Easebourne Scouts & Guides

Privacy policy

Last updated: 27 September 2026

This page describes what data Easebourne Scouts & Guides collects and how it is used. It is written in plain English and reflects what the code actually does — the source is open and you can verify any claim here against the schema at github.com/DWOF/opensignup.

The OpenSignup project is an open-source coordination tool released under AGPL-3.0. This page applies to this instance — the deployment you are currently using. The data controller for this instance is 1st Easebourne Scout Group.

What we collect from organizers

Organizers (people who create signups) sign in without a password — either via a magic link sent to their email or, where the operator has enabled it, an optional third-party sign-in such as Google. We store:

  • Email address (used to send magic-link sign-in emails).
  • Optional display name and organization name.
  • The signups, slots, and settings you create.
  • An append-only activity log of organizer actions (sign-ins, creating and editing signups, sending magic links), participant commitments on your signups, and reminder dispatches. This exists so an organizer can audit what happened in their own workspace and so the operator can investigate abuse. The same log records anonymous view telemetry on the marketing home page and on your public signup pages (see “Logs and rate-limiting” below).
  • For up to 15 minutes after a sign-in email is sent, the six-digit code printed in it (stored as a keyed hash) and the encrypted sign-in link it stands for, so you can finish signing in from the window you started in. A code is single use; used and expired records cannot be redeemed and are deleted by an hourly cleanup.
  • If you connect an app or AI assistant to your account, a record of that approval and the tokens that keep it working. See “Connected apps and AI assistants” below.

No password is ever stored — sign-in is passwordless.

What we collect from participants

Participants (people signing up for a slot) never create an account. When you commit to a slot we store only what is needed to honour your commitment:

  • Display name.
  • Email address. This is required so we can send you a confirmation, optional reminders, and a link to edit or cancel your commitment.
  • Your slot selection, quantity, and any optional notes.
  • Whether you have opted out of reminder emails for that signup, and when.

A short-lived browser cookie lets you return and edit or cancel your own commitment without re-entering your email. See the cookies page for details.

Logs and rate-limiting

To prevent abuse, the server records request IP addresses in short-lived rate-limit records (e.g. to throttle magic-link sends). These rows are scoped to individual buckets and are not joined to your account or commitment for analytics. Server-side application logs are standard request/error logs and do not include cookies, tokens, or magic-link URLs.

For each view of a public signup page, the server writes a single activity entry containing a user-agent class (browser, bot, or unknown), the host of the referring page (not the full referer URL), the signup's status, and whether the viewer is a returning participant on that signup. We do not record your IP address on this entry. Bot traffic and requests carrying a Do Not Track or Global Privacy Control signal are skipped. The same applies when you follow an “edit your commitment” link, when you load the marketing home page, and when you click the “Start a signup” button on it (where we record only the user-agent class and the referring host).

Email delivery

Easebourne Scouts & Guides sends three kinds of email: organizer magic-link sign-in emails, a confirmation to a participant when they commit to a slot, and a reminder before a dated slot. Moving to a different slot sends a fresh confirmation, because the private link in the old one stops working. Confirmations and reminders each contain a private link that lets you change or cancel that commitment without signing in, so treat them as you would a password and don't forward them. Reminders go out the day before the slot; organizers can turn them off for a signup entirely. Every reminder carries a link that stops reminders for that signup; we record only the time you opted out, and it does not affect any other signup or your slot itself. Delivery uses whichever transport the operator has configured (SMTP, a transactional provider, or local console output in development). No marketing email is ever sent.

Connected apps and AI assistants

An organizer can connect a third-party app, typically an AI assistant such as the Claude app, Claude Code, or ChatGPT, to their Easebourne Scouts & Guides account. Nothing is connected unless the organizer approves it on a consent screen that names the domain the app identified itself from (or, for an app the operator of this instance registered in advance, the name the operator gave it) and lists exactly what it will be able to do. Participants are never asked to sign in and cannot connect anything.

A connected app acts as the organizer who approved it, across every workspace that organizer belongs to, with the same role and never more access than the organizer has themselves. Permissions are approved individually: seeing your signups and their slots, and creating, editing, publishing and deleting signups. Participant names and email addresses sit behind a separate permission an app has to ask for explicitly; the consent screen flags it in amber and says plainly that participants gave those details to you, not to the app. An app that was not granted that permission cannot read participant details at all.

For each connected app we store the approval (which organizer, which app, which permissions, when it was approved, when it was last used, and when it expires), the app's identifier and the name it reports about itself, the refresh tokens that keep the connection alive, and, for the minute it takes to set a connection up, the single-use code that establishes it. Access tokens themselves are not stored. The activity log records that a connection was approved, declined, or disconnected, together with the app's domain (or its configured identifier, for a pre-registered app), and, for every change a connected app makes on your behalf, which app made it. It never records a token or an email address.

You can see and end every connection from Connected apps in your account settings. Disconnecting deletes the approval and every refresh token under it at once, so the app can get no new access; an access token it already holds keeps working until it expires, which is at most 15 minutes. No approval survives longer than 90 days without you approving the app again.

Whatever a connected assistant reads under the permissions you approved is then processed by that assistant's vendor under their own terms and privacy policy, not ours. By itself, Easebourne Scouts & Guides sends nothing to an AI vendor: only an app you connected, acting on your instructions, can pull data out.

Third parties

OpenSignup is designed to have no required external dependencies beyond a Postgres database. Optional integrations (email provider, error reporting, product analytics, AI draft generation, and third-party sign-in) are off by default and only enabled if the operator has configured them via environment variables. Where this instance has enabled any such integration, the operator will list it on request. Separately from anything the operator configures, an organizer can connect an app or AI assistant to their own account. See “Connected apps and AI assistants” above.

If third-party sign-in (for example, Google) is enabled and you choose it, you authenticate on the provider's own site and they return your email, name, avatar, and a unique account identifier. We store the link between that provider account and your organizer record — along with the standard sign-in tokens the provider issues — so we can recognise you on future sign-ins. We do not use those tokens to access anything on the provider beyond the basic profile needed to sign you in.

Your rights

You can request a copy of the data we hold about you, or ask us to delete it, by emailing glv@easebournrscouts.org.uk. Today this is a manual process — self-service export and deletion endpoints are on the roadmap. Organizers can already delete a signup from its settings. That takes the signup and everyone's commitments to it off the site at once: its page and everyone's edit links stop working, lists and exports stop showing them, and nobody can sign up to it. The records themselves stay in our database until someone asks us to erase them, as above.

Self-hosting note

If you are reading this on a self-hosted copy of OpenSignup, the operator of that instance — not the OpenSignup project — is responsible for how your data is handled. The OpenSignup project publishes source code only; it does not operate or have access to data on other people's deployments.

Contact

Questions about this policy or about data we hold: glv@easebournrscouts.org.uk.