Privacy Policy

How the Ghana Robotics Competition collects, uses, and protects information about coaches, students, judges, volunteers, and visitors to this site.

Last updated: May 25, 2026

The short version

The Ghana Robotics Competition ("GRC", "we", "us") is an annual STEM competition run by Firefly IO LBG. We collect the minimum information needed to register participants, run matches, manage payments, and communicate with you about the event. We do not sell your data. We never share student information with advertisers.

This policy explains what we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over your information. If anything here is unclear, write to grc@fireflyio.com and we'll explain.

1

Who we are

The Ghana Robotics Competition is operated by Firefly IO LBG, registered in Ghana, with offices at Gye Nyame Street 117, Taifa, Accra.

We are the data controller for all information collected through this website and the participant portal at portal.grcprojects.org. For privacy questions or requests, reach us at grc@fireflyio.com.

2

Information we collect

We collect information in three ways: information you give us directly, information generated as you use the portal, and information from a small number of third-party services we rely on (payments, messaging).

Information you give us

  • Coach & school details — name, email, phone number, school name, region, district.
  • Team & student details — team name, league, members' first and last names, age, gender, optional photo, optional parental consent form.
  • Judge / volunteer / referee details — name, email, phone, role, area of expertise, gender, photo for the event badge.
  • Payment details — registration fee payments are processed by Paystack. We see the amount, team(s) it covers, and a reference number; we never see your full card details.
  • School inquiries & sponsor enquiries — contact details submitted through forms on this site.
  • Direct messages — content of messages you send to the GRC admin team through the portal or WhatsApp.

Information generated by use of the portal

  • Login timestamps and authentication tokens (stored locally in your browser).
  • Match data — scores, rankings, alliance picks, judge evaluations, robot inspections.
  • Audit trail entries — actions such as approving a user, editing a team, or resetting a password.
  • Push-notification device tokens (only if you grant notification permission on your phone).

Information from third parties

  • Paystack — payment confirmation references and statuses.
  • Meta (WhatsApp Cloud API) — the body of WhatsApp messages you send to our official WhatsApp number, plus your WhatsApp display name and phone number.
3

Why we use it

We use the information to:

  • Create accounts and verify that registrants are who they say they are.
  • Print competitor badges and check teams into the venue.
  • Schedule and run matches, allocate fields, assign judges, and publish leaderboards.
  • Process registration fees through Paystack and reconcile payments per team.
  • Send registration invites, reminders, payment chases, approval confirmations, match notifications, and event updates by email and WhatsApp.
  • Allow direct messaging between participants and the GRC admin team for support.
  • Award medals and certificates and publish the names of winning teams.
  • Keep the portal secure — detecting abuse, preventing unauthorised access, recording who changed what.
4

Who we share it with

We share information only with the people and services we need to run the competition. We never sell personal information to anyone.

Service providers

  • Paystack — payment processing. Paystack privacy
  • Meta Platforms, Inc. (WhatsApp Cloud API) — delivery of WhatsApp messages. WhatsApp policy
  • Email delivery providers — Mailgun and/or Postmark (transactional email).
  • Railway — backend application hosting and Postgres database.
  • Cloudflare — DNS, CDN, and static site hosting for grcprojects.org.
  • Expo / Apple / Google — push notification delivery to mobile devices, only if you have installed the GRC mobile app.

Other competitors, judges, and the public

  • Team names, team numbers, league, and scores are public on the live scoreboard during the event.
  • Judges see the teams they are assigned to evaluate, including students' first names and team photos.
  • Winning teams may be named in press releases, social media, and on this website.

Legal requirements

We will disclose information if required to do so by law, court order, or to protect the rights and safety of GRC participants.

5

Children and parental consent

Many GRC competitors are under 18. We take the privacy of young participants seriously.

  • Schools register teams on behalf of their students. Coaches confirm they have parental/guardian consent for every minor competitor before adding them to the portal.
  • We provide a downloadable consent form template that coaches must distribute to parents before registration.
  • Student photos used for badges are visible only to GRC staff and the assigned judges. They are not displayed on the public scoreboard.
  • Parents may withdraw consent at any time by emailing grc@fireflyio.com. Once consent is withdrawn, the student will be removed from their team in the portal.
6

WhatsApp messaging

We use the official Meta WhatsApp Cloud API to send registration invites, reminders, payment chases, and two-way support conversations.

  • Messages we send to you are limited to event-related communication — invites, reminders, account changes, and replies to your own messages.
  • We do not use WhatsApp for marketing third-party products and we do not share your WhatsApp number with advertisers.
  • Replies you send to our WhatsApp number are stored in the portal as part of your direct-message thread with the GRC admin team.
  • You can stop receiving WhatsApp messages at any time by replying STOP or by emailing grc@fireflyio.com. We will continue to communicate with you by email.
  • Once a WhatsApp message reaches Meta's servers, it is also subject to WhatsApp's own business policy.
7

How we protect your information

  • All traffic to grcprojects.org, portal.grcprojects.org, and api.grcprojects.org is encrypted in transit with HTTPS / TLS.
  • Passwords are stored as bcrypt hashes — not in plain text. We cannot recover a forgotten password; we can only reset it.
  • Login sessions use short-lived signed tokens. Accounts are temporarily locked after multiple failed login attempts.
  • Access to administrative data is limited to authorised GRC staff. Every administrative action is recorded in an audit log.
  • Databases are hosted on Railway with daily managed backups.

No system is perfectly secure. If you suspect your account has been compromised, change your password immediately and email grc@fireflyio.com.

8

Cookies and local storage

The portal uses your browser's local storage to keep you signed in (an access token) and to remember preferences like dark mode and sound settings. This is essential — without it you would have to log in on every page.

The public site (grcprojects.org) does not currently use advertising or analytics cookies. If we add analytics in the future to understand how visitors find us, we will update this policy and present an in-page choice.

9

How long we keep it

  • Account data — kept while you have an active account. If you ask us to delete it, we remove or anonymise it within 30 days, unless we're legally required to keep it.
  • Competition results — match scores, rankings, and award winners are kept indefinitely as part of the GRC public record.
  • Payment records — kept for at least 7 years to comply with Ghanaian financial-records legislation.
  • Direct messages & WhatsApp threads — kept for one competition season after the event ends, then deleted.
10

Your rights

You have the right to:

  • Ask what information we hold about you, and request a copy.
  • Ask us to correct information that is wrong or out-of-date.
  • Ask us to delete your information (subject to the retention rules above).
  • Withdraw consent for marketing-style communication at any time.
  • Complain to the Data Protection Commission, Ghana if you believe your rights have been infringed.

To exercise any of these rights, email grc@fireflyio.com from the address registered to your account. We respond within 30 days.

11

International data transfers

Some of our service providers (Railway, Cloudflare, Meta, Paystack, Mailgun, Postmark) host data on servers outside Ghana. By using the portal you understand and accept that your information may be processed in countries other than Ghana, including in the United States and the European Union, under the privacy frameworks of those providers.

12

Changes to this policy

We may update this policy from time to time as our operations evolve or the law changes. When we do, we update the "Last updated" date at the top of this page and, for significant changes, post a notice on the portal home page. Continued use of GRC after changes are posted means you accept the updated policy.

Questions about your data?

Write to grc@fireflyio.com with the email address registered to your account. We'll get back to you within 30 days — usually much sooner.

Firefly IO LBG · Gye Nyame Street 117, Taifa · Accra, Ghana