HeySoror Tech Inc.
Privacy Policy
Effective Date: August 21, 2026 Last Updated: August 21, 2026
heysoror.io | contact@heysoror.io
HeySoror Tech Inc. ("HeySoror," "we," "us," or "our") is committed to protecting the personal information of every member of our community. This Privacy Policy explains how we collect, use, store, share, and protect your data when you use the HeySoror platform, including our mobile application, our websites (heysoror.io and join.heysoror.io), and all related services (collectively, the "Platform").
This Policy applies to everyone who uses the Platform, including people who have joined our waitlist and people who are completing membership verification. By using the Platform, you agree to the practices described in this Policy. If you do not agree, please do not use the Platform.
Read this Policy alongside our Terms of Service. Capitalized terms not defined here have the meaning given in our Terms of Service.
1. Our Commitment to You
HeySoror serves a community defined by trust, sisterhood, and shared identity. Our members are sorors whose organizational memberships, professional lives, location information, and personal networks are meaningful and sometimes sensitive. We approach data stewardship accordingly.
Our data commitments:
- We do not sell your personal information. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under applicable U.S. state privacy law.
- We do not use advertising trackers. We do not run advertising trackers on your device, and we do not allow advertisers to target you using your personal information. We do use product analytics to understand how the Platform is used and improve it — described in Section 4.3 — but never for advertising.
- We do not send your data to AI systems. We do not provide your personal information to any third-party artificial-intelligence or machine-learning service, and we do not use it to train AI models. If that ever changes, we will update this Policy and obtain your consent first.
- Verification information is used only to confirm eligibility. Information you provide to support your D9 membership is used to confirm your eligibility for the Platform, and for no other purpose.
- You have real control. You can review and correct your profile, adjust your privacy settings, and delete your account and personal data from within the app.
Section 4.5 explains the one circumstance in which your information could transfer to another company: a merger, acquisition, or sale of our business.
2. Information We Collect
Below is a complete account of what we collect. We have tried to describe it precisely rather than generally, including the items members are least likely to expect.
2.1 Information You Provide Directly
Waitlist Sign-Up
Before creating an account, you may join our waitlist. This collects your email address, first and last name, and — if you choose to select one — the sorority you are interested in. We also store the campaign-attribution information described in Section 2.2 alongside your waitlist entry, and we record the date you signed up.
Account Registration
- Email address (required, and verified by our authentication provider)
- Password — created and managed by our authentication provider, Clerk. HeySoror never sees or stores your password
- If you register using Apple or Google sign-in, the basic profile information that provider sends us (typically name and email)
Profile Information
Your profile is created in our registration wizard and can be edited later in the mobile app. It may include:
- Username — required, unique, and visible to every other member, including members who cannot otherwise see your profile. Your username is also searchable
- Display name — a name you choose. This is not a legal-name field, and we do not collect or verify your legal name
- Profile photograph, and optionally a cover/banner image
- Short bio, and a separate longer "About" description (both optional)
- Sorority affiliation (Alpha Kappa Alpha, Delta Sigma Theta, Sigma Gamma Rho, or Zeta Phi Beta)
- Chapter, and initiation year. If your chapter is not in our directory, the chapter name you type in
- Home city — stored both as a place label and as map coordinates (see Section 6)
- Job title (optional)
- Instagram handle (optional)
- Interests, chosen from a fixed list of twenty
- Phone number (optional). Phone is not collected during registration; you can add it later in the mobile app
- Your privacy preferences, including who may see your profile, who may message you, and your location settings
Presence Information
We record when you were last active and a basic activity status, so other members can see whether you are around. You can turn off activity visibility in your settings.
Membership Verification
Every account goes through a membership-verification step:
- You identify your sorority and your chapter (or provide the chapter name if it is not in our directory)
- If your chapter is already recognized in our system, verification may complete automatically
- If it is not, a member of our team reviews your submission before verification is granted
- If you email our support team additional proof of membership, that correspondence lives in our email system and is not uploaded into or stored within the Platform. Section 8 describes how long we keep it
We may introduce additional or stronger verification methods in the future — potentially including identity-document verification or knowledge-based verification questions. We do not do any of that today. If we add it, we will update this Policy before that feature is enabled.
