Privacy
Your information should have a clear purpose.
This policy explains how the public site and secure applicant/member portal handle account, profile, and chapter-participation data. Chapter leadership must review it before accepting real student records.
Last updated July 30, 2026
What we collect
The public site stores contact submissions. Registered accounts also store authentication state, ordinary profile fields, opt-in directory choices, academic-year membership, role history, and separately encrypted restricted fields such as student ID, optional GPA, emergency contact, dietary restrictions, and accommodations. Election eligibility is identity-linked, while encrypted ballot choices are deliberately stored without a user identifier.
How we use it
Information is used only for stated chapter workflows: account recovery, membership, payments, events, competitions, safety, leadership, elections, service verification, and support. Access depends on granular permissions, ownership checks, academic-year scope, and narrow field projections. We do not sell personal information or expose private profile data publicly.
Retention
Contact submissions receive a 180-day retention deadline. Expired authentication tokens and signed-download grants are removed after a short operational window; rendered email variables are redacted after 90 days. Membership, payment, attendance, volunteer, travel, election, audit, and document records follow the purpose-specific schedule in the published privacy inventory and may be held for an incident or approved records obligation.
Access and choices
You may contact deca@uh.edu to request access, correction, account deactivation, export, or deletion review. Signed-in members can also download their own audited JSON export from Profile. Directory and alumni visibility are off until you opt in, and email/phone sharing are separate choices. Some minimum payment, election-integrity, security, or audit records may be retained when an approved obligation applies.
Security and scope
The platform uses server-side validation, private database access, restricted administrative tools, and privacy-safe logs. No internet system can guarantee absolute security. This policy applies to the chapter platform, not linked external sites or University of Houston systems.
Consent and sensitive information
Application consent covers only the stated membership workflow. Emergency, dietary, accessibility, travel, resume, headshot, and supervisor details should be provided only when the relevant workflow explains its purpose and access audience. Contact chapter leadership before submitting sensitive information if the purpose is unclear.