Privacy Policy
Last updated September 4, 2026
This Privacy Policy explains how GreekCore, Inc. (“GreekCore,” “we,” or “us”) handles information when chapters and members use our web workspace, mobile app, banking features, and public website (the “Service”).
Information we collect
- Account and profile data — your Clerk account identifier, name, email addresses, phone number, profile photo, chapter memberships, roles, class or pledge year, address, birthday, emergency contacts, and social or payment-profile links you provide.
- Chapter and user content — events and check-ins, announcements and comments, projects and tasks, recruitment records and notes, votes and polls, meal ratings, chat messages and attachments, contracts, documents, album photos and videos, and captions.
- Payments and commerce — dues and payment ledger activity, contracts, merchandise orders, poll selections, marketplace redemptions, and banking activity. Stripe and its financial partners collect sensitive bank, card, and identity-verification details directly; GreekCore receives the records needed to operate and display those features.
- Device and service data — IP address, request time, browser or device platform, device model, app version/build, random installation identifier, raw Expo push token, delivery/open status, and security or error logs.
- Camera and media — photos or videos you choose to capture or upload for albums, chat, or your profile. GreekCore does not access your camera or library in the background.
- Precise location for event check-in — only when you choose to check in to a location-restricted event, the app obtains your current precise coordinates and sends them once to determine whether you are inside the event radius. We do not continuously or in the background track location.
How we use information
We use this information to authenticate you; provide chapter, communication, file, payment, and banking features; deliver notifications; verify event attendance; prevent fraud and abuse; moderate user-generated content; support members; diagnose failures; and meet legal and recordkeeping obligations. We do not sell personal information or use it for cross-company advertising.
Cookies and analytics
Our public marketing and legal pages do not set analytics or advertising cookies. Signed-in web applications use only the session technology Clerk needs to authenticate you. The mobile app has no advertising SDK, advertising identifier, product analytics, session replay, or cross-app tracking. Crash reports may be sent to Sentry with personal-data collection disabled; server request and security logs can still contain an IP address, app version, route, timestamp, and error context.
Chat, notifications, and hosting providers
- Stream processes chat profile identifiers, display name and image, channel membership, messages, files, images, video, reactions, reports, and blocks so chat works.
- Knock processes your GreekCore identifier, name, email, phone number where a workflow uses SMS, notification preferences, and device/install metadata including the raw Expo push token so it can orchestrate in-app, email, SMS, and push delivery.
- Expo relays mobile push notifications to Apple or Google when push is enabled.
- Clerk provides authentication and stores sign-in identity data.
- Stripe and its financial partners provide payments, Connect, Treasury, Issuing, and identity/banking infrastructure.
- Render and Neon host the API/worker and PostgreSQL database.
- Cloudflare Pages and R2 host web applications and user-uploaded files/media.
- Sentry receives configured crash reports; email and SMS delivery providers receive the destination and message data needed to deliver a notification.
User-generated content safety
GreekCore applies a deterministic text-policy gate to supported comments, notes, ratings, and captions. Every new album photo or video is held before publication: its file signature is checked and camera metadata is stripped, and it is published only after GreekCore staff approve it. Until then only the uploader can see it, marked as in review. Chat moderation relies on member reports and blocks rather than automated screening. Members can report supported content and block another member. GreekCore staff review an immutable report snapshot, may remove or dismiss content, and can approve, reject, or retry quarantined media. We target review of safety reports within 24 hours and escalate credible imminent threats promptly; the target is not a guarantee.
How we share information
Content and profile fields are shared with chapter members and officers according to chapter roles and visibility settings. We share data with the providers above only to operate the Service, with advisers or acquirers under appropriate restrictions, or when law, safety, rights protection, or enforcement of our Terms requires it.
Retention and account deletion
We keep operational information while an account or chapter uses GreekCore and as needed for security, disputes, legal duties, and financial records. On deletion, memberships are deactivated and GreekCore deletes local profile fields, preferences, emergency contacts, devices, and raw push tokens. We then request deletion of the Clerk sign-in identity. If that provider call fails, the already-scrubbed local account is tombstoned so sign-in cannot restore its profile, and the deletion must be retried or investigated. Chat history remains part of other members’ conversations, but GreekCore asks Stream to replace your name with “Deleted user” and remove your profile image.
Chapter records that must remain coherent can survive with your user reference removed or your local user row anonymized. These can include dues/payment and accounting entries, audit trails, project/task/announcement comments, chat messages, album photos/videos and captions, vault files, and other shared content. Signed contracts retain their signer identity snapshot, and paid merchandise orders/invoices retain transaction and shipping details required as business records; those records can still identify you. Election ballots were anonymous when cast. Identifiable merchandise design-poll votes, marketplace application data, preferences, devices, raw push tokens, emergency contacts, and similar user-owned records are removed locally. Knock, Stream, Clerk, Expo, email/SMS, and other providers may retain delivery, security, or content records under their own legal/operational schedules. Provider cleanup is not represented as instantaneous.
Your choices and rights
You can correct many fields in the Service, disable notifications in device or account settings, revoke camera/photo/location permission in system settings, and delete your account. A machine-readable account export is currently available on the web only. Depending on where you live, you may also request access, correction, deletion, portability, restriction, or objection.
Security, age, and changes
We use encryption in transit and at rest, role-based access controls, tenant isolation, and other safeguards. No system is perfectly secure. The Service is intended for people at least 18 years old, or the age of majority where they live, and is not directed to children under 13. We may update this Policy; material changes will be dated above and communicated where appropriate.
Contact us
Questions or privacy requests: [email protected]. Safety reports should normally use the in-product Report action so the report includes the correct content snapshot.