Privacy Policy
Last updated: August 3, 2026
FRC Team 1811 “FRESH” is a student robotics team competing in the FIRST Robotics Competition. This policy explains what information we collect, why we collect it, who it is shared with, and how you can have it removed. We collect as little as we can, and we do not sell personal information to anyone, ever.
1. What this policy covers
- Our public website —
frc1811.com, open to everyone. - Our team admin panel —
admin.frc1811.comand its API atadmin-api.frc1811.com, private and restricted to team members and mentors.
2. Information we collect
Visitors to the public website
- Analytics. We use Google Analytics to count visits and see which pages are read. This includes approximate location, browser and device type, and pages viewed.
- Contact form. If you send us a message, we receive whatever you type into it, including your name and email address, so we can reply.
You do not need an account, and we do not require you to give us any personal information, to read the public website.
Team members using the admin panel
Accounts are created only for members and mentors of the team. Depending on what the team needs, a member record may include:
- Account details — username, a securely hashed password, display name, rank, and account settings.
- Member profile — full and preferred name, email address, phone number, birthday, graduation year, student ID, shirt size, subteam roles, and profile photo.
- Safety and logistics information — allergies, dietary restrictions, transportation needs, and a parent or guardian's name and phone number, so we can keep members safe at meetings, competitions, and travel events.
- Team activity — meeting attendance and check-ins, to-dos, event RSVPs, notes written by mentors or leads, poll responses, and content you post such as blogs or announcements.
- Sign-in and device information — session tokens, the browser and device you signed in from, and your IP address at sign-in, so we can keep accounts secure and let you sign out of other devices.
- Passkeys — if you set up Face ID, Touch ID, or Windows Hello, we store only a public key and a device label. We never receive your fingerprint, face data, or device PIN.
- Push notifications — if you allow them, a subscription identifier from your browser so we can send team alerts.
3. Google Sign-In
Team members may optionally link a Google account to sign in more quickly. This is entirely optional — a username and password always works instead.
- We request only the
openid,email, andprofilescopes. - From those we receive and store your Google account ID, your email address, your name, and your profile picture URL.
- This information is used for one purpose only: to recognize which team account belongs to you when you sign in. It is not used for advertising, is not sold, and is not shared with anyone else.
- We never receive access to your Gmail, Google Drive, Contacts, Calendar, or any other Google service.
- We never receive your Google password.
Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. You can unlink your Google account at any time in the admin panel under Settings → Privacy → Account Linking, which immediately deletes the stored link. You can also revoke our access from your Google account permissions page.
4. How we use information
- To run the team: tracking attendance, organizing events, assigning tasks, and communicating with members.
- To keep members safe, including responding to allergies, dietary needs, and emergencies during meetings and travel.
- To operate accounts securely and prevent unauthorized access.
- To share the team's work publicly through our website, outreach, and awards submissions — using photos, names, and quotes as permitted by our Membership Agreement & Code of Conduct.
- To understand, in aggregate, how our public website is used.
We do not sell personal information, and we do not use it for advertising or automated decision-making.
5. Students, parents, and guardians
Most of our members are minors. Membership on the team — and the collection of the information described above — is agreed to by the student and their parent or guardian as part of joining the team, alongside our Membership Agreement & Code of Conduct and any forms required by our school. The admin panel is not open to the general public and is not directed to children outside our team. We do not knowingly collect personal information from anyone who is not a team member. A parent or guardian may review, correct, or request deletion of their student's information at any time using the contact details below.
6. Who we share information with
We share information only with the service providers that make our site and tools work, and only as needed to operate them:
- Cloudflare — website hosting and content delivery.
- Railway — hosting for our admin API and its database.
- MongoDB — storage for personal display settings.
- ImageKit — storage and delivery of uploaded images.
- Google — Analytics on the public website, and Sign-In if you choose to link a Google account.
- Our school and FIRST — where required for registration, eligibility, travel, or supervision.
We may also disclose information if required by law, or to protect someone's safety.
7. Cookies and local storage
- The admin panel sets a secure,
HttpOnlycookie to keep you signed in. It cannot be read by scripts. - The admin panel stores your preferences (theme, accessibility options) in your browser's local storage.
- The public website uses Google Analytics cookies. You can block these with your browser settings or an ad blocker without losing any functionality.
8. How long we keep information
- Member records are kept while you are on the team, and for a reasonable period afterwards for alumni records and team history.
- Sign-in sessions expire automatically, and revoked or expired tokens are cleared.
- Linked Google accounts are deleted immediately when you unlink them.
- Published content such as blogs, photos, and award submissions may remain part of the team's public history.
9. How we protect information
All traffic is encrypted with HTTPS. Passwords are stored only as salted bcrypt
hashes — we cannot read them. Sign-in uses short-lived access tokens with
rotating refresh tokens stored in HttpOnly cookies, and passkeys are
supported for stronger sign-in. Access inside the admin panel is limited by rank,
so members only see what their role requires. No system is perfectly secure, but we
take these protections seriously and fix problems promptly when we learn of them.
10. Your choices and rights
- Ask us what information we hold about you, and get a copy.
- Ask us to correct anything that is wrong.
- Ask us to delete your information, subject to school or FIRST records we are required to keep.
- Ask us to remove a photo of you from our website or social media.
- Unlink a connected Google account, or turn off push notifications, at any time from the admin panel.
To make any of these requests, email us at the address below. We will respond as soon as we reasonably can.
11. Changes to this policy
If we change this policy we will update the “Last updated” date at the top of this page. Significant changes affecting team members will also be announced in the admin panel.
12. Contact us
Questions about this policy, or requests about your information, can be sent to:
- Team email: [email protected]
- Team coaches: David Koethe ([email protected]) · Silvia Duarte ([email protected]) · Jonas Pains ([email protected])
See also our Terms of Service and Membership Agreement & Code of Conduct.