Privacy & Data Governance 🛡️
At ClubConnect, we treat your community data with institutional-grade seriousness. Here is how we maintain a secure environment.
1. Role-Based Access Control (RBAC)
We use a strictly gated permission model.
- Members: Can only see their own registrations and public club data.
- Executives: Have full oversight of their specific club's roster and event metadata.
- Staff/Admins: Maintain global platform health and verify club authenticity.
2. Institutional Firewalls
All administrative operations are gated by server-side verification.
- Service Tokens: Sensitive operations (like deleting users or modifying global settings) require specific, encrypted secret keys that never leave our secure server environment.
- Audit Logs: Every major administrative action is logged, ensuring complete accountability.
3. Data Minimization
We only collect what we need to verify your institutional identity.
- Email Encryption: We use GITAM Single Sign-On (SSO) to prove you are a student without requiring additional personal passwords.
- Limited Tracking: We do not track your browsing habits outside the platform.
Identity Verification
Attempting to bypass institutional domain restrictions or impersonate staff will result in an immediate and permanent platform ban.
