Chaptara Privacy Policy

Effective date: July 10, 2026

Last updated: July 10, 2026

 

1. Introduction

This Privacy Policy explains how Chaptara, Inc., a Delaware corporation (“Chaptara,” “we,” “us,” or “our”) collects, uses, discloses, and protects information about you when you use the Chaptara mobile application, our web application, and related services (collectively, the “Service”).

Chaptara is a private membership-management platform for collegiate fraternity and sorority chapters. Access is invitation-based: you use Chaptara because a chapter you belong to uses it to run events, attendance, messaging, house points, study hours, and related activities.

By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, do not use the Service.

Your use of the Service is also governed by our Terms of Service, including its dispute-resolution provisions. This Policy and the Terms of Service should be read together.

This Policy is written for users located in the United States. The Service is operated from and its data is stored in the United States.

2. Who controls your information

Two parties handle information within Chaptara:

  • Chaptara operates the platform, the servers, and the underlying infrastructure. This Policy describes how *we* handle your information.
  • Your chapter and its administrators (officers, chapter admins, and organization/university administrators, as applicable — your “Organization” and its “Administrators” as defined in our Terms of Service) use Chaptara to administer your membership. They control much of the content and configuration within your chapter — for example, who is invited, what custom profile questions are asked, what events are mandatory, and how house points and study hours are run. When your chapter’s administrators handle your information, they do so under their own policies and their relationship with you, not this Policy.

If you have questions about how your specific chapter uses your information, contact your chapter’s leadership directly.

3. Eligibility (16 and older; parental consent for minors)

The Service is intended for individuals 16 years of age or older who are members (or invited prospective members) of a collegiate fraternity or sorority chapter.

If you are 16 or 17 years old (a “Minor User” under our Terms of Service), you may use the Service only if you have been invited by your Organization and your parent or legal guardian has reviewed and accepted our Terms of Service — on their own behalf and on yours — through the parental-consent process we provide, as described in Section 2.2 of the Terms of Service. Your parent or guardian may review the information we have collected about you, revoke their consent, and request deletion of your account at any time by contacting us at support@chaptara.com. If consent is revoked, we will close the account and delete personal information as described in Section 15. We may limit, modify, or disable certain features for Minor User accounts.

When a Minor User turns 18, we will present the Terms of Service for acceptance in the user’s own capacity, as described in Section 2.3 of the Terms of Service.

We do not knowingly collect personal information from anyone under 16, and never from children under 13. If you are under 16, do not use the Service or provide any information to us. If we learn that we have collected personal information from a child under 16, or from a 16- or 17-year-old without parental consent, we will delete it. See Section 14 (Children’s Privacy).

4. Information we collect

We collect the following categories of information.

4.1 Information you provide to us

Account and identity information. When you register (via an invitation from your chapter) and manage your account, we collect:

  • Email address
  • Password (stored only as a salted hash — we never store your plaintext password)
  • First and last name
  • Date of birth — used to verify your eligibility and, if you are 16 or 17, to route your registration through the parental-consent process (see Section 3)
  • Phone number (used for verification and two-factor authentication)
  • Invitation token that authorizes your registration
  • For Minor Users (16–17): your parent or legal guardian’s name and contact information, and a record of their consent (including the date, time, and method of consent)

Profile information. You may add:

  • Profile photo (and system-generated resized/thumbnail versions)
  • Birthday display preferences (your date of birth is collected at registration; you control how your birthday is displayed to your chapter)
  • Pledge class
  • Major
  • Hometown
  • Chapter position or title
  • Residency status (whether you live in the chapter house)
  • Social media links
  • Answers to custom profile questions defined by your chapter

Content you create and submit. As you use the Service, we collect and store the content you generate, including:

  • Messages, replies, reactions, poll votes, and captions in direct, group, and chapter-wide (“blast”) conversations
  • Photos, videos, and documents you upload to chats, photo albums, event attachments, and chapter file folders
  • Photo tags identifying members. Tags are applied manually by members — we do not use facial recognition, face detection, or any other biometric technology to identify, tag, or group people in photos
  • Event check-in notes, event registration and sign-up form responses
  • Excuse requests and appeals — including the reason, written details, and any supporting photos or documents you attach (these may contain personal or sensitive information, such as medical or family circumstances, if you choose to include them)
  • House-points submissions (proof photos, comments) and appeals
  • Study-hours records and responses
  • Votes and ballots, including any write-in text
  • Meal ratings and late-plate requests
  • Reports you submit about other users or content, and users you block

Communications with us. If you contact us for support, we collect the information you provide in that correspondence.

