organizer’s registration questions, teams, invitations and join requests, project submissions (descriptions, code links, images, video, demo links), discussion threads and replies, likes, and reports you file.
- Award applications: the project name and description, video link, code and demo links, screenshots, your answers to the application questions, the teammates you list, and the tools you used.
- Hosts: the “Hosted by” name and public contact email for each hackathon you create, the co-hosts you add, plus hackathon details, rules, prizes, judges, sponsors, and announcements you publish.
- Messages to us: what you write when you email support or legal, and our replies.
Data from sign-in providers
If you sign in with Google or GitHub, we receive your email address (with GitHub, this can be an address you keep private there), whether it is verified, and your profile photo URL. With GitHub we also store your GitHub user ID and username, so we can show a “GitHub connected” badge. We ask only for basic profile and email access. We never get access to your repositories, Gmail, Drive, or contacts. We use data from Google and GitHub only to sign you in and as this policy describes, we don’t sell it or use it for advertising, and we handle Google user data in line with the Google API Services User Data Policy.
Data collected automatically
- Technical and security data: IP address, browser and device type, pages requested, and timestamps, recorded in our hosting provider’s request and error logs and by Firebase Authentication to protect sign-in. We use IP addresses for security and rate limiting, not to track you.
- Cookies and local storage that keep you signed in (section 7).
- Email delivery records: which service emails we sent you and whether they were delivered.
We don’t use analytics or advertising trackers, and we don’t collect precise location, contacts, biometric data, or payment information. Please don’t put sensitive personal information (such as health information or government ID numbers) in your profile, projects, or posts.
3. How we use it
- to create and secure your account, check your age, and keep you signed in;
- to run hackathons: registration, teams, submissions, judging tools for organizers, winner announcements, and public galleries;
- to show your portfolio and compute reputation, levels, and wins from platform records;
- to send the emails described in section 8;
- to keep HackHoster safe: rate limits, filtering blocked words from handles and posts, reviewing reports, moderation, and preventing fraud and abuse;
- to fix bugs and keep the service running;
- to comply with the law and enforce our Terms.
We don’t use your data for advertising, sell it, or use it to build profiles for anyone else. We don’t use your content to train AI models.
4. What is public
| Public | Private |
|---|---|
| Handle, display name, avatar, bio, country (adults only), links, skills, interests, level, reputation, wins, GitHub username if connected, and public projects | Email address, date of birth, sign-in methods, email settings, reports you file, and registration answers |
| Projects after the hackathon announces winners, including the names of the team members | Projects before winners are announced (visible only to the team and the organizer) |
| A Project of the Month winning application, with its team, and the badge on winners’ profiles | All other award applications (visible only to you, the teammates you list, and the HackHoster team) |
| Discussion threads and replies on a hackathon, shown with your handle | Join requests and invitations (visible to the team captain and the person invited) |
| Your name in a hackathon’s participant list (you can turn this off) | Registrations if you turn off “Show me in hackathon participant lists” (you are counted, not listed) |
Public information can be seen by anyone, including search engines, and others may copy it. Think before you post. HackHoster has no private messaging between users.
6. Sharing with organizers
When you register for a hackathon, we share your name, handle, and email address with that hackathon’s organizer, along with your country (adults only), level, team, registration date, whether you submitted, your answers to their registration questions, and your submitted project. The registration dialog tells you this, and you agree to it before you register. Organizers can download this list.
Organizers use this data to run their hackathon: to contact participants, judge projects, and deliver prizes. They must follow our Terms, which forbid selling it or using it for unrelated purposes, but they are independent of HackHoster and responsible for their own handling of the data. To ask an organizer about your data, use the contact email on their hackathon page. Unregistering stops future sharing but can’t recall data an organizer already downloaded.
8. Emails
- Service emails you can’t turn off while you have an account: email verification and password reset, team invitations, submission confirmations, award application confirmations, winner notices (for hackathons and Project of the Month), and security or moderation notices.
- Optional emails you can turn off: announcements from organizers of hackathons you joined, registration confirmations, winner round-ups, and Project of the Month results. Every optional email has a one-click unsubscribe link, and you can change them any time in Settings → Notifications.
- We don’t send marketing email, and we never send email on behalf of advertisers.
9. How long we keep data
| Data | Kept for |
|---|---|
| Account, profile, and age check | Until you delete your account (we delete it within 30 days of your request) |
| Projects, posts, registrations, and award applications | Until you delete them or your account; team projects stay with your teammates, with you removed |
| Database backups | 7 days, then overwritten |
| Email delivery records | 30 days (in our database and at our email provider) |
| Request, error, and security logs, including IP addresses | About 30 days; our sign-in provider keeps IP addresses for a few weeks |
| Rate-limit counters | Up to 1 day |
| Reports and moderation records | As long as needed to keep the platform safe, handle appeals, and meet legal obligations; kept after account deletion |
| Under-13 sign-up attempts | Not kept: the account and its data are deleted immediately |
We may keep data longer when the law requires it or to resolve a dispute that is under way.
