Privacy policy
What we collect on this site and in the members portal, who can see it, and how IFMSA handles exchange data. Written to be read, not skimmed past.
Last updated 24 September 2026
Who we are
AUSSS is the Ain Shams University Students' Scientific Society, the student society of the Faculty of Medicine, Ain Shams University, Cairo. We are the Ain Shams local committee of IFMSA-Egypt, which is a member of the International Federation of Medical Students' Associations (IFMSA).
This policy covers this website and the members portal at /portal. The Secretary General is the contact for anything about your data.
Browsing the public site
You can read every public page without an account and without giving us any information.
We do not use advertising cookies or trackers. Vercel Web Analytics counts page views without cookies and without identifying you.
Some pages embed content from Google Drive, Canva and Google Maps. When such an embed loads, that provider receives your browser request under its own privacy policy.
Forms on the site
- Recruitment waitlist: your name and email address, so we can tell you when applications open.
- Applications to open calls, when a committee is recruiting: the details you enter on the form, used only to consider your application.
- Exchange stories: your name, email, phone number, destination, year and your story, used to publish the story on the exchange pages if you agree.
- Merch orders: your name, email, phone number, year, the items you ordered and the payment receipt you upload, used only to prepare and hand over your order.
- Membership status check: the name or email you type is sent to our database, which answers with your own membership record and nothing else. No names or emails from the roster are ever sent to your browser.
Form submissions are stored in spreadsheets in the society's Google account, or in the society's database for open calls, and are seen only by the officers who run that activity.
The members portal
Signing in uses Google or an emailed sign-in link. We never store a password.
- From your sign-in provider: your email address, display name and profile picture.
- What you add yourself: phone number, faculty year, and whether you want to appear in a members directory (off by default).
- From the membership roster: your membership status and tier, the year you joined and the positions you hold each term. The roster is the same membership record the society already keeps; the portal links your account to it by email.
- Verification requests: if the roster does not match your email, you can ask the Executive Board to confirm you. We keep the request and the decision.
- An audit trail: the portal records who changed what and when, so that membership and position changes can always be traced.
Your session is kept in your own browser storage so you stay signed in. Signing out clears it.
Who can see portal data
- You can always see and edit your own details.
- Members of the Executive Board and the webmaster can see all member records, because they administer membership.
- Officers of a committee can see the members who hold a position in that committee this term, and nothing beyond it.
- Other members cannot see your record. A directory, when it exists, will show only people who opted in.
These rules are enforced in the database itself, not only in the screens you see.
Services that hold data for us
- Supabase hosts the portal database and sign-in service.
- Vercel hosts the website and counts page views.
- Google provides sign-in, and Google Sheets and Drive hold form submissions and society documents.
- Resend delivers sign-in and notification emails.
Each of these processes data on our instructions. We do not sell or rent your information, and we do not share it with anyone for advertising.
IFMSA exchanges
If you apply for a SCOPE or SCORE exchange, your application goes through the IFMSA Exchange Database, which IFMSA operates as its own data controller. IFMSA describes this in its Exchanges Privacy notice, summarised here so you know what to expect.
- The database collects what hosting organisations need to place you: name, gender, nationality, date of birth, passport or ID details, language, university details, contact details, and the documents a host requires, such as proof of enrolment, a photo, a passport copy, insurance, immunisation records and a police clearance.
- Inside IFMSA, access is limited to the Local and National Exchange Officers of the sending and hosting organisations and the international Standing Committee teams, through password-protected accounts. Outside IFMSA, your details are shared only with the hosting institution.
- IFMSA keeps the data for as long as the exchange and its evaluation need it, and lists your rights to get a copy, correct, delete or withdraw consent.
Our Local Exchange Officers act within that framework. For questions about the IFMSA database itself, use the contact given on the IFMSA notice.
Your choices
- See and correct your portal details at any time under Profile.
- Ask us for a copy of what we hold about you, or to correct or delete it, by emailing the Secretary General. Deleting your portal account removes your sign-in and profile; membership records that the society must keep, such as the roster and past positions, are kept for its records.
- Ask to be taken off the recruitment waitlist at any time by writing to us.
Changes to this policy
We will update this page when what we collect or how we use it changes, and note the date at the top. Last updated 24 September 2026.
Questions about your data?
The Secretary General handles data requests and member correspondence.
Email the Secretary Generalausss.secgen@gmail.com
See also the Constitution & Bylaws, which governs membership records.