Privacy Policy
Last updated: July 15, 2026
At the Young Scandinavians Club ("YSC", "we", "us"), we believe that being a member-run organization means treating your data with the same respect we show you at our events. This policy explains—in plain language—what personal data we collect through ysc.org, why we collect it, who we share it with, and what rights you have.
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, the sections on lawful bases and your rights apply to you under the General Data Protection Regulation (GDPR) and similar laws.
1. What Information We Collect
We follow data minimization: we collect only what we need to run the Club, process memberships, and deliver the services you ask for.
Account & membership information
- Name, email address, phone number, and date of birth
- Mailing address and billing address
- Password (stored as a secure hash—we never store plain-text passwords)
- Family member names and birth dates (for family memberships)
- Profile photo (if you upload one or sign in with Google or Facebook)
- Passkey credentials (if you enable passwordless login)
- Membership eligibility information required by our Bylaws (for example, place of birth, citizenship, and your connection to Scandinavia)
- Notification preferences (email and SMS opt-in choices)
Payment & billing information
- Payment card or bank account details are collected and processed by Stripe. We do not store your full card number on our servers.
- We store payment metadata (such as card brand, last four digits, and expiry) so you can manage saved payment methods.
- Transaction history (dues, event tickets, cabin bookings, refunds)
- Bank account details for expense reimbursements (encrypted on our servers; only if you submit an expense report)
Activity & booking information
- Event ticket purchases and, when required for an event, attendee names and emails
- Cabin reservation details, including guest names and check-in information
- Event check-in and QR scan records
- Posts, comments, and photos you choose to share on the site
- Volunteer sign-ups, contact form messages, and conduct violation reports you submit
Communications
- Newsletter email address and optional name (only if you subscribe)
- SMS message content and delivery status (only if you opt in to text notifications)
- Email delivery, open, and click data for club newsletters (not for one-time transactional emails)
Technical & security information
- IP address, browser type, device information, and login timestamps
- Approximate location derived from IP address (for security alerts about new sign-ins)
- Session cookies that keep you logged in (see Cookies below)
- Error and performance data when something goes wrong on the site (see third parties below)
We do not knowingly collect information from children under 13. Our services are intended for adults (18+).
2. Why We Collect It (Lawful Bases)
We process your personal data only when we have a valid legal reason:
- Contract: To create and manage your membership, process payments, fulfill event tickets and cabin bookings, and provide account features you sign up for.
- Consent: For optional communications such as the newsletter, SMS notifications (when you opt in), and certain profile choices. You can withdraw consent at any time.
- Legitimate interests: To keep the site secure (login monitoring, fraud prevention), improve reliability, and run club operations—balanced against your privacy rights.
- Legal obligation: To maintain financial and tax records where required by law.
3. How We Use Your Information
- Club operations: Processing memberships, managing cabin bookings, organizing events, and verifying eligibility.
- Communication: Sending newsletters (if subscribed), club announcements, booking confirmations, and responding to inquiries.
- Security: Sending transactional SMS for two-factor authentication, login verification, and urgent booking alerts (for example, weather closures at the Tahoe cabin).
- Member directory: If you choose to be listed, your name and contact information may be visible to other logged-in members. You control visibility in your account settings.
- Accounting: Syncing membership and payment records with our accounting system for club financial management.
4. How We Store & Share Your Data
Where data is stored
Your data is stored on secure servers in the United States, operated by our hosting provider. Uploaded files (such as profile photos and expense receipts) are stored in object storage with access controls.
Who can access it
Within YSC, personal information is limited to Board members and authorized volunteers who need it for their duties (for example, the Treasurer for billing or event organizers for check-in lists). All such access is on a need-to-know basis.
Third-party service providers
We use trusted partners to deliver specific services. They process data on our instructions and only for the purposes described here:
- Stripe — payment processing
- Fly.io — application hosting and database
- Amazon Web Services (SES) — outbound email delivery
- FlowRoute — transactional SMS delivery
- Intuit QuickBooks — club accounting and financial records
- Sentry — error monitoring and application stability
- Cloudflare — content delivery, security (including bot protection on forms), and optional privacy-friendly analytics
- Radar — address autocomplete and maps on registration and booking forms
- Google and Facebook — optional social login (email and basic profile only, if you choose to use them)
- Apple Wallet and Google Wallet — digital membership or event passes you choose to add to your phone
When you click links to external sites (such as Partiful event pages or social media), those sites have their own privacy policies.
