Campus Connect
Privacy Policy
Last updated: 26 July 2026
Campus Connect is a guest-first university communication product. Students can browse published announcements and events without creating an account. This policy explains what information is processed when you use the student app or the staff administration portal.
Who this policy covers
- Students and visitors using the mobile app as guests
- University staff who sign in to publish content
Information we process
Guest mobile app
- Device-generated installation identifiers used only when push notifications are enabled
- Push notification tokens (for example Firebase Cloud Messaging tokens) needed to deliver optional alerts
- Basic technical request data such as approximate time of access and platform (iOS or Android) associated with notification registration
The guest app does not require a student name, email address, student ID, or password.
Staff administration portal
- Staff name, work email address, role, and password credentials
- Session cookies used to keep staff signed in securely
- Content authored by staff, including announcement and event text, scheduling metadata, and optional images
Media uploads
Images uploaded by staff are stored in Cloudflare R2 object storage and served through the configured media URL so published content can be shown in the student app.
How we use information
- Publish and display university announcements and events
- Authenticate and authorize staff users
- Send optional push notifications when staff choose to notify
- Operate, secure, and troubleshoot the service
Push notifications
Notifications are optional. If you enable them, Campus Connect stores an anonymous installation identifier and push token so the university can deliver alerts about published content. You can disable notifications in the app; doing so stops future delivery and marks the stored token as disabled.
Sharing
We use service providers that process data on our behalf to run Campus Connect, including hosting, database, object storage (Cloudflare R2), and push delivery (Firebase). We do not sell personal information.
Retention
- Published content and staff accounts are retained while the university operates the service, unless staff delete or archive that content
- Disabled push tokens may be retained briefly for operational cleanup and then removed or ignored
- Operational backups of the database may exist for disaster recovery according to the university's hosting practices
Security
Staff passwords are stored as one-way hashes. Staff sessions use HTTP-only cookies. Production traffic should be served over HTTPS through a reverse proxy. Access to staff tools is limited to authorized university accounts.
Your choices
- Browse as a guest without enabling notifications
- Disable push notifications at any time in the app
- Staff may request account deactivation through a university administrator
Children
Campus Connect is intended for university communications. It is not directed at children under 13, and it does not knowingly collect account information from children.
Contact
For privacy questions about Campus Connect, contact the university support email shown in the mobile app's More screen or configured in the staff settings portal. For product operation questions from the hosting team, use the university's designated IT contact.
Changes
We may update this policy as the product or hosting setup changes. The “Last updated” date at the top of this page will change when we do.