We've updated our Privacy Policy. Please take a moment to review the new changes. View Updates

Privacy Policy

Last updated: September 4, 2026

This policy describes how gmhsminithon.org collects, uses, and handles your information. It covers the public website, the newsletter signup, the members-only portal, and the admin portal that club officers use to edit site content.

Information We Collect

Newsletter subscriptions. If you sign up for our newsletter, we collect your email address and pass it to EmailOctopus, which stores it and sends the emails.

Member and admin sign-in. When you sign into the members portal or the admin portal via Shoo (shoo.dev), we verify your Shoo identity token and use your Shoo user ID (pairwise_sub) to decide whether your account is approved. That ID is specific to this site. We do not store the name, email address, or profile picture that a Shoo token may carry.

Content entered in the admin portal. When an administrator saves a change, we store the content they entered, any images they upload, and their Shoo user ID alongside the change so the portal can show who edited what and when.

Technical and operational data. Our hosting infrastructure automatically processes standard request metadata, server logs, and performance data necessary to deliver and secure the site.

We do not collect more information than what is described above.

How We Use Your Information

  • To operate the public website, members portal, and admin portal.
  • To verify portal access against administrator-maintained approval lists.
  • To keep an internal record of who changed site content, so mistakes can be traced and corrected.
  • To send newsletter updates to subscribers.
  • To monitor site performance, diagnose issues, and protect against misuse.

We do not use your information for advertising, and we do not profile visitors.

Members Portal

The members portal uses Shoo (shoo.dev) for authentication. After Shoo verifies your identity, this site checks your Shoo user ID against a private approval list maintained by GMHS Mini-THON administrators. Approved IDs may come from any combination of our content database, server environment variables, and an optional private Google Sheet configured by administrators.

If your account is not yet approved, the sign-in flow may display your Shoo user ID so you can share it with an administrator to request access.

Upon successful authentication, the site issues a session cookie that expires after 24 hours, so you can navigate protected pages without re-authenticating on each load.

Admin Portal

The admin portal at /admin is limited to club administrators. It uses the same Shoo sign-in as the members portal, with the additional requirement that the Shoo user ID appears on the admin list. Admin sessions use a separate cookie that expires after 8 hours, and every request re-checks the admin list, so removing an ID takes effect immediately.

Administrators can add or remove Shoo user IDs from the member and admin lists, and can attach a short label to an entry (for example, a member's name) to keep the list readable. The portal keeps an activity log recording the acting administrator's Shoo user ID, the action taken, the affected item, and a timestamp. This log is visible only to signed-in administrators.

Images uploaded through the admin portal are stored with UploadThing and served publicly from its content delivery network, because they appear on the public website.

Third-Party Services

Service Purpose
Shoo (shoo.dev) Member and admin portal authentication
Vercel Hosting, image optimization, web analytics, and speed insights
Neon Postgres database for site content, portal approval lists, and the admin activity log
UploadThing Storage and delivery of images uploaded by administrators
EmailOctopus Newsletter subscriptions and delivery
Google Sheets Optional administrator-managed member approval list, read as a published CSV
Google Fonts Web fonts; your browser requests them directly from Google, which receives your IP address

When you interact with these services through this site, their own privacy policies and terms of service also apply. We encourage you to review those policies directly.

Data Sharing and Retention

We do not sell personal information.

We share data only with the service providers listed above, and only as necessary to operate the site. Retention works as follows:

  • Session cookies expire automatically - 24 hours for member sessions, 8 hours for admin sessions - and are cleared when you sign out.
  • Approval list entries are kept until an administrator removes them, or until the environment variable or Google Sheet that supplied them is updated.
  • The admin activity log is retained as an audit trail of content changes for 18 months, after which entries are deleted automatically.
  • Newsletter subscriptions are kept until you unsubscribe or ask us to remove your address.
  • Uploaded images remain available until an administrator deletes them.
  • Server logs and analytics are retained by our hosting provider for a limited period under its own retention schedule.

Cookies and Browser Storage

This site sets cookies only for signing in. The members portal sets a member_session cookie and the admin portal sets an admin_session cookie. Both are signed, marked HttpOnly and SameSite=Lax, sent only over HTTPS in production, and cannot be read by scripts in your browser. We do not use advertising or cross-site tracking cookies.

The site also uses your browser's sessionStorage for small interface details, such as carrying a sign-in error message across a page navigation and remembering whether the navigation animation has already played. That data stays in your browser and is cleared when you close the tab.

Vercel Web Analytics and Speed Insights measure traffic and performance without using cookies to identify you across sites.

Security

The site is served over HTTPS. Sign-in tokens are verified on the server, session cookies are cryptographically signed, API keys and database credentials are held in server-side environment variables and never sent to your browser, and admin write requests are rejected unless they originate from this site. No system is perfectly secure, but we aim to collect as little as possible so there is little to expose.

Your Privacy Rights

Depending on your location, you may have the right to access, correct, delete, or restrict certain personal data we hold. You can also unsubscribe from newsletter emails at any time using the unsubscribe link in any email we send.

Browsing the public site requires no account. You are not required to use the members portal or newsletter signup. To ask about, update, or request removal of information associated with this site, contact us at hello@gmhsminithon.org .

Children's Privacy

This site is intended for the GMHS Mini-THON school community. We do not knowingly collect personal information from children under 13 without appropriate parental or school authorization in compliance with the Children's Online Privacy Protection Act (COPPA). Student participation in the portal requires only a Shoo user ID, not a name, address, or other personal details. If you believe a child under 13 has submitted personal information in error, contact us at hello@gmhsminithon.org and we will promptly review and address it.

Changes to This Policy

We may update this policy to reflect changes to the site or its services. Material updates will be noted by a revised "Last updated" date at the top of this page.

Contact

Questions about this policy or your data:

hello@gmhsminithon.org

This policy explains our current data practices in plain language. It is not legal advice. This site may link to third-party services outside our control - we are not responsible for their privacy practices.