Privacy Policy
Effective July 23, 2026 (draft)
This policy explains what information Adonify collects, how it’s used, who can see it, and the choices you have. The short version: we collect what’s needed to run a chapter-management product, we don’t sell it, and we don’t run ads or third-party analytics.
1. Who we are
Adonify is a chapter-management platform for Greek chapters and student organizations: point tracking, leaderboards, tasks and events with attendance, goals, opportunities, committees, dues record-keeping, chat, email notifications, and admin reports. Adonify operates the service and is the point of contact for privacy questions at adonifycto@gmail.com.
2. Information we collect
Information you provide
- Your name, email address, and password. Passwords are hashed by our authentication provider (Supabase Auth) — we never see or store the plain text.
- An optional profile photo.
- Chat messages and file attachments you send, and proof photos you attach to point requests.
- Feedback you submit through the in-app feedback form, including an optional screenshot.
- Your notification preferences and a timestamp of your acceptance of the Terms of Service.
Information your organization provides about you
- Your membership in the organization, your role (admin or member), and any title or committee assignments.
- Participation records entered or triggered by your organization’s admins: point entries and adjustments, event attendance, task completions, and goal progress.
- Dues records entered by admins (amounts owed, logged payments, notes). These are bookkeeping entries only — Adonify never collects payment card or bank details.
Information collected automatically
- Transactional email logs: the recipient address, subject, and delivery status of emails we send you.
- Rate-limit counters used to throttle abuse (for example, repeated login attempts). The keys for these counters are stored hashed.
- Standard server request logs (such as IP address and request metadata) kept by our hosting infrastructure for security and debugging.
We do notuse advertising trackers, third-party analytics scripts, or social-media pixels, and we don’t collect precise location or payment card data.
3. How we use information
- To provide the product: leaderboards, point tracking, approvals, events and attendance, goals, committees, dues record-keeping, chat, and reports.
- To keep accounts secure: authentication (including optional two-factor authentication), session management, rate limiting, and abuse prevention.
- To send transactional and notification email — email confirmation, password resets, and (subject to your organization’s settings and your own preferences) reminders and digests. Every send is logged so we can verify delivery and never double-send.
- To respond when you contact us or submit feedback.
We do not sell personal information, and we don’t share it with advertisers.
Note for EEA/UK visitors: this is a US-focused working draft. Regional terms — including legal bases for processing under the GDPR and equivalent laws — will be finalized as part of the pending legal-counsel review.
4. Who can see your information within the product
- Members of your organization can see roster display information (name, photo, title, committees) and — subject to visibility controls your admins configure — leaderboard standings and participation history. Your data is never visible to other organizations.
- Admins of your organization can additionally see and manage your point history, attendance, task completions, requests, at-risk status, and dues records, and can generate organization-wide reports and CSV exports.
- Adonify staff access personal data only as needed to operate the service and support users, not to browse organization content.
- Feedback you submit (including any screenshot) goes to the Adonify team.
5. Sharing and subprocessors
We share data only with the infrastructure providers that run the service, each processing it on our behalf:
| Provider | Purpose |
|---|---|
| Supabase | Database (Postgres with row-level security), authentication, and file storage for uploads like profile photos, proof photos, and chat attachments. |
| Vercel | Application hosting and delivery, including request logs. |
| Resend | Transactional email delivery (confirmations, resets, reminders, digests). |
We may also disclose information if required by law, or to protect the rights, safety, and security of Adonify and its users. More operational detail is in the Data Handling Policy.
6. Cookies
Adonify uses only essential cookies — secure, HTTP-only session cookies that keep you signed in, plus a preference cookie for your active organization. No advertising or analytics cookies. Details in the Cookie Policy.
7. Retention and deletion
- Your account data is kept while your account is active.
- Self-serve account deletion.You can delete your account yourself from Account → Security (you’ll type DELETE to confirm). Deletion permanently removes your login credentials, email address, profile photo, notification preferences, and personal profile.
- What your organization keeps.Organization-scoped records you contributed to — point entries, attendance, task completions, chat messages, dues records, and finance ledger entries — are retained by the organization for its operational integrity, in anonymized form: your name is replaced with “Former Member” on those historical records.
- Solo organizations. If you are the only remaining member of an organization you administer, that organization and all of its data are deleted with your account.
- Last-admin rule. If you are the last admin of an organization that still has other members, you must promote another admin before deleting your account.
- Removed members. If you leave or are removed from an organization, you lose access to it immediately; your historical participation records are retained by the organization so its totals and reports stay truthful.
- Email logs (recipient, subject, delivery status) are retained for up to 90 days for delivery verification and abuse prevention.
8. Your rights and choices
- Delete your account yourself at any time from Account → Security, with the retention rules described above.
- Export your own data as a CSV from your dashboard when your organization has enabled member self-export. Organization admins can separately export organization reports.
- Control email. Notification settings are per-user; turning all email streams off is a full opt-out of non-essential email. Essential account email (like password resets you request) still works.
- Ask us. For access, correction, or anything not covered by the self-serve tools, email adonifycto@gmail.com. We don’t discriminate against you for exercising privacy rights.
9. Security
Every table in our database is protected by default-deny row-level security, sessions live exclusively in HTTP-only cookies (never tokens in local storage), authorization is enforced server-side on every request, and authentication and abuse-prone endpoints are rate-limited. You can add two-factor authentication (authenticator app / TOTP) to your account. Adonify never collects payment card data. The full picture is in the Data Handling Policy. No system is perfectly secure, so if we learn of a breach affecting your data, we’ll notify you as required by law.
10. Children and eligibility
Adonify is for college communities and is not directed to children. You must be at least 17 to create an account. We do not knowingly collect data from anyone under that age; if you believe a minor has created an account, contact us and we’ll delete it.
11. Changes to this policy
If we make material changes, we’ll notify you by email or an in-product notice before they take effect. The effective date at the top always reflects the current version.
12. Contact
Privacy questions or requests: adonifycto@gmail.com.