Privacy Policy
Updated 8/23/2026
# ICPH Platform Privacy and Data Protection Notice
Last Updated: August 22, 2026
## 1. Introduction
ICPH is committed to protecting the privacy, security, and confidentiality of individuals who use, access, participate in, or interact with the ICPH digital platform.
This Privacy and Data Protection Notice explains the types of information that may be collected and processed through the platform, why such information may be necessary, how it may be used, who may be permitted to access it, and the measures taken to protect information from unauthorized access, disclosure, alteration, misuse, or loss.
The ICPH platform may provide services and features including, but not limited to, member management, zone administration, public member verification, event management, QR-based attendance, event attendance records, event photo albums, optional venue or location verification, zone information, uploaded media, support communications, and administrative management.
By accessing or using the platform, users acknowledge that certain information may be processed as reasonably necessary to provide these services and maintain the security and integrity of the ICPH community.
Public disclosure of information is limited to information that has been specifically designated, approved, or authorized for public display.
---
## 2. Scope of This Notice
This Privacy and Data Protection Notice applies to information processed through the official ICPH platform, including information associated with:
* ICPH members;
* Zone Leaders and other authorized zone officers;
* Administrators and authorized ICPH leadership;
* Event organizers and event participants;
* Visitors using public verification services;
* Individuals submitting support requests;
* Individuals interacting with public ICPH pages; and
* Other authorized users of the platform.
Different levels of access may apply depending on the user's role, responsibilities, and authorization within ICPH.
---
## 3. Information the Platform May Process
Depending on the features being used and the user's role within the platform, ICPH may process different categories of information.
### 3.1 Member Identity and Membership Information
The platform may process information necessary to establish, maintain, manage, and verify ICPH membership records.
This information may include:
* Member name;
* Badge or membership number;
* Assigned ICPH zone;
* Membership status;
* Registration or activation information;
* Profile information;
* Membership-related identifiers;
* Approved profile photograph;
* Account information;
* Membership history; and
* Other information reasonably necessary for membership administration.
Access to member information may be restricted according to the responsibilities and authorization level of the person accessing the platform.
Not all information contained in a member's internal record is intended to be publicly available.
---
## 4. Zone Information
The platform may process information relating to official ICPH zones for organizational, administrative, directory, mapping, and community purposes.
Zone information may include:
* Zone name;
* Zone code or identifier;
* Zone description;
* Assigned Zone Leader;
* Geographic coverage or service area;
* Zone boundaries;
* Approved contact information;
* Zone logo, banner, or media;
* Zone statistics;
* Upcoming or previous events;
* Local sponsors where applicable; and
* Other information approved for display by authorized ICPH leadership.
Certain zone information may be publicly visible because the platform may provide a public directory or interactive map showing officially recognized ICPH zones.
Administrative information that is not intended for public use will remain restricted to authorized accounts.
---
## 5. Public Member Verification
The ICPH platform may provide a public verification service allowing individuals to verify whether a person or membership credential is associated with an official ICPH membership record.
The purpose of this service is to help protect the integrity of ICPH membership and reduce unauthorized claims of membership.
Public verification results are designed to disclose only limited information that has been approved for public verification.
The platform should not expose unnecessary private account information through the public verification system.
Information such as passwords, private communications, authentication information, administrative notes, session information, and other restricted data is not intended to be displayed through public verification.
ICPH may modify the information displayed on public verification pages when necessary to protect members, improve security, or comply with organizational policies.
---
## 6. Event Management and Attendance Records
Authorized Zone Leaders or other authorized ICPH officers may create events through the platform.
Events may include:
* Tambike or community gatherings;
* Eyeballs or EB events;
* Meetings;
* Rides;
* Charity activities;
* National events;
* Local zone activities;
* Official gatherings; and
* Other authorized ICPH activities.
For events using the platform's attendance system, participants may be required to provide or verify information such as their badge number, membership identifier, name, or other approved information.
Attendance records may contain:
* Event information;
* Member identifier;
* Badge number;
* Attendance date;
* Attendance time;
* Verification status;
* Check-in information;
* Event participation status; and
* Other information reasonably required to establish attendance.
Attendance records are maintained for legitimate organizational purposes, including event administration, participation records, statistics, recognition, security, and internal reporting.