4.2 Information we collect automatically

Device and technical information. When you use the Service, we automatically collect:

  • Device model and platform (iOS or Android)
  • A device identifier we assign for “trusted device” management
  • IP address and user-agent string (recorded with login sessions and trusted devices)
  • App version and update information

Push notification token. If you enable notifications, we collect a push-notification token for your device so we can deliver alerts.

Usage and activity information. To operate the Service, we record activity such as your last-active timestamp, message read/receipt state, online/typing presence (temporary), attendance and check-in records, study-session activity, and participation in chapter features.

Precise location information. With your permission, we collect your device’s precise GPS location only in connection with check-in features, for specific, limited purposes:

  • Event check-in — to confirm you are physically present at an event when you check in by location
  • Study-hours sessions — at check-in, at check-out, and at randomized location checkpoints that occur during an active study session, to verify presence at a designated study location and its geofenced area

We store the coordinates and, for study hours, an accuracy value, associated with the specific check-in or session. Outside of these check-in actions and active study sessions, we do not collect your location, and we do not build a continuous location history of your movements. You can decline or revoke the location permission in your device settings; without it, you will not be able to use location-based check-in, but you can still use other check-in methods where offered (e.g., QR code or administrator/proctor confirmation).

4.3 Information from your device that we access but do not collect

Certain device features are accessed locally on your device and are not transmitted to or stored by us except as content you choose to send:

  • Camera — used to scan event check-in QR codes and to take photos you choose to send. QR data is parsed on-device; captured photos are only uploaded if you send them.
  • Photo library — used to let you pick photos/videos to send. We receive only the specific files you select.

We do not access your contacts, microphone/audio, calendar, health data, or biometric data.

4.4 Sensitive information

Some information described above is treated as “sensitive” under certain U.S. state laws. This includes:

  • Precise geolocation (Section 4.2)
  • Account log-in credentials (your email in combination with your password)
  • Health-related or other sensitive details you voluntarily include in excuse requests, appeals, or custom form responses

We use sensitive information only for the purposes described in this Policy and to provide the features you request — not for advertising, profiling, or inferring characteristics about you. Where a feature invites content that may include health-related details (such as excuse requests), we present a notice at the point of submission reminding you that your submission will be visible to your chapter’s authorized officers and asking you to include only the information needed. See Section 12 (Your Privacy Rights).

5. How we use information

We use the information we collect to:

  • Create, authenticate, and secure your account, including two-factor authentication and trusted-device management
  • Provide the Service’s core features: events and attendance, messaging, photo albums, chapter files, house points, study hours, voting, menus, and chapter administration
  • Verify presence for event and study-hall check-ins
  • Deliver push notifications and in-app alerts you have enabled
  • Operate real-time messaging, presence, and typing indicators
  • Enable moderation and safety features, including reporting and blocking
  • Maintain administrative and audit records (e.g., role changes, suspensions, device revocations, point adjustments) for accountability and security
  • Communicate with you about your account, security, and the Service
  • Monitor, troubleshoot, secure, and improve the Service, and prevent fraud and abuse
  • Comply with legal obligations and enforce our Terms

We do not use your information for third-party advertising, and we do not sell it or share it for cross-context behavioral advertising. See Section 8.

6. Text messaging (SMS) terms

If you provide your phone number and consent, we send SMS text messages via our messaging provider for account verification and two-factor authentication (for example, one-time passcodes) and related security notices. We do not send marketing or promotional text messages.