International transfers
If you access our site from outside the United States, your data may be transferred to and processed in the US. We rely on appropriate safeguards with our service providers (such as standard contractual clauses) where required by law.
No selling of data
We do not sell, rent, or trade your personal information. Ever.
5. How Long We Keep Your Data
We keep personal data only as long as needed for the purposes above:
- Active membership: For the duration of your membership and a reasonable period afterward for account recovery and club records.
- Financial records: As long as required for tax, accounting, and audit purposes.
- Security logs: Login and security event data for a limited period to detect abuse and protect accounts.
- Newsletter: Until you unsubscribe, plus a short suppression period to honor your opt-out.
When data is no longer needed, we delete or anonymize it where feasible.
6. How We Protect Your Data
Encryption
We use industry-standard TLS encryption for data in transit between your browser and our servers. Sensitive data such as bank account numbers for reimbursements is encrypted at rest.
Access controls
Administrative access is restricted, authenticated, and logged. Payment data is handled within Stripe's PCI-compliant environment.
Data breaches
In the unlikely event of a data breach that affects your personal data, we will notify affected members and relevant authorities as required by law, typically within 72 hours where GDPR applies.
7. SMS & Mobile Privacy
We maintain strict SMS isolation:
No marketing blasts
Your mobile number is used for transactional purposes you opt into: two-factor authentication, booking alerts, and account security—not promotional text campaigns.
No sharing for third-party marketing
We do not share your mobile opt-in data with third parties or affiliates for their marketing purposes.
How to opt out
Reply STOP to unsubscribe from SMS, or change your preferences in account settings. Note that opting out of security texts may affect login if two-factor authentication is enabled.
8. Cookies & Similar Technologies
We use cookies (small files on your device) and similar technologies:
Essential cookies (required)
-
Session cookie (
_ysc_key): Keeps you logged in and powers the member portal and booking system.
Optional cookies
-
Remember-me cookie (
_ysc_web_user_remember_me): Only set if you check "Remember me" at login (up to 60 days). - Admin preferences: Sidebar and layout preferences for board administrators only.
Analytics
We do not use Google Analytics or advertising trackers. We may use privacy-respecting analytics (such as Cloudflare Web Analytics) to understand which pages are popular and improve the site. These tools do not track you across other websites.
Your choices
You can disable cookies in your browser settings, but the member portal and booking system may not work without essential session cookies.
9. Your Rights
Depending on where you live, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Correct inaccurate or incomplete data. You can update most profile information by logging into your account at ysc.org.
- Erasure ("right to be forgotten"): Request deletion of your personal data when it is no longer necessary or when you withdraw consent, subject to legal exceptions (for example, financial record-keeping).
- Restriction: Ask us to limit how we use your data in certain circumstances.
- Portability: Request your data in a structured, commonly used format where technically feasible.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Unsubscribe from the newsletter via the link in any email, opt out of SMS via STOP or account settings, or contact us for other consent-based processing.
To exercise any of these rights, email us at [email protected] with the subject line "Privacy Request" and describe what you need (for example, a copy of your data or account deletion). Requests are handled manually by the Board—we do not offer automated self-service export or deletion in the member portal. We will respond within 30 days (or sooner where required by law) and may verify your identity before fulfilling a request.
If you are in the EEA or UK and believe we have not addressed your concern, you have the right to lodge a complaint with your local data protection authority.
10. California Privacy (CCPA / CalOPPA)
California residents have additional rights under state law:
- Right to know what personal information we collect and how it is used (this policy)
- Right to delete personal information, subject to exceptions
- Right to opt out of the "sale" of personal information—we do not sell your data
- Right to non-discrimination for exercising privacy rights
We honor Do Not Track signals where technically feasible.
11. Children's Privacy (COPPA)
Our website is intended for adults (18+). We do not knowingly collect information from children under the age of 13. If you believe we have collected a child's information, contact us and we will delete it promptly.
12. Email & Newsletter (CAN-SPAM)
We agree to:
- Not use false or misleading email subjects or addresses
- Include our physical mailing address in club-wide emails
- Provide an easy "unsubscribe" link at the bottom of newsletters
13. Changes to This Policy
We may update this policy from time to time. We will post the revised version on this page with an updated "Last updated" date. For material changes, we may also notify members by email.
14. Contact Us
For privacy questions, data requests, or concerns about how we handle your information, contact the Board:
Young Scandinavians Club
28 Geary St
Ste 650 #304
San Francisco, CA 94108
USA
Email:
[email protected]
(use subject "Privacy Request" for data rights requests)