---
## 7. QR Code Attendance
Certain ICPH events may use QR codes to facilitate attendance registration.
When an authorized event organizer enables this feature, participants may scan an event QR code and submit the requested attendance information.
QR codes may be publicly visible at the event venue or distributed through authorized ICPH channels.
However, the existence of a public QR code does not automatically make the resulting attendance records public.
Attendance information collected through the QR attendance system is considered an organizational record and should only be accessible to individuals with appropriate authorization unless specific information has been approved for public display.
ICPH may implement safeguards designed to prevent duplicate, fraudulent, automated, or unauthorized attendance submissions.
---
## 8. Event Attendance Photos
Certain ICPH events may allow authorized organizers to collect or upload photographs related to attendance or event participation.
Attendance proof photographs may be used for purposes such as:
* Confirming event participation;
* Supporting attendance verification;
* Preventing fraudulent attendance;
* Resolving attendance disputes;
* Maintaining internal event documentation; and
* Supporting legitimate organizational records.
Attendance proof photographs are considered private by default.
They are not automatically published simply because they were submitted through the attendance system.
Access should be limited to authorized individuals who require the information for legitimate event or administrative purposes.
---
## 9. Public Event Photo Albums
Event photographs may be published separately as part of an approved public event photo album.
A private attendance proof photograph does not automatically become a public event photograph.
Publication requires an authorized manager, Zone Leader, administrator, or other person with appropriate permissions to deliberately select or approve the photograph for publication.
This distinction is intended to separate internal attendance verification from public community documentation.
Authorized managers should review photographs before publication and should avoid publishing photographs that are inappropriate, unnecessarily sensitive, misleading, or unrelated to the event.
Where appropriate and reasonably possible, requests concerning published photographs may be submitted to authorized ICPH leadership for review.
---
## 10. Optional Location Verification
Certain events may enable venue or location verification as an additional method of confirming that an attendance submission is being made from an appropriate event location.
Location information is not intended to be requested continuously or by default for every platform activity.
Location access should only be requested when a specific event has enabled location verification or when another platform feature clearly requires location information.
When enabled, location information may be used to determine whether the participant appears to be within an approved event area or reasonable geographic radius.
The platform may process information such as:
* Approximate or device-provided location;
* Geographic coordinates;
* Verification result;
* Distance from the designated event venue; or
* Related technical information required to perform the verification.
Location verification is intended primarily for event validation and fraud prevention.
The platform is not intended to function as a continuous member tracking system.
Users may also be asked by their browser or device operating system to grant permission before location information can be accessed.
---
## 11. Uploaded Media and Files
Users with appropriate permissions may upload content to the platform.
Uploaded content may include:
* Profile photographs;
* Zone logos;
* Zone banners;
* Event photographs;
* Attendance proof photographs;
* Sponsor logos;
* Event promotional materials;
* Documents;
* Support attachments; and
* Other authorized media.
Uploaded content may be classified as private, restricted, administrative, or public depending on its purpose and the feature through which it was submitted.
Uploading a file does not automatically mean that the file will become publicly accessible.
Public publication should occur only when the applicable platform feature, authorization level, or approval process permits it.
---
## 12. Support Communications
The platform may provide a support ticket or communication system through which authorized users can contact ICPH leadership regarding technical, membership, zone, event, administrative, or other organizational concerns.
Support communications may include:
* Message content;
* Sender information;
* Date and time;
* Ticket status;
* Assigned administrator;
* Related member or zone information;
* Attachments; and
* Administrative responses.
Support tickets and private support communications are not intended to be publicly accessible.
Access should be limited to authorized ICPH personnel responsible for reviewing, investigating, responding to, or managing the concern.
Information contained in support communications should only be used for legitimate organizational, administrative, security, dispute-resolution, or support purposes.
---
## 13. Account and Session Information
To provide secure access to restricted platform features, the system may process technical information associated with authentication and account sessions.
This may include:
* Secure session identifiers;
* Authentication cookies;
* Session expiration information;
* Browser-related information;
* Security tokens;
* Login timestamps;
* Device or technical information necessary for security;
* IP-related security information where applicable; and
* Other technical information required to maintain platform security.