Communications
- Direct messages you send to other members
- Event registrations and related communications
- Support requests and correspondence with HeySoror staff
- Reports you submit about content or conduct, including any free-text description
- Survey responses, feedback, and bug reports you choose to submit
Referral / Ambassador Program
Some members receive a personal referral code to share with other eligible D9 members. If you sign up using someone's code, we record which code was used and connect your account with the member who shared it — each of you becomes visible to the other as a connection. Redemptions may be reviewed by our team for authenticity. There is no monetary compensation, discount, or commission in this program.
Financial Information
If you subscribe to a paid tier, your payment information is collected and processed by Stripe, our payment processor, on our website. HeySoror never receives or stores your full card number. We retain records of transaction amounts, dates, and subscription status. No purchases happen inside our mobile apps.
Bug Reports & Diagnostics
If you report a bug using our in-app reporting tool, we collect:
- An annotated screenshot of your screen at that moment. Our bug-reporting tool applies its own automatic redaction, but it does not yet mask message content or other members' profile details, so a report may capture whatever was visible. We are adding that masking. Until then, please be mindful of what is on screen before submitting a report
- Your device type, operating system name and version, and app version
- Your account identifiers (your authentication ID and profile ID) and your username — but not your email address or phone number
- The screen you are on. We record your current screen as you navigate, so a report includes where you had been
- A log of recent network activity. We automatically strip authentication headers before this leaves your device. That filtering covers request headers; it does not cover data that might appear inside a web address or a request body
Bug reports are processed by Shake, our bug-reporting vendor, and are visible to our engineering team through our issue-tracking and team-messaging tools.
Internal Labels
We may attach internal labels to your profile for our own operational purposes — for example, marking an account as part of an early-tester group or as a test account.
2.2 Information Collected Automatically
- Device and app information: Device type, operating system name and version, and app version. We do not collect advertising identifiers or unique device identifiers, and we do not track you across other apps or websites
- Usage information: Which features you use, and the presence information described above
- Location information: described in Section 6
- Push notification information: If you enable notifications, we register a push token together with your device's language and time zone, so notifications arrive correctly formatted
- Log and security information: Your IP address is used to rate-limit requests and prevent automated abuse. On our waitlist form, your IP address is transmitted to Cloudflare as part of its bot-detection check. We keep error logs and system-activity records needed for security monitoring
- Campaign attribution: When you arrive from a link or campaign, we capture the campaign parameters in that web address (source, medium, campaign name) and any referral code, and we store them with your account once you register, along with the plan you selected. This is first-party measurement — it tells us which outreach brought members in. It is not an advertising tracker, it is not shared with advertisers, and no third-party analytics service receives it
- Cookies and browser storage (websites only): described in Section 14. Our mobile app does not use cookies
2.3 Information From Third Parties
- Sign-in providers: If you register via Apple or Google, we receive basic profile information from that provider under their terms
- D9 national organizations: We have no data-sharing integration with any D9 national organization today, and we do not receive member data from any of them. Our chapter directory is a dataset we assembled ourselves. If we ever enter a formal written data-sharing agreement with a national organization, we will update this Policy before it takes effect
3. How We Use Your Information
3.1 Core Platform Operations
- Creating and maintaining your account
- Authenticating you and securing your session
- Showing your profile to other verified members, as controlled by your privacy settings
- Showing your location on our interactive map, as controlled by your location settings
- Enabling direct messaging between verified members
- Sending notifications you have enabled
3.2 Membership Verification
- Processing your D9 membership verification and confirming your sorority and chapter affiliation
- Detecting fraudulent claims of membership
3.3 Community Safety
- Investigating reports of prohibited conduct or Terms of Service violations
- Monitoring for fraudulent account activity and unauthorized access
- Keeping administrative and audit records of verification and safety decisions
- Suspending or terminating accounts when warranted
3.4 Communications
- Sending messages required to operate the Platform (account confirmations, security alerts, verification status updates)
- Sending communications about events you registered to attend
- Sending optional community updates, with your consent. You may opt out at any time
3.5 Platform Improvement
- Reviewing aggregate usage internally to improve features
- Understanding which outreach and campaigns bring members to the Platform
- Testing and debugging, including through the bug-report tool described in Section 2.1
We do not use your personal information to train artificial-intelligence or machine-learning models, and we do not send it to any third-party AI service. We do not profile you for advertising. We do not use your sorority affiliation, verification information, or connections for any commercial purpose beyond operating the Platform.
