← back to hackathons

// privacy

privacy policy

What this site collects, what it does not, and who else sees anything. Written to describe the software that actually runs, not a template.

last updated 26 September 2026

The short version. The only tracking on this site is ad measurement with Meta, and it runs from our server — no code from Meta runs in your browser. It does not start until you accept it in the banner — cookie settings changes that at any time. Nothing else is loaded from an analytics company. You can browse every listing without giving us anything. The only personal data we hold is what you type in yourself — an email address if you subscribe to the newsletter, or your event details if you submit a hackathon.

who we are

UK Hackathons (ukhackathons.com) is an independent directory of hackathons in the United Kingdom. For anything in this policy — including a request to see or delete your data — contact hello@ukhackathons.com. We are the data controller for the data described below.

cookies

This site sets cookies of its own only when you press a button. The banner asks whether ad measurement with Meta may run; your answer is stored as hx_consent (granted or denied, six months, readable only by our server, never sent to anyone else) so we do not ask on every page. Until you answer, nothing tracks you and no tracking cookie is set; if you decline, nothing ever does. Cookie settings shows your answer and changes it with one click.

If you accept, our server sets three more cookies. hx_id is a random visitor number that contains nothing about you (HttpOnly, six months, readable only by our server); Meta never receives it as it is — only its SHA-256 hash, as external_id. _fbp is a browser id set by this site, not by Meta: fb.1. followed by the time it was created and a random number (90 days, not HttpOnly); an _fbp left from an earlier visit is reused. When you arrive from a Meta ad, _fbc holds the ad's click id and the time you arrived (90 days, not HttpOnly). Declining, or withdrawing consent in cookie settings, deletes hx_id, _fbp and _fbc. See Meta below.

Two further values are stored in your own browser, and neither is ever sent to us:

nl_shown
Session storage. Records that the newsletter popup has already appeared, so it does not reappear while you keep the tab open. Cleared when you close the tab.
nl_subscribed
Local storage. Records that you already subscribed, so the popup stops appearing for good. Cleared whenever you clear site data.

Both hold the literal value 1. They contain no identifier and are readable only by your browser on this site.

analytics

There is no Google Analytics, no tag manager and no session-recording tool on this site. No code from Meta runs in your browser either: ad measurement with Meta is done from our server, described under Meta, and only after you accept it. The small amount of JavaScript that runs (the search box, the subscribe forms, the submit wizard) is written inline and talks only to this site's own API; the only script from another company is PayPal's, on the submit page.

how we count what's popular

We do measure which listings get looked at, so we know which events are worth featuring and whether the directory is useful. This happens on our server, not in your browser: there is no tracking script, no beacon and no cookie involved in that count.

Each listing keeps four running counters, per day: times shown in a list, times clicked from a list, times its page was opened, and times its registration link was followed. What gets stored is:

Stored
Which event, which calendar date (UTC), which of the four counters, and a count.
Not stored
Your IP address. Your browser's user-agent string. The page you came from. Any session or visitor ID. The time of day. Any free-text field.

To avoid counting the same person twice in one day, the server takes your IP address and browser user-agent, combines them, and stores a shortened one-way SHA-256 hash of the result. It also uses them, in memory, to discard traffic from bots and crawlers. The IP address and user-agent themselves are never written to disk — only the hash is kept, and it is deleted automatically after 90 days.

We want to be precise rather than flattering here: that hash is pseudonymous, not anonymous. It cannot be read back to reveal an IP address, but the same visitor produces the same hash on the same day, and under UK GDPR that makes it personal data. So we tell you it exists, what it is for, and when it disappears. The daily counters that remain afterwards are plain totals with nothing personal in them, and we keep those indefinitely.

Lawful basis: legitimate interests — understanding which listings are useful, using the least identifying method we could implement. You can object at any time using the address above.

the newsletter

If you subscribe, here is the entire record we create:

Your email address
Lowercased and trimmed.
A timestamp
When you subscribed.

That is genuinely all of it — the database table has three columns and the third is an ID number. We do not record your IP address, your browser, or which page you subscribed from, and the three signup forms on the site all behave identically in this respect.

Your address is stored in this site's own database on our own server. It is not sent to a mailing-list provider, not shared, not sold, and not used to build a profile. If we later start sending through an email provider, that provider will be named here before any address reaches it.

Lawful basis: consent, given by entering your address. Withdraw it at any time by emailing hello@ukhackathons.com — we will delete the record, not merely flag it. We keep addresses until you unsubscribe.

submitting an event

The submit form collects the event's details — name, URL, description, organisation, city, venue, address, postcode, dates, ticket price, prize and an image link — plus a contact email address, which is the only part that is necessarily personal data. If you buy a featured listing, we also record the PayPal order ID.

Event details are published on this site, which is the point of submitting them. Your contact email is not published — it is used to reach you about the listing.

Please note: when you press submit, your browser sends the form directly to a Bunny.net edge endpoint that receives our submissions. That means Bunny.net, our infrastructure provider, receives your IP address along with the submission, including your contact email. This happens only when you actually submit the form.

