Privacy Policy
OurWay is operated by Engage Campus Technologies LLC.
Last updated:
What this covers
OurWay is a campus community platform for college students. This policy describes the information the service stores, why it stores it, and who can see it.
Information you provide
When you create an account and use OurWay, the service stores:
- Account details — your email address and an authentication record, handled by Supabase Auth. OurWay does not store your password; it is hashed and held by the authentication provider.
- Profile details — first and last name are required when you sign up. Your display name defaults to your first name if you do not choose one. You also choose a student or external-affiliate account type. Avatar image, school, graduation year, major, pronouns, a short bio and a social link are optional profile details.
- Content you create — clubs you submit, posts, events, event RSVPs and saved items, direct messages, club chat messages, connection requests, and any files you attach.
- Your safety actions — users you block, and reports you submit.
- Club payment information, when that feature is enabled — obligations, amounts, payment status, receipts, transaction and provider references, officer notes, and any private proof of payment you submit. The production payment feature is gated off unless the operator explicitly enables a compatible release.
Who can see what
Visibility is enforced in the database, not only in the interface. Your Settings include controls for whether your profile is shown to other members, whether your joined clubs and officer roles are shown, whether you appear in member discovery, and whether other students may send you connection requests, club invitations, or direct messages.
- Your account email is not part of your public profile. Contact details you choose to include in a club submission, profile text or other shared content can be visible to the audience for that content. Choose what you share carefully.
- Direct messages are available to the two authorized participants. Sending a direct message requires an accepted connection, and blocking prevents further contact. Reported messages can be reviewed by authorized platform administrators. Service providers also process messages as needed to host and operate the service.
- Club chat messages are visible to the members of that club, and to club officers who hold moderation permission.
- Reports you submit are visible only to platform administrators reviewing them. They are not shown to the person you reported.
Moderation and safety records
When you report a message, the report — including the reported content and your identity as the reporter — is retained so administrators can review it and so a pattern of behaviour remains reviewable. When a club officer removes a message, the original text is retained and a neutral placeholder is shown in its place, so the removal can be reviewed or undone. Administrative actions are written to an audit log.
Why the service uses information
We use account and profile information to authenticate you and provide your account; content and participation records to operate clubs, events and conversations; and reports, blocks and audit records to review safety concerns and protect the service. Technical request information helps host, secure and troubleshoot the app. Optional analytics is described separately below.
Your information and choices
You can edit your profile and privacy preferences in Settings. When account export is available, Download account data in Settings creates a file containing records about your account. It does not include other members' private information, internal moderation notes or uploaded file contents. If an option is unavailable or you need help with access, correction or deletion, see Support. We verify account ownership before providing private data or deleting an account.
Deleting your account
When self-service deletion is available, use Settings → Account in the app or on the web. The account deletion page is accessible without signing in and explains the available request and recovery options. If no support address is configured and self-service is unavailable, that page cannot accept a request.
Deleting your account removes your Auth account, refresh sessions, profile and personal details. This device returns to the signed-out screen, and you cannot sign in again. A short-lived access token issued before deletion can remain valid until it expires, while the deleted profile and membership records remove their app access. Some records are not deleted, because deleting them would either destroy another person's content or remove a safety record:
- Messages you sent in club chats remain in the club's shared conversation, shown without your profile attached.
- Reports about your content, and moderation actions taken on it, are retained so a safety record does not disappear when an account is removed.
- Clubs, posts and events belong to the club rather than to an individual and are not removed when a member leaves.
- Club payment obligations, transaction, receipt and audit records, and private payment proof files remain as financial records. Direct links to your deleted profile are removed, but retained transaction notes or references and a proof file's technical storage path can still contain account-related data, including the former account identifier. The legal retention period for these records has not yet been decided by the owner and legal counsel, so payments must remain gated until that policy is set.
Retained shared content and moderation records may still contain personal information in their text or attachments after your profile is removed. Deletion does not promise immediate removal of every provider log or backup. Club owners need to transfer ownership before deleting their account. Recent uploads can temporarily delay deletion while the service safely prepares uploaded files.
Data practices the service does not use
OurWay does not sell personal information. It does not run third-party advertising. The app does not collect precise GPS location. Hosting providers can derive approximate city and country from your IP address as described below.
Cookies, local storage and optional analytics
Essential cookies maintain your sign-in session. Local storage remembers app preferences, such as appearance and recent searches, and your analytics choice. Rejecting optional analytics does not disable sign-in or the app. Your analytics choice is stored on this browser for up to 180 days and is separate from your account. Clearing browser storage clears that choice; optional analytics then stays off until you accept again.
When enabled for this deployment, Vercel Web Analytics measures visits only after you choose Accept optional analytics. This integration measures only the public welcome, Privacy Policy, Terms of Use and Community Guidelines pages on our production website. It excludes account and sign-in pages, profiles, clubs, events, messages, search, support and deletion pages. Its page-view payload does not include account identifiers, message content, form entries, search terms, URL query parameters or URL fragments. Visits with other referring pages are also excluded to avoid sending sensitive links.
Vercel processes the public page address, visit time and technical request information to produce aggregate statistics, including browser, device and approximate location. Vercel describes its default analytics as using a request-derived hash rather than third-party cookies; its visitor session is discarded after 24 hours. This is not a promise that aggregate statistics are deleted after 24 hours. See Vercel's analytics privacy documentation.
Use Privacy preferences below and choose Reject optional analytics to withdraw permission for future visits. Withdrawal does not remove aggregate statistics already collected. Global Privacy Control and Do Not Track signals keep optional analytics off, as does unavailable browser storage. These choices apply to optional analytics, while essential hosting and security processing continues.
Service providers
OurWay uses Supabase for authentication, database storage and file storage. Vercel hosts the web application. Supabase Auth sends transactional authentication emails through Resend as its production email delivery provider. These providers process data to deliver their respective services. If the separately gated club payment feature is enabled, Stripe processes supported online payments and its provider references are stored with the financial record.
Vercel processes IP addresses, request and device information, runtime logs, diagnostics and performance information to operate its hosting services. It can derive approximate city and country from IP addresses, rather than precise GPS coordinates. See Vercel's Privacy Notice. These hosting activities are separate from information you share with other members.
Policy updates
Updates are posted here with a revised last-updated date. If a change requires additional notice or permission, updating this page alone does not replace that requirement.
Contact
A public support address has not been configured for this deployment yet. See Support.