GreekCoreBook a demo
← Back to home

Privacy Policy

Last updated September 27, 2026

This Privacy Policy explains how GreekCore, Inc. (“GreekCore,” “we,” or “us”) handles information when chapters and members use our web workspace, mobile app, Chapter Account and card features, and public website (the “Service”).

Information we collect

  • Account and profile data — your Clerk account identifier, name, email addresses, phone number, profile photo, chapter memberships, roles, class or pledge year, address, birthday, emergency contacts, and social or payment-profile links you provide.
  • Chapter and user content — events and check-ins, announcements and comments, projects and tasks, recruitment records and notes, votes and polls, meal ratings, chat messages and attachments, contracts, documents, album photos and videos, and captions.
  • Payments and commerce — dues and payment ledger activity, contracts, merchandise orders, poll selections, marketplace redemptions, and Chapter Account and card activity. Stripe and its financial partners collect sensitive bank, card, and identity-verification details directly; GreekCore receives the records needed to operate and display those features.
  • Device and service data — IP address, request time, browser or device platform, device model, app version/build, random installation identifier, raw Expo push token, delivery/open status, and security or error logs.
  • Camera and media — photos you choose to capture or upload for albums, chat, your profile, or point-request proof, plus saved videos and file attachments where the Service supports them. The app takes still photos rather than recording video or voice notes; selected files or saved videos may contain audio. GreekCore does not access your camera or library in the background.
  • Precise location for attendance — when you choose a location-restricted event check-in, the app sends your current coordinates to check whether you are inside the event radius. If you choose Start tracking for an enabled event or study session and grant the requested location permissions, the app repeatedly reports your location to verify attendance and count time at the venue. This can continue while the app is in the background or the screen is locked. The event screen shows tracking status, and the operating system displays its location indicator or tracking notification. Choose Stop tracking on the event screen to stop that session; location reporting stops when no tracked sessions remain. You can also revoke location permission in device settings. Location is not collected for attendance tracking unless you start a session.

How we use information

We use this information to authenticate you; provide chapter, communication, file, payment, Chapter Account, and card features; deliver notifications; verify event attendance; prevent fraud and abuse; moderate user-generated content; support members; diagnose failures; and meet legal and recordkeeping obligations. We do not sell personal information or use it for cross-company advertising.

Cookies and analytics

Our public marketing and legal pages do not set analytics or advertising cookies. Signed-in web applications use only the session technology Clerk needs to authenticate you. The mobile app has no advertising SDK, advertising identifier, product analytics, session replay, or cross-app tracking. Crash reports may be sent to Sentry with personal-data collection disabled; server request and security logs can still contain an IP address, app version, route, timestamp, and error context.

Chat, notifications, and hosting providers

  • Stream processes chat profile identifiers, display name and image, channel membership, messages, files, images, video, reactions, reports, and blocks so chat works.
  • Knock processes your GreekCore identifier, name, email, phone number where a workflow uses SMS, notification preferences, and device/install metadata including the raw Expo push token so it can orchestrate in-app, email, SMS, and push delivery.
  • Expo relays mobile push notifications to Apple or Google when push is enabled.
  • Clerk provides authentication and stores sign-in identity data.
  • Stripe and its financial partners provide payments, Connect, Treasury, Issuing, identity verification, and financial account infrastructure.
  • Render and Neon host the API/worker and PostgreSQL database.
  • Cloudflare Pages and R2 host web applications and user-uploaded files/media.
  • Sentry receives configured crash reports; email and SMS delivery providers receive the destination and message data needed to deliver a notification.

User-generated content safety

GreekCore applies a deterministic text-policy gate to supported comments, notes, ratings, and captions. Every new album photo or video is checked automatically before publication: its file signature must match its file type, and camera and location metadata is stripped. Until the checks finish, only the uploader can see it, marked as processing. A file that passes is published to the album without a separate approval step; a file that fails is not published. These checks are technical and do not classify the content of a photo or video. Chat moderation relies on member reports and blocks rather than automated screening. Members can report supported content and block another member. GreekCore staff review an immutable report snapshot and may remove or dismiss content. We target review of safety reports within 24 hours and escalate credible imminent threats promptly; the target is not a guarantee.

How we share information

Content and profile fields are shared with chapter members and officers according to chapter roles and visibility settings. We share data with the providers above only to operate the Service, with advisers or acquirers under appropriate restrictions, or when law, safety, rights protection, or enforcement of our Terms requires it.

Retention and account deletion

We keep operational information while an account or chapter uses GreekCore and as needed for security, disputes, legal duties, and financial records. On deletion, memberships are deactivated and GreekCore deletes local profile fields, preferences, emergency contacts, devices, and raw push tokens. We then request deletion of the Clerk sign-in identity. If that provider call fails, the already-scrubbed local account is tombstoned so sign-in cannot restore its profile, and the deletion must be retried or investigated. Chat history remains part of other members’ conversations, but GreekCore asks Stream to replace your name with “Deleted user” and remove your profile image.

Chapter records that must remain coherent can survive with your user reference removed or your local user row anonymized. These can include dues/payment and accounting entries, audit trails, project/task/announcement comments, chat messages, album photos/videos and captions, vault files, and other shared content. Signed contracts retain their signer identity snapshot, and paid merchandise orders/invoices retain transaction and shipping details required as business records; those records can still identify you. Election ballots were anonymous when cast. Identifiable merchandise design-poll votes, marketplace application data, preferences, devices, raw push tokens, emergency contacts, and similar user-owned records are removed locally. Knock, Stream, Clerk, Expo, email/SMS, and other providers may retain delivery, security, or content records under their own legal/operational schedules. Provider cleanup is not represented as instantaneous.

Your choices and rights

You can correct many fields in the Service, disable notifications in device or account settings, revoke camera/photo/location permission in system settings, and delete your account. A machine-readable account export is currently available on the web only. Depending on where you live, you may also request access, correction, deletion, portability, restriction, or objection.

Security, age, and changes

We use encryption in transit and at rest, role-based access controls, tenant isolation, and other safeguards. No system is perfectly secure. The Service is intended for people at least 18 years old, or the age of majority where they live, and is not directed to children under 13. We may update this Policy; material changes will be dated above and communicated where appropriate.

Contact us

Questions or privacy requests: privacy@greekcore.com. Safety reports should normally use the in-product Report action so the report includes the correct content snapshot.