Privacy Notice
Effective date: 9 October 2026.
CampusLedger is the financial governance and recordkeeping service developed under NOVAHEX at campusledger.me. For privacy questions or requests, contact charlesngatia522@gmail.com.
Information used by the service
We process the account details you provide, including your name and email address; organization memberships and roles; contributions, budgets, expenses, approvals, payment references and reconciliation records; and supporting documents you upload. Records may include phone numbers, payee information and payment-account details where you or your organization supply them. Only upload information you are authorized to share.
For security, we process password hashes, encrypted authenticator-app setup information, recovery-code hashes, passkey public credentials, sessions and authentication activity. Your device handles passkey fingerprints, face recognition or device unlock; CampusLedger does not receive your biometric template or device unlock code. Service providers may process connection information such as your IP address and browser details when you use the service.
Google and GitHub sign-in
If you choose Google sign-in, we request only OpenID identity and email access. We use your Google account identifier and verified email address to authenticate you and, when you explicitly choose to link it, associate that identity with your CampusLedger account. We do not request access to Gmail messages, Drive files, contacts or calendars. GitHub sign-in uses your GitHub account identifier and verified primary email address; it does not request repository access.
Provider access tokens are used for the sign-in exchange and are not retained as ongoing access credentials. CampusLedger keeps the linked provider identifier until the link is removed or the account is handled through a deletion request. Provider identity data is used for account access and security, not advertising or sale. Account security lets you remove a linked provider when another sign-in method remains. You can also revoke CampusLedger access in your Google or GitHub account settings. Revoking provider access does not itself erase organization records.
Purposes and recipients
We use information to provide account access, verify email ownership, protect against abuse, manage organization permissions, record financial activity, support approvals and reconciliation, and investigate service or security problems.
Organization information is shared with authorized members according to their roles. Organization administrators manage membership and access. CampusLedger support may need to review information to investigate an issue or fulfill a request. Do not send passwords, verification codes or recovery codes to support.
Microsoft Azure provides hosting, database, file storage, secret management and monitoring infrastructure. Cloudflare Turnstile provides security verification. Resend delivers authentication emails and processes the recipient address and delivery information. Google and GitHub process sign-in under their own policies when you select them. Where enabled, external payment providers such as M-Pesa/Daraja or Paystack process payment-related information under their own terms. CampusLedger does not hold organization funds. Providers may process data outside your country, depending on their infrastructure and service arrangements.
We may disclose information when necessary to address abuse, protect users, or respond to a valid legal requirement. We do not sell account or organization data or use Google identity data for advertising.
Cookies, storage and security
The service uses cookies and browser storage needed for sessions, security checks and sign-in flows. Blocking essential cookies can prevent sign-in. Security controls include encrypted connections, role-based access, mandatory multi-factor authentication and protected secret storage. No system can guarantee absolute security.
Retention and your choices
Account and organization records are retained to operate the service, preserve financial audit history, resolve disputes and meet applicable obligations. There is no published fixed deletion schedule or automatic account-deletion feature at this time. Authentication challenges expire; their expiry does not necessarily mean every associated record or backup is immediately erased.
Contact the address above to request access, correction, export or deletion, or to raise a privacy concern. We may verify your identity and coordinate with your organization. Organization financial records and audit history may need to remain even when account access is removed; we will explain any applicable limitations. Backup copies may remain until normal backup expiry. Rights available to you depend on applicable law.
Updates
We will update the date on this notice when it changes. Review it when using new features. Material changes affecting how information is used will be communicated through the service or account contact information where appropriate.