Legal
Privacy Policy
1. Who we are
Hackollab (“Hackollab”, “we”, “us”, “our”) is a UK student collaboration product that helps university builders find partners, ship projects, and publish peer-verified proof of work.
Hackollab is operated by its founders: Maahir Shah (CEO) and Sahil Basumatary (CTO). For privacy purposes, the primary contact is Sahil Basumatary. Until a UK limited company is incorporated and named in an updated version of this policy, the founders of Hackollab are the data controllers for personal data processed through the service.
Privacy contact: sahil@sahilbasumatary.dev
Website: https://hackollab.com
2. Scope
This policy covers personal data we process when you:
- visit our marketing or product websites;
- create an account or sign in;
- complete onboarding or edit your profile;
- use projects, partner discovery, forum, requests, proof, leaderboards, or settings;
- publish or view public profiles and public proof pages;
- contact us about privacy or support.
The service is currently intended for UK university students (in particular King’s College London users with eligible institutional email addresses). Access may be limited by email allowlists or similar controls.
3. Personal data we collect
We collect the categories below. Exact fields depend on what you choose to provide.
3.1 Account and identity
- name and email address;
- authentication identifiers from our auth provider (Clerk), including user ID;
- username and profile photo (if provided);
- sign-in and security settings you manage through Clerk (for example password, passkeys, or multi-factor authentication where enabled).
3.2 Profile and connections
- bio, pronouns, role, skills, interests, and solo/team preferences;
- optional linked profiles or booking links (for example GitHub, LinkedIn, Discord, calendar URLs) and whether you choose to show them publicly;
- other social links you add;
- profile visibility settings (including private profile).
3.3 Product activity
- projects you create or join (name, description, stack, status, progress, visibility);
- build-log updates and contribution notes;
- forum threads, posts, tags, votes, and related in-app notifications;
- invites, join requests, messages, and related request status;
- peer signatures / attestations and related statements;
- published proof pages (slug, summary, publish time, and related public content);
- leaderboard-relevant activity derived from published and attested work;
- in-app notifications and notification preferences;
- product preferences (theme, timezone, language, startup page, shortcuts);
- cookie preference choices.
3.4 Technical and usage data
- IP address, device/browser information, and approximate location derived from network data;
- pages visited, timestamps, referrers, and diagnostic logs;
- cookies and similar technologies as described in section 8.
3.5 Data from third parties
- Clerk provides authentication and account security. When you sign up or sign in, Clerk processes identity data and may send us account events (for example create/update/delete) via secured webhooks.
- If you later connect social accounts through verified OAuth (for example Discord or LinkedIn), we may receive verified account identifiers and basic profile information those providers release with your consent.
- Hosting, database, and file storage providers process technical data as our processors (see section 6).
3.6 Early-access list
- first name and KCL email if you join from the marketing page (this does not create an account);
- a hashed network identifier and limited browser string used only to rate-limit abuse.
We use this only to send the occasional notes you asked for, and to honour unsubscribe requests. You can leave the list from the link in those emails.
We do not require special-category data (such as health, religion, or political opinions). Please do not submit that kind of information in profiles, messages, forum posts, or proof content.
4. Why we use your data (purposes and lawful bases)
Under UK GDPR we need a lawful basis for each purpose. The main bases we rely on are contract, legitimate interests, consent, and legal obligation.
| Purpose | Lawful basis |
|---|---|
| Create and manage your account; authenticate you; keep the service secure | Contract; legitimate interests (security) |
| Provide core product features (projects, partners, forum, requests, proof, leaderboards, settings) | Contract |
| Show public profiles and published proof pages you choose to make public | Contract; legitimate interests (showing verified student work) |
| Send product notifications you enable (inbox, project activity, digests) | Contract; consent where required for optional email |
| Remember preferences and cookie choices | Legitimate interests; consent for non-essential cookies |
| Prevent abuse, debug outages, and maintain service integrity | Legitimate interests; legal obligation where applicable |
| Respond to privacy or support requests | Legitimate interests; legal obligation |
| Optional product updates / marketing emails (if you opt in) | Consent (you can withdraw anytime) |
Where we rely on legitimate interests, we balance those interests against your rights and expectations as a student user of a collaboration and proof product.
