Plain data notice

Privacy and Referral Notice

What the event collects

Depending on what you do, the event may collect a display name, private contact email, age band (16–17 or 18+), itch handle, roles, consent choices, Courier code, public post URL, RSVP, check-in, and submission metadata.

Referral cookies

A Courier link sets first-party signed cookies containing a random visitor identifier and the first valid Courier code. They expire after 30 days. No advertising cookie, cross-site profile, full browser fingerprint, or raw IP address is stored in the event database.

Why data is used

Data is used to operate registration, attribute meaningful referrals, prevent duplicates and abuse, administer the showcase, grant digital honours, respond to safety issues, and publish opt-in aggregate results.

Who can see it

Private contact information is encrypted before database storage and is visible only through authorized administrative recovery or private export processes. Moderators see only the records needed for review. Public pages show names or pseudonyms only with consent.

Retention

Private contacts, referral sessions, operational identities, and rate-limit records are scheduled for deletion 90 days after the event. A separate future-contact choice, if ever offered, must be independent of event administration.

What is never collected

The event does not collect donor identities, donation amounts, payment records, medical documents, exact birth dates, identity documents, or private-message contents.

Your choices

You may participate without public credit, manually enter the Courier code you intend to credit, ask the organizer to correct an attribution, or request access, correction, or deletion through the published organizer contact route. Some records may need to remain briefly for abuse prevention or required operational reporting.

Deployment must replace the organizer contact and official fundraiser link before public activation.