1. Who we are
The Aeronautical Society of Nepal ("AeSN", "we", "us") operates this website and member portal. This policy explains what personal data we collect, why, and the choices you have. If you have questions, contact the Executive Committee through the details on our About page.
2. What we collect
- Account data: your name, email address, and password (stored only as an irreversible hash).
- Profile data you choose to provide: preferred name, phone number, photo, organization, job title, location, education, bio, and social links.
- Membership data: applications, membership tier and number, payment records, and ID card status.
- Activity data: event registrations, articles and comments you post, store orders, and notification preferences.
- Technical data: minimal logs needed to run and secure the service.
3. Why we use it
- To operate your membership: process applications and payments, issue membership numbers and ID cards, and manage renewals.
- To run the portal: show you your profile, events, articles, and notifications, and let other (or the public, if you opt in) members find you in the directory.
- To communicate: transactional email such as sign-in links, password resets, application updates, and renewal reminders. Marketing-style announcements only if you are subscribed, with an unsubscribe option.
- To keep the site safe: preventing abuse, fraud, and unauthorized access.
4. Legacy data from the old website
Members of the previous AeSN website have their historical record (name, membership tier and number, registration date) carried into this site. It is stored separately and attached to your new account only when you sign up or sign in with the same email address, or when staff link it for you after verifying your identity.
Legacy data is used only to restore your membership history — never shared publicly beyond what this policy describes.
5. Who can see your profile
- By default, your profile is visible to other signed-in members in the members-only directory.
- You control extra visibility from your portal profile page: public listing, public email/phone/organization/bio/social links, and directory opt-in. Nothing is made public without your explicit opt-in.
- Staff with membership-management duties can view member records as needed to run the Society. Access is permission-gated and audit-logged.
6. Sharing
We do not sell your data. We share it only with service providers necessary to run the site (hosting, database, and email delivery providers such as Supabase), under their own data-protection obligations, and where required by law.
7. Retention
We keep membership records while your membership is active and for a reasonable period afterwards so your history (renewals, contributions) survives a rejoin. Application and payment records are kept as required for accounting purposes.
You may delete your account at any time from the console or by contacting us; we will remove your profile and personal data, except records we must keep for legal or accounting reasons.
8. Your choices
- Access and correct your details any time in the portal (Account settings → profile).
- Control visibility and directory listing from your profile page.
- Unsubscribe from non-essential email via the link in any campaign.
- Ask us to export or delete your data by contacting the Executive Committee.
9. Security
Data is stored with a managed database provider using encryption in transit and at rest, row-level access control, and audited staff access. No system is perfectly secure; we apply industry-standard measures and review them regularly.
10. Changes
We may update this policy as the service evolves; the date above reflects the latest revision. Significant changes will be announced on the site.