10. Deleting your account
Request deletion from Settings → Account → Delete my account, or email support@hackhoster.org from the address on your account. We delete your account within 30 days. That removes your sign-in, profile, private data (email address, date of birth, settings), reputation, co-host roles, uploads, and solo projects. Team projects you contributed to stay for your teammates with you removed, and your discussion posts stay with the author shown as “Deleted user”. We keep reports and moderation records so we can keep the platform safe. Copies in our database backups disappear within 7 days after that, and our sign-in provider (Google Firebase) removes the deleted sign-in record from its backups within 180 days. Data that organizers already downloaded is under their control.
11. Your rights and choices
- See and correct: you can view and edit most of your data in your profile and Settings. Ask us for anything else.
- Get a copy: email legal@hackhoster.org and we’ll send your personal data in a common, machine-readable format.
- Delete: see section 10.
- Control visibility and email: hide yourself from participant lists in Settings → Privacy, and turn optional emails off in Settings → Notifications.
- Object or withdraw consent: tell us, and we’ll stop the processing unless we have a legal reason to continue.
We answer requests within 30 days (45 days where state law allows, and we’ll tell you if we need the extra time). We may ask you to confirm the request from your account email so we know it is you. An authorized agent can make a request for you with your signed permission. If we decline a request, we explain why, and you can appeal by replying; we answer appeals within 45 days. We won’t treat you differently for using your rights.
12. Children and teens
- HackHoster is not for children under 13. Our sign-up asks for a date of birth without hinting at the cutoff. If it shows someone under 13, we delete the account and everything collected from it immediately and don’t keep the attempt. If you are a parent and believe your child under 13 has given us data, email legal@hackhoster.org and we will delete it.
- Teens aged 13 to 17 need a parent or guardian’s permission. By default their public profile shows a first name only and no country. We collect and use teens’ data only as needed to provide the service they asked for (joining hackathons, teams, and projects), never sell it, and never use it for advertising.
- New York’s Child Data Protection Act. Because we ask everyone’s age, we know who is under 18. For those users we process personal data only when it is strictly necessary: to provide the service they asked for, to run and secure HackHoster, to prevent fraud and abuse, and to comply with the law. We don’t sell their data, and we don’t ask them to consent to any other use.
- There is no private messaging, so adults can’t contact teens privately through HackHoster.
- Parents and guardians can ask to see or delete their teen’s data by emailing us.
13. California and other U.S. states
Residents of California (CCPA as amended by the CPRA) and of other states with comprehensive privacy laws, such as Colorado, Connecticut, Virginia, and Oregon, have rights to know what personal information we collect and how we use and disclose it, to access it, to correct it, to delete it, to get a portable copy, and to opt out of its sale, its sharing for targeted advertising, and certain profiling. Based on its size, HackHoster is not currently required to follow most of these laws, but we honor these rights for everyone.
- HackHoster does not sell personal data or share it for cross-context behavioral advertising, including data of users under 16, and has not done so in the past 12 months. We don’t profile users to make decisions with legal or similarly significant effects.
- Categories we collect (described in section 2): identifiers (name, handle, email, IP address); age (date of birth, which we use only to check eligibility); internet activity on HackHoster; the profile and professional information you add; and your content. Sources: you, your sign-in provider, and your device. Purposes: section 3. Recipients: section 5. Retention: section 9.
- We use date of birth only to check age, which is a permitted use, so there is nothing to limit under the right to limit sensitive data.
- To make a request, email legal@hackhoster.org.
14. EEA, UK, and Swiss users
If data protection law in the European Economic Area, the United Kingdom, or Switzerland applies to you, our legal bases are:
- Contract: to provide the service you signed up for, including sharing your registration with the organizer of a hackathon you join;
- Legitimate interests: to secure and improve HackHoster, prevent abuse, and compute reputation, balanced against your rights;
- Consent: for optional emails, which you can withdraw at any time;
- Legal obligation: to comply with the law.
You have the rights to access, correct, delete, restrict, and port your data, to object to processing based on legitimate interests, and not to be subject to decisions based solely on automated processing (we make none). Please raise any complaint with us first at legal@hackhoster.org; we acknowledge complaints within 30 days. You can also complain to your local data protection authority. Your data is processed in the United States, where our providers store it; Google and Resend transfer data under the European Commission’s standard contractual clauses or the EU-U.S. Data Privacy Framework.
15. Security and storage location
Your data is stored in the United States on Google Cloud (Firestore in a U.S. multi-region and Cloud Storage in Iowa). Data is encrypted in transit and at rest. Our database can’t be read directly from browsers; every request goes through our server, which checks who you are and what you may see. Uploaded files are served only through unguessable links, which we change when a project is hidden. We keep secrets in a secrets manager, limit who can access production data, and record moderation actions.
No system is perfectly secure. If a breach affects your personal data, we’ll notify you and the authorities as the law requires, without unreasonable delay and within the deadlines that apply (for New York residents, 30 days from discovery).
16. Changes to this policy
We’ll update this policy when our practices change. The date at the top shows the latest version. If we make a material change, such as using data for a new purpose, we’ll tell you on the site or by email before it takes effect and ask for consent where the law requires it. Questions about this policy: legal@hackhoster.org. See also the Terms of Service.
Contact
HackHoster is operated by its owner, an individual operating HackHoster as a sole proprietorship, in the United States. Legal and privacy requests: legal@hackhoster.org. Everything else: support@hackhoster.org.