Privacy Policy

Last updated 9 August 2026

GinCode is a hackathon and coding-competition platform. This policy describes exactly what we collect, why we hold it, who else sees it, and how you get it deleted. It covers gincode.online and the GinCode API.

1. Who we are

GinCode (“we”, “us”) is based in Kampala, Uganda, and operates the competition platform at gincode.online. We are the data controller for the information described below. For anything in this policy, write to gincode@gmail.com.

2. What we collect

We collect only what a competition platform needs to run. In practice that is:

  • Account details. Your name, email address and profile picture. If you register with a password we store a hash of it, never the password itself. If you sign in with Google we receive your name, email address and profile picture from Google and nothing else — we request only the openid, email and profile scopes, and we never gain access to your Gmail, Drive, Calendar or contacts.
  • Competition activity. The events you register for, the teams you join, your submissions (repository link, demo link, video link, written explanation and tech stack), the scores and written feedback your submissions receive, your ranking, and any certificate issued to you.
  • Payment details. When an event charges an entry fee we record the amount, the currency, the payment status, and the mobile-money phone number used to pay. We never see or store your card number, PIN or mobile-money password — those are entered with our payment provider, not with us.
  • Payout details. If you win prize money, the payout method and destination you give us (a mobile-money number or bank account) so we can pay you. This is collected only when it is needed.
  • Referral activity. Your referral code, and which accounts signed up through it, so referral rewards can be credited.
  • Basic usage data. Aggregate page-view analytics with no advertising profile attached, plus ordinary server logs.

We do not collect special-category data — no health, biometric, religious, political or racial information. Please do not put such data in a submission write-up.

3. Why we hold it, and on what basis

  • To perform our contract with you: creating your account, registering you for events, taking entry fees, judging submissions, publishing results, issuing certificates and paying prizes.
  • Because we have to by law: keeping records of payments for accounting and tax purposes.
  • Because we have a legitimate interest: keeping the platform secure, preventing fraud and duplicate entries, and fixing faults.
  • Because you consented: any optional marketing email. You can withdraw consent at any time and it will not affect your account.

4. What other people can see

Some information is public by design, because competitions are public:

  • Your name, profile picture, team membership, public leaderboard position and any certificate issued to you are visible to anyone, including people without a GinCode account. A certificate can be checked by its ID at /verify/<id>.
  • Your submission and its scores and feedback are visible to the organiser of that event and to its judges. Scores and rankings become public when the organiser publishes results.
  • Never public: your email address, your password, your payout details, and the phone number used to pay.

5. Who we share it with

We do not sell your data and we never have. We share it only with the service providers that make the platform work, and only with the part of it they need:

  • Neon — the database that stores everything above.
  • Vercel and Render — hosting for the website and the API, including aggregate page-view analytics.
  • MarzPay — processes mobile-money and card entry-fee payments. Receives the amount, a reference and your paying phone number.
  • Cloudinary — stores images and videos you upload, such as profile pictures, event banners and demo videos.
  • Google — only if you choose to sign in with Google.
  • AI judging providers. Submissions are scored by an AI panel, so the contents of your submission — the public repository contents, the write-up, the links and, where the organiser has enabled it, the demo video — are sent to the model provider configured for that event. Depending on the event this is one or more of Google (Gemini), Anthropic, OpenAI, DeepSeek, Groq or OpenRouter. Your name, email address, phone number and payout details are never included in what is sent for judging.

When you submit a public repository link we also fetch that repository’s public metadata and README from GitHub, and a public file from Google Drive if you link one. We only ever read what is already public.

We will also disclose information where the law requires it, or to establish or defend a legal claim.

6. Where your data goes

Our providers operate data centres outside Uganda, including in the European Union and the United States, so your data is transferred internationally. We only use providers that commit contractually to protecting it to a comparable standard.

7. How long we keep it

  • Your account: until you delete it.
  • Competition records — submissions, scores, rankings and certificates: kept indefinitely, because a certificate has to stay verifiable and a published result has to stay accurate. If you delete your account these are detached from your personal details.
  • Payment records: kept for as long as accounting and tax law requires, typically seven years, even after account deletion.
  • Server logs: a short rolling window, then discarded.

8. Your rights

You can ask us to:

  • give you a copy of the data we hold about you;
  • correct anything that is wrong — most of it you can edit yourself in your profile;
  • delete your account and personal data, subject to the payment and competition-record exceptions in section 7;
  • stop sending you marketing, which you may do at any time;
  • restrict or object to a particular use of your data.

Email gincode@gmail.com and we will respond within 30 days. If you believe we have mishandled your data, you may complain to the Personal Data Protection Office of Uganda, or to the data-protection authority where you live.

9. Security

Traffic is encrypted in transit. Passwords are stored only as hashes. Access to the production database is limited to the people who operate the platform. No system is perfectly secure, so if a breach affects you we will tell you and the relevant regulator without undue delay.

10. Children

GinCode is not intended for children under 13, and where an event charges an entry fee you must be 18 or older to pay. If you believe a child has given us personal data, write to gincode@gmail.com and we will remove it.

11. Cookies

We use cookies and similar browser storage to keep you signed in and to remember whether you chose light or dark mode. We do not use advertising or cross-site tracking cookies. Blocking the sign-in cookie will stop you from logging in.

12. Changes

If we change this policy we will update the date at the top of the page, and for any change that materially affects your rights we will tell account holders by email before it takes effect.