4. How We Share Your Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
4.1 With Other Verified Platform Members
The following are visible to other verified members:
- Your username — always, including to members who cannot see the rest of your profile
- Your display name and profile photo
- Your sorority affiliation
- Your bio, About text, cover image, job title, Instagram handle, and interests, subject to your profile-visibility setting
- Your home city label, subject to your profile-visibility setting
- Your location on the map, subject to your location settings (see Section 6)
- Whether you are active or recently active, unless you turn activity visibility off
- Trips and events you choose to share
- If you joined via someone's referral code, that connection is visible to both of you
The following are never shown to other members:
- Your password
- Your email address or phone number, unless you explicitly choose to display them
- Your payment information
- Your verification submissions
You can adjust profile visibility, messaging permissions, activity visibility, and location settings in your account settings.
4.2 D9 National Organizations
We do not share your information with any D9 national organization today, and no integration exists to do so. If we ever offer such sharing, it will be at your request or under a formal written agreement we tell you about first, and we will never share your data with a D9 organization to which you do not belong.
4.3 Service Providers
We share data with vendors who help us operate the Platform. They are contractually limited to using your data to provide services to us. Our current providers:
- Appwrite — our core hosting provider: our database, your uploaded images, our backend application, and background jobs
- Vercel — hosts our registration website and the browser version of our app. Information you enter during registration passes through Vercel's infrastructure on its way to us
- Clerk — authentication and sign-in, including email verification codes, invitations, and Apple/Google sign-in
- Stripe — subscription billing, under Stripe's own Privacy Policy
- Mapbox — converts addresses into map coordinates and renders our interactive map
- Typesense (which we self-host on Fly.io) — powers search and nearby-discovery features
- Knock — delivers in-app and push notifications, and sends certain operational emails
- Expo — relays push notifications to Apple's and Google's push systems, and delivers app updates. Expo receives your push token and a request from your device each time the app launches to check for updates
- Apple and Google — deliver push notifications to your device through their own push systems
- Cloudflare (Turnstile) — a bot-detection check on our waitlist form
- Shake — our in-app bug-reporting tool (see Section 2.1)
- Sentry — crash diagnostics. When the app stops unexpectedly on your device, Sentry receives a technical report describing what the app was doing at that moment: your device type, its operating-system version, the app version, and the place in our own code where the failure happened. The report does not include your messages, your profile, your location, or the contents of your screen. Sentry stores these reports in the United States
- PostHog — product analytics. Our servers, never the app on your device, send PostHog a record of which screens and features are opened, which steps are abandoned, and how quickly the app starts. Each record carries a pseudonymous identifier, the app version, your platform and operating-system version. It does not carry your name, your messages, your profile, your location, or anything you type — including what you search for, where only the number of results travels, never the words. PostHog stores these records in the United States
- GitHub and Slack — our issue-tracking and team-messaging tools, where bug reports and their screenshots are reviewed by our engineering team
Product analytics. PostHog, named above, is the product-analytics provider we are adopting so we can understand how the Platform is used and improve it — which features are opened, which steps people abandon, and where the app is slow or failing. It is being introduced with an upcoming app release. It is not receiving any of your information as of this Policy's effective date, and we are naming it here before we turn it on rather than after. What reaches PostHog is sent by our own servers, not from your device: there is no analytics software inside the app, and no analytics cookie, tracking pixel, or cross-site tracking on our website. That kind of measurement is product analytics, never advertising: we do not build advertising profiles, and we do not sell or share what it collects. Where the law requires your consent for it, we will ask for it.
