Privacy Policy
Last updated: 10 August 2026
This policy explains what information TMCG IdeaSprint 4.0 (“the event”, “we”, “us”) — jointly organized by TMCG and Meta Developer Communities (MDC) GITAM Visakhapatnam — collects through this website, why we collect it, and who can see it. It applies to this site only, not to GITAM University or Google’s own services.
Information we collect
We collect information at two points: when a team registers, and when a participant signs in.
- Team registration — each participant’s name, GITAM email, phone number, registration number, year of study, school, department, branch, gender, and stay preference, plus the team’s name and chosen domain. This is submitted directly by the registering team, before anyone signs in.
- Google sign-in — your name, email address, and profile photo, as provided by Google. Sign-in is restricted to @student.gitam.edu and @gitam.in accounts; we only use this to confirm you’re the person who registered and are a member of the GITAM community — we never request access to your Gmail, Drive, Calendar, or any other Google data.
- Documents you upload — No Objection Certificates (NOCs) and team exit forms, submitted as PDF files through your dashboard.
- Event records — attendance and meal-coupon redemption status, recorded by event staff during the event itself.
How we use it
Solely to run the event: verifying registrations, granting dashboard access, managing problem statement selection, tracking attendance and meal coupons, processing NOC/exit form submissions, and sending you notifications about your team’s status. We don’t use it for advertising, and we don’t sell or rent it to anyone.
Who can see it
Access is limited by role, enforced at the database level, not just hidden in the interface:
- You can always see your own information.
- Your Team Lead can see your team’s roster and NOC status.
- The SPOC (single point of contact) assigned to your team can see your team’s information for coordination and verification.
- Event organizers (Super Admin) can see all participant and team data, for running the event.
No one outside these roles — and no one outside the organizing team — has access to participant data.
How it’s stored
Data is stored with Supabase (a hosted PostgreSQL provider). Uploaded documents (NOCs, exit forms) are kept in private storage — they are never publicly accessible by URL, and are only ever served through short-lived signed links generated when someone with permission chooses to view them. Sign-in is handled by Google and Supabase Auth; we never see or store your Google password.
Cookies
We use one cookie, set by Supabase Auth, to keep you signed in between page loads. We don’t use advertising, tracking, or analytics cookies.
How long we keep it
Participant and team data is retained for the duration of the event and for a reasonable period afterward for record-keeping and reporting to the organizing institutions, after which it may be deleted. If you’d like your data removed sooner, contact us using the details below.
Contact
Questions about this policy, or requests to access, correct, or delete your data, can be sent to [organizer contact email].
Changes to this policy
If this policy changes, we’ll update the “Last updated” date above. Continued use of the site after a change means you accept the update.