  • Consent: By verifying your phone number, you consent to receive these messages at that number. We record the date, time, and method of your consent.
  • Frequency: Message frequency varies based on your account activity (for example, when you log in from a new device).
  • Rates: Message and data rates may apply, depending on your mobile carrier and plan.
  • Opt-out — any reasonable method: You may revoke your consent to receive SMS messages at any time and by any reasonable method — for example, by replying STOP (or similar words such as QUIT, CANCEL, END, UNSUBSCRIBE, or OPT OUT) to any message, or by contacting us at support@chaptara.com. We honor revocation requests promptly, and in any event within ten (10) business days. After you opt out, we may send a single message confirming your opt-out, and no others.
  • Account security after opt-out: Because SMS is one method we use for two-factor authentication, if you opt out of SMS we will stop sending text messages to your number — including verification codes — and will offer you an alternative verification method by reaching out to support@chaptara.com so you can continue to access and secure your account.
  • Help: Reply HELP to any message, or contact support@chaptara.com, for assistance.
  • Carriers: Mobile carriers are not liable for delayed or undelivered messages.

We do not share your phone number with third parties for their marketing, and we do not use it for advertising.

7. How we share information

We share information only as described below.

7.1 Within your chapter

Chaptara is a shared community platform. By design, other members and administrators of your chapter can see certain information:

  • Other members can see your profile information, your presence in shared conversations, your messages and content in conversations and albums you participate in, and features like the member directory, family tree (big/little pairings), and votes you participate in.
  • Officers, chapter admins, and other authorized administrators can additionally access administrative information about you — such as your attendance and check-in records (including check-in location where applicable), study-hours records and locations, excuse submissions and their details, house-points submissions, form responses, good-standing progress, and moderation reports — in order to run the chapter.

Consider what you share, post, and submit. Content you send in conversations or submit through the Service may be seen, saved, or forwarded by others, notwithstanding features like screenshot prevention (which cannot be guaranteed on all devices).

7.2 Service providers (subprocessors)

We share information with vendors that perform services for us, under contracts that limit their use of the information to providing those services. Our current subprocessors are:

Provider Purpose Information shared
Amazon Web Services (AWS) — US (us-east-2) Cloud hosting, database, cache, media storage (S3), and content delivery (CloudFront) All Service data, stored and processed on AWS infrastructure
Twilio Sending SMS verification/2FA codes and transactional emails (invitations, password resets) Phone number and message content (SMS); email address and message content (email)
Expo Delivering push notifications and app updates Device push token, platform, and notification content
Google (Maps Platform / Places) Address autocomplete and map display when creating or viewing event/study locations Location text you type into address fields, and map display requests
Finix Payment processing (see Section 9) Payment and transaction information you provide when paying

 

We may add or change subprocessors as the Service evolves; material changes will be reflected in this Policy.

7.3 Legal, safety, and protection

We may disclose information if we believe in good faith that it is necessary to: comply with a law, regulation, legal process, or governmental request; enforce our Terms; detect, prevent, or address fraud, security, or technical issues; or protect the rights, property, or safety of Chaptara, our users, or the public.

7.4 Business transfers

If Chaptara is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will require the recipient to honor this Policy or provide notice of any material change.

7.5 Aggregated or de-identified information

We may create and use aggregated or de-identified information that cannot reasonably be used to identify you. When we do, we maintain and use it in de-identified form and do not attempt to re-identify it, except to assess whether de-identification is sufficient.

7.6 What we do NOT do

  • We do not sell your personal information.
  • We do not share your personal information for cross-context behavioral (targeted) advertising.
  • We do not use third-party advertising networks, ad SDKs, or cross-app tracking, and we do not collect advertising identifiers (e.g., IDFA).
  • We do not use third-party behavioral-analytics, session-replay, or user-tracking tools in the app. Our infrastructure providers (Section 7.2) may process limited technical and diagnostic data (such as device identifiers, delivery receipts, and error information) as an inherent part of providing their services to us — not for advertising or for their own commercial purposes.

