01 · Information collected
Only what is needed to operate CSC activities.
We use approved-member records and profile information such as name, email, phone, company, role, industry, city, photo, bio, professional social links, sports interests and sport-specific skill level. Event records include registration, payment-receipt review, attendance, team assignment, result and achievement badge data.
Revenue information and business supporting documents from the original CSC application are not imported.
02 · Purpose and choice
Account access, event operations, safety and trusted networking.
CSC uses this information to verify approved membership, deliver secure sign-in links, manage event capacity and payment review, check members in, create balanced teams, issue results and badges, send operational notices, prevent abuse, and enable event-scoped connections.
Phone/WhatsApp sharing is optional and can be changed in the member profile at any time.
03 · Visibility
No public directory and no cross-event attendee list.
- Email addresses are never shown in the attendee directory.
- Confirmed registrants can see the name and company of other confirmed registrants for the same activity before check-in.
- Full profiles, including photos, biographies and professional social links, remain available only to checked-in CEOs from the same activity.
- Phone/WhatsApp appears in that checked-in directory only when the member opts in.
- Staff with an individual login and two-factor authentication can access information needed for operations.
- Payment receipts are private to their owner and authorized staff.
04 · Service providers and location
Controlled processors, not advertisers.
The portal uses Supabase for authentication, database and private storage; Vercel for application hosting; Resend or CSC’s SMTP provider for email; and Cloudflare Turnstile for abuse prevention. They process data only to provide these services under CSC’s configuration and agreements. The configured primary data region is Singapore (ap-southeast-1). CSC does not sell member data.
05 · Retention
Delete operational copies when their purpose ends.
- Uploaded payment-receipt images: 180 days after a completed or cancelled event, after manual reconciliation.
- Expired opaque event-pass records: seven days; scanner security attempts: 30 days.
- Authentication-abuse hashes: 30 days; expired invitation-use records: 90 days.
- Sent email queue records: 90 days; routine portal notifications: one year.
- Security audit logs: two years, unless an active investigation requires a documented hold.
- Profile, attendance, team and achievement history remains while the membership account is active or while CSC has a documented operational or legal need.
06 · Access and correction
You can ask what CSC holds and request changes.
Members may update profile fields directly and may request access, correction, withdrawal of optional phone sharing, account deletion or information about processors and transfers. CSC will verify identity before fulfilling a request and explain any information it must retain.
Contact privacy owner07 · Security and incidents
Layered access controls and accountable staff actions.
Controls include allowlisted activation, one-time magic links, mandatory staff MFA, database Row Level Security, private object storage, short-lived signed asset access, re-encoded uploads, opaque rotating QR passes, rate limits, security headers and attributed audit history. If a suspected breach affects member information, CSC will contain and assess it, preserve evidence, and make required notifications under the applicable process.