Account privacy
Your identity. Your place in C3.
How information is used when you sign in, verify an email address or ask to join an organisation.
Scope and contact
C3 is operated by Ihab Tarrafti. Contact privacy@c3hq.org with questions about account information. This notice covers account and admission processing. The website privacy notice covers enquiries submitted through c3hq.org.
Records an organisation puts into its workspace are separate from signing in. Requests concerning those records may need to be handled with that organisation.
Information used
Microsoft Entra provides authentication. If you choose Google, Google participates in verifying your identity. Depending on the provider, identity information includes a provider account identifier, an email address and a display name.
C3 also processes email addresses used for mailbox verification, invitation and activation references, access requests, membership roles and records of administrative decisions. Signing in confirms an identity; it does not automatically grant organisation access or merge accounts using different providers.
Why it is used and who receives it
This information supports authentication, email verification, organisation admission, account support and protection against misuse. Authorised organisation operators can review the information needed to decide access requests and manage memberships.
Microsoft supports authentication; Google authenticates identities when selected; Resend delivers C3 verification messages. Railway and Cloudflare support hosting and service delivery. Authentication providers also operate their own sign-in pages under their own privacy notices. These services can involve processing in countries other than your own; this notice does not promise that all account data stays in one country.
Browser storage
C3 uses browser session storage for authentication state. Provider sign-in pages maintain their own sessions. Changing the account in C3 clears local C3 authentication state but does not delete the account held by Microsoft or Google.
Access expiry and retention
Deactivating membership removes access; it does not delete historical decisions or identity records. Expiry of a verification code likewise does not mean that every associated record has been erased.
Inactive customer accounts and rejected access requests are retained for manual review or until a verified deletion request is considered. C3 does not currently apply a fixed automatic deletion period to those records. Review takes account of organisation records, historical decisions and any continuing need to retain specific information.
The verification cleanup process removes expired delivery records and unused verification challenges after seven days from their relevant expiry. Consumed founding proofs remain as audit evidence. Backup copies and authentication-provider records have separate lifecycles; this cleanup is not a promise of simultaneous deletion from those systems.
Requests about your information
You can request access, correction or deletion by contacting privacy@c3hq.org. C3 needs to verify your identity and determine which records the request concerns before acting. Organisation records and historical decisions may require a separate review with the organisation.