Crash diagnostics. Sentry, named above, is being introduced with an upcoming app release. It is not receiving any of your information as of this Policy's effective date, and we are naming it here before we turn it on rather than after. Sentry receives crash reports only — it does not receive your activity or your content, we do not use it to build a profile of you, and it is never used for advertising.
We do not use any third-party advertising vendor, SMS vendor, or AI service. Our data is stored in the United States.
4.4 Legal Requirements
We may disclose your information where we have a good-faith belief it is necessary to:
- Comply with applicable law, regulation, or valid legal process
- Protect the rights, property, or safety of HeySoror, our members, or the public
- Prevent fraud, misrepresentation of D9 membership, or other illegal activity
Where the law permits it and it is practicable to do so, we will try to notify you before disclosing your information in response to a legal request.
4.5 Business Transfers
If HeySoror is involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such transfer and of any material change to how your data is handled, and where the law requires your consent, we will seek it.
5. Membership Verification Data
Information you provide to support your D9 membership is handled with additional care:
- Minimum collection: We collect only what we need to confirm D9 membership status
- Restricted to staff: Verification submissions are visible only to HeySoror administrators, not to other members
- No commercial use: Verification information is never analyzed for commercial purposes, sent to any AI service, used to train models, or shared with any third party
- Administrative records: Verification decisions — approvals, requests for more information, and rejections — are recorded in an administrative log
We do not collect identity documents today. If we introduce identity-document verification, we will update this Section to describe how those documents are handled and deleted before that feature is enabled.
6. Location Information
Location is the most sensitive category we handle, so this Section describes it in detail.
6.1 What We Collect
- Your home city. During registration you tell us where you are based. We store this as a place label and as map coordinates
- Your device's position, when you turn it on. While you have the app open and location enabled, the app reads your device's position and sends it to us to place your pin on our interactive map. This position replaces your home-city coordinates as your current map position. Your position is only read while the app is open and in the foreground — the app does not have permission to access your location in the background, and cannot collect it when the app is closed
- Places you enter. When you or an event organizer types an address for an event or trip, we send that address to Mapbox to convert it into coordinates, and we keep a copy of the result to avoid repeat lookups
6.2 Your Controls
Your account settings control location in two ways:
- Whether we read your device's position at all. You can turn this off. Turning it off stops us collecting any new position
- Who can see your location. You can choose to show your map location to all verified members, only to your connections, or to no one
Choosing "no one" removes your pin from other members' view.
6.3 What Other Members See
Members who can see your location see the position we most recently recorded. Your home city label is governed by your profile-visibility setting rather than by your location setting, so if you want your city hidden as well, restrict your profile visibility.
6.4 What We Do Not Do
- We do not collect your location in the background or while the app is closed
- We do not sell or share location information with advertisers or data brokers
- We never send location information to any AI or machine-learning service
- We do not share your location with any D9 organization
6.5 Location History
While you have location turned on, we keep a history of your recent positions in addition to your current pin.
What that history is, exactly:
- What we store. The position readings described in Section 6.1 — precise coordinates with a timestamp — recorded no more often than roughly once every two minutes, or when you have moved about 100 meters
- How long we keep it. Ninety days. An automatic daily process permanently deletes anything older. Deleting your account deletes your entire history immediately
- What it is for. Reviewing safety incidents. When a member reports a serious safety concern, a HeySoror administrator can review the relevant history to help establish what happened. We may also have to produce it in response to valid legal process (Section 4.4)
- Who can see it. No other member can ever see your location history — it is not shown on the map, in search, or anywhere else in the app. Access is limited to HeySoror administrators, using an administrative tool that records every access in our audit log before any data is displayed — the same audit-before-display mechanism that governs administrative access to messages (Section 7). As Section 9 explains, administrator access is a single permission level, so any administrator can reach this tool; the audit log, not a separate permission, is what holds that access accountable
- How to stop it. Turning location off in your settings stops any new history immediately, and the ninety-day deletion continues to run against what was already collected
7. Direct Messages & Communications
Messages between members travel over encrypted connections and are stored using our hosting provider's standard security controls. Messages are not end-to-end encrypted. They are stored as ordinary application data, and access is restricted at the application level to the participants in a conversation.
