Skip to main content
Fingerprinting

Privacy Policy

What BadgeReg collects about Scouts, parents and organizers, why we hold it, who it reaches, and how to have it corrected or removed.

Last updated July 27, 2026. Questions about this page? Get in touch.

Who this policy covers

BadgeReg is used by three kinds of people, and this policy covers all of them: parents and guardians who register Scouts, the adult volunteers who organize and staff an event, and visitors to this marketing website who have not signed up for anything.

Each merit badge college is run by a Scouting unit, not by BadgeReg. The unit decides what to ask for and what to do with it; BadgeReg provides and operates the software that holds it. In data-protection terms the unit is the controller of its event's data and BadgeReg is the processor acting on its instructions. For this marketing website, BadgeReg is the controller.

What we collect about a Scout

When a parent registers a Scout for classes, BadgeReg stores the information needed to run the event and to place that Scout correctly:

  • Name.
  • Date of birth, because merit badge classes can carry age or rank restrictions and organizers have to be able to honour them.
  • Gender, where the event asks for it.
  • Unit type and unit number, so Scouts can be grouped by their home unit.
  • Contact email and phone number, and the registering parent's email address.
  • Allergies and health concerns, only if a parent chooses to enter them, so the adults running the event can keep the Scout safe.
  • Class registrations, schedule, attendance, and the payments made for them.

What we collect about parents and organizers

An adult account holds a username, a bcrypt hash of the password (never the password itself), name, email address, phone number, unit type and number, and the role that account has been granted for the event. Organizers may also record an emergency contact name, phone number, and relationship.

Administrative actions inside an event are written to an audit log so an organizer can answer who moved a Scout between classes or who issued a refund. Those entries name the account that acted.

Health information and other sensitive details

Two categories in the list above deserve separate treatment, because they are sensitive: the allergy and health notes a parent can enter, and the fact that most of the people described in BadgeReg are children.

Health notes are optional. They exist so the adults running an event can keep a Scout safe on the day, and they are used for nothing else. They are not used for marketing, not used to make decisions about anyone, not sold, and not shared outside the event. They are visible to the parent who entered them and to the event's organizers and counselors who need them. A parent can edit or remove them at any time, and where the law requires consent for health information, entering it is that consent and removing it withdraws it.

Payment information

Card and bank details are entered on PayPal's checkout and are never sent to or stored by BadgeReg. What we retain is the transaction record: PayPal's capture reference, the amount, the processing fee, the net figure, and what was purchased. That is what produces receipts, the organizer's ledger, and refunds.

PayPal handles that payment as an independent company under its own privacy policy, which governs what it does with the details you give it.

Cookies and similar technologies

BadgeReg uses no advertising cookies, no cross-site tracking, and no third-party analytics scripts. The storage it does use is the minimum needed to keep you signed in safely:

  • A session cookie named jwt, set when you sign in to an event. It is httpOnly, so scripts cannot read it, and Secure, so browsers only return it over HTTPS. It is what keeps you signed in, and it is cleared when you sign out.
  • A cookie named XSRF-TOKEN, which pairs with a header on every state-changing request so another site cannot silently act as you. It exists purely as a security measure.
  • On this marketing site, a per-tab identifier in session storage rather than a cookie, used only for the anonymous page counting described in the next section.
  • Your browser's local storage on the event site, which holds your display preferences and the profile details already shown to you in the interface.

What we collect on this website

This marketing site records anonymous, aggregate page views so we can tell which pages help units find and understand BadgeReg. That measurement is deliberately narrow:

  • No cookies are used for analytics, and no advertising or third-party tracking scripts run on this site.
  • A random identifier is generated per browser tab and kept only in that tab's session storage. It disappears when you close the tab and it is not linked to you, to any account, or to any visit from a different tab or day.
  • What is sent is the name of the page viewed and nothing else. There is no field for a referrer, a search term, or an identifier, and the server rejects anything that is not one of a fixed list of page names.
  • If you fill in the contact form we receive what you typed (your name, email address, and message), because that is how we reply to you.

Error reports and server logs

When something breaks we need to know what happened, so the application can send error reports to our own self-hosted monitoring system. Those reports carry the error and the page it happened on, and when you are signed in they also carry your user id, username, and name so we can tell whether a fault hit one account or everyone.

Our servers also keep ordinary operational logs of requests, which include IP addresses, for security and troubleshooting. Neither the error reports nor the logs are used for advertising or profiling, neither is sold, and both are kept only as long as they are useful for fixing problems and investigating abuse.

Why we hold it and on what basis

Scout and parent information is held to deliver the event the family signed up for: placing a Scout in classes, taking payment, sending receipts, taking attendance, and reporting to the unit afterwards. Account information is held to authenticate you and to apply the right level of access. Contact form messages are held to answer them.

For anyone covered by UK or EU data protection law, the legal bases are these: performing the contract, for registration, payment, receipts, and running the event; legitimate interests, for keeping the service secure, preventing fraud, fixing faults, counting page views, and replying to enquiries; explicit consent, for the optional allergy and health notes; and legal obligation, for the financial records we are required to retain.