Secure session cookies may be used to keep authenticated users signed in, protect restricted pages, prevent unauthorized access, and maintain session integrity.
Session cookies are not intended to publicly identify users.
---
## 14. Cookies and Similar Technologies
The platform may use cookies and similar technologies that are reasonably necessary for the operation and security of the service.
These may be used for purposes including:
* User authentication;
* Maintaining login sessions;
* Security protection;
* Remembering necessary preferences;
* Preventing unauthorized requests;
* Protecting forms;
* Preventing abuse;
* Maintaining platform functionality; and
* Improving reliability.
Some cookies may be essential for authenticated areas of the platform to function correctly.
Users may be able to control certain cookies through their browser settings. However, disabling essential cookies may prevent login, attendance, administrative, or other secured features from operating correctly.
---
## 15. Public and Private Information
ICPH recognizes an important distinction between information maintained internally and information intentionally published.
Information stored by the platform should therefore be considered private or restricted by default unless the relevant feature, permission, or authorized administrator specifically designates it for public display.
Examples of information that may be publicly displayed include:
* Approved zone information;
* Approved public member verification information;
* Public event information;
* Approved event photographs;
* Public zone statistics;
* Approved sponsor information; and
* Other content specifically authorized for publication.
Private information may include:
* Attendance proof photographs;
* Support messages;
* Internal administrative records;
* Authentication information;
* Security information;
* Private member information;
* Internal notes;
* Restricted event information; and
* Other information not approved for public publication.
The exact information displayed publicly may change as ICPH improves its privacy and security practices.
---
## 16. Role-Based Access and Authorization
The platform may use role-based access controls to determine which information and administrative features a user is permitted to access.
Roles may include, depending on the organizational structure:
* Member;
* Zone Leader;
* Authorized officer;
* Administrator;
* Super Administrator;
* Founder;
* Co-Founder; and
* Other specifically authorized management roles.
Having an account does not automatically provide access to all platform information.
Administrative access should be granted according to organizational responsibility and legitimate operational requirements.
Certain sensitive platform functions may be restricted exclusively to higher-level authorized leadership.
---
## 17. Purpose of Information Processing
Information processed through the ICPH platform may be used for legitimate organizational purposes including:
* Managing ICPH membership;
* Verifying membership identity;
* Maintaining zone records;
* Operating the zone directory;
* Managing events;
* Recording event attendance;
* Preventing fraudulent attendance;
* Providing optional venue verification;
* Maintaining event documentation;
* Publishing approved event media;
* Managing public verification;
* Providing member and administrator support;
* Protecting accounts and platform infrastructure;
* Investigating misuse or security incidents;
* Generating organizational statistics;
* Maintaining accurate historical records;
* Improving platform functionality;
* Enforcing applicable platform rules; and
* Supporting authorized ICPH administrative activities.
Information should not be intentionally used for unrelated purposes without appropriate authorization or justification.
---
## 18. Information Security
Reasonable technical and organizational safeguards should be maintained to protect information processed through the ICPH platform.
Depending on the nature of the platform and information involved, safeguards may include:
* Secure authentication;
* Password protection;
* Role-based permissions;
* Session management;
* Access controls;
* Database security;
* Input validation;
* Request validation;
* Logging;
* Administrative access restrictions;
* Secure communication protocols;
* File upload controls;
* Security monitoring; and
* Other appropriate technical safeguards.
No internet-connected system can guarantee absolute security.
ICPH therefore aims to use reasonable measures appropriate to the nature of the information and the risks associated with unauthorized access or misuse.
---
## 19. Data Accuracy and Corrections
ICPH aims to maintain accurate and reasonably current membership, zone, event, and verification information.
Members who believe that information associated with their membership record is inaccurate, incomplete, outdated, or improperly displayed may request a review or correction.
Requests should be submitted through the appropriate ICPH support channel or directly to authorized ICPH leadership.
ICPH may require reasonable verification before modifying membership or identity-related information to prevent unauthorized changes.
---
## 20. Requests for Review
Individuals may contact authorized ICPH leadership regarding concerns involving information processed through the platform.
Requests may include:
* Correction of inaccurate information;
* Review of membership information;
* Review of public verification information;
* Review of published event photographs;
* Questions regarding attendance records;
* Questions regarding zone information;
* Privacy concerns;
* Security concerns; or
* Other legitimate information-related inquiries.
