Legal
Privacy policy
Last updated 17 September 2026
This page explains what FindHackathons collects about you, why, and what you can do about it. The short version: we keep only what the service needs to sign you in, verify your hackathon results and show the profile you choose to make public. We do not run ads or sell data.
What we collect
Account. Your email address, the display name you choose and your username. If you sign in with GitHub, we store your GitHub username, your GitHub account id and the verified email GitHub reports. Sign-in codes are stored hashed and expire after fifteen minutes.
Devpost. When you link a Devpost profile we read its public pages and keep your Devpost username and the public list of your projects, submissions, prizes and hackathons entered, including project names, thumbnails and links. While the profile stays linked we refresh this nightly so certificates reflect published results.
Certificates. The full name you choose to appear on certificates, the prize, project and hackathon each one records, when it was issued, and whether it was revoked and why.
Security records. The IP address and browser identifier of each sign-in and session, used only for rate limiting and abuse prevention. Actions organizers and admins take on a listing are written to an audit log with their account id.
Organizer data. For organizers: the hackathons you manage, who invited you, and edits you make, including any images you upload and the signature name and role you register for certificates.
What is public
Nothing is public until you choose a username. After that, your profile at /u/your-username shows what your visibility settings allow: wins, projects, hackathons entered, and your GitHub and Devpost handles. Your email is hidden unless you turn it on. You can switch the whole profile off.
A certificate is public by design: anyone who has its link or scans its code can open it and see the recipient name, the award, the hackathon, the year and the issue date. You can hide a certificate from your profile, but the link keeps resolving, because that is what makes it checkable.
Cookies
One cookie keeps you signed in for up to ninety days. During Google or GitHub sign-in a second, short-lived cookie protects the hand-off. There are no analytics or advertising cookies and no third-party trackers.
We email you only for things you set in motion or need to know about: sign-in codes, organizer invitations, ownership transfers and notices about a certificate you hold. There is no newsletter.
Where it lives and who sees it
The service runs on Amazon Web Services in the United States. Email is sent through Amazon SES. Devpost and GitHub are separate services with their own policies; we read from them, we do not write to them. We do not share your data with anyone else, except where the law requires it.
How long we keep it
Sign-in codes for fifteen minutes. Sessions until you sign out or ninety days pass. Imported Devpost data until you unlink, at which point everything not recorded on an issued certificate is deleted. Certificates are kept as long as the service runs, because people rely on the links.
Your choices
Edit your name, username and visibility on your profile page. Unlink Devpost or disconnect GitHub there too. To delete your account, email us from the address on the account (see contact). We then remove your email, name, sessions, sign-in methods and imported data. Certificates already issued stay verifiable under the recipient name printed on them, since they record a published result; ask if you want one revoked as well. You can also ask for a copy of the data we hold about you.
Age
The service is for people taking part in collegiate hackathons and is not intended for anyone under 13. If you believe a younger child has created an account, contact us and we will remove it.
Changes
When this policy changes, the date at the top changes with it. Substantive changes to what we collect are announced on the site before they take effect.
Questions about this page? Contact us.