8. No sale or sharing of personal information; no targeted advertising

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (as amended by the CPRA) and similar U.S. state laws. We have not done so in the preceding 12 months. Because we do not engage in these practices, there is no “Do Not Sell or Share My Personal Information” mechanism to enable — but you retain the rights described in Section 12. This applies to all users, including users under 18.

Opt-out preference signals (“Do Not Track” / Global Privacy Control). Because we do not sell or share personal information, do not engage in targeted advertising, and do not track users across third-party services, there is no data practice for these signals to opt you out of. Accordingly, the Service does not respond to “Do Not Track” or Global Privacy Control browser signals; our data practices are the same for all users and are as described in this Policy.

9. Payments

Chaptara uses Finix as our third-party payment processor for any payments made through the Service.

When you make a payment, your payment details (such as card or bank-account information) are collected and processed directly by Finix under Finix’s own privacy policy and security controls. Chaptara does not collect or store your full payment card number or bank credentials on our systems. We receive and store limited transaction information necessary to record and administer the payment — for example, a transaction identifier, amount, date, status, and a description of what the payment was for.

We use payment information to process transactions you authorize, maintain financial records, prevent fraud, and comply with legal and accounting obligations. For details on how Finix handles your information, please review Finix’s privacy policy.

10. Data retention

We retain personal information for as long as your account is active and as needed to provide the Service, and thereafter as required for legitimate business purposes such as security, dispute resolution, audit, and legal compliance.

Specifics:

  • Account, profile, and content are retained for the life of your account. Some content you contribute to a chapter (for example, messages in a shared conversation, attendance records, house-points, study-hours, votes, and moderation records) may persist within the chapter’s records even after you leave or your account is deleted, in a form that reflects chapter activity.
  • Deleted messages are hidden from view but may be retained in our systems for a period for integrity, moderation, and backup purposes before being purged.
  • Login sessions and refresh tokens expire on a rolling basis and can be revoked by you (via logout or device management) or by an administrator.
  • Trusted-device records expire automatically (currently after 90 days) or when revoked.
  • Verification codes are short-lived and stored only transiently.
  • Administrative and audit logs (e.g., moderation actions, suspensions) are retained as records of chapter governance and platform safety.
  • Backups are retained for a limited period and then rotated out.

When you delete your account, your identifying information is erased from our live systems immediately, and certain shared chapter records are retained in anonymized form, as described in detail in Section 15 (Account Deletion).

Legal holds. Notwithstanding anything above, we may preserve information for longer where required by law, court order, subpoena, or other valid legal process, or where we have a good-faith belief that preservation is necessary in connection with actual or reasonably anticipated litigation, investigations, or enforcement of our Terms. Information subject to such a hold is retained only for as long as the hold remains in effect and is used only for the purposes of the hold.

11. Security

We implement technical and organizational measures designed to protect your information, including:

  • Encryption of data in transit using TLS/HTTPS (including for real-time messaging and file uploads)
  • Storage of passwords only as salted bcrypt hashes
  • Two-factor authentication and trusted-device controls
  • Storage of sensitive device tokens in the operating system’s secure keychain/keystore
  • Time-limited, signed URLs for access to uploaded media and files
  • Role-based access controls that scope data to your chapter and to authorized administrators
  • Session management with token rotation and revocation
  • Screen-capture prevention on chat screens (where supported by the device)

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential. If you believe your account has been compromised, contact us immediately.

12. Your privacy rights

Depending on your U.S. state of residence, you may have some or all of the following rights regarding your personal information:

  • Right to know / access the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties to whom we disclose it.
  • Right to correct inaccurate personal information.
  • Right to delete personal information we have collected from you, subject to exceptions.
  • Right to data portability — to obtain a copy of your personal information in a portable format.
  • Right to opt out of the sale or sharing of personal information and of targeted advertising. *As noted in Section 8, we do not sell or share personal information or conduct targeted advertising, so there is nothing to opt out of.*
  • Right to limit the use of sensitive personal information. We use sensitive personal information only for permitted purposes — to provide the Service you request and for security — and not to infer characteristics about you or for advertising.
  • Right to non-discrimination — we will not discriminate against you for exercising any of these rights.

