Global SDGs Alliance participant app · Last updated 7 August 2026
This app is run by Taiwan Institute of Innoactive Education (社團法人台灣永續創新行動教育協會), an incorporated association registered in Taiwan, unified business number 26879192, at 8F., No. 42, Xuchang St., Zhongzheng Dist., Taipei City, Taiwan. We run events under the name Global SDGs Alliance.
For anything in this policy, contact Jimmy Wei at privacy@sdgs-alliance.com.
The app is used only by people taking part in the event: students, the teachers travelling with them, and our organising staff. Accounts are created by us and activated with an invitation code — there is no public sign-up. Many of the students are under 18. We collect nothing beyond what running the trip requires, we show no advertising, and we never make a student’s data available to anyone outside the organising team except as described below.
If you are a parent or guardian and want to know what we hold about your child, ask us at privacy@sdgs-alliance.com.
We do not collect your location. We do not use advertising, analytics or tracking services of any kind, we do not sell or trade your data, and we do not use it for automated decision-making. Everything we hold is listed above: this app has no public profile wall, no questionnaires, and no coursework uploads, so it collects nothing of that sort.
We use this data to run the event: to set up your account, publish the agenda, assign rooms and transport, count everyone in at roll calls so that nobody is left behind, keep the team points, send you event notifications, cater for your dietary and accessibility needs, reach your emergency contact if something happens, report participant numbers to the partners who funded the event, and keep a record of who took part. We process it to perform our agreement with you as a participant, and to keep participants safe. Your health and accessibility information we use on the basis of your consent.
Telling you about future events. When you activate your account you can tick an optional box to hear about future Global SDGs Alliance events. This is separate from running this event, so we do it only if you tick it, and we record that you did along with the date. Leaving it unticked changes nothing else. You can change your mind at any time by emailing privacy@sdgs-alliance.com and we will stop; every message we send will also tell you how to stop.
Most fields are optional, but some things will not work without them: without dietary or accessibility information we cannot cater for you or arrange adjustments, and without flight details we cannot arrange airport pickup.
Food allergies, dietary restrictions, health notes and accessibility needs are sensitive personal data under Article 6 of Taiwan’s Personal Data Protection Act and Article 9 of the GDPR. You gave your consent to our collecting and using this information when you registered for the event. The fields in the app let you keep it up to date; you can change or clear them at any time under Profile › Health & diet (個人 › 健康與飲食), and you can withdraw your consent by contacting us.
This information is available only to members of the organising team, including the teachers travelling with the group, and only for these purposes: briefing caterers, arranging accessible rooms, venues and transport, and responding if you need medical help. A teacher who scans your name badge can open your allergy, dietary and emergency-contact details on the spot — that is what the badge is for in an emergency. In a medical emergency we may pass the relevant details to medical or emergency personnel — the law permits this to protect your life or health, and we will do it whether or not we can reach you at the time. We do not use this information for any other purpose, and it is never shown to other participants.
If you clear this information or withdraw your consent before or during the event, we may no longer be able to accommodate the need it described.
Other participants. There is no participant list or profile wall in this app, so other participants cannot look you up. What they can see is: every team’s points entries, including the reason a teacher wrote and that teacher’s name — and a teacher’s note may mention a participant by name; and, if you post or hand in a lost item, the name shown against that item. They cannot see your contact details, your date of birth, your health or dietary information, your flight details, your emergency contact, which team you are in, or any roll-call record.
Roommates. If you are sharing a room, the people in it can additionally see your name, your profile photo and your room number. They can see your phone number only if you turn on the separate “share my phone with roommates” setting on the Accommodation screen (住宿), which starts switched off.
Teachers and organising staff. Accounts we have marked as staff, organiser or administrator — which includes the teachers travelling with the group — can see participant records, including the health, dietary, travel and emergency-contact information described above, and all roll-call records. They can reach that information from the roster or by scanning a name badge. We keep the number of such accounts small, but we do not want to overstate it: at present these roles are not separated from one another by what they can read.
We use Supabase, Inc. (database and sign-in), Cloudflare, Inc. (file storage and web hosting), Resend (delivery of account emails such as address confirmation and password resets), and Expo, Apple and Google (push notifications and app distribution). They process data on our instructions under contract and are required to protect it to a standard at least equal to ours. Their servers are outside Taiwan, including in the United States and the European Union, so your data is transferred internationally. We may also disclose data where the law requires it or where necessary to protect someone’s safety.
Your account is designed to carry across events, so that you do not have to register again for the next one. That means different things happen to different parts of your data:
We may keep records for longer where the law requires it, or where they are needed to establish or defend a legal claim.
We answer requests to see or copy your data within 15 days, and requests to correct, stop or delete within 30 days, as Taiwan’s Personal Data Protection Act requires; either period may be extended once for complex requests. The first request is free; we may charge the necessary cost for repeated or excessive requests. If the GDPR applies to you, you also have the right to restrict or object to processing, to receive your data in a portable format, and to complain to your data protection authority.
Traffic is encrypted with TLS, passwords are stored only as salted hashes, and access to records is controlled in the database rather than only in the app. Files you upload are served by web address, so anyone who has that address can open the file without signing in. No system can be made completely secure; if a breach occurs that is likely to affect you, we will notify you and the relevant authority as the law requires.
If we change this policy we will update the date at the top of this page, and tell you in the app or by email if the change materially affects you.