Privacy Policy
This policy explains what data the Open Radio Linking Project (“ORLP”) collects through orlp.io, why we collect it, how it is protected, and the choices you have. We practise data minimisation: we collect only what is necessary, and we never sell personal data.
Data we collect
Node operators
When you register a node we collect your callsign, a contact email (used for administrative communication only and never published), and node details such as frequency, CTCSS tone, and operating system. Your contact email and operator name are encrypted at rest (AES-256-GCM); the database never stores them in plain text. Approximate, city-level location is derived from the node’s IP address on its first check-in for the public map — never your precise location.
Website visitors
We do not collect personal data from general visitors. We offer Vercel Analytics and Speed Insights, which measure aggregate traffic and page performance using privacy-friendly methods — no cross-site tracking and no personal identifiers. These are only loaded if you consent via our cookie banner; if you decline, they are never loaded.
Administrators
The hidden admin panel stores an admin email (encrypted) and a bcrypt-hashed password only.
Cookies
Strictly necessary (set without consent): an admin-panel session cookie (httpOnly, Secure, SameSite=Strict, 8-hour expiry, admin area only), a CSRF-protection token, and your saved theme / contrast preference. These are required for the site to function and are never used for tracking or advertising. We also store your cookie choice itself in a first-party orlp_consent cookie (12 months) so we don’t ask again on every visit.
Functional storage (no consent required; stays on your device): if you use the practice exam, your study progress is saved in your browser’s localStorage (orlp_practice_progress) so you can pick up where you left off. It never leaves your device, contains no personal data, and you can clear it any time with the “Reset progress” button on that page.
Non-essential (loaded only with your consent): Vercel Analytics and Speed Insights. We show a cookie banner on your first visit so you can accept all, reject non-essential, or choose per category; you can change your choice any time via the Cookies link in the footer. If you reject, these scripts are never loaded.
Analytics & error logging
Vercel Analytics provides aggregate, non-personal metrics. For operational error logging, IP addresses are anonymised (first three octets only) and sensitive fields — passwords, session tokens, and full email addresses — are scrubbed before transmission.
Third-party services
- Vercel — hosting and privacy-friendly analytics (USA; EU-US Data Privacy Framework).
- Neon — PostgreSQL database (Standard Contractual Clauses).
- Groups.io — the community forum embedded on our Community page. Your use of it is subject to Groups.io’s own privacy policy; ORLP passes no data to it.
How long we keep data
- Active node records: retained while the node is registered.
- Inactive node records: deleted after 24 months of no activity.
- Admin session tokens: deleted after 8 hours or on logout.
- Operational error logs: 90-day retention, then automatically deleted.
Your rights
Depending on your jurisdiction (including the EU/UK GDPR and California’s CCPA) you may have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Exercise any of these by emailing privacy@orlp.io; we respond within 30 days, free of charge. See our Data Protection page for the full GDPR statement.
No sale of data; no advertising
We never sell personal data — to anyone, under any circumstances — and we run no advertising infrastructure. Vercel Analytics is not advertising.
Children
The services are not directed at children under 13, and we do not knowingly collect their personal data.
Changes & contact
We will post material changes here with an updated effective date. Questions or requests: privacy@orlp.io.