Requests may be subject to identity verification when necessary to protect member information and prevent unauthorized disclosure or modification.
---
## 21. Data Retention
Information may be retained for as long as reasonably necessary for legitimate ICPH organizational, membership, administrative, security, historical, event, dispute-resolution, or legal purposes.
Different categories of information may require different retention periods.
For example, membership history may need to be maintained longer than temporary session information.
Information that is no longer reasonably necessary should be reviewed for deletion, anonymization, archival, or other appropriate handling according to approved ICPH policies.
---
## 22. Administrative Logs and Security Records
The platform may maintain logs relating to important administrative or security activities.
These records may include actions such as:
* Account access;
* Membership updates;
* Event creation or modification;
* Attendance management;
* Photo publication;
* Zone updates;
* Administrative actions;
* Security events; and
* Other significant platform activity.
Such logs may be maintained for accountability, troubleshooting, security, fraud prevention, and dispute resolution.
Security and administrative logs are not intended for public display.
---
## 23. Unauthorized Access and Misuse
Users must not attempt to access information or platform functions for which they have not been authorized.
Prohibited activities may include attempting to bypass authentication, access another user's account, obtain private attendance records, retrieve private photographs, manipulate attendance, alter membership information without permission, interfere with public verification, or exploit platform vulnerabilities.
ICPH may restrict, suspend, or terminate access when reasonably necessary to protect the platform, its members, or organizational information.
Serious misuse may also be referred to appropriate authorized ICPH leadership for investigation and action.
---
## 24. Third-Party Services
The ICPH platform may rely on third-party infrastructure or technology providers for services such as hosting, email delivery, security, storage, mapping, analytics, or other technical functions.
Where third-party services are used, only information reasonably necessary for the applicable service should be shared or processed.
Third-party providers may maintain their own privacy policies, security practices, and terms.
ICPH leadership should review significant third-party services before they are officially integrated into the platform.
---
## 25. Changes to This Privacy Notice
This Privacy and Data Protection Notice may be updated periodically to reflect:
* New platform features;
* Changes to organizational processes;
* Changes to information handling practices;
* Security improvements;
* Administrative requirements;
* Changes in applicable policies; or
* Applicable legal and regulatory requirements.
When material changes are made, the "Last Updated" date should be revised accordingly.
Continued use of the platform after an updated notice becomes effective may be subject to the applicable platform terms and policies.
---
## 26. Contact and Privacy Concerns
Questions, correction requests, privacy concerns, or requests for review should be directed to authorized ICPH leadership through the official communication or support channels designated by ICPH.
Individuals should avoid sending passwords, authentication codes, or other unnecessary sensitive security information when submitting a request.
ICPH leadership may request additional information when reasonably necessary to verify identity, locate the relevant record, investigate the concern, or prevent unauthorized changes.
---
## 27. Organizational Approval and Publication
This document is currently a draft Privacy and Data Protection Notice prepared for the ICPH platform.
It must not be considered an officially adopted ICPH privacy policy solely because it appears in a development, staging, demonstration, or testing version of the platform.
Before official publication, this document should be reviewed by authorized ICPH leadership to confirm that:
* The descriptions accurately reflect actual platform functionality;
* The described information collection practices are correct;
* Public and private information classifications are appropriate;
* Administrative roles and permissions are accurately described;
* Contact and correction procedures are properly established;
* Data retention practices are appropriate;
* Third-party services have been properly identified where necessary; and
* The policy satisfies applicable organizational and legal requirements.
Authorized ICPH leadership should formally approve the final version before it is published as an official organizational policy.
---
## 28. Final Statement
ICPH recognizes that responsible information management is essential to maintaining trust within the organization.
The platform is therefore designed around the principle that access to information should be limited according to legitimate organizational needs and authorization.
Public pages should display only information that has been specifically approved or designated for public use. Attendance proof photographs, support communications, internal administrative information, security records, and other restricted information should remain private unless an authorized process specifically permits publication.
Location information should only be requested when a feature, such as event venue verification, requires it and should not be used as a general-purpose continuous tracking mechanism.
ICPH will continue to review its platform, policies, security controls, and information-handling practices as the organization and its digital services develop.
