Privacy Policy
Privacy Policy
This covers MS Thrive KC, the community at msthrivekc.org, and what happens to information about you here.
The short version: everything is on one machine, nothing is sold, nothing is shared with advertisers, and no page on this site loads anything from anybody else's server.
Who is responsible
The administrators of this community. Under the UK GDPR and the EU GDPR we are the data controller. Reply to any email from this community to reach us.
The authors of the software this runs on have no access to any of it, and neither does anybody else who is not an administrator here.
What we hold
Because you gave it to us
- Your email address. It is how you sign in and how we reach you.
- Anything you wrote: your profile, your answers to the community's questions, posts, comments, replies to events.
- Whether you said you are coming to something, and how many people you are bringing.
Because the software records it
- When your account was created, when you last signed in, and whether an administrator has approved you.
- Your sessions: when each began, roughly when it was last used, and the browser it belongs to. The sign-in token itself is stored only as a one-way hash — a copy of the database is not a list of logins.
- A short-lived record of recent requests, held in memory only and lost when the server restarts: the page asked for, the time, the response, your IP address and your browser's user agent string.
- If somebody invited you: that the invitation was sent, whether the image in it was fetched, and whether you joined.
What we do not hold
- Passwords in readable form. If this community uses passwords at all, they are stored scrambled in a way that cannot be reversed.
- Payment details. No money moves through this site.
- Anything from an advertising network, a data broker, or a social network. There are none here.
- Your location, your contacts, or anything from your device beyond what your browser sends with an ordinary request.
Cookies
This site uses cookies. There are two, both strictly necessary, and neither of them tracks you.
| Cookie | What it is for | How long it lasts |
|---|---|---|
| The session cookie | Remembers that you are signed in. Without it, every page would ask you to sign in again. | Until you sign out, or until the session expires |
| The CSRF token | Proves that a form you submitted came from a page on this site, rather than from somebody else's page pointing at ours. | The same |
Both are set by this site and read only by this site. There are no analytics cookies, no advertising cookies, and no third-party cookies of any kind — so there is nothing here to consent to or opt out of, which is why this site does not ask you to click through a banner before reading anything.
Under the ePrivacy rules, cookies that are strictly necessary for a service you asked for do not require consent. These are those, and there are no others.
If your browser blocks them, you can read whatever is public and will not be able to sign in.
The app version of this site may also use your browser's local storage to remember that you have dismissed a notice. That never leaves your device.
We send email for things you asked for: a sign-in code, a notification you turned on, a summary you chose, an invitation.
If this community sends mail through a provider, your address and the message pass through that provider's systems in order to be delivered. Nothing else about you is sent to them.
Invitations contain a small image that tells us the message was opened. It is a poor signal in both directions — most email clients block it, and some fetch it automatically before anybody has read anything — and we treat it as such. Blocking images stops it entirely.
Notification emails and digests contain no tracking of any kind.
Notifications on your device
If you turn on push notifications, your browser gives this site a key that lets it send a message to that browser. That key belongs to the session you turned it on in: signing out deletes it, and the notification stops working.
A notification says who did something and where, never what they said. It travels across your browser vendor's push service to reach your device, so we deliberately do not put the contents of anything in it.
Why we are allowed to hold it (GDPR)
- To run the community you asked to join. Your account, your posts, your sessions. Legal basis: performance of a contract, and our legitimate interest in operating a members' community.
- To keep it working and safe. The request log, failed sign-in counts, bans. Legal basis: legitimate interests — a community that cannot keep out somebody who has been removed cannot protect its members.
- To send you things you turned on. Notifications and digests. Legal basis: consent, which you withdraw by changing the setting.
Who else sees it
Other members see what you post and what is on your profile. Administrators see that plus your email address and your answers to the joining questions.
Beyond that: the hosting provider, who has the machine; the email provider, if this community uses one; and nobody else. Nothing here is sold, rented, or handed over for advertising. We would hand something over if the law actually required it, and we would tell you unless we were forbidden to.
Where it lives
On the machine that serves this site, in a single database file, held by whoever provides that machine. If that machine is outside the UK or the EEA, the transfer is a necessary part of providing the service you asked for.
How long it is kept
- Your account and profile: while you are a member.
- Posts and comments: conversations on the board may expire after a period this community sets, and expire with their notifications.
- Sessions: until they expire or you sign out. Signing out deletes the session, rather than marking it dead.
- The request log: in memory, a few thousand requests, gone on restart.
- If an administrator rejects an application: the account, the profile and the answers are deleted outright. There is no reason to keep the data of somebody who is not joining.
If you leave, tell us and we will delete your account.
Your rights
You can ask us to:
- show you what we hold about you;
- correct anything that is wrong — most of it you can edit yourself;
- delete your account and what is attached to it;
- give you a copy in a portable form;
- stop using it in a particular way, or object to us using it at all.
Ask, and we will do it. There is no charge and no form.
If you think we have got this wrong, you can complain to your data protection authority — in the UK that is the Information Commissioner's Office at ico.org.uk, and in the EU it is the supervisory authority where you live.
Children
This community is not intended for children, and accounts are for adults unless this community has said otherwise.
Changes
If this changes, the new version appears here. If a change matters, we will say so where members will see it.