Privacy Policy
This policy explains what personal information Civil Engineering Students' Association collects through its membership portal at cesa-frontend-thbzhamx4q-ew.a.run.app, why we collect it, who we share it with, and the choices you have — including the data we access through Google APIs.
Last updated 24 August 2026
1. Who we are
Civil Engineering Students' Association, University of Energy and Natural Resources, Sunyani, operates this website and the membership portal behind it. In this policy "we", "us" and "our" mean the association; "you" means anyone whose personal information we hold — members, prospective members, alumni, guardians and site visitors.
The service exists to run the association: membership records, dues and payments, receipts, announcements and the public pages you are reading now. We are the data controller for that information.
2. Information we hold
Membership records. Given by you when you register, or entered by association administrators from the association's own records — including bulk imports from spreadsheets. These cover your name, index or reference number, gender, date of birth, contact email, phone and WhatsApp number, nationality, region, hometown, residential address, department, programme, level, year of admission and expected graduation year, membership status, guardian details where provided, employment history where you supply it, and a profile photograph.
Account and sign-in. Your email address, a hashed password (we never store the password itself) and your role in the portal. If you sign in with Google we also store the stable account identifier Google issues for you, plus the name and email address in the identity token Google returns. We never receive your Google password.
Payments. The amount, purpose, status, gateway reference and receipt number of each dues payment or donation. Card and mobile-money credentials are entered on Paystack's own checkout and never reach our servers.
Communications. The content and delivery status of SMS messages sent to you by the association, and the delivery status of transactional email such as receipts and password resets.
Technical and audit records. Every change an administrator makes is logged with the record affected, a before-and- after snapshot, the administrator's identity, their IP address and browser user-agent string. Signing in sets a single session cookie, readable only by the server, that keeps you logged in.
3. Google user data
Two Google permissions are used, each requested only at the moment the matching feature is used, and each shown to you on Google's own consent screen before anything is accessed.
Signing in with Google. We read only your basic profile — the identifier, name, email address and email-verified flag inside the identity token — and use it to find or create your portal account. Nothing else in your Google account is touched.
Google Photos (photospicker.mediaitems.readonly). An administrator may import photographs by choosing them in Google's own picker. We receive only the specific items chosen — never the rest of the library — copy them once into our storage so the gallery does not depend on continued access, and discard the credentials as soon as the import finishes.
Google Drive folders are not one of these permissions. A photo gallery collection can list its images from a Drive folder, but we never ask you for access to your Drive. Instead an administrator shares one folder, inside Google Drive, with this site's own Google service account — the same way a folder is shared with any colleague. We can read that folder because it was shared with us and nothing else in the Drive it came from; requests for a sized image redirect the visitor's browser to Google's own image servers, so the photographs are not copied onto our servers. Un-sharing the folder in Drive ends our access immediately, and there is no grant to withdraw because none was ever given.
We do not use Google user data for advertising, do not sell it, do not use it to train artificial-intelligence or machine-learning models, and do not transfer it to anyone except as described in section 5.
Limited Use disclosure. Civil Engineering Students' Association's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can withdraw either of these permissions at any time at myaccount.google.com/permissions. Doing so stops any further access immediately; Drive-linked gallery collections will simply stop showing photographs.
4. How we use your information
- Maintaining the membership register and confirming who is a member in good standing.
- Billing, recording and receipting dues and donations, and issuing verifiable receipts.
- Sending you association announcements, event notices, payment reminders and birthday greetings by email or SMS.
- Publishing association content — executives, events, photo galleries and society pages — on the public site.
- Keeping the service secure and accountable, through audit records of administrative changes.
- Producing aggregate statistics, such as the number of members on a programme or dues collected in a year.
We do not sell your personal information, and we do not use it for advertising.
6. How long we keep it
Membership records are kept for as long as you are a member and afterwards as part of the association's alumni history, which is a core purpose of the register. Payment records and receipts are kept as the association's financial record. Audit records are pruned automatically on a rolling window. Google credentials are held only for as long as the feature that needs them: a Drive collection's token until that collection is deleted or re-linked, and a Photos import's credentials only for the seconds the import runs.
You may ask us to correct your record at any time, or to erase it where we are not required to keep it. Write to us using the details in section 9.
7. How we protect it
Traffic to the site and the API is encrypted in transit. Passwords are stored only as hashes. The session cookie cannot be read by scripts in your browser. Access inside the portal is restricted by role and by position-level permissions, so an administrator sees only what their office requires, and every change they make is recorded.
No system is perfectly secure. If a breach affects your personal information we will act on it and notify those affected where we are required to.
8. Children
The portal serves students and alumni of a tertiary institution and is not directed at children. We do not knowingly collect information from anyone under 13; if you believe we have, contact us and we will remove it.
9. Changes and contact
We will update this policy when the service changes, and the date at the top of the page will move with it. Material changes will be announced on the site.
For any question about this policy, to exercise any right described in it, or to report a concern, contact support@cesauenr.com.
See also our Terms of Service.
