Back to Home
PRIVACY POLICY & UK GDPR STATEMENT
UK GDPR & Data Protection Act 2018 Compliant

Privacy Policy — Society Tracker (UCL Tools)

Society Tracker is a student-facing web and native mobile application designed for the UCL community. This Privacy Policy explains how we collect, process, store, and protect your personal data, as well as your legal rights under UK GDPR.

1. Overview & Scope

Society Tracker (also referred to as UCL Tools) aggregates UCL student society events, personal calendar schedules, community notice boards, peer-to-peer ticket listings, room booking tools, Students’ Union democracy tools (zone meetings, the Union policy register with advisory policy stances, and officer accountability tracking), and society administration utilities.

Society Tracker is published by MaybeItsSoftware Ltd, a company registered in the United Kingdom, which is the data controller for the personal data described in this policy.

We process personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the UK Data Protection Act 2018.

2. Information We Collect and Process

2.1 User Account & Authentication

When you sign in to Society Tracker via Microsoft Entra ID Single Sign-On (SSO):

  • UCL Email address (e.g., @ucl.ac.uk)
  • Full Display Name & Department
  • User Persistent Identifier (upi)

2.2 Followed Societies & Starred Events

We store the societies you follow and the events you star, so we can highlight them in the calendar and order societies you follow first. We no longer store personal calendar preferences or an iCal subscription token.

2.3 Ticket Marketplace & Notice Board

Listings and notices include titles, descriptions, price, quantity, and optional contact phone numbers. Contact details are revealed strictly to matched peers or authenticated users viewing active listings.

2.4 Society Expenses & Receipts

Expense submissions (vendor, amount, date, notes, receipt image uploads) are stored securely in restricted Cloudflare R2 bucket storage, accessible strictly by authorized society committee treasurers and platform administrators.

If you give reimbursement details, the payee's sort code and account number are encrypted (AES-256-GCM); only the account name and the last four digits are stored readable, for display. Only the President or Treasurer of that society can reveal the full details, and every reveal — including one made by the Connector extension to fill in the Union's payment form — is recorded with who made it and when. The details are deleted 7 days after the claim is marked paid. Your data export shows them masked.

2.5 Who Knows Who (Strictly Opt-In)

Who Knows Who is 100% opt-in. You are neither searchable nor displayed until you explicitly choose to join. Leaving flips your opt-in status back and hides you everywhere immediately — you stop being searchable, you leave the graph, and your connections stop showing to anyone. Those connection records are kept but hidden, so rejoining restores them. To erase them for good instead, tick the deletion checkbox in the leave dialog (off by default) — that is permanent and cannot be undone.

2.6 WhatsApp Gateway Audit Logs

Timestamped visit logs record authenticated visits to society invite gates to prevent spam. IP addresses and User-Agent headers are explicitly excluded from gate logs to preserve privacy.

2.7 Society Membership & the Connector Extension

When an authorised society principal connects the Students' Union membership page, we store the society member names, membership category and membership date range shown there. Principals can link a roster row to an existing Toolbox account, adding that account's name and UCL email. The society's principals can view its roster. A separately approved society integration can receive that society's roster through a scoped API token; access is logged and is not granted to existing integrations automatically. We do not collect the over-18 field shown by the Union.

The A.C.T. Connector browser extension (Chrome, Edge, Firefox and Safari on Mac) does this from the principal's own browser, signed in as them. It talks only to studentsunionucl.org and adamscampustoolbox.org.uk, and contains no analytics, advertising or remote code.

  • Students' Union login. When the principal syncs, or turns on Remote auto sync, the extension sends their Union login session cookie to us. We keep it in Google Cloud Secret Manager, one per society, never return it through any page or API, and use it only to read that society's membership page and check the login still works. It stops working when the principal signs out of the Union site, is replaced whenever a newer one is sent, and any of the society's principals can delete it at any time with “Remove stored SU login” on the Toolbox's Connector page, which also switches off Remote auto sync.
  • Auto sync (optional, per society, off by default). Local: the browser re-reads the membership page about once a day and sends the roster; the login is not sent. Remote: after confirming, the principal's browser keeps the stored login current so the roster can refresh overnight. Remote uses a separate credential limited to that society, lasting 90 days, which the principal can revoke from the Toolbox at any time.
  • In the browser. The extension keeps its connection token, the auto sync settings and a copy of the member list in the browser's own storage, so the principal can view and export it there. Disconnecting deletes the copy.
  • Union account number. The extension reports the numeric id of the Union account the browser is signed in to (not the name, email or login), so we can tell which Union account a connected browser belongs to.
  • Form filling. When a treasurer chooses “Fill SU form”, the extension fetches that receipt's details — including the payee's bank details — and types them into the Union's payment request form in a window of its own. It never stores the bank details or submits the form; the treasurer checks and submits it. We record that the fill happened and which fields could not be filled, never the values typed.

2.8 Democracy: Manifesto Votes & Policy Stances

If you vote on whether an officer has fulfilled a manifesto point, or record a Support, Oppose or Abstain stance on a Union policy, we store that answer against your account so you count once and can change or clear it. Your individual answers are visible only to you; only aggregate counts are shown publicly. Policy stances are an advisory opinion signal, not a vote of the Students' Union, and are not passed to the Union as votes. Deleting your account deletes them.

3. Legal Bases for Processing (UK GDPR)

Consent (Art. 6(1)(a))Opt-in Who Knows Who directory, optional phone numbers.
Contract (Art. 6(1)(b))Core SSO auth, calendar feeds, expense processing, and society membership administration.
Legitimate Interest (Art. 6(1)(f))Platform security, WhatsApp spam prevention, bug telemetry.

4. Cookies & Session Storage

Society Tracker uses minimal essential cookies. The primary cookie is user_token (an encrypted session JWT, HttpOnly, SameSite=Lax, 30-day lifespan). No non-essential tracking cookies or third-party ad pixels are used.

5. Your UK GDPR Rights

Under the UK GDPR, you hold the following rights:

  • Right of Access (Art. 15): Request a copy of all personal data held about you.
  • Right to Erasure / Right to be Forgotten (Art. 17): Permanently delete your account and submitted data.
  • Right to Data Portability (Art. 20): Export your data in a structured machine-readable JSON file.
  • Right to Withdraw Consent: Opt out of Who Knows Who or notifications at any time.

You can exercise these rights directly within the application under User Settings → Privacy & GDPR or by using our API endpoints (/api/user/export and /api/user/account).

6. Contact & Maintainers

If you have any questions or require assistance with data requests, contact the maintainers:

Data Controller: MaybeItsSoftware Ltd, United Kingdom