Sitelet https://hackyard.tech/privacy

// Privacy

What we collect, and what we don't.

Hackyard is free and doesn't sell anything, so there's no business reason to hoard your data. This is the whole list, in plain words.

Last updated · October 2026

Who we are

Hackyard (hackyard.tech) is operated by Matthew Hixon ("Hackyard", "we", "us"), an individual based in Pennsylvania, USA. For anything in this policy, including a request about your data, reach us through the contact page or @HackyardSocial. We're the party responsible for the data described here (the "data controller", if you speak GDPR).

What we collect

Your account. An email address and password, or your GitHub account if you sign in that way. When you use GitHub, we receive your GitHub username, email, and avatar, nothing else from your GitHub account. Accounts and sign-in are handled by Supabase, our auth and database provider.

Your profile. A handle, and optionally a bio, a profile picture, and a link to your X. All of it is public on your profile page, that's the point of it.

What you submit. Your repo link, writeup, demo video link, screenshot, the AI model you declare, and any receipt link you attach. All public.

Spot claims and votes. Which Yard you claimed a spot in and when, and which submission you voted for. Your claim is public. Your individual vote is not shown to anyone, only the totals, and only after voting closes.

Technical basics. Like every website, our host (Vercel) processes basic request data such as your IP address and browser type to serve pages and keep the site secure. Vercel Analytics counts page views without cookies and without building a profile of you.

Page views. We also count page views ourselves, in our own database: the page you opened, the site that linked you there (like x.com) and any campaign tag in the link, plus a random visit number your browser forgets when you close the tab. No IP address, no account, no cookie, so it can't follow you from one visit to the next. We use the totals to see what's working and to report traffic to Yard sponsors.

What we don't collect

No payment details. Hackyard is free and has no checkout. No tracking cookies, no advertising pixels, no third-party ad networks, no precise location, and none of the "sensitive" categories (things like health, biometrics, or government IDs). We don't buy data about you, and we don't sell, rent, or "share" yours to anyone, ever, including for cross-context advertising as California defines it.

Cookies and similar tech

We keep this simple. The only cookie Hackyard needs is a strictly-necessary one that keeps you logged in after you sign in. Without it, accounts wouldn't work. There are no analytics, advertising, or tracking cookies, so there's no consent banner to click through. Vercel Analytics measures traffic without cookies at all, and our own page view count uses only a random visit number held in your browser until you close the tab.

Why we're allowed to use it

For anyone in the EU/UK, here are our lawful bases, in plain terms. We process your account and submissions to actually run the service you signed up for (that's performance of a contract). We process technical data to keep the site working and secure, and to prevent abuse like vote-stuffing (that's our legitimate interest). Where the law requires your permission, we ask for it (that's consent), and you can withdraw it any time.

Email

We use your email for the things you'd expect: confirming your account, confirming a spot you claimed, reminding you to check in before kickoff, and telling you when a build week is announced. We may also email people who signed up but haven't claimed a spot, to let them know spots are still open.

That's it. No newsletter you didn't ask for, no drip campaign, no selling your address on. Email is delivered through Brevo. If you'd rather not hear from us at all, tell us and we'll stop, we keep a short suppression list only so we can honor that.

Who else touches your data

Only the services that make the site run: Supabase (database, accounts, file storage), Vercel (hosting and privacy-friendly analytics), and Brevo (sending the emails above). Each is a processor acting on our instructions, under its own data-processing agreement, and each only receives what it needs to do its job.

When your submission page loads, we ask GitHub's public API when your repo was created and how many commits it has. That's public information about a public repo, we don't send GitHub anything about you.

These providers may process data on servers in the United States and elsewhere. Where data moves out of the EU/UK, they rely on recognized safeguards for international transfers, such as Standard Contractual Clauses.

How long we keep it

Your account and profile stay until you delete them. Public records that are part of a completed Yard, who claimed a spot, what was submitted, who won, and the vote totals, remain as that Yard's history (see "Deleting your stuff" below). Technical logs are short-lived and handled by our host. Our email suppression list is kept for as long as needed to keep you off lists you opted out of.

Your rights

Wherever you live, you can ask us to show you the data we hold about you, correct it, delete it, or hand you a copy to take elsewhere. You can object to or ask us to limit certain uses. We won't charge you or treat you differently for asking.

If you're in California: we do not sell or share your personal information and never have, so there's nothing to opt out of, but your rights to know, delete, and correct still apply. If you're in the EU/UK and think we've gotten something wrong, you also have the right to complain to your local data protection authority, though we'd appreciate the chance to fix it first. To exercise any of this, just contact us.

Children

Hackyard is for builders aged 13 and up. If you're under 18, you need a parent or guardian's permission to use it. We don't knowingly collect anything from children under 13. If you believe a child under 13 has created an account, tell us and we'll remove it.

Security

Accounts, passwords, and files are managed on Supabase's infrastructure, and the site runs on Vercel, both of which maintain industry-standard security. We take reasonable steps to protect your data, but no online service can promise perfect security, so please use a strong, unique password.

When the law asks

We'll only hand over your data if we're legally required to, for example a valid legal request, or if it's genuinely necessary to protect someone's safety or defend Hackyard's rights. It's not something we do lightly.

Deleting your stuff

You can edit or clear your profile any time in settings, and you can release a claimed spot yourself.

For full account deletion, email hixon@hackyard.tech from the address on your account (or message us on X) and we'll remove your account along with your submissions. One honest caveat: badges and vote counts from a completed Yard are part of that Yard's public record. We can remove your name and profile from them, but we don't retroactively rewrite who won a past event.

Changes, and how to reach us

If this page changes in a way that actually matters, we'll say so rather than quietly editing the date. Questions, or a request about your data: @HackyardSocial or the contact page.