Many of these rights are provided under state laws including the California Consumer Privacy Act (as amended by the CPRA), and comparable laws in states such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others, to the extent they apply to you.

How to exercise your rights. You can access and update much of your profile information directly in the app. To make a formal privacy request, contact us at support@chaptara.com. We will verify your request (typically by confirming control of your account email) before responding. You may use an authorized agent where permitted by law; we may require proof of authorization.

Response times. We will respond within the timeframes required by applicable law (generally within 45 days, extendable where permitted).

Appeals. If we deny your request and your state provides an appeal right, you may appeal by replying to our response or contacting support@chaptara.com. If you have concerns about our handling of your request, you may contact your state Attorney General.

Note on chapter-controlled data. For certain requests, we may act at the direction of, or refer you to, your chapter or organization where they control the relevant information (see Section 2).

13. Your choices and controls

  • Device permissions. You can grant or revoke camera, photo library, location, and notification permissions at any time in your device’s settings. Some features will not function without the relevant permission.
  • Push notifications. You can disable notifications on your device, and you can mute individual conversations in the app.
  • Location is used only for check-in actions and only while you use the app; you can decline it and use alternative check-in methods where available.
  • Trusted devices and sessions. You can view and revoke trusted devices and log out of sessions in the app.
  • Blocking and reporting. You can block other users and report content or users for moderation.
  • Account deletion. You can request deletion of your account (see Section 10 and Section 15).

14. Children’s privacy

The Service is intended for collegiate fraternity and sorority members age 16 and older and is not directed to children. We do not knowingly collect personal information from anyone under 16, and specifically not from children under 13 (as defined by the Children’s Online Privacy Protection Act).

Users who are 16 or 17 may use the Service only with the consent of a parent or legal guardian (see Section 3). A parent or guardian of a 16- or 17-year-old user may contact us at support@chaptara.com to review the personal information we have collected about their child, request corrections or deletion, or revoke their consent to further collection and use — in which case we will close the account and delete personal information as described in Section 15.

We treat the personal information of all minor users the same protective way we treat all users’: we do not sell it, do not share it for targeted advertising, and do not use it for profiling. If you believe a child under 16, or a minor without parental consent, has provided us personal information, contact us at support@chaptara.com and we will take steps to delete it.

15. Account deletion

You can delete your Chaptara account yourself, at any time, directly in the app: go to Edit Profile → Delete Account. For security, you will be asked to re-enter your password and confirm your choice twice. You do not need to email us or contact support to delete your account, though you may always contact support@chaptara.com for help or to make a formal privacy request under Section 12.

Deletion is immediate, permanent, and irreversible. There is no waiting period and no grace period. Once you confirm, your account cannot be recovered or restored — by you, by your chapter, or by Chaptara.

15.1 What is deleted immediately

The following is erased from our live systems the moment you confirm deletion:

  • Your identity and profile — your name, email address, phone number (including phone-verification and SMS-consent records), password, birthday, major, hometown, position/title, pledge class, live-in-house status, social media links, and all answers to chapter-defined custom profile questions. Your profile photos, in all sizes, are deleted from our cloud storage.
  • Your access — every login session and refresh token is revoked (you are signed out of all devices immediately), all trusted-device records are removed, and all push-notification registrations are deleted, so no further notifications of any kind are sent.
  • Your associations — your chapter membership is severed and you are removed from the chapter roster, member directory, groups, and member statistics; you are removed from every conversation’s member list; every photo tag identifying you is deleted; and all blocks and role assignments are removed.

15.2 What is retained, in anonymized form

Certain records are inherently part of your chapter’s shared records or are needed for community safety, and are retained after deletion — but they are anonymized: they are no longer linked to your identity, and any attribution displays only as “Former Member,” with all of the identifying information described in Section 15.1 erased. These are:

  • Chapter operational records — event attendance and check-in history, excuse requests, house-point submissions and adjustments, study-hours sessions, and good-standing history
  • Vote ballots, retained to preserve the integrity of past chapter election results
  • Messages you sent in conversations (the content remains visible to other participants; the sender is shown as “Former Member”)
  • Photos you uploaded to shared chapter albums
  • Family-tree (big/little) pairing records
  • Records of invites, events, albums, folders, and conversations you created (with creator attribution anonymized)
  • Moderation records — reports filed by or about you — retained for safety and audit purposes

We retain these anonymized records for the legitimate interests of chapter record-keeping, election integrity, and community safety.