Authorized HeySoror administrators can read message content, and our administrative tools include a feature for doing so. We use it in specific, limited circumstances — to investigate a credible report of a Terms of Service violation such as harassment or threats, to comply with valid legal process, or when you have asked our support team for help with a message problem. Each such access is recorded in our administrative log before the messages are displayed.
Please report any communication that makes you feel unsafe using our in-app reporting feature or by emailing contact@heysoror.io.
8. Data Retention
8.1 While Your Account Is Active
We keep your personal data for as long as your account is active, and afterward only as described below or as the law requires.
8.2 When You Delete Your Account
You can delete your account from within the mobile app. Deletion is processed immediately, in a single operation, not scheduled for later. It removes your profile, your connections, the messages you sent, your trips, your location history, your search-index entry, your profile photo, and your notification records, cancels any active subscription, and deletes your authentication account.
8.3 What Survives Account Deletion
Some information does not go away when you delete your account. We would rather tell you plainly than describe deletion as more complete than it is:
- Messages other members received from you remain in their copy of the conversation, and conversations you took part in are retained with your membership removed
- Safety reports you filed are retained, with your identity replaced by a marker. Because that marker is derived from your account identifier, this is pseudonymization rather than true anonymization — it reduces, but does not eliminate, the possibility of re-identification
- Safety reports filed about you are retained in full, including your account identifier, so we can maintain a record of safety decisions
- Events you organized are retained with your name replaced by a generic label, though your organizer identifier is preserved
- Administrative and audit records of verification and safety decisions, and of the deletion itself, are retained for security, audit, and dispute-resolution purposes
- Campaign attribution records, waitlist entries, referral and invitation records, and payment records held by Stripe are retained
- Some uploaded images other than your profile photo — for example a cover image, or images attached to trips or events — may remain in our storage
- Cached address lookups are retained without being connected to your account
If you want any of the above removed, contact us at contact@heysoror.io and we will remove what the law entitles you to have removed.
Deletion runs as a series of steps, and if one fails — because a third-party service is unavailable, for example — some data may remain behind. If you contact us, we will check and finish the job.
8.4 Specific Retention Periods
- Transaction and tax records: seven years, consistent with financial record-keeping requirements
- Location history, if that feature is enabled: 90 days
- Waitlist entries: kept until we no longer need them to operate the waitlist, or until you ask us to remove them
- Administrative and security audit records: kept for the life of the account and for a period afterward, for security, audit, and dispute-resolution purposes
- Bug reports: kept in our bug-tracking systems for as long as needed to diagnose and fix the issue
9. Security
We use standard security practices to protect your personal information:
- Encryption in transit (TLS) for Platform traffic
- Our hosting provider's encryption of data at rest. We do not add our own application-level encryption on top of it today
- Access to administrative tools is restricted to accounts we designate as administrators
- Multi-factor authentication is required on all HeySoror staff and administrator accounts
- Administrative access to member messages, verification data, and location history is recorded in an audit log
Please note what we are not claiming. We do not operate end-to-end encryption. We do not encrypt individual database fields ourselves. Administrator access is a single permission level rather than a tiered, least-privilege system, so an administrator who can view one kind of member data can generally view others.
No system is immune to security incidents. If a breach affects your personal information, we will notify you as promptly as we can and no later than applicable law requires, and describe what happened, what data was involved, and what we are doing.
