Legal

Privacy Policy

This policy describes what information GavelMUN collects, how it is used, and who else processes it.
Last updated 26 July 2026

Summary

We collect the information required to operate the service and nothing for advertising purposes. This site contains no tracking pixels, no analytics cookies and no third-party advertising. We do not sell personal information, and we do not receive or store card numbers.

Information we collect

Account information. A username, an email address, a conference name, and a password stored only as a salted hash. Passwords cannot be read by us, which is why a reset issues a new password rather than disclosing the existing one.

Committee data. Information entered by users, including delegation names, country codes, roll call records, speaking times, motions, and any custom flag images uploaded.

Payment information. Processed by Stripe. We receive the email address supplied at checkout, the amount paid and a payment reference. We do not receive card numbers.

Technical information. Server logs, and the IP address associated with a free account registration. The latter is retained in order to limit the number of free accounts created from a single source.

Information about students

Committee accounts are typically held by students, and delegations are normally identified by country rather than by name. Users are asked not to enter personal information about delegates beyond what is necessary to run a session. The service does not require any such information, and we recommend that the names of minors are not entered.

Information stored in your browser

Authentication tokens and a copy of your delegate list are stored in your browser using local storage, and the application caches its own files using a service worker. This is what allows committee mode to operate without a network connection. None of it is used for tracking, and signing out clears it.

Service providers

  • Stripe, for payment processing and checkout;
  • Resend, for transactional email such as verification and account setup links;
  • Google Cloud, for hosting and for storage of uploaded flag images.

These providers process information on our behalf. Some of them store information on servers outside Canada, including in the United States. Information held in another jurisdiction may be accessible to the authorities of that jurisdiction under its applicable laws.

Retention

Account and committee data is retained for as long as the account exists. A paid plan is deactivated twelve months after purchase; deactivation does not delete data. Uploaded flag images are removed from storage when an account expires.

On request, we will delete an account and its associated committee data. Records of payments are retained for as long as tax and accounting obligations require.

Security

Traffic is encrypted in transit. Passwords are stored as salted hashes, are never stored in readable form, and are never sent by email. Access to the production environment is restricted to the maintainers of the service.

No system can be guaranteed secure. If you identify a vulnerability, we ask that you report it to us before disclosing it publicly. Reports made in good faith will not result in action against the reporter.

Your rights

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), you may request access to the personal information we hold about you, request its correction, or request its deletion. Requests should be sent to [email protected], and will be answered within 30 days. You may change your own password at any time from your account page.

Changes to this policy

Where this policy is amended in a manner that materially affects how personal information is handled, account holders will be notified by email.

For questions about this document, contact [email protected].