We do not build advertising profiles, we do not run behavioural advertising, and we do not sell personal information to anyone. We will not use event data to market to your families. There is no automated decision-making that produces legal or similarly significant effects.

Who we share it with

The adults running your event see the data for your event, at the level their role allows. Beyond that, personal data reaches only the parties needed to operate the service:

  • PayPal, to take payment and issue refunds.
  • The email account the organizer configures for their event. Receipts and notices are sent using SMTP credentials the unit supplies, which means those messages go out through the organizer's own mail provider rather than through an email vendor of ours.
  • Our hosting provider, which runs the servers and database the software sits on.
  • Our self-hosted error monitoring, described above, which we operate ourselves rather than handing to a third-party analytics company.
  • Anyone we are legally required to disclose to, such as in response to a valid legal demand. Where we are allowed to tell the affected organizer first, we will.
  • A successor, if BadgeReg is ever transferred to someone else, in which case this policy travels with the data and you will be told before anything changes.

Where your information is stored

BadgeReg is operated from the United States and the servers holding event data are located there. If you use BadgeReg from outside the United States, your information is transferred to and processed in the United States, which may have different data protection rules than your own country.

How long we keep it

Event data is retained while the event is live and for a period afterwards so the unit can close out its books, produce reports, and handle late refunds. Financial records, including the transaction ledger, are kept for as long as tax and accounting rules require, which is typically several years. Audit log entries are kept with the event's records. Contact form messages are kept while we are in touch and for a reasonable period afterwards. Error reports and server logs are kept only briefly. Anonymous page counts hold no personal data, so there is nothing in them to remove.

Because retention is ultimately the unit's decision, ask your event's organizer if you want to know their intention for a specific event, and export what your unit needs for its own records rather than relying on us to hold it indefinitely.

Your choices and how to exercise them

You can sign in and correct your own account details and your Scouts' details at any time, which is the fastest route for most changes. Beyond that you can ask us to give you a copy of the personal data we hold about you or your Scout, correct it, or delete it. You can also ask us to stop emailing you, though we cannot remove transactional receipts for a payment you have made.

To make a request, contact support@badgereg.com or use the contact form on this site, and tell us which event you registered for so we can find the right records. We may need to verify that you are the account holder or the Scout's parent or guardian before we act, precisely because the alternative would let a stranger request a child's data. We aim to respond within 30 days and will tell you if we need longer.

Requests that reach us about an event we merely host are passed to that event's organizer, since the unit decides what happens to its own records.

Your rights under US state privacy laws

If you live in California, or in another state with a comparable law such as Colorado, Connecticut, Texas, or Virginia, you have specific rights over your personal information. You can ask us what we have collected about you and why, get a copy of it, have it corrected, and have it deleted, subject to the records we are required to keep.

For the disclosures California asks for specifically: the categories we collect are identifiers (name, email, phone, username), commercial information (registrations and payments), internet activity limited to the narrow page counting described above, and sensitive personal information in the form of health notes and information about children under 16. We collect it from you, from the parent or organizer who registered a Scout, and from PayPal in the form of transaction records. We use it only for the purposes set out in this policy.

We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We do not use sensitive personal information for any purpose beyond running the event. We will not discriminate against you for exercising any of these rights, and you can use an authorized agent to make a request on your behalf. If we turn a request down, you can ask us to reconsider by replying to our response.

Your rights in the UK and EU

If UK or EU data protection law applies to you, you have the right to access your personal data, correct it, have it erased, restrict or object to how we use it, and receive it in a portable form. Where we rely on consent, such as for health notes, you can withdraw it at any time without affecting what was done beforehand.

Use the contact details below to exercise any of these. If you are not satisfied with how we handle it, you can complain to your national data protection authority, and in the UK that is the Information Commissioner's Office.

Children's information

BadgeReg exists to register young people, so most of the data in it is about minors. We do not knowingly collect it from children directly: a Scout's registration is created by a parent, a guardian, or an event organizer acting for the unit, and the account that holds it belongs to an adult. Accounts require the holder to be 18 or over, and there is no route for a child to sign up, be marketed to, or make their information public through BadgeReg.

We collect only what the event needs to place a Scout in classes and run the day safely, and we do not condition a Scout's participation on giving us more than that.

A parent or guardian can review what has been entered about their Scout, correct it, or ask for it to be deleted using the routes above. If you believe a child's information has reached BadgeReg without the involvement of a parent, guardian, or unit leader, contact us and we will remove it.

Security, and what happens if something goes wrong

Encryption in transit, bcrypt password hashing, role-based access enforced on the server, and separation between events are described in detail on our security page, along with the protections BadgeReg does not claim to have. No service can promise perfect security, and we do not.

If a breach affects personal data we hold, we will investigate it, tell the affected event organizers without undue delay, and give them what they need to inform their families and meet their own obligations. Where the law requires us to notify a regulator or individuals directly, we will do that too.

Changes to this policy

If we change how we handle personal data we will update this page and move the date at the top. Material changes affecting event data will also be raised with event organizers directly rather than left to be discovered here.

Contact

Questions about this policy, or a request about your data, can go to support@badgereg.com or through the contact form on this site. BadgeReg is operated from California, United States.