← back to hackathons

// privacy

privacy policy

What this site collects, what it does not, and who else sees anything. Written to describe the software that actually runs, not a template.

last updated August 27, 2026

The short version. This site sets no cookies and uses no third-party analytics. You can browse every listing without giving us anything. The only personal data we hold is what you type in yourself — an email address if you subscribe to the newsletter, or your event details if you submit a hackathon.

who we are

Hackathons USA (hackathonsusa.com) is an independent directory of hackathons in the United States. For anything in this policy — including a request to see or delete your data — use the submit form; this edition has no inbound email address, so that form is the working route in. We are responsible for the data described below.

cookies

This site sets no cookies. Not for analytics, not for advertising, not for preferences. That is why you have never seen a cookie banner here — there is nothing to ask you to consent to.

Two small values are stored in your own browser, and neither is ever sent to us:

nl_shown
Session storage. Records that the newsletter popup has already appeared, so it does not reappear while you keep the tab open. Cleared when you close the tab.
nl_subscribed
Local storage. Records that you already subscribed, so the popup stops appearing for good. Cleared whenever you clear site data.

Both hold the literal value 1. They contain no identifier and are readable only by your browser on this site.

analytics

There is no Google Analytics, no tag manager, no advertising pixel and no session-recording tool on this site. No third-party analytics service of any kind is loaded. The site also ships no JavaScript bundles — the handful of small scripts it does run (the search box, the subscribe forms, the submit wizard) are written inline and talk only to this site's own API.

how we count what's popular

We do measure which listings get looked at, so we know which events are worth featuring and whether the directory is useful. This happens on our server, not in your browser: there is no tracking script, no beacon and no cookie involved.

Each listing keeps four running counters, per day: times shown in a list, times clicked from a list, times its page was opened, and times its registration link was followed. What gets stored is:

Stored
Which event, which calendar date (UTC), which of the four counters, and a count.
Not stored
Your IP address. Your browser's user-agent string. The page you came from. Any session or visitor ID. The time of day. Any free-text field.

To avoid counting the same person twice in one day, the server takes your IP address and browser user-agent, combines them, and stores a shortened one-way SHA-256 hash of the result. It also uses them, in memory, to discard traffic from bots and crawlers. The IP address and user-agent themselves are never written to disk — only the hash is kept.

We want to be precise rather than flattering here: that hash is pseudonymous, not anonymous. It cannot be read back to reveal an IP address, but the same visitor produces the same hash on the same day. That is enough for us to treat it as personal information and tell you it exists, what it is for, and when it disappears. Anything older than 90 days is deleted — to be exact about the mechanism, that cleanup runs when the service restarts rather than on a timer, so a hash can outlive 90 days by however long the service has been up. The daily counters that remain afterwards are plain totals with nothing personal in them, and we keep those indefinitely.

Why we do it: to understand which listings are useful, using the least identifying method we could implement. You can ask us to stop counting you at any time using the route above.

the newsletter

If you subscribe, here is the entire record we create:

Your email address
Lowercased and trimmed.
A timestamp
When you subscribed.

That is genuinely all of it — the database table has three columns and the third is an ID number. We do not record your IP address, your browser, or which page you subscribed from, and the three signup forms on the site all behave identically in this respect.

Your address is stored in this site's own database on our own server. It is not sent to a mailing-list provider, not shared, not sold, and not used to build a profile. If we later start sending through an email provider, that provider will be named here before any address reaches it.

Lawful basis: consent, given by entering your address. Withdraw it at any time through the submit form — we will delete the record, not merely flag it. We keep addresses until you unsubscribe.

submitting an event

The submit form collects the event's details — name, URL, description, organisation, city, venue, address, ZIP code, dates, ticket price, prize and an image link — plus a contact email address, which is the only part that is necessarily personal data. If you buy a featured listing, we also record the PayPal order ID.

Event details are published on this site, which is the point of submitting them. Your contact email is not published — it is used to reach you about the listing.

Please note: when you press submit, your browser sends the form directly to a Bunny.net edge endpoint that receives our submissions. That means Bunny.net, our infrastructure provider, receives your IP address along with the submission, including your contact email. This happens only when you actually submit the form.

Lawful basis: legitimate interests, and the steps necessary to list an event at your request. Submissions are kept as our record of what was published and why.

other companies that see something

We deliberately keep this list as short as we can, but it is not empty, and pretending otherwise would be the easiest thing in this policy to get wrong:

Google Fonts
Every page loads two typefaces from Google's font servers, so Google receives your IP address, your user-agent and the address of the page you are viewing — on every page view, before you interact with anything. This is the most significant third-party data flow on the site. We intend to self-host the fonts, which removes it entirely.
PayPal
The /submit page loads PayPal's payment script, so PayPal receives the IP address and user-agent of everyone who opens that page, whether or not they pay, and sets its own cookies under paypal.com. No other page loads it. Payment is handled entirely on PayPal's side — we never see or store card details, only an order ID.
Bunny.net
Hosts the endpoint that receives event submissions, as described above. It is not involved in ordinary browsing.

Each of these companies processes data under its own privacy policy, and we cannot tell you where in the world they do it. Beyond these three, no third party receives anything about you.

links out to organisers

Registration links go through a /go/ address on this site. That step adds one to the "registration link followed" counter described above and then immediately forwards you to the organiser's page on Luma or Eventbrite. It stores nothing else. The links are marked so that the organiser's site is not told which page you came from.

Once you land on an organiser's site — or any other site we link to — you are covered by their privacy policy, not ours. Event images shown here are currently copied and served from our own domain rather than loaded from the organiser, so simply viewing a listing does not reveal you to them.

logs

The application itself keeps no visitor log files: no access log, no request log, no record of which pages you viewed. As with any website, the web server and network provider in front of it may hold short-lived operational logs for security and reliability.

your rights

You may ask us for a copy of the data we hold about you, to correct it, or to delete it. We do not sell personal information to anyone, and we have never disclosed any of it for money or for anyone else's advertising. In practice, for this site that means:

Ask through the submit form. There is no charge and we do not require a particular form of words, and we will not treat you differently for asking. Depending on where you live, your state may give you additional rights over your personal information; ask and we will honour them. If you think we have handled your data badly, tell us first — we would rather put it right than have you take it elsewhere.

children

This is a listings site for public events and is not directed at children. We do not knowingly collect data from anyone under 13. Some listed hackathons are student events with their own age rules — those are set by the organiser, not by us.

changes

This policy describes the site as it works on the date shown at the top. If what the site does changes — a mailing provider, self-hosted fonts, a different submission endpoint — this page gets updated to match, and the date changes with it. We make no claim to hold any privacy certification or third-party audit; this is a plain description of the system, and you are welcome to ask us about any part of it.