10. Your Privacy Rights
Depending on where you live, you may have some or all of the rights below. Where a right applies to you under law, we will honor it. We also extend the first three to every member regardless of location, as a matter of practice:
- Access: Request a copy of the personal data we hold about you
- Correction: Update or correct your information in your account settings, or by contacting us
- Deletion: Delete your account and personal data from within the app, or by contacting us — subject to what Section 8.3 describes
- Portability: Request your personal data in a structured, machine-readable format. We assemble this manually on request; it is not yet a self-service export, so please allow us the time the law provides
- Restriction and objection: Ask us to limit how we use your data, or object to particular uses, including any direct marketing
- Withdraw consent: Where we rely on your consent — location, or optional community emails — withdraw it at any time without penalty
To exercise a right, contact us at contact@heysoror.io. We will respond within the period applicable law requires, generally 45 days, and will tell you if we need longer. We will not discriminate against you or restrict your access to the Platform for exercising your rights.
11. U.S. State Privacy Rights
11.1 General
If you live in California, you have rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act, including the rights to know, delete, correct, and opt out of the sale or sharing of personal information. As stated throughout this Policy, we do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of.
If you live in another state with a comprehensive privacy law — Virginia, Colorado, Connecticut, Texas, Oregon, and others — you may have comparable rights. Contact us at contact@heysoror.io. We will verify your identity before processing your request, and we will not discriminate against you for making one.
11.2 Sensitive Information
Your precise location, where you have enabled it, is treated as sensitive personal information under California and other state privacy laws.
We collect it for one purpose: to place your pin on our interactive map when you have asked us to. We do not use it to infer any characteristic about you, we do not sell or share it, and we do not use it for any purpose beyond operating the Platform and its safety functions. You can turn it off at any time in your settings, and Section 6 describes those controls in full.
12. Age of Members
The Platform is intended exclusively for initiated D9 sorority members who are 18 or older. We ask you to confirm you meet this requirement, and we rely on your confirmation — we do not collect your date of birth and we do not otherwise verify your age.
We do not knowingly collect personal information from anyone under 18. If we learn that someone under 18 has created an account, we will delete it. If you believe a minor has an account on the Platform, contact us at contact@heysoror.io.
13. Members Outside the United States
We operate from the United States, and your data is stored and processed there. If you use the Platform from another country, your information is transferred to the United States, which may have different data-protection laws than your own.
The Platform is currently offered to members in the United States. We have not yet built the additional compliance measures that other jurisdictions require — including, in the European Economic Area and the United Kingdom, appointing a local representative and establishing transfer safeguards. If we begin offering the Platform in those regions, we will put those measures in place and update this Policy before doing so.
14. Cookies & Browser Storage
Our websites use:
- Essential cookies: A set of authentication and session cookies from Clerk, our authentication provider, which keep you signed in and protect against session tampering. On our waitlist form, our bot-detection provider (Cloudflare Turnstile) may also set a cookie. These are required for the sites to work
- No analytics or advertising cookies: We do not currently use analytics cookies, advertising cookies, tracking pixels, or cross-site tracking of any kind, and we do not permit any third party to track you across other websites. If we adopt a product-analytics provider that uses cookies or similar storage, we will update this Policy first
- Browser storage during registration: While you work through the registration wizard, your browser temporarily stores your in-progress answers — including your display name, bio, chapter, interests, and home-city coordinates — so you do not lose them if you refresh. This is cleared when registration completes
Our mobile app does not use cookies.
15. Changes to This Privacy Policy
We may update this Policy. When we make a material change, we will notify you through the Platform or by email to the address on your account before it takes effect, and we will update the "Last Updated" date above.
Your continued use of the Platform after a revised Policy takes effect means you accept the change. If you do not agree with a material change, you may delete your account.
16. Contact Us
Questions, concerns, or requests about this Policy or your personal data:
HeySoror Tech Inc. — Privacy Inquiries Email: contact@heysoror.io Website: heysoror.io Mailing Address: 1100 New Jersey Ave SE #2142, Washington, DC 20003
We aim to resolve privacy concerns promptly. If you believe your concern has not been adequately addressed, you may have the right to complain to your applicable data-protection authority.
© 2026 HeySoror Tech Inc. All Rights Reserved. | Sisterhood Knows No Borders™