5. Public information
Some content is designed to be public when you publish or when your profile is not set to private. That can include your display name, username, bio, selected skills, badges, linked connection links you mark as visible, and published proof pages.
Peer attestations on published builds may identify teammates who participated. If a member’s profile is private, we redact identifying fields where the product supports that, while still reflecting that a person contributed.
Public pages may be indexed by search engines or shared by others. Think carefully before publishing.
6. Who we share data with
We do not sell your personal data. We share data only as needed to run Hackollab, with your direction, or where the law requires.
- Other users — according to product visibility (for example teammates on a project, or the public internet for published proof).
- Clerk — authentication and account security (Clerk privacy).
- Vercel — application hosting, edge/network logs, and optional file storage such as avatars (Vercel privacy).
- Neon / PostgreSQL hosting — primary application database storage (Neon privacy).
- Resend — email delivery for the early-access list when that mail path is enabled (Resend privacy).
- Professional advisers or authorities — if required to comply with law, enforce terms, or protect rights, safety, and security.
- Successors — if Hackollab is involved in a reorganisation, incorporation, financing, or transfer of assets, personal data may transfer under appropriate safeguards and notice where required.
These providers act as processors or independent controllers depending on the service. We configure them to support Hackollab’s purposes and UK user expectations as far as practicable.
7. International transfers
Some providers may process data outside the UK (for example in the EEA or United States). Where that happens, we rely on appropriate transfer mechanisms available to those providers, such as adequacy regulations or standard contractual clauses, together with their security and access controls.
8. Cookies
We use cookies and similar technologies in these groups:
- Necessary — sign-in, security, load balancing, and core preferences needed to operate the service. These stay on.
- Preferences — remembering choices such as interface preferences where stored client-side.
- Analytics — understanding product usage only if you allow them.
- Marketing — only if you allow them.
You can review or change non-essential cookie choices in product settings (Preferences → cookies) or through the cookie banner where shown. Browser controls can also block cookies, but necessary cookies may be required for sign-in to work.
9. Retention
We keep personal data only as long as needed for the purposes above:
- Account data — for as long as your account remains open.
- Project, proof, and attestation data — while needed to provide the product and maintain the integrity of published proof; public proof may remain available until unpublished, deleted, or otherwise removed under product rules.
- Early-access list — until you unsubscribe, after which we keep a suppression record so we do not email you again by mistake.
- Security and server logs — for a limited operational period, then deleted or aggregated.
- Legal holds — longer where we must retain data for disputes, security investigations, or legal obligations.
When you delete your account, we delete or anonymise personal data we control, except where retention is required by law or needed to preserve the integrity of already published multi-person proof records (for example replacing your identity with a redacted label rather than rewriting history falsely).
10. Security
We use technical and organisational measures appropriate to a student collaboration product, including encrypted transport (HTTPS), access-controlled cloud infrastructure, authenticated APIs, and least-privilege practices for production systems. No method of transmission or storage is perfectly secure. If we become aware of a personal data breach that must be notified under UK law, we will do so as required.
11. Your rights
Under UK GDPR you may have the right to:
- access your personal data;
- correct inaccurate data;
- request deletion;
- restrict or object to certain processing;
- data portability for data you provided to us;
- withdraw consent where processing is consent-based;
- complain to the UK Information Commissioner’s Office (ICO).
To exercise these rights, email sahil@sahilbasumatary.dev. We may need to verify your identity first. You can also update many profile and preference fields directly in Settings, and leave the early-access list from the unsubscribe link in those emails.
ICO website: https://ico.org.uk
12. Children
Hackollab is aimed at university students in the UK. It is not directed at children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data, contact us and we will take appropriate steps.
13. Automated decision-making
We use product logic such as match scoring and leaderboard ranking based on activity you generate in the service. These features help surface relevant partners or rankings. They are not used to make legal or similarly significant decisions about you without human involvement.
14. Changes to this policy
We may update this policy as Hackollab evolves (for example when we incorporate a company, add OAuth connections, or expand beyond the UK). We will change the “Last updated” date above and, where changes are material, provide additional notice in the product or by email where appropriate.
15. Contact
Questions about this policy or your personal data:
Hackollab — Privacy
Email: sahil@sahilbasumatary.dev
Web: https://hackollab.com