Legal
Privacy Policy
This Privacy Policy explains how TakeAttend collects, uses, stores, and protects your personal information. We respect your privacy and are committed to handling your data responsibly.
1. Who We Are
TakeAttend ("we", "us", "our") operates the attendance management platform accessible at this website. We are the data controller responsible for the personal information we collect through the Platform, and we act as a data processor for attendee data that an organization's organizers and staff add to their own event rosters.
If you have any questions about how we handle your data, please see Section 12 for our contact details.
2. Data We Collect
2.1 Information you provide directly
- Account information - first name, last name, email address, phone number, date of birth, and password (stored as a one-way hash) when you register.
- Organization & event content - your organization's name, any custom grouping labels you set up (such as Stakes/Wards) and the groups themselves, and each event's title, date, and description.
- Attendee roster data - when you or your staff add someone to an event roster, we store the details provided: first and last name, phone, email, membership status, group assignment, living area, and number of dependents. Attendees who use self check-in only provide a first and last name.
- Profile photo - an optional image you upload to your profile.
- Communications - any messages you send to us through contact forms or support channels.
2.2 Information collected automatically
- Usage data - pages visited and features used on the Platform.
- Device and connection data - IP address, browser type, operating system, and device type, collected when you access the Platform.
- Session data - login timestamps and session identifiers used to keep you signed in.
- Remember Me tokens - a secure token stored in a cookie on your device if you choose "Remember me" at login, allowing automatic sign-in on return visits.
2.3 Information we do not collect
We do not collect payment card details directly. Where paid plans are available, payments are processed by a third-party payment processor and we do not store your full card number on our servers. We do not collect government-issued ID numbers.
3. How We Use Your Data
We use the information we collect to:
| Purpose | Legal basis |
|---|---|
| Create and manage your account | Contract performance |
| Let you create and manage organizations, events, and attendee rosters | Contract performance |
| Power self check-in and keep an organizer's roster up to date | Contract performance |
| Send transactional emails (account confirmation, staff invites, password reset) | Contract performance |
| Send push notifications you opt into | Consent |
| Detect and prevent fraud and abuse | Legitimate interest |
| Improve the Platform through aggregated usage analytics | Legitimate interest |
| Comply with legal obligations | Legal obligation |
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects. We do not sell your personal data to third parties. We do not display advertising on the Platform.
4. Data Sharing
4.1 Within an organization
When you or your staff add someone to an event roster, that attendee's details - name, contact information, group assignment, and check-in status - are visible to the admins and staff of that organization within their dashboard. Attendee data is never shared with other organizations or made public.
An event's public check-in page only shows the organization name, event title, and date - no roster or attendee data is displayed publicly.
4.2 With service providers
We share data with trusted third-party service providers who help us operate the Platform, including:
- Cloud storage - profile photos are stored on a cloud object storage service (S3-compatible). Files are stored securely and are only accessible through our Platform.
- Email delivery - transactional emails are sent through a third-party email service. We only share the minimum data needed (your name and email address) to deliver these messages.
- Push notifications - if you opt in, browser push notifications are delivered through a third-party push service using a subscription token tied to your device.
- Payments - if your organization is on a paid plan, payment processing is handled by a third-party payment processor.
- Hosting - our Platform is hosted on a third-party cloud hosting provider.
All service providers are contractually required to process your data only as instructed by us and to maintain appropriate security standards.
4.3 Legal requirements
We may disclose your information if required to do so by law, court order, or in response to a valid request from a government authority, or if we believe disclosure is necessary to protect the rights, property, or safety of TakeAttend, our users, or the public.
5. Cookies
We use the following types of cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Keeps you signed in during your visit | Until browser is closed |
| Remember Me token | Keeps you signed in across visits when requested | 30 days |
| CSRF token | Protects forms from cross-site request forgery | Session |
We do not use advertising cookies, tracking pixels, or third-party analytics cookies. You can control cookies through your browser settings. Disabling session cookies will prevent you from signing in to the Platform.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide our services.
- Account data - retained while your account is active. If you close your account, we delete or anonymise your personal data within 30 days, except where we are required by law to retain it longer.
- Organizations, events & rosters - deleted or anonymised within 30 days of account closure or organization deletion.
- Profile photos - deleted from our storage within 30 days of account closure.
- Logs - security and access logs are retained for up to 12 months for fraud prevention purposes.
7. Security
We take reasonable technical and organisational measures to protect your personal data, including:
- Passwords are stored as bcrypt hashes - never in plain text
- HTTPS encryption on all data in transit
- CSRF protection on all forms
- Session regeneration on login
- S3 object storage with access controls on uploaded files
- IP address and device logging for session security
No system is completely secure. In the event of a data breach that poses a risk to your rights, we will notify affected users and the appropriate authorities as required by law.
8. Your Rights
You have the following rights regarding your personal data:
- Access - you can request a copy of the personal data we hold about you.
- Correction - you can update your name, phone number, and profile photo directly from your profile page. Contact us to correct other data.
- Deletion - you can request deletion of your account and associated data. We will action requests within 30 days.
- Portability - you can request an export of your personal data in a machine-readable format.
- Objection - you can object to processing based on legitimate interests. We will consider your request and respond within 30 days.
- Withdraw consent - where processing is based on consent, you may withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact us using the details in Section 12. We may need to verify your identity before actioning your request.
If you are an attendee and believe an organization has added inaccurate information about you to a roster, please contact that organization directly - they control the content of their own rosters. If you're unable to reach them, contact us and we'll assist where we can.
9. Children's Privacy
The Platform is not intended for anyone under 18 years of age. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a minor, please contact us and we will delete it promptly.
10. Third-Party Links
The Platform may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. We recommend reading the privacy policy of any website you visit.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and notify registered users by email or through a notice on the Platform.
We encourage you to review this page periodically. Continued use of the Platform after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights, or want to report a concern about how we handle your data, please contact us:
TakeAttend