Lawful basis: legitimate interests, and the steps necessary to list an event at your request. Submissions are kept as our record of what was published and why.

other companies that see something

We deliberately keep this list as short as we can, but it is not empty, and pretending otherwise would be the easiest thing in this policy to get wrong:

Google Fonts
Every page loads two typefaces from Google's font servers, so Google receives your IP address, your user-agent and the address of the page you are viewing — on every page view, before you interact with anything. This is the most significant third-party data flow on the site. We intend to self-host the fonts, which removes it entirely.
Meta (Facebook)
We advertise this directory on Facebook and Instagram and use Meta's tools to see whether those ads bring visitors. No code from Meta runs in your browser, and nothing is reported until you accept the banner: from then on our server reports to Meta's Conversions API directly. It reports a page view, an event page opened, a registration link followed, a newsletter signup, an event you submit through the submit form (ListingSubmitted — the listing type, never your contact email) and a featured-listing payment (Purchase — the price and the PayPal order id). Each report carries your IP address, your browser's user-agent string, the click id (_fbc) and browser id (_fbp) if they exist, and the SHA-256 hash of hx_id as external_id; a newsletter signup also carries your email address as a SHA-256 hash so Meta can match the signup to an ad — we never send the address itself, and nothing else you type — and signups, submissions and payments carry a hash of this site's country code. To stop it: withdraw any time at cookie settings, one click: that deletes hx_id, _fbp and _fbc and stops every report from the next page. What Meta already holds is governed by Meta's own tools. Meta processes this under its own privacy policy, partly outside the EU/UK.
PayPal
The /submit page loads PayPal's payment script, so PayPal receives the IP address and user-agent of everyone who opens that page, whether or not they pay, and sets its own cookies under paypal.com. No other page loads it. Payment is handled entirely on PayPal's side — we never see or store card details, only an order ID.
Bunny.net
Hosts the endpoint that receives event submissions, as described above.

Each of these companies processes data under its own privacy policy, and we cannot tell you where in the world they do it. Beyond these three, no third party receives anything about you.

links out to organisers

Registration links go through a /go/ address on this site. That step adds one to the "registration link followed" counter described above and then immediately forwards you to the organiser's page on Luma or Eventbrite. It stores nothing else. The links are marked so that the organiser's site is not told which page you came from.

Once you land on an organiser's site — or any other site we link to — you are covered by their privacy policy, not ours. Event images shown here are currently copied and served from our own domain rather than loaded from the organiser, so simply viewing a listing does not reveal you to them.

logs

The application itself keeps no visitor log files: no access log, no request log, no record of which pages you viewed. As with any website, the web server and network provider in front of it may hold short-lived operational logs for security and reliability.

organiser accounts

Organiser accounts are optional. You only have one if you made it yourself at /organiser/register, to list a hackathon or to claim one we already list. Browsing this site never creates an account and never needs one.

If you do have one, this is everything it holds:

The account
Your email address, the name you chose to give (optional) and the language you signed up in. The password itself is never stored — only an argon2id hash of it, which cannot be turned back into the password.
Sign-in sessions
One record per device you are signed in on: your browser's user-agent string, a truncated hash of your IP address rather than the address itself, and when the session was created and last used. A session expires 30 days after it was last used, and you can end any of them yourself.
Your organisation
Its name, website, description, contact address and logo link, plus who else is a member and at what role. An invitation you send holds the invited address until it is accepted, revoked or expires.
What you create
The listings you publish through the portal, and any claim you file on a listing we scraped — including the evidence you wrote and the decision made on it.

The numbers an organiser sees. The per-listing counts described above are broken down, for that listing's organiser, by city and by where the visit came from. The city is worked out from the visitor's IP address against a database file held on our own server (DB-IP City Lite, CC BY 4.0), so no lookup leaves this machine and the address itself is never written down: what is stored is the city name, one of five coarse traffic labels (search, social, this site, other, direct) and the same truncated 90-day hash of IP address and browser string the counters already use. None of it identifies a visitor, and none of it is shown to anyone but that listing's organiser.

The weekly summary email is off until you switch it on. An organiser can ask for a short weekly email of their own listing numbers from the portal dashboard, and switch it off again in the same place.

Who can see it. Your organisation's details and its listings are visible to the other members of that organisation. A claim you file is read by the person who runs this site, in order to approve or reject it. None of it is published — the contact address on a listing is never shown on the site — and none of it is sold, shared or handed to an advertiser.

A copy of it, or the door. /organiser/account downloads everything above as a JSON file, and deletes the account — with its sign-in sessions and any organisation you were the only member of — from one form. Deletion is refused while you are the last owner of an organisation that still has listings: hand ownership over, or remove those listings, first, so nothing goes dark by accident.

your rights

Under UK GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. In practice, for this site that means:

Email hello@ukhackathons.com. There is no charge and we do not require a particular form of words. If you think we have handled your data badly, you can complain to the UK Information Commissioner's Office at ico.org.uk — though we would rather you gave us the chance to put it right first.

children

This is a listings site for public events and is not directed at children. We do not knowingly collect data from anyone under 13. Some listed hackathons are student events with their own age rules — those are set by the organiser, not by us.

changes

This policy describes the site as it works on the date shown at the top. If what the site does changes — a mailing provider, self-hosted fonts, a different submission endpoint — this page gets updated to match, and the date changes with it. We make no claim to hold any privacy certification or third-party audit; this is a plain description of the system, and you are welcome to ask us about any part of it.