15.3 What you should know about the limits of deletion

  • Photos of you uploaded by others are not deleted. Deletion removes your tags, but a photo another member uploaded that happens to depict you remains in the album it was posted to. You can report a specific photo in the app for review and removal by chapter administrators.
  • Deleted data may persist in routine encrypted database backups for a limited period (30 Days) before those backups are rotated out; backup data is not restored to live systems except for disaster recovery.
  • Service providers. Our SMS provider (Twilio) retains message logs under its own retention schedule; push-notification device tokens are deleted at the time of account deletion; profile images are deleted from cloud storage at the time of deletion, and any content-delivery-network cached copies expire with their short-lived signed URLs.
  • Other people’s devices. Content you sent that others already received (messages, photos) may persist on their devices — for example, in app caches or screenshots — as with any messaging service.
  • Deletion is not a ban. If you are re-invited by a chapter, you may create a new account later; nothing links a new account to a deleted one.
  • Legal holds. In rare cases, we may be required to preserve information notwithstanding a deletion request, as described in Section 10; preserved information is used only for the purposes of the legal hold.

Note: Chaptara staff (global administrator) accounts cannot self-delete through the app and are managed under our internal procedures.

16. Data location

Chaptara is operated in the United States, and your information is stored and processed on infrastructure located in the United States (AWS, us-east-2 region). If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States.

17. Third-party links and content

The Service may contain links or references to third-party websites or services (for example, social-media links on member profiles, or map providers). We are not responsible for the privacy practices of those third parties. Review their privacy policies before providing them information.

18. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date and provide advance notice (such as an in-app notice or email), and — where required by law or by our Terms of Service — we will ask you to affirmatively accept the change. Otherwise, your continued use of the Service after an update means you accept the revised Policy. Changes apply prospectively only.

19. Contact us

If you have questions or requests regarding this Policy or your personal information, contact us at:

Chaptara, Inc.

Attn: Privacy
7829 E Rockhill St., Suite 307, Wichita, Kansas 67206
Email: support@chaptara.com
Support: support@chaptara.com

 

 

Appendix A — Categories of personal information (CCPA/CPRA)

The following table summarizes the categories of personal information (as defined by the California Consumer Privacy Act) that we collect, the sources, the business purposes, and the categories of parties to whom we disclose them for a business purpose. We do not sell or share any category for cross-context behavioral advertising.

CCPA category Collect? Examples Source Disclosed to (business purpose)
Identifiers Yes Name, email, phone number, account ID, device identifier, IP address, push token; for Minor Users, parent/guardian name and contact information You; your parent or guardian; automatically from your device AWS, Twilio, Expo (service providers)
Personal records (Cal. Civ. Code §1798.80) Yes Name, phone number, payment/transaction records (via Finix) You; Finix AWS, Finix
Protected classifications Yes Age / date of birth You AWS
Commercial information Yes (when payments are used) Transaction records, amounts, descriptions You; Finix AWS, Finix
Internet / network activity Yes App usage, feature interactions, presence, read receipts Automatically AWS
Geolocation data (precise) Yes GPS coordinates at event and study check-ins Your device (with permission) AWS
Audio/visual information Yes Photos, videos, and documents you upload; profile photos You AWS
Sensitive personal information Yes Precise geolocation; account log-in credentials; health/family details you voluntarily include in excuses, appeals, or forms You; your device AWS
Professional / employment information No
Education information (FERPA) No
Biometric information No Photo tags are applied manually by members; no facial recognition or biometric technology is used
Inferences Limited Group/segment membership computed from profile attributes (e.g., pledge class